Files
2020-07-15 21:14:02 +00:00

17 KiB

1Technique IDDetection AvailableLinkscore
2T1193Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml49
3T1193Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml49
4T1566.001No-51
5T1204.002No-50
6T1027No-48
7T1059.001No-44
8T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml38
9T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml38
10T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml38
11T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml38
12T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml38
13T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml38
14T1059.003No-41
15T1105No-40
16T1060No-38
17T1547.001No-38
18T1071.001No-34
19T1107No-30
20T1070.004No-30
21T1053.005No-28
22T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml22
23T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml22
24T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml22
25T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml22
26T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml22
27T1059.005No-26
28T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml23
29T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml23
30T1566.002No-24
31T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml3
32T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml3
33T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml3
34T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml3
35T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml3
36T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml3
37T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml3
38T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml3
39T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml3
40T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml3
41T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml3
42T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml3
43T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml3
44T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml3
45T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml3
46T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml3
47T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml3
48T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml3
49T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml3
50T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml3
51T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml3
52T1192Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml23
53T1083No-23
54T1203No-23
55T1005No-22
56T1057No-22
57T1016No-22
58T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml19
59T1076Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml18
60T1076Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml18
61T1056.001No-20
62T1140No-19
63T1018No-19
64T1036.005No-19
65T1204.001No-19
66T1033No-18
67T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml10
68T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml10
69T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml10
70T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml10
71T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml10
72T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml10
73T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml10
74T1189No-17
75T1543.003No-16
76T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml2
77T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
78T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml2
79T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
80T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml2
81T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml2
82T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml2
83T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml2
84T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
85T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
86T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
87T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
88T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml2
89T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml2
90T1560.001No-16
91T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml13
92T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml13
93T1503No-15
94T1555.003No-15
95T1087.001No-14
96T1553.002No-14
97T1049No-14
98T1074.001No-14
99T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml12
100T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml12
101T1116No-14
102T1046No-13
103T1045No-12
104T1027.002No-12
105T1041Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml11
106T1113No-12
107T1518.001No-11
108T1571No-11
109T1574.002No-11
110T1063No-11
111T1218.011No-11
112T1073No-11
113T1085Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml10
114T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml4
115T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml4
116T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml4
117T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml4
118T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml4
119T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml4
120T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml4
121T1133No-11
122T1021.002No-11
123T1136.002No-10
124T1505.003No-10
125T1087.002No-10
126T1055No-10
127T1100No-10
128T1562.001No-9
129T1560No-9
