mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
21ee673940
* Fix Issues and Updates * Update add_or_set_windows_defender_exclusion.yml * Update windows_curl_download_to_suspicious_path.yml * Fix more issues and bugs * Update deprecation_mapping.YML * Update windows_application_whitelisting_bypass_attempt_via_rundll32.yml * More updates and fixes * update `Windows Change Default File Association For No File Ext` * A couple more updates for ya * rename * add / update rules * Update windows_symlink_evaluation_change_via_fsutil.yml * Update windows_symlink_evaluation_change_via_fsutil.yml * Update linux_service_started_or_enabled.yml * Update linux_service_started_or_enabled.yml --------- Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
1102 lines
61 KiB
YAML
1102 lines
61 KiB
YAML
detections:
|
|
- content: Windows Change Default File Association For No File Ext
|
|
removed_in_version: 5.18.0
|
|
reason: Detection has been deprecated since it has been replaced with a better named detection that reflect a much better consistent logic
|
|
replacement_content:
|
|
- Windows Change File Association Command To Notepad
|
|
- content: Detect Rundll32 Application Control Bypass - setupapi
|
|
removed_in_version: 5.18.0
|
|
reason: Detection has been deprecated since it has been replaced with a better named detection that reflect a much better consistent logic
|
|
replacement_content:
|
|
- Windows Application Whitelisting Bypass Attempt via Rundll32
|
|
- content: Detect Rundll32 Application Control Bypass - syssetup
|
|
removed_in_version: 5.18.0
|
|
reason: Detection has been deprecated since it has been replaced with a better named detection that reflect a much better consistent logic
|
|
replacement_content:
|
|
- Windows Application Whitelisting Bypass Attempt via Rundll32
|
|
- content: Detect Rundll32 Application Control Bypass - advpack
|
|
removed_in_version: 5.18.0
|
|
reason: Detection has been deprecated since it has been replaced with a better named detection that reflect a much better consistent logic
|
|
replacement_content:
|
|
- Windows Application Whitelisting Bypass Attempt via Rundll32
|
|
- content: Windows Set Private Network Profile via Registry
|
|
removed_in_version: 5.18.0
|
|
reason: Renamed the detection for much clearer description with an updated detection logic.
|
|
replacement_content:
|
|
- Windows Set Network Profile Category to Private via Registry
|
|
- content: Cisco Secure Application Alerts
|
|
removed_in_version: 5.14.0
|
|
reason: Detection has been deprecated since it has been replaced with a better named detection to reflect the correct product
|
|
replacement_content:
|
|
- Splunk AppDynamics Secure Application Alerts
|
|
- content: Windows InstallUtil Uninstall Option with Network
|
|
removed_in_version: 5.12.0
|
|
reason: Detection has been deprecated as its scope is already covered by "Windows InstallUtil Remote Network Connection".
|
|
replacement_content:
|
|
- Windows InstallUtil Remote Network Connection
|
|
- content: Any Powershell DownloadString
|
|
removed_in_version: 5.12.0
|
|
reason: Detection has been replaced by a new detection with a better logic and grouping in order to ease its management.
|
|
replacement_content:
|
|
- Windows File Download Via PowerShell
|
|
- content: Any Powershell DownloadFile
|
|
removed_in_version: 5.12.0
|
|
reason: Detection has been replaced by a new detection with a better logic and grouping in order to ease its management.
|
|
replacement_content:
|
|
- Windows File Download Via PowerShell
|
|
- content: Windows AD Suspicious GPO Modification
|
|
removed_in_version: 5.10.0
|
|
reason: Detection deprecated due to lack of data and consistency. Research is being done to create potential replacement in a future release.
