Files
splunk-security_content/docs/mitre-map/coverage.csv
2020-08-27 18:42:27 +00:00

7.4 MiB

1Technique IDDetection AvailableLinkscore
2T1055.009No-0
3T1017No-0
4T1565.002No-0
5T1037.003No-0
6T1480.001No-0
7T1075No-0
8T1059No-15
9T1222.002No-0
10T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
11T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
12T1547No-3
13T1215No-0
14T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
15T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
16T1055.012No-0
17T1561.001No-0
18T1074.001No-0
19T1546.003No-0
20T1216No-0
21T1114No-3
22T1085No-0
23T1143No-0
24T1489No-0
25T1218.004No-0
26T1055.014No-0
27T1069No-0
28T1555.003No-0
29T1195No-0
30T1132.002No-0
31T1192No-0
32T1059.007No-0
33T1137.004No-0
34T1184No-0
35T1221No-0
36T1218.003No-0
37T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
38T1531No-0
39T1153No-0
40T1136.002No-0
41T1546.014No-0
42T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
43T1574.008No-0
44T1056.002No-0
45T1037No-0
46T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
47T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
48T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
49T1148No-0
50T1056No-0
51T1159No-0
52T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
53T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
54T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
55T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
56T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
57T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
58T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
59T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
60T1071No-10
61T1104No-0
62T1021.003No-0
63T1015No-0
64T1003.008No-0
65T1058No-0
66T1134.005No-0
67T1010No-0
68T1043No-0
69T1206No-0
70T1020No-0
71T1546.006No-0
72T1222No-1
73T1498.001No-0
74T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
75T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
76T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
77T1003.005No-0
78T1539No-0
79T1175No-0
80T1188No-0
81T1137.001No-0
82T1109No-0
83T1152No-0
84T1218.007No-0
85T1158No-0
86T1021.006No-0
87T1550.004No-0
88T1037.005No-0
89T1574No-1
90T1558No-1
91T1578.003No-0
92T1053.002No-0
93T1567.002No-0
94T1019No-0
95T1155No-0
96T1574.011No-0
97T1568.001No-0
98T1134.002No-0
99T1128No-0
100T1547.011No-0
101T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
102T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
103T1027.003No-0
104T1191No-0
105T1487No-0
106T1543No-1
107T1100No-0
108T1223No-0
109T1562.007No-0
110T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
111T1065No-0
112T1564.003No-0
113T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml25
114T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_assume_role_abuse.yml25
115T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_role_creation.yml25
116T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_attach_to_role_policy.yml25
117T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_permanent_key_creation.yml25
118T1546.010No-0
119T1108No-0
120T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
121T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
122T1497.001No-0
123T1552No-0
124T1064No-0
125T1491.002No-0
126T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
127T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
128T1568.003No-0
129T1555No-0
130T1041No-0
131T1080No-0
132T1053.001No-0
133T1218.010No-0
134T1090.004No-0
135T1528No-0
136T1056.003No-0
137T1552.002No-0
138T1558.001No-0
139T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
140T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
141T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
142T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
143T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
144T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
145T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
146T1070.005No-0
147T1003.006No-0
148T1213.002No-0
149T1218.001No-0
150T1018No-0
151T1210No-0
152T1196No-0
153T1003No-12
154T1016No-0
155T1013No-0
156T1197No-0
157T1564.005No-0
158T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
159T1131No-0
160T1562.003No-0
161T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml5
162T1503No-0
163T1023No-0
164T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
165T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
166T1026No-0
167T1497No-0
168T1011.001No-0
169T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
170T1022No-0
171T1081No-0
172T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
173T1193No-0
174T1574.006No-0
175T1548.002No-0
176T1094No-0
177T1567.001No-0
178T1550Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_get_session_token_abuse.yml2
179T1505No-0
180T1060No-0
181T1505.001No-0
182T1178No-0
183T1199No-0
184T1571No-0
185T1050No-0
186T1492No-0
187T1556.003No-0
188T1570No-0
189T1574.007No-0
190T1096No-0
191T1053No-4
192T1071.003No-0
193T1110.002No-0
194T1204.001No-0
195T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
196T1012No-0
197T1130No-0
198T1550.003No-0
199T1102No-0
200T1574.001No-0
201T1518.001No-0
202T1036.001No-0
203T1059.002No-0
204T1180No-0
205T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
206T1007No-0
207T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
208T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
209T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
210T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
211T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
212T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
213T1114.003No-0
214T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
215T1182No-0
216T1207No-0
217T1091No-0
218T1133No-0
219T1499No-0
220T1098.003No-0
221T1150No-0
222T1186No-0
223T1102.002No-0
224T1211No-0
225T1055.001No-0
226T1137.005No-0
227T1574.004No-0
228T1563.001No-0
229T1001.001No-0
230T1514No-0
231T1552.003No-0
232T1002No-0
233T1546.005No-0
234T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
235T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
236T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
237T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
238T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
239T1543.004No-0
240T1110.004No-0
241T1170No-0
242T1055.004No-0
243T1059.005No-0
244T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml3
245T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml3
246T1115No-0
247T1564.006No-0
248T1032No-0
249T1033No-0
250T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
251T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
252T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
253T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
254T1560.002No-0
255T1564.004No-0
256T1536No-0
257T1149No-0
258T1132No-0
259T1051No-0
260T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
261T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
262T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
263T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
264T1154No-0
265T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
266T1573.001No-0
267T1140No-0
268T1527No-0
269T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
270T1502No-0
271T1552.005No-0
272T1556.001No-0
273T1098No-0
274T1127No-0
275T1574.002No-0
276T1164No-0
277T1157No-0
278T1162No-0
279T1547.008No-0
280T1562.006No-0
281T1547.010No-0
282T1168No-0
283T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
284T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
285T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
286T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
287T1166No-0
288T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
289T1057No-0
290T1559.001No-0
291T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
292T1483No-0
293T1053.003No-0
294T1103No-0
295T1522No-0
296T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
297T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
298T1542.001No-0
299T1120No-0
300T1543.001No-0
301T1552.001No-0
302T1562.002No-0
303T1573.002No-0
304T1496No-0
305T1171No-0
306T1055.008No-0
307T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
308T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
309T1220No-0