130T1143No-9
131T1564.003No-9
132T1090.002No-9
133T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml7
134T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml7
135T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
136T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
137T1119No-9
138T1559.002No-9
139T1173No-9
140T1102.002No-8
141T1548.002No-8
142T1003.004No-8
143T1035No-8
144T1219No-8
145T1132.001No-8
146T1218.010No-8
147T1569.002No-8
148T1071.004No-8
149T1117No-8
150T1190No-8
151T1065No-8
152T1135No-8
153T1221No-7
154T1027.005No-7
155T1023No-7
156T1573.001No-7
157T1069.002No-7
158T1012No-7
159T1066No-7
160T1070.001No-7
161T1007No-7
162T1059.007No-7
163T1555No-7
164T1552.001No-7
165T1021.004No-7
166T1547.009No-7
167T1106No-7
168T1009No-6
169T1027.001No-6
170T1036.004No-6
171T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml5
172T1048.003No-6
173T1114.002No-6
174T1027.003No-5
175T1001.002No-5
176T1573.002No-5
177T1546.008No-5
178T1102.001No-5
179T1059.006No-5
180T1074.002No-5
181T1550.002No-5
182T1566.003No-5
183T1055.001No-5
184T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml4
185T1075Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml4
186T1084Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml2
187T1084Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml2
188T1084Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml2
189T1040No-5
190T1223No-5
191T1170No-5
192T1090No-5
193T1564.001No-5
194T1158No-5
195T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml4
196T1218.001No-5
197T1218.005No-5
198T1099No-5
199T1194No-5
200T1015Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml2
201T1015Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml2
202T1015Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml2
203T1110No-5
204T1120No-5
205T1546.003No-5
206T1070.006No-5
207T1094No-4
208T1574.001No-4
209T1014No-4
210T1038No-4
211T1570No-4
212T1078.003No-4
213T1036.002No-4
214T1487No-4
215T1093No-4
216T1071.002No-4
217T1560.003No-4
218T1561.002No-4
219T1003.005No-4
220T1102Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml3
221T1124No-4
222T1025No-4
223T1496No-4
224T1055.012No-4
225T1036.003No-4
226T1097No-3
227T1550.003No-3
228T1020No-3
229T1104No-3
230T1091No-3
231T1197No-3
232T1188No-3
233T1486No-3
234T1067No-3
235T1572No-3
236T1027.004No-3
237T1090.003No-3
238T1039No-3
239T1071.003No-3
240T1529No-3
241T1069.001No-3
242T1053.002No-3
243T1518No-3
244T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml2
245T1110.002No-3
246T1078.002No-3
247T1071No-3
248T1485No-3
249T1110.003No-3
250T1500No-3
251T1542.003No-3
252T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml2
253T1098Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml2
254T1008No-3
255T1004No-2
256T1069No-2
257T1201No-2
258T1059.004No-2
259T1187No-2
260T1195.002No-2
261T1055.002No-2
262T1137No-2
263T1115No-2
264T1222.002No-2
265T1090.001No-2
266T1125No-2
267T1547.004No-2
268T1559.001No-2
269T1542.002No-2
270T1114.001No-2
271T1176No-2
272T1191No-2
273T1109No-2
274T1213.002No-2
275T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml-2
276T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml-2
277T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml-2
278T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml-2
279T1134.002No-2
280T1080No-2
281T1564.005No-2
282T1087.003No-2
283T1199No-2
284T1218.003No-2
285T1560.002No-2
286T1032No-2
287T1037.001No-2
288T1210No-2
289T1480.001No-2
290T1565.001No-2
291T1492No-2
292T1567.002No-2
293T1218.007No-2
294T1126No-1
295T1213No-1
296T1127.001No-1
297T1174No-1
298T1030No-1
299T1214No-1
300T1546.012No-1
301T1546.011No-1
302T1504No-1
303T1489No-1
304T1056.004No-1
305T1565.002No-1
306T1056.002No-1
307T1074Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml-1
308T1074Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml-1
309T1001.003No-1
310T1497.002No-1
311T1134.001No-1
312T1026No-1
313T1216.001No-1
314T1534No-1
315T1183No-1
316T1220No-1
317T1546.001No-1
318T1070.005No-1
319T1494No-1
320T1010No-1
321T1546.013No-1
322T1138Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml-2
323T1138Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml-2
324T1138Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml-2
325T1573No-1
326T1096No-1
327T1146No-1
328T1543.002No-1
329T1037No-1
330T1211No-1
331T1021.005No-1
332T1186No-1
333T1070.003No-1
334T1092No-1
335T1565.003No-1
336T1001.001No-1
337T1558.001No-1
338T1021.006No-1
339T1501No-1
340T1546.015No-1
341T1137.006No-1
342T1562.002No-1
343T1145No-1
344T1172No-1
345T1568.003No-1
346T1042Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml-2
347T1042Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml-2
348T1042Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml-2
349T1482No-1
350T1052.001No-1
351T1028No-1
352T1001No-1
353T1568.001No-1
354T1055.013No-1
355T1574.006No-1
356T1552.002No-1
357T1137.001No-1
358T1564.004No-1
359T1090.004No-1
360T1102.003No-1
361T1552.006No-1
362T1078.004No-1
363T1098.002No-1
364T1568.002No-1
365T1070.002No-1
366T1122No-1
367T1036.001No-1
368T1134No-1
369T1556.002No-1
370T1546.009No-1
371T1137.002No-1
372T1137.004No-1
373T1550.001No-1
374T1497.001No-1
375T1182No-1
376T1053.003No-1
377T1218.008No-1
378T1483No-1
379T1200No-1
380T1123No-1
381T1195No-1
382T1527No-1
383T1552.004No-1
384T1561.001No-1
385T1491.001No-1
386T1488No-1
387T1493No-1
388T1528No-1
389T1574.012No-1