|
|
- content: Windows Remote Access Software Hunt
|
|
removed_in_version: 5.8.0
|
|
reason: Detection has been replaced by a new detection with a more specific name and logic
|
|
replacement_content:
|
|
- Detect Remote Access Software Usage Process
|
|
- content: CertUtil Download With URLCache and Split Arguments
|
|
removed_in_version: 5.8.0
|
|
reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert
|
|
replacement_content:
|
|
- Windows File Download Via CertUtil
|
|
- content: Windows CertUtil Download With URL Argument
|
|
removed_in_version: 5.8.0
|
|
reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert
|
|
replacement_content:
|
|
- Windows File Download Via CertUtil
|
|
- content: CertUtil Download With VerifyCtl and Split Arguments
|
|
removed_in_version: 5.8.0
|
|
reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert
|
|
replacement_content:
|
|
- Windows File Download Via CertUtil
|
|
- content: Detect Large Outbound ICMP Packets
|
|
removed_in_version: 5.6.0
|
|
reason: Detection has been replaced by a new detection with a more specific name
|
|
replacement_content:
|
|
- Detect Large ICMP Traffic
|
|
- content: Windows Service Created Within Public Path
|
|
removed_in_version: 5.6.0
|
|
reason: Detection has been replaced by a new detection with a more specific name
|
|
replacement_content:
|
|
- Windows Service Created with Suspicious Service Path
|
|
- content: GitHub Actions Disable Security Workflow
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- GitHub Organizations Disable Classic Branch Protection Rule
|
|
- content: Github Commit Changes In Master
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Github Commit In Develop
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: GitHub Dependabot Alert
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- GitHub Enterprise Disable Dependabot
|
|
- content: GitHub Pull Request from Unknown User
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Known Services Killed by Ransomware
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Security And Backup Services Stop
|
|
- content: Remote Desktop Network Bruteforce
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Remote Desktop Network Bruteforce Attempt
|
|
- content: Suspicious Driver Loaded Path
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Suspicious Driver Loaded Path
|
|
- content: Suspicious Event Log Service Behavior
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Event Logging Service Has Shutdown
|
|
- content: Suspicious Process File Path
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Suspicious Process File Path
|
|
- content: AWS Cross Account Activity From Previously Unseen Account
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: aws detect attach to role policy
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: aws detect permanent key creation
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: aws detect role creation
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: aws detect sts assume role abuse
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: aws detect sts get session token abuse
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: AWS SAML Access by Provider User and Principal
|
|
removed_in_version: 5.4.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: ASL AWS Excessive Security Scanning
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: AWS Cloud Provisioning From Previously Unseen Region
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Cloud Provisioning Activity From Previously Unseen Region
|
|
- content: First time seen command line argument
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Windows connhost exe started forcefully
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Detect Mimikatz Using Loaded Images
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Kubernetes Azure detect sensitive role access
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Web Fraud - Anomalous User Clickspeed
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: EC2 Instance Started With Previously Unseen Instance Type
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Cloud Compute Instance Created With Previously Unseen Instance Type
|
|
- content: EC2 Instance Started With Previously Unseen AMI
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Cloud Compute Instance Created With Previously Unseen Image
|
|
- content: Domain Group Discovery With Net
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Group Discovery Via Net
|
|
- content: Kubernetes AWS detect sensitive role access
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Winword Spawning Windows Script Host
|
|
removed_in_version: 5.2.0
|
|
reason: "The following analytics was deprecated in favour of a more generic approach.
|
|
Where instead of creating specific analytic for every potentially suspicious child
|
|
of an office product. We group them by threat level.\nThis would ease management
|
|
and false positives tuning."
|
|
replacement_content:
|
|
- Windows Office Product Spawned Uncommon Process
|
|
- content: Winword Spawning PowerShell
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Office Product Spawned Uncommon Process
|
|
- content: Attempted Credential Dump From Registry via Reg exe
|
|
removed_in_version: 5.2.0
|
|
reason: This analytic had some overlap with another one, hence the deprecation.
|
|
It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry
|
|
Hive Dump Via CommandLine
|
|
replacement_content:
|
|
- Windows Sensitive Registry Hive Dump Via CommandLine
|
|
- content: Detect processes used for System Network Configuration Discovery
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Potential System Network Configuration Discovery Activity
|
|
- content: Execution of File With Spaces Before Extension
|
|
removed_in_version: 5.2.0
|
|
reason: Updated to a new detection name
|
|
replacement_content:
|
|
- Execution of File with Multiple Extensions
|
|
- content: EC2 Instance Started In Previously Unseen Region
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Cloud Compute Instance Created In Previously Unused Region
|
|
- content: Office Document Spawned Child Process To Download
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Office Product Spawned Child Process For Download
|
|
- content: Detect new API calls from user roles
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Cloud API Calls From Previously Unseen User Roles
|
|
- content: Cmdline Tool Not Executed In CMD Shell
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Cmdline Tool Execution From Non-Shell Process
|
|
- content: Linux Auditd Find Private Keys
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Linux Auditd Private Keys and Certificate Enumeration
|
|
- content: Detect AWS API Activities From Unapproved Accounts
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Monitor DNS For Brand Abuse
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Kubernetes GCP detect sensitive object access