310T1499.001No-0
311T1569.001No-0
312T1069.002No-0
313T1054No-0
314T1056.004No-0
315T1074No-0
316T1546No-5
317T1144No-0
318T1046No-0
319T1066No-0
320T1055.002No-0
321T1491No-0
322T1027.001No-0
323T1124No-0
324T1129No-0
325T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
326T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
327T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
328T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
329T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
330T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
331T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
332T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
333T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml2
334T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml2
335T1560.003No-0
336T1123No-0
337T1048.001No-0
338T1090.002No-0
339T1110.001No-0
340T1497.003No-0
341T1055.011No-0
342T1505.003No-0
343T1547.009No-0
344T1213No-0
345T1001.003No-0
346T1565.003No-0
347T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
348T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
349T1578No-0
350T1036.003No-0
351T1547.004No-0
352T1102.001No-0
353T1125No-0
354T1505.002No-0
355T1160No-0
356T1003.007No-0
357T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml5
358T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml5
359T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml5
360T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_gcp_storage_buckets.yml5
361T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_gcp_storage_access_from_a_new_ip.yml5
362T1561No-0
363T1031No-0
364T1568.002No-0
365T1198No-0
366T1049No-0
367T1195.002No-0
368T1519No-0
369T1165No-0
370T1561.002No-0
371T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml3
372T1099No-0
373T1548No-0
374T1009No-0
375T1201No-0
376T1555.001No-0
377T1101No-0
378T1110No-0
379T1548.003No-0
380T1538No-0
381T1139No-0
382T1077No-0
383T1553No-1
384T1181No-0
385T1055.005No-0
386T1556.002No-0
387T1001.002No-0
388T1055.013No-0
389T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
390T1056.001No-0
391T1547.006No-0
392T1076No-0
393T1055.003No-0
394T1137.003No-0
395T1092No-0
396T1195.003No-0
397T1119No-0
398T1578.001No-0
399T1084No-0
400T1217No-0
401T1113No-0
402T1552.004No-0
403T1062No-0
404T1004No-0
405T1163No-0
406T1213.001No-0
407T1070.003No-0
408T1090.001No-0
409T1083No-0
410T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
411T1504No-0
412T1044No-0
413T1055No-0
414T1063No-0
415T1563.002No-0
416T1559.002No-0
417T1574.010No-0
418T1547.002No-0
419T1027.005No-0
420T1014No-0
421T1038No-0
422T1550.001No-0
423T1090.003No-0
424T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
425T1174No-0
426T1499.003No-0
427T1216.001No-0
428T1034No-0
429T1132.001No-0
430T1547.007No-0
431T1097No-0
432T1146No-0
433T1098.002No-0
434T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
435T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
436T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
437T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
438T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
439T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
440T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
441T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
442T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
443T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
444T1497.002No-0
445T1137No-0
446T1156No-0
447T1088No-0
448T1021.004No-0
449T1562No-3
450T1578.002No-0
451T1134No-0
452T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
453T1145No-0
454T1537No-0
455T1087No-0
456T1087.002No-0
457T1177No-0
458T1529No-0
459T1499.002No-0
460T1546.013No-0
461T1204No-1
462T1006No-0
463T1003.004No-0
464T1021.005No-0
465T1138No-0
466T1548.001No-0
467T1036.005No-0
468T1542.002No-0
469T1189No-0
470T1086No-0
471T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
472T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
473T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
474T1029No-0
475T1089No-0
476T1028No-0
477T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml4
478T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml4
479T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml4
480T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml4
481T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
482T1542.003No-0
483T1546.004No-0
484T1194No-0
485T1069.001No-0
486T1558.002No-0
487T1134.003No-0
488T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
489T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
490T1560No-0
491T1067No-0
492T1061No-0
493T1173No-0
494T1499.004No-0
495T1069.003No-0
496T1187No-0
497T1564.001No-0
498T1546.009No-0
499T1486No-0
500T1001No-0
501T1118No-0
502T1208No-0
503T1185No-0
504T1053.004No-0
505T1212No-0
506T1534No-0
507T1111No-0
508T1553.003No-0
509T1554No-0
510T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
511T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
512T1035No-0
513T1542No-0
514T1546.015No-0
515T1042No-0
516T1098.001No-0
517T1167No-0
518T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
519T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
520T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
521T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
522T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
523T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
524T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
525T1121No-0
526T1490No-0
527T1106No-0
528T1005No-0
529T1484No-0
530T1079No-0
531T1105No-0
532T1137.002No-0
533T1059.004No-0
534T1142No-0
535T1553.001No-0
536T1122No-0
537T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml2
538T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml2
539T1572No-0
540T1547.005No-0
541T1482No-0
542T1098.004No-0
543T1087.001No-0
544T1037.001No-0
545T1102.003No-0
546T1574.012No-0
547T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
548T1501No-0
549T1543.002No-0
550T1151No-0
551T1024No-0
552T1147No-0
553T1205No-0
554T1027.004No-0
555T1565.001No-0
556T1564.002No-0
557T1205.001No-0
558T1493No-0
559T1202No-0
560T1045No-0
561T1574.005No-0
562T1040No-0
563T1021No-6
564T1134.004No-0
565T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
566T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
567T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
568T1179No-0
569T1559No-0
570T1048.002No-0
571T1030No-0
572T1037.002No-0
573T1110.003No-0
574T1567No-0
575T1569No-1
576T1548.004No-0
577T1172No-0
578T1134.001No-0
579T1036.006No-0
580T1209No-0
581T1087.004No-0
582T1073No-0
583T1090No-0
584T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
585T1218No-1
586T1578.004No-0
587T1070.006No-0
588T1161No-0
589T1218.009No-0
590T1480No-0
591T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
592T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
593T1011No-0
594T1500No-0
595T1052.001No-0
596T1136.003No-0
597T1176No-0
598T1553.002No-0
599T1127.001No-0
600T1036.004No-0
601T1546.007No-0
602T1137.006No-0
603T1557.001No-0
604T1218.008No-0
605T1039No-0
606T1218.005No-0
607T1059.006No-0
608T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
609T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
610T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
611T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
612T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
613T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
614T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
615T1565No-0
616T1036.002No-0
617T1564No-0
618T1563No-0
619T1218.002No-0
620T1546.002No-0
621T1135No-0
622T1547.003No-0
623T1494No-0
624T1506No-0
625T1573No-0
626T1008No-0
627T1141No-0
628T1183No-0
629T1219No-0
630T1027.002No-0
631T1214No-0
632T1568No-0
633T1037.004No-0
634T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml13
635T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml13
636T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml13
637T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml13
638T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml13
639T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml13
640T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml13
641T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml13
