Files
2020-08-04 21:37:21 +00:00

19 KiB

1Technique IDDetection AvailableLinkscore
2T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml49
3T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml49
4T1193No-51
5T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml49
6T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml47
7T1086No-44
8T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml36
9T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml36
10T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml36
11T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml36
12T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml36
13T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml36
14T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml36
15T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml36
16T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml34
17T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml34
18T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml34
19T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml34
20T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml34
21T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml34
22T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml34
23T1105No-40
24T1060No-38
25T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml35
26T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml35
27T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml35
28T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml32
29T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml32
30T1107No-30
31T1070.004No-30
32T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml24
33T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml24
34T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml24
35T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml24
36T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml20
37T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml20
38T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml20
39T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml20
40T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml20
41T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml20
42T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml20
43T1059.005No-26
44T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml23
45T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml23
46T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml23
47T1192No-24
48T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml23
49T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml21
50T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml21
51T1083No-23
52T1005No-22
53T1016No-22
54T1057No-22
55T1076No-20
56T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml16
57T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml16
58T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml16
59T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml16
60T1056.001No-20
61T1018No-19
62T1140No-19
63T1204.001No-19
64T1036.005No-19
65T1033No-18
66T1189No-17
67T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml11
68T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml11
69T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml11
70T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml11
71T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml11
72T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml11
73T1560.001No-16
74T1043No-16
75T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml15
76T1555.003No-15
77T1503No-15
78T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml13
79T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml13
80T1049No-14
81T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml11
82T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml11
83T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml11
84T1553.002No-14
85T1074.001No-14
86T1087.001No-14
87T1116No-14
88T1046No-13
89T1113No-12
90T1045No-12
91T1027.002No-12
92T1041No-12
93T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml10
94T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml9
95T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml9
96T1063No-11
97T1073No-11
98T1133No-11
99T1574.002No-11
100T1518.001No-11
101T1059No-11
102T1085No-11
103T1571No-11
104T1505.003No-10
105T1087.002No-10
106T1136.002No-10
107T1055No-10
108T1100No-10
109T1559.002No-9
110T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml7
111T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml7
112T1564.003No-9
113T1560No-9
114T1143No-9
115T1173No-9
116T1090.002No-9
117T1003No-9
118T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml7
119T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml7
120T1119No-9
121T1218.010No-8
122T1035No-8
123T1219No-8
124T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml7
125T1132.001No-8
126T1102.002No-8
127T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml1
128T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml1
129T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml1
130T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml1
131T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml1
132T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml1
133T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml1
134T1135No-8
135T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml6
136T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml6
137T1117No-8
138T1548.002No-8
139T1065No-8
140T1003.004No-8
141T1027.005No-7
142T1106No-7
143T1066No-7
144T1007No-7
145T1059.007No-7
146T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml5