642T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml13
643T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml13
644T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml13
645T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml13
646T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml13
647T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
648T1195.001No-0
649T1491.001No-0
650T1488No-0
651T1025No-0
652T1052No-0
653T1070.002No-0
654T1116No-0
655T1560.001No-0
656T1169No-0
657T1087.003No-0
658T1074.002No-0
659T1555.002No-0
660T1093No-0
661T1546.012No-0
662T1107No-0
663T1117No-0
664T1070.004No-0
665T1495No-0
666T1518No-0
667T1556No-0
668T1126No-0
669T1552.006No-0
670T1055.009No-0
671T1017No-0
672T1565.002No-0
673T1037.003No-0
674T1480.001No-0
675T1075No-0
676T1059No-15
677T1222.002No-0
678T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
679T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
680T1547No-3
681T1215No-0
682T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
683T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
684T1055.012No-0
685T1561.001No-0
686T1074.001No-0
687T1546.003No-0
688T1216No-0
689T1114No-3
690T1085No-0
691T1143No-0
692T1489No-0
693T1218.004No-0
694T1055.014No-0
695T1069No-0
696T1555.003No-0
697T1195No-0
698T1132.002No-0
699T1192No-0
700T1059.007No-0
701T1137.004No-0
702T1184No-0
703T1221No-0
704T1218.003No-0
705T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
706T1531No-0
707T1153No-0
708T1136.002No-0
709T1546.014No-0
710T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
711T1574.008No-0
712T1056.002No-0
713T1037No-0
714T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
715T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
716T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
717T1148No-0
718T1056No-0
719T1159No-0
720T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
721T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
722T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
723T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
724T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
725T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
726T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
727T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
728T1071No-10
729T1104No-0
730T1021.003No-0
731T1015No-0
732T1003.008No-0
733T1058No-0
734T1134.005No-0
735T1010No-0
736T1043No-0
737T1206No-0
738T1020No-0
739T1546.006No-0
740T1222No-1
741T1498.001No-0
742T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
743T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
744T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
745T1003.005No-0
746T1539No-0
747T1175No-0
748T1188No-0
749T1137.001No-0
750T1109No-0
751T1152No-0
752T1218.007No-0
753T1158No-0
754T1021.006No-0
755T1550.004No-0
756T1037.005No-0
757T1574No-1
758T1558No-1
759T1578.003No-0
760T1053.002No-0
761T1567.002No-0
762T1019No-0
763T1155No-0
764T1574.011No-0
765T1568.001No-0
766T1134.002No-0
767T1128No-0
768T1547.011No-0
769T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
770T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
771T1027.003No-0
772T1191No-0
773T1487No-0
774T1543No-1
775T1100No-0
776T1223No-0
777T1562.007No-0
778T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
779T1065No-0
780T1564.003No-0
781T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml25
782T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_assume_role_abuse.yml25
783T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_role_creation.yml25
784T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_attach_to_role_policy.yml25
785T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_permanent_key_creation.yml25
786T1546.010No-0
787T1108No-0
788T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
789T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
790T1497.001No-0
791T1552No-0
792T1064No-0
793T1491.002No-0
794T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
795T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
796T1568.003No-0
797T1555No-0
798T1041No-0
799T1080No-0
800T1053.001No-0
801T1218.010No-0
802T1090.004No-0
803T1528No-0
804T1056.003No-0
805T1552.002No-0
806T1558.001No-0
807T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
808T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
809T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
810T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
811T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
812T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
813T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
814T1070.005No-0
815T1003.006No-0
816T1213.002No-0
817T1218.001No-0
818T1018No-0
819T1210No-0
820T1196No-0
821T1003No-12
822T1016No-0
823T1013No-0
824T1197No-0
825T1564.005No-0
826T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
827T1131No-0
828T1562.003No-0
829T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml5
830T1503No-0
831T1023No-0
832T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
833T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
834T1026No-0
835T1497No-0
836T1011.001No-0
837T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
838T1022No-0
839T1081No-0
840T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
841T1193No-0
842T1574.006No-0
843T1548.002No-0
844T1094No-0
845T1567.001No-0
846T1550Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_get_session_token_abuse.yml2
847T1505No-0
848T1060No-0
849T1505.001No-0
850T1178No-0
851T1199No-0
852T1571No-0
853T1050No-0
854T1492No-0
855T1556.003No-0
856T1570No-0
857T1574.007No-0
858T1096No-0
859T1053No-4
860T1071.003No-0
861T1110.002No-0
862T1204.001No-0
863T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
864T1012No-0
865T1130No-0
866T1550.003No-0
867T1102No-0
868T1574.001No-0
869T1518.001No-0
870T1036.001No-0
871T1059.002No-0
872T1180No-0
873T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
874T1007No-0
875T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
876T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
877T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
878T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
879T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
880T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
881T1114.003No-0
882T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
883T1182No-0
884T1207No-0
885T1091No-0
886T1133No-0
887T1499No-0
888T1098.003No-0
889T1150No-0
890T1186No-0
891T1102.002No-0
892T1211No-0
893T1055.001No-0
894T1137.005No-0
895T1574.004No-0
896T1563.001No-0
897T1001.001No-0
898T1514No-0
899T1552.003No-0
900T1002No-0
901T1546.005No-0
902T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
903T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
904T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
905T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
906T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
907T1543.004No-0
908T1110.004No-0
909T1170No-0
910T1055.004No-0
911T1059.005No-0
912T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml3
913T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml3
914T1115No-0
915T1564.006No-0
916T1032No-0
917T1033No-0
918T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
919T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
920T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
921T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
922T1560.002No-0
923T1564.004No-0
924T1536No-0
925T1149No-0
926T1132No-0
927T1051No-0
928T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
929T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
930T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
931T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
932T1154No-0
933T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
934T1573.001No-0
935T1140No-0
936T1527No-0
937T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
938T1502No-0
939T1552.005No-0
940T1556.001No-0
941T1098No-0
942T1127No-0
943T1574.002No-0
944T1164No-0
945T1157No-0
946T1162No-0
947T1547.008No-0
948T1562.006No-0
949T1547.010No-0
950T1168No-0
951T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
952T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
953T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
954T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
955T1166No-0
956T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
957T1057No-0
958T1559.001No-0
959T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
960T1483No-0
961T1053.003No-0
962T1103No-0
963T1522No-0
964T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
965T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
966T1542.001No-0
967T1120No-0
968T1543.001No-0
969T1552.001No-0
970T1562.002No-0
971T1573.002No-0
972T1496No-0
973T1171No-0
974T1055.008No-0
975T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
976T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
977T1220No-0
978T1499.001No-0
979T1569.001No-0
980T1069.002No-0
981T1054No-0
982T1056.004No-0
983T1074No-0
984T1546No-5
985T1144No-0
986T1046No-0
987T1066No-0
988T1055.002No-0
989T1491No-0
990T1027.001No-0
991T1124No-0
992T1129No-0
993T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
994T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
995T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
996T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
997T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
998T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
999T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
1000T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
1001T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml2
1002T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml2
1003T1560.003No-0
1004T1123No-0
1005T1048.001No-0
1006T1090.002No-0
1007T1110.001No-0
1008T1497.003No-0
1009T1055.011No-0
1010T1505.003No-0
1011T1547.009No-0
1012T1213No-0
1013T1001.003No-0
1014T1565.003No-0
1015T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
1016T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
1017T1578No-0
1018T1036.003No-0
1019T1547.004No-0
1020T1102.001No-0
1021T1125No-0
1022T1505.002No-0
1023T1160No-0
1024T1003.007No-0
1025T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml5
1026T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml5
1027T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml5
1028T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_gcp_storage_buckets.yml5
1029T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_gcp_storage_access_from_a_new_ip.yml5
1030T1561No-0
1031T1031No-0
1032T1568.002No-0
1033T1198No-0
1034T1049No-0
1035T1195.002No-0
1036T1519No-0
1037T1165No-0
1038T1561.002No-0
1039T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml3
1040T1099No-0
1041T1548No-0
1042T1009No-0
1043T1201No-0
1044T1555.001No-0
1045T1101No-0
1046T1110No-0
1047T1548.003No-0
1048T1538No-0
1049T1139No-0
1050T1077No-0
1051T1553No-1
1052T1181No-0
1053T1055.005No-0
1054T1556.002No-0
1055T1001.002No-0
1056T1055.013No-0
1057T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
1058T1056.001No-0
1059T1547.006No-0
1060T1076No-0
1061T1055.003No-0
1062T1137.003No-0
1063T1092No-0
1064T1195.003No-0
1065T1119No-0
1066T1578.001No-0
1067T1084No-0
1068T1217No-0
1069T1113No-0
1070T1552.004No-0
1071T1062No-0
1072T1004No-0
1073T1163No-0
1074T1213.001No-0
1075T1070.003No-0
1076T1090.001No-0
1077T1083No-0
1078T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
1079T1504No-0
1080T1044No-0
1081T1055No-0
1082T1063No-0
1083T1563.002No-0
1084T1559.002No-0
1085T1574.010No-0
1086T1547.002No-0
1087T1027.005No-0
1088T1014No-0
1089T1038No-0
1090T1550.001No-0
1091T1090.003No-0
1092T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
1093T1174No-0
1094T1499.003No-0
1095T1216.001No-0
1096T1034No-0
1097T1132.001No-0
1098T1547.007No-0
1099T1097No-0
1100T1146No-0
1101T1098.002No-0
1102T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
1103T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
1104T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
1105T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
1106T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
1107T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
1108T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
1109T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
1110T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
1111T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
1112T1497.002No-0
1113T1137No-0
1114T1156No-0
1115T1088No-0
1116T1021.004No-0
1117T1562No-3
1118T1578.002No-0
1119T1134No-0
1120T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
1121T1145No-0
1122T1537No-0
1123T1087No-0
1124T1087.002No-0
1125T1177No-0
1126T1529No-0
1127T1499.002No-0
1128T1546.013No-0
1129T1204No-1
1130T1006No-0
1131T1003.004No-0
1132T1021.005No-0
1133T1138No-0
1134T1548.001No-0
1135T1036.005No-0
1136T1542.002No-0
1137T1189No-0
1138T1086No-0
1139T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
1140T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
1141T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
1142T1029No-0
1143T1089No-0
1144T1028No-0
1145T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml4
1146T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml4
1147T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml4
1148T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml4
1149T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
1150T1542.003No-0
1151T1546.004No-0
1152T1194No-0
1153T1069.001No-0
1154T1558.002No-0
1155T1134.003No-0
1156T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
1157T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
1158T1560No-0
1159T1067No-0
1160T1061No-0
1161T1173No-0
1162T1499.004No-0
1163T1069.003No-0
1164T1187No-0
1165T1564.001No-0
1166T1546.009No-0
1167T1486No-0
1168T1001No-0
1169T1118No-0
1170T1208No-0
1171T1185No-0
1172T1053.004No-0
1173T1212No-0
1174T1534No-0
1175T1111No-0
1176T1553.003No-0
1177T1554No-0
1178T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
1179T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
1180T1035No-0
1181T1542No-0
1182T1546.015No-0
1183T1042No-0
1184T1098.001No-0
1185T1167No-0
1186T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
1187T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
1188T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
1189T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
1190T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
1191T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
1192T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
1193T1121No-0
1194T1490No-0
1195T1106No-0
1196T1005No-0
1197T1484No-0
1198T1079No-0
1199T1105No-0
1200T1137.002No-0
1201T1059.004No-0
1202T1142No-0
1203T1553.001No-0
1204T1122No-0
1205T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml2
1206T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml2
1207T1572No-0
1208T1547.005No-0
1209T1482No-0
1210T1098.004No-0
1211T1087.001No-0
1212T1037.001No-0
1213T1102.003No-0
1214T1574.012No-0
1215T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
1216T1501No-0
1217T1543.002No-0
1218T1151No-0
1219T1024No-0
1220T1147No-0
1221T1205No-0
1222T1027.004No-0
1223T1565.001No-0
1224T1564.002No-0
1225T1205.001No-0
1226T1493No-0
1227T1202No-0
1228T1045No-0
1229T1574.005No-0
1230T1040No-0
1231T1021No-6
1232T1134.004No-0
1233T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
1234T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
1235T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
1236T1179No-0
1237T1559No-0
1238T1048.002No-0
1239T1030No-0
1240T1037.002No-0
1241T1110.003No-0
1242T1567No-0
1243T1569No-1
1244T1548.004No-0
1245T1172No-0
1246T1134.001No-0
1247T1036.006No-0
1248T1209No-0
1249T1087.004No-0
1250T1073No-0
1251T1090No-0
1252T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
1253T1218No-1
1254T1578.004No-0
1255T1070.006No-0
1256T1161No-0
1257T1218.009No-0
1258T1480No-0
1259T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
1260T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
1261T1011No-0
1262T1500No-0
1263T1052.001No-0
1264T1136.003No-0
1265T1176No-0
1266T1553.002No-0
1267T1127.001No-0
1268T1036.004No-0
1269T1546.007No-0
1270T1137.006No-0
1271T1557.001No-0
1272T1218.008No-0
1273T1039No-0
1274T1218.005No-0
1275T1059.006No-0
1276T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
1277T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
1278T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