147T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml5
148T1573.001No-7
149T1023No-7
150T1552.001No-7
151T1555No-7
152T1547.009No-7
153T1221No-7
154T1069.002No-7
155T1021.004No-7
156T1012No-7
157T1009No-6
158T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml4
159T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml4
160T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml4
161T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml4
162T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml5
163T1036.004No-6
164T1027.001No-6
165T1074.002No-5
166T1218.005No-5
167T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml4
168T1059.006No-5
169T1223No-5
170T1573.002No-5
171T1099No-5
172T1055.001No-5
173T1120No-5
174T1218.001No-5
175T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml4
176T1564.001No-5
177T1546.003No-5
178T1027.003No-5
179T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml4
180T1001.002No-5
181T1040No-5
182T1070.006No-5
183T1084No-5
184T1015No-5
185T1194No-5
186T1075No-5
187T1110No-5
188T1090No-5
189T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml0
190T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml0
191T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml0
192T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml0
193T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml0
194T1158No-5
195T1170No-5
196T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml4
197T1102.001No-5
198T1102No-4
199T1003.005No-4
200T1124No-4
201T1570No-4
202T1014No-4
203T1025No-4
204T1487No-4
205T1496No-4
206T1574.001No-4
207T1036.002No-4
208T1036.003No-4
209T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml3
210T1093No-4
211T1094No-4
212T1055.012No-4
213T1561.002No-4
214T1038No-4
215T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
216T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
217T1560.003No-4
218T1110.002No-3
219T1020No-3
220T1053.002No-3
221T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml2
222T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml2
223T1027.004No-3
224T1090.003No-3
225T1542.003No-3
226T1008No-3
227T1529No-3
228T1069.001No-3
229T1097No-3
230T1197No-3
231T1104No-3
232T1110.003No-3
233T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml2
234T1188No-3
235T1039No-3
236T1550.003No-3
237T1572No-3
238T1486No-3
239T1500No-3
240T1071.003No-3
241T1518No-3
242T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml2
243T1071No-3
244T1067No-3
245T1091No-3
246T1098No-3
247T1176No-2
248T1187No-2
249T1032No-2
250T1137No-2
251T1564.005No-2
252T1210No-2
253T1559.001No-2
254T1080No-2
255T1560.002No-2
256T1115No-2
257T1218.007No-2
258T1542.002No-2
259T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
260T1547.004No-2
261T1199No-2
262T1087.003No-2
263T1090.001No-2
264T1218.003No-2
265T1037.001No-2
266T1222.002No-2
267T1567.002No-2
268T1134.002No-2
269T1191No-2
270T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml-2
271T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml-2
272T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml-2
273T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml-2
274T1213.002No-2
275T1492No-2
276T1201No-2
277T1125No-2
278T1565.001No-2
279T1004No-2
280T1055.002No-2
281T1109No-2
282T1195.002No-2
283T1069No-2
284T1059.004No-2
285T1480.001No-2
286T1501No-1
287T1070.002No-1
288T1558.001No-1
289T1195No-1
290T1042No-1
291T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml-2
292T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml-2
293T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml-2
294T1183No-1
295T1493No-1
296T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml0
297T1561.001No-1
298T1562.002No-1
299T1186No-1
300T1134No-1
301T1126No-1
302T1074No-1
303T1001No-1
304T1172No-1
305T1504No-1
306T1213No-1
307T1216.001No-1
308T1052.001No-1
309T1211No-1
310T1137.002No-1
311T1568.001No-1
312T1123No-1
313T1137.001No-1
314T1528No-1
315T1056.004No-1
316T1146No-1
317T1546.012No-1
318T1056.002No-1
319T1573No-1
320T1543.002No-1
321T1053.003No-1
322T1534No-1
323T1483No-1
324T1546.009No-1
325T1574.012No-1
326T1552.004No-1
327T1546.015No-1
328T1001.003No-1
329T1218.008No-1
330T1090.004No-1
331T1182No-1
332T1574.006No-1
333T1174No-1
334T1546.013No-1
335T1564.004No-1
336T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml-12
337T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml-12
338T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml-12
339T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml-12
340T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml-12
341T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml-12
342T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml-12
343T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml-12
344T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml-12
345T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml-12
346T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml-12
347T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml-12
348T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml-12
349T1001.001No-1
350T1030No-1
351T1568.003No-1
352T1122No-1
353T1565.003No-1
354T1220No-1
355T1489No-1
356T1550.001No-1
357T1556.002No-1
358T1010No-1
359T1102.003No-1
360T1482No-1
361T1497.002No-1
362T1200No-1
363T1527No-1
364T1494No-1
365T1070.003No-1
366T1096No-1
367T1214No-1
368T1021.006No-1
369T1488No-1
370T1055.013No-1
371T1134.001No-1
372T1021.005No-1
373T1138No-1
374T1026No-1
375T1070.005No-1
376T1037No-1
377T1565.002No-1
378T1568.002No-1
379T1098.002No-1
380T1137.004No-1
381T1036.001No-1
382T1092No-1
383T1497.001No-1
384T1552.002No-1
385T1491.001No-1
386T1137.006No-1
387T1127.001No-1
388T1145No-1
389T1552.006No-1
390T1028No-1