1279T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
1280T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
1281T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
1282T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
1283T1565No-0
1284T1036.002No-0
1285T1564No-0
1286T1563No-0
1287T1218.002No-0
1288T1546.002No-0
1289T1135No-0
1290T1547.003No-0
1291T1494No-0
1292T1506No-0
1293T1573No-0
1294T1008No-0
1295T1141No-0
1296T1183No-0
1297T1219No-0
1298T1027.002No-0
1299T1214No-0
1300T1568No-0
1301T1037.004No-0
1302T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml13
1303T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml13
1304T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml13
1305T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml13
1306T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml13
1307T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml13
1308T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml13
1309T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml13
1310T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml13
1311T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml13
1312T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml13
1313T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml13
1314T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml13
1315T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
1316T1195.001No-0
1317T1491.001No-0
1318T1488No-0
1319T1025No-0
1320T1052No-0
1321T1070.002No-0
1322T1116No-0
1323T1560.001No-0
1324T1169No-0
1325T1087.003No-0
1326T1074.002No-0
1327T1555.002No-0
1328T1093No-0
1329T1546.012No-0
1330T1107No-0
1331T1117No-0
1332T1070.004No-0
1333T1495No-0
1334T1518No-0
1335T1556No-0
1336T1126No-0
1337T1552.006No-0
1338T1055.009No-0
1339T1017No-0
1340T1565.002No-0
1341T1037.003No-0
1342T1480.001No-0
1343T1075No-0
1344T1059No-15
1345T1222.002No-0
1346T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
1347T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
1348T1547No-3
1349T1215No-0
1350T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
1351T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
1352T1055.012No-0
1353T1561.001No-0
1354T1074.001No-0
1355T1546.003No-0
1356T1216No-0
1357T1114No-3
1358T1085No-0
1359T1143No-0
1360T1489No-0
1361T1218.004No-0
1362T1055.014No-0
1363T1069No-0
1364T1555.003No-0
1365T1195No-0
1366T1132.002No-0
1367T1192No-0
1368T1059.007No-0
1369T1137.004No-0
1370T1184No-0
1371T1221No-0
1372T1218.003No-0
1373T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
1374T1531No-0
1375T1153No-0
1376T1136.002No-0
1377T1546.014No-0
1378T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
1379T1574.008No-0
1380T1056.002No-0
1381T1037No-0
1382T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
1383T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
1384T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
1385T1148No-0
1386T1056No-0
1387T1159No-0
1388T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
1389T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
1390T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
1391T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
1392T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
1393T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
1394T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
1395T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
1396T1071No-10
1397T1104No-0
1398T1021.003No-0
1399T1015No-0
1400T1003.008No-0
1401T1058No-0
1402T1134.005No-0
1403T1010No-0
1404T1043No-0
1405T1206No-0
1406T1020No-0
1407T1546.006No-0
1408T1222No-1
1409T1498.001No-0
1410T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
1411T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
1412T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
1413T1003.005No-0
1414T1539No-0
1415T1175No-0
1416T1188No-0
1417T1137.001No-0
1418T1109No-0
1419T1152No-0
1420T1218.007No-0
1421T1158No-0
1422T1021.006No-0
1423T1550.004No-0
1424T1037.005No-0
1425T1574No-1
1426T1558No-1
1427T1578.003No-0
1428T1053.002No-0
1429T1567.002No-0
1430T1019No-0
1431T1155No-0
1432T1574.011No-0
1433T1568.001No-0
1434T1134.002No-0
1435T1128No-0
1436T1547.011No-0
1437T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
1438T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
1439T1027.003No-0
1440T1191No-0
1441T1487No-0
1442T1543No-1
1443T1100No-0
1444T1223No-0
1445T1562.007No-0
1446T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
1447T1065No-0
1448T1564.003No-0
1449T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml25
1450T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_assume_role_abuse.yml25
1451T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_role_creation.yml25
1452T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_attach_to_role_policy.yml25
1453T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_permanent_key_creation.yml25
1454T1546.010No-0
1455T1108No-0
1456T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
1457T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
1458T1497.001No-0
1459T1552No-0
1460T1064No-0
1461T1491.002No-0
1462T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
1463T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
1464T1568.003No-0
1465T1555No-0
1466T1041No-0
1467T1080No-0
1468T1053.001No-0
1469T1218.010No-0
1470T1090.004No-0
1471T1528No-0
1472T1056.003No-0
1473T1552.002No-0
1474T1558.001No-0
1475T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
1476T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
1477T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
1478T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
1479T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
1480T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
1481T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
1482T1070.005No-0
1483T1003.006No-0
1484T1213.002No-0
1485T1218.001No-0
1486T1018No-0
1487T1210No-0
1488T1196No-0
1489T1003No-12
1490T1016No-0
1491T1013No-0
1492T1197No-0
1493T1564.005No-0
1494T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
1495T1131No-0
1496T1562.003No-0
1497T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml5
1498T1503No-0
1499T1023No-0
1500T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
1501T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
1502T1026No-0
1503T1497No-0
1504T1011.001No-0
1505T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
1506T1022No-0
1507T1081No-0
1508T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
1509T1193No-0
1510T1574.006No-0
1511T1548.002No-0
1512T1094No-0
1513T1567.001No-0
1514T1550Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_get_session_token_abuse.yml2
1515T1505No-0
1516T1060No-0
1517T1505.001No-0
1518T1178No-0
1519T1199No-0
1520T1571No-0
1521T1050No-0
1522T1492No-0
1523T1556.003No-0
1524T1570No-0
1525T1574.007No-0
1526T1096No-0
1527T1053No-4
1528T1071.003No-0
1529T1110.002No-0
1530T1204.001No-0
1531T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
1532T1012No-0
1533T1130No-0
1534T1550.003No-0
1535T1102No-0
1536T1574.001No-0
1537T1518.001No-0
1538T1036.001No-0
1539T1059.002No-0
1540T1180No-0
1541T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
1542T1007No-0
1543T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
1544T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
1545T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
1546T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
1547T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
1548T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
1549T1114.003No-0
1550T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
1551T1182No-0
1552T1207No-0
1553T1091No-0
1554T1133No-0
1555T1499No-0
1556T1098.003No-0
1557T1150No-0
1558T1186No-0
1559T1102.002No-0
1560T1211No-0
1561T1055.001No-0
1562T1137.005No-0
1563T1574.004No-0
1564T1563.001No-0
1565T1001.001No-0
1566T1514No-0
1567T1552.003No-0
1568T1002No-0
1569T1546.005No-0
1570T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
1571T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
1572T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
1573T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
1574T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
1575T1543.004No-0
1576T1110.004No-0
1577T1170No-0
1578T1055.004No-0
1579T1059.005No-0
1580T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml3
1581T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml3
1582T1115No-0
1583T1564.006No-0
1584T1032No-0
1585T1033No-0
1586T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
1587T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
1588T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
1589T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
1590T1560.002No-0
1591T1564.004No-0
1592T1536No-0
1593T1149No-0
1594T1132No-0
1595T1051No-0
1596T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
1597T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
1598T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
1599T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
1600T1154No-0
1601T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
1602T1573.001No-0
1603T1140No-0
1604T1527No-0
1605T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
1606T1502No-0
1607T1552.005No-0
1608T1556.001No-0
1609T1098No-0
1610T1127No-0
1611T1574.002No-0
1612T1164No-0
1613T1157No-0
1614T1162No-0
1615T1547.008No-0
1616T1562.006No-0
1617T1547.010No-0
1618T1168No-0
1619T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
1620T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
1621T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
1622T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
1623T1166No-0
1624T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
1625T1057No-0
1626T1559.001No-0
1627T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
1628T1483No-0
1629T1053.003No-0
1630T1103No-0
1631T1522No-0
1632T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
1633T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
1634T1542.001No-0
1635T1120No-0
1636T1543.001No-0
1637T1552.001No-0
1638T1562.002No-0
1639T1573.002No-0
1640T1496No-0
1641T1171No-0
1642T1055.008No-0
1643T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
1644T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
1645T1220No-0
1646T1499.001No-0
1647T1569.001No-0
1648T1069.002No-0
1649T1054No-0
1650T1056.004No-0
1651T1074No-0
1652T1546No-5
1653T1144No-0
1654T1046No-0
1655T1066No-0
1656T1055.002No-0
1657T1491No-0
1658T1027.001No-0
1659T1124No-0
1660T1129No-0
1661T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
1662T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
1663T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
1664T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
1665T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
1666T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
1667T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
1668T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
1669T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml2
1670T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml2
1671T1560.003No-0
1672T1123No-0
1673T1048.001No-0
1674T1090.002No-0
1675T1110.001No-0
1676T1497.003No-0
1677T1055.011No-0
1678T1505.003No-0
1679T1547.009No-0
1680T1213No-0
1681T1001.003No-0
1682T1565.003No-0
1683T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
1684T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
1685T1578No-0
1686T1036.003No-0
1687T1547.004No-0
1688T1102.001No-0
1689T1125No-0
1690T1505.002No-0
1691T1160No-0
1692T1003.007No-0
1693T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml5
1694T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml5
1695T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml5
1696T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_gcp_storage_buckets.yml5
1697T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_gcp_storage_access_from_a_new_ip.yml5
1698T1561No-0
1699T1031No-0
1700T1568.002No-0
1701T1198No-0
1702T1049No-0
1703T1195.002No-0
1704T1519No-0
1705T1165No-0
1706T1561.002No-0
1707T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml3
1708T1099No-0
1709T1548No-0
1710T1009No-0
1711T1201No-0
1712T1555.001No-0
1713T1101No-0
1714T1110No-0
1715T1548.003No-0
1716T1538No-0
1717T1139No-0
1718T1077No-0
1719T1553No-1
1720T1181No-0
1721T1055.005No-0
1722T1556.002No-0
1723T1001.002No-0
1724T1055.013No-0
1725T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
1726T1056.001No-0
1727T1547.006No-0
1728T1076No-0
1729T1055.003No-0
1730T1137.003No-0
1731T1092No-0
1732T1195.003No-0
1733T1119No-0
1734T1578.001No-0
1735T1084No-0
1736T1217No-0
1737T1113No-0
1738T1552.004No-0
1739T1062No-0
1740T1004No-0
1741T1163No-0
1742T1213.001No-0
1743T1070.003No-0
1744T1090.001No-0
1745T1083No-0
1746T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
1747T1504No-0
1748T1044No-0
1749T1055No-0
1750T1063No-0
1751T1563.002No-0
1752T1559.002No-0
1753T1574.010No-0
1754T1547.002No-0
1755T1027.005No-0
1756T1014No-0
1757T1038No-0
1758T1550.001No-0
1759T1090.003No-0
1760T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
1761T1174No-0
1762T1499.003No-0
1763T1216.001No-0
1764T1034No-0
1765T1132.001No-0
1766T1547.007No-0
1767T1097No-0
1768T1146No-0
1769T1098.002No-0
1770T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
1771T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
1772T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
1773T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
1774T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
1775T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
1776T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
1777T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
1778T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
1779T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
1780T1497.002No-0
1781T1137No-0
1782T1156No-0
1783T1088No-0
1784T1021.004No-0
1785T1562No-3
1786T1578.002No-0
1787T1134No-0
1788T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
1789T1145No-0
1790T1537No-0
1791T1087No-0
1792T1087.002No-0
1793T1177No-0
1794T1529No-0
1795T1499.002No-0
1796T1546.013No-0
1797T1204No-1
1798T1006No-0
1799T1003.004No-0
1800T1021.005No-0
1801T1138No-0
1802T1548.001No-0
1803T1036.005No-0
1804T1542.002No-0
1805T1189No-0
1806T1086No-0
1807T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
1808T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
1809T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
1810T1029No-0
1811T1089No-0
1812T1028No-0
1813T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml4
1814T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml4
1815T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml4
1816T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml4
1817T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
1818T1542.003No-0
1819T1546.004No-0
1820T1194No-0
1821T1069.001No-0
1822T1558.002No-0
1823T1134.003No-0
1824T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
1825T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
1826T1560No-0
1827T1067No-0
1828T1061No-0
1829T1173No-0
1830T1499.004No-0
1831T1069.003No-0
1832T1187No-0
1833T1564.001No-0
1834T1546.009No-0
1835T1486No-0
1836T1001No-0
1837T1118No-0
1838T1208No-0
1839T1185No-0
1840T1053.004No-0
1841T1212No-0
1842T1534No-0
1843T1111No-0
1844T1553.003No-0
1845T1554No-0
1846T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
1847T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
1848T1035No-0
1849T1542No-0
1850T1546.015No-0
1851T1042No-0
1852T1098.001No-0
1853T1167No-0
1854T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
1855T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
1856T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
1857T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
1858T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
1859T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
1860T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
1861T1121No-0
1862T1490No-0
1863T1106No-0
1864T1005No-0
1865T1484No-0
1866T1079No-0
1867T1105No-0
1868T1137.002No-0
1869T1059.004No-0
1870T1142No-0
1871T1553.001No-0
1872T1122No-0
1873T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml2
1874T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml2
1875T1572No-0
1876T1547.005No-0
1877T1482No-0
1878T1098.004No-0
1879T1087.001No-0
1880T1037.001No-0
1881T1102.003No-0
1882T1574.012No-0
1883T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
1884T1501No-0
1885T1543.002No-0
1886T1151No-0
1887T1024No-0
1888T1147No-0
1889T1205No-0
1890T1027.004No-0
1891T1565.001No-0
1892T1564.002No-0
1893T1205.001No-0
1894T1493No-0
1895T1202No-0
1896T1045No-0
1897T1574.005No-0
1898T1040No-0
1899T1021No-6
1900T1134.004No-0
1901T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
1902T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
1903T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
1904T1179No-0
1905T1559No-0
1906T1048.002No-0
1907T1030No-0
1908T1037.002No-0
1909T1110.003No-0
1910T1567No-0
1911T1569No-1
1912T1548.004No-0
1913T1172No-0
1914T1134.001No-0
1915T1036.006No-0
1916T1209No-0
1917T1087.004No-0
1918T1073No-0
1919T1090No-0
1920T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
1921T1218No-1
1922T1578.004No-0
1923T1070.006No-0
1924T1161No-0
1925T1218.009No-0
1926T1480No-0
1927T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
1928T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
1929T1011No-0
1930T1500No-0
1931T1052.001No-0
1932T1136.003No-0
1933T1176No-0
1934T1553.002No-0
1935T1127.001No-0
1936T1036.004No-0
1937T1546.007No-0
1938T1137.006No-0
1939T1557.001No-0
1940T1218.008No-0
1941T1039No-0
1942T1218.005No-0
1943T1059.006No-0
1944T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
1945T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
1946T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
1947T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
1948T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
1949T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
1950T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
1951T1565No-0
1952T1036.002No-0
1953T1564No-0
1954T1563No-0
1955T1218.002No-0
1956T1546.002No-0
1957T1135No-0
1958T1547.003No-0
1959T1494No-0
1960T1506No-0
1961T1573No-0
1962T1008No-0
1963T1141No-0
1964T1183No-0
1965T1219No-0
1966T1027.002No-0
1967T1214No-0
1968T1568No-0
1969T1037.004No-0
1970T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml13
1971T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml13
1972T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml13
1973T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml13
1974T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml13
1975T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml13
1976T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml13
1977T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml13
1978T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml13
1979T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml13
1980T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml13
1981T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml13
1982T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml13
1983T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
1984T1195.001No-0
1985T1491.001No-0
1986T1488No-0
1987T1025No-0
1988T1052No-0
1989T1070.002No-0
1990T1116No-0
1991T1560.001No-0
1992T1169No-0
1993T1087.003No-0
1994T1074.002No-0
1995T1555.002No-0
1996T1093No-0
1997T1546.012No-0
1998T1107No-0
1999T1117No-0
2000T1070.004No-0
2001T1495No-0
2002T1518No-0
2003T1556No-0
2004T1126No-0
2005T1552.006No-0
2006T1055.009No-0
2007T1017No-0
2008T1565.002No-0
2009T1037.003No-0
2010T1480.001No-0
2011T1075No-0
2012T1059No-15
2013T1222.002No-0
2014T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
2015T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
2016T1547No-3
2017T1215No-0
2018T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
2019T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
2020T1055.012No-0
2021T1561.001No-0
2022T1074.001No-0
2023T1546.003No-0
2024T1216No-0
2025T1114No-3
2026T1085No-0
2027T1143No-0
2028T1489No-0
2029T1218.004No-0
2030T1055.014No-0
2031T1069No-0
2032T1555.003No-0
2033T1195No-0
2034T1132.002No-0
2035T1192No-0
2036T1059.007No-0
2037T1137.004No-0
2038T1184No-0
2039T1221No-0
2040T1218.003No-0
2041T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
2042T1531No-0
2043T1153No-0
2044T1136.002No-0
2045T1546.014No-0
2046T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
2047T1574.008No-0
2048T1056.002No-0
2049T1037No-0
2050T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
2051T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
2052T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
2053T1148No-0
2054T1056No-0
2055T1159No-0
2056T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
2057T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
2058T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
2059T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
2060T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
2061T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
2062T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
2063T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
2064T1071No-10
2065T1104No-0
2066T1021.003No-0
2067T1015No-0
2068T1003.008No-0
2069T1058No-0
2070T1134.005No-0
2071T1010No-0
2072T1043No-0
2073T1206No-0
2074T1020No-0
2075T1546.006No-0
2076T1222No-1
2077T1498.001No-0
2078T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
2079T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
2080T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
2081T1003.005No-0
2082T1539No-0
2083T1175No-0
2084T1188No-0
2085T1137.001No-0
2086T1109No-0
2087T1152No-0
2088T1218.007No-0
2089T1158No-0
2090T1021.006No-0
2091T1550.004No-0
2092T1037.005No-0
2093T1574No-1
2094T1558No-1
2095T1578.003No-0
2096T1053.002No-0
2097T1567.002No-0
2098T1019No-0
2099T1155No-0
2100T1574.011No-0
2101T1568.001No-0
2102T1134.002No-0
2103T1128No-0
2104T1547.011No-0
2105T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
2106T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
2107T1027.003No-0
2108T1191No-0
2109T1487No-0
2110T1543No-1
2111T1100No-0
2112T1223No-0
2113T1562.007No-0
2114T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
2115T1065No-0
2116T1564.003No-0
2117T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml25
2118T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_assume_role_abuse.yml25
2119T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_role_creation.yml25
2120T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_attach_to_role_policy.yml25
2121T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_permanent_key_creation.yml25
2122T1546.010No-0
2123T1108No-0
2124T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
2125T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
2126T1497.001No-0
2127T1552No-0
2128T1064No-0
2129T1491.002No-0
2130T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
2131T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
2132T1568.003No-0
2133T1555No-0
2134T1041No-0
2135T1080No-0
2136T1053.001No-0
2137T1218.010No-0
2138T1090.004No-0
2139T1528No-0
2140T1056.003No-0
2141T1552.002No-0
2142T1558.001No-0
2143T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
2144T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
2145T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
2146T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
2147T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
2148T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
2149T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
2150T1070.005No-0
2151T1003.006No-0
2152T1213.002No-0
2153T1218.001No-0
2154T1018No-0
2155T1210No-0
2156T1196No-0
2157T1003No-12
2158T1016No-0
2159T1013No-0
2160T1197No-0
2161T1564.005No-0
2162T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
2163T1131No-0
2164T1562.003No-0
2165T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml5
2166T1503No-0
2167T1023No-0
2168T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
2169T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
2170T1026No-0
2171T1497No-0
2172T1011.001No-0
2173T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
2174T1022No-0
2175T1081No-0
2176T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
2177T1193No-0
2178T1574.006No-0
2179T1548.002No-0
2180T1094No-0
2181T1567.001No-0
2182T1550Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_get_session_token_abuse.yml2
2183T1505No-0
2184T1060No-0
2185T1505.001No-0
2186T1178No-0
2187T1199No-0
2188T1571No-0
2189T1050No-0
2190T1492No-0
2191T1556.003No-0
2192T1570No-0
2193T1574.007No-0
2194T1096No-0
2195T1053No-4
2196T1071.003No-0
2197T1110.002No-0
2198T1204.001No-0
2199T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
2200T1012No-0
2201T1130No-0
2202T1550.003No-0
2203T1102No-0
2204T1574.001No-0
2205T1518.001No-0
2206T1036.001No-0
2207T1059.002No-0
2208T1180No-0
2209T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
2210T1007No-0
2211T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
2212T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
2213T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
2214T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
2215T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
2216T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
2217T1114.003No-0
2218T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
2219T1182No-0
2220T1207No-0
2221T1091No-0
2222T1133No-0
2223T1499No-0
2224T1098.003No-0
2225T1150No-0
2226T1186No-0
2227T1102.002No-0
2228T1211No-0
2229T1055.001No-0
2230T1137.005No-0
2231T1574.004No-0
2232T1563.001No-0
2233T1001.001No-0
2234T1514No-0
2235T1552.003No-0
2236T1002No-0
2237T1546.005No-0
2238T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
2239T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
2240T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
2241T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
2242T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
2243T1543.004No-0
2244T1110.004No-0
2245T1170No-0
2246T1055.004No-0
2247T1059.005No-0
2248T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml3
2249T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml3
2250T1115No-0
2251T1564.006No-0
2252T1032No-0
2253T1033No-0
2254T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
2255T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
2256T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
2257T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
2258T1560.002No-0
2259T1564.004No-0
2260T1536No-0
2261T1149No-0
2262T1132No-0
2263T1051No-0
2264T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
2265T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
2266T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
2267T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
2268T1154No-0
2269T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
2270T1573.001No-0
2271T1140No-0
2272T1527No-0
2273T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
2274T1502No-0
2275T1552.005No-0
2276T1556.001No-0
2277T1098No-0
2278T1127No-0
2279T1574.002No-0
2280T1164No-0
2281T1157No-0
2282T1162No-0
2283T1547.008No-0
2284T1562.006No-0
2285T1547.010No-0
2286T1168No-0
2287T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
2288T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
2289T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
2290T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
2291T1166No-0
2292T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
2293T1057No-0
2294T1559.001No-0
2295T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
2296T1483No-0
2297T1053.003No-0
2298T1103No-0
2299T1522No-0
2300T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
2301T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
2302T1542.001No-0
2303T1120No-0
2304T1543.001No-0
2305T1552.001No-0
2306T1562.002No-0
2307T1573.002No-0
2308T1496No-0
2309T1171No-0
2310T1055.008No-0
2311T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
2312T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
2313T1220No-0
2314T1499.001No-0
2315T1569.001No-0
2316T1069.002No-0
2317T1054No-0
2318T1056.004No-0
2319T1074No-0
2320T1546No-5
2321T1144No-0
2322T1046No-0
2323T1066No-0
2324T1055.002No-0
2325T1491No-0
2326T1027.001No-0
2327T1124No-0
2328T1129No-0
2329T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
2330T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
2331T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
2332T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
2333T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
2334T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
2335T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
2336T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
2337T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml2
2338T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml2
2339T1560.003No-0
2340T1123No-0
2341T1048.001No-0
2342T1090.002No-0
2343T1110.001No-0
2344T1497.003No-0
2345T1055.011No-0
2346T1505.003No-0
2347T1547.009No-0
2348T1213No-0
2349T1001.003No-0
2350T1565.003No-0
2351T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
2352T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
2353T1578No-0
2354T1036.003No-0
2355T1547.004No-0
2356T1102.001No-0
2357T1125No-0
2358T1505.002No-0
2359T1160No-0
2360T1003.007No-0
2361T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml5
2362T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml5
2363T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml5
2364T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_gcp_storage_buckets.yml5
2365T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_gcp_storage_access_from_a_new_ip.yml5
2366T1561No-0
2367T1031No-0
2368T1568.002No-0
2369T1198No-0
2370T1049No-0
2371T1195.002No-0
2372T1519No-0
2373T1165No-0
2374T1561.002No-0
2375T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml3
2376T1099No-0
2377T1548No-0
2378T1009No-0
2379T1201No-0
2380T1555.001No-0
2381T1101No-0
2382T1110No-0
2383T1548.003No-0
2384T1538No-0
2385T1139No-0
2386T1077No-0
2387T1553No-1
2388T1181No-0
2389T1055.005No-0
2390T1556.002No-0
2391T1001.002No-0
2392T1055.013No-0
2393T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
2394T1056.001No-0
2395T1547.006No-0
2396T1076No-0
2397T1055.003No-0
2398T1137.003No-0
2399T1092No-0
2400T1195.003No-0
2401T1119No-0
2402T1578.001No-0
2403T1084No-0
2404T1217No-0
2405T1113No-0
2406T1552.004No-0
2407T1062No-0
2408T1004No-0
2409T1163No-0
2410T1213.001No-0
2411T1070.003No-0
2412T1090.001No-0
2413T1083No-0
2414T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
2415T1504No-0
2416T1044No-0
2417T1055No-0
2418T1063No-0
2419T1563.002No-0
2420T1559.002No-0
2421T1574.010No-0
2422T1547.002No-0
2423T1027.005No-0
2424T1014No-0
2425T1038No-0
2426T1550.001No-0
2427T1090.003No-0
2428T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
2429T1174No-0
2430T1499.003No-0
2431T1216.001No-0
2432T1034No-0
2433T1132.001No-0
2434T1547.007No-0
2435T1097No-0
2436T1146No-0
2437T1098.002No-0
2438T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
2439T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
2440T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
2441T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
2442T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
2443T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
2444T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
2445T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
2446T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
2447T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
2448T1497.002No-0
2449T1137No-0
2450T1156No-0
2451T1088No-0
2452T1021.004No-0
2453T1562No-3
2454T1578.002No-0
2455T1134No-0
2456T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
2457T1145No-0
2458T1537No-0
2459T1087No-0
2460T1087.002No-0
2461T1177No-0
2462T1529No-0
2463T1499.002No-0
2464T1546.013No-0
2465T1204No-1
2466T1006No-0
2467T1003.004No-0
2468T1021.005No-0
2469T1138No-0
2470T1548.001No-0
2471T1036.005No-0
2472T1542.002No-0
2473T1189No-0
2474T1086No-0
2475T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
2476T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
2477T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
2478T1029No-0
2479T1089No-0
2480T1028No-0
2481T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml4
2482T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml4
2483T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml4
2484T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml4
2485T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
2486T1542.003No-0
2487T1546.004No-0
2488T1194No-0
2489T1069.001No-0
2490T1558.002No-0
2491T1134.003No-0
2492T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
2493T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
2494T1560No-0
2495T1067No-0
2496T1061No-0
2497T1173No-0
2498T1499.004No-0
2499T1069.003No-0
2500T1187No-0
The file is too large to be shown. View Raw