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Kubernetes Azure scan fingerprint
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: ASL AWS Password Policy Changes
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: O365 Suspicious Admin Email Forwarding
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- O365 Mailbox Email Forwarding Enabled
|
|
- content: AWS Cloud Provisioning From Previously Unseen City
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Cloud Provisioning Activity From Previously Unseen City
|
|
- content: Kubernetes AWS detect service accounts forbidden failure access
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Osquery pack - ColdRoot detection
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Windows Modify Registry Reg Restore
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Registry Entries Restored Via Reg
|
|
- content: Kubernetes GCP detect most active service accounts by pod
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Scheduled tasks used in BadRabbit ransomware
|
|
removed_in_version: 5.2.0
|
|
reason: Updated to a new detection name
|
|
replacement_content:
|
|
- Scheduled Task Deleted Or Created via CMD
|
|
- content: Suspicious Rundll32 Rename
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Remote System Discovery with Net
|
|
removed_in_version: 5.2.0
|
|
reason: "This analytic was focusing on 2 separate and unrelated type of threats
|
|
or actions. PLease use the replacement content"
|
|
replacement_content:
|
|
- Windows Sensitive Group Discovery With Net
|
|
- content: DNS Query Requests Resolved by Unauthorized DNS Servers
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Suspicious Changes to File Associations
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: GCP Detect high risk permissions by resource and account
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Office Product Writing cab or inf
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Office Product Dropped Cab or Inf File
|
|
- content: Identify New User Accounts
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Office Product Spawn CMD Process
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Office Product Spawned Uncommon Process
|
|
- content: Windows DLL Search Order Hijacking Hunt
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Windows DLL Search Order Hijacking Hunt with Sysmon
|
|
- content: ASL AWS CreateAccessKey
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- ASL AWS Create Access Key
|
|
- content: Okta ThreatInsight Login Failure with High Unknown users
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Detect Spike in Security Group Activity
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Abnormally High Number Of Cloud Security Group API Calls
|
|
- content: Office Product Spawning BITSAdmin
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Office Product Spawned Uncommon Process
|
|
- content: Create local admin accounts using net exe
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Create Local Administrator Account Via Net
|
|
- content: Abnormally High AWS Instances Terminated by User - MLTK
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Windows Office Product Spawning MSDT
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Office Product Spawned MSDT
|
|
- content: Detect Spike in AWS API Activity
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Office Product Spawning Windows Script Host
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Office Product Spawned Uncommon Process
|
|
- content: Prohibited Software On Endpoint
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Attacker Tools On Endpoint
|
|
- content: AWS Cloud Provisioning From Previously Unseen Country
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Cloud Provisioning Activity From Previously Unseen Country
|
|
- content: Detect Critical Alerts from Security Tools
|
|
removed_in_version: 5.2.0
|
|
reason: As discussed internally, this analytic was too generic for an analyst to
|
|
do anything with it. It was deprecated in favor of the more specific approach
|
|
provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender
|
|
Incident Alerts. Going forward analytics from leveraging alerts from vendors will
|
|
have their specific analytics.
|
|
replacement_content:
|
|
- Microsoft Defender ATP Alerts
|
|
- Microsoft Defender Incident Alerts
|
|
- content: Excel Spawning PowerShell
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Office Product Spawned Uncommon Process
|
|
- content: Office Application Spawn rundll32 process
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Office Product Spawned Uncommon Process
|
|
- content: Excessive Usage Of Net App
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Excessive Usage Of Net App
|
|
- content: Elevated Group Discovery With Net
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Sensitive Group Discovery With Net
|
|
- content: Local Account Discovery with Net
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows User Discovery Via Net
|
|
- content: Windows Command Shell Fetch Env Variables
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows List ENV Variables Via SET Command From Uncommon Parent
|
|
- content: Suspicious Email - UBA Anomaly
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Detect web traffic to dynamic domain providers
|
|
removed_in_version: 5.2.0
|
|
reason: Updated to use a different log source
|
|
replacement_content:
|
|
- Detect hosts connecting to dynamic domain providers
|
|
- content: Okta Failed SSO Attempts
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Okta Unauthorized Access to Application
|
|
- content: Kubernetes AWS detect RBAC authorization by account
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Kubernetes Azure detect service accounts forbidden failure access
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Remote Registry Key modifications
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: O365 Suspicious User Email Forwarding
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- O365 Mailbox Email Forwarding Enabled
|
|
- content: Office Product Spawning MSHTA
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Office Product Spawned Uncommon Process
|
|
- content: Kubernetes AWS detect most active service accounts by pod
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Correlation by Repository and Risk
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the datamodel
|
|
replacement_content:
|
|
- Risk Rule for Dev Sec Ops by Repository
|
|
- content: Kubernetes Azure detect RBAC authorization by account
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Clients Connecting to Multiple DNS Servers
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Excessive Service Stop Attempt
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Excessive Service Stop Attempt
|
|
- content: Multiple Okta Users With Invalid Credentials From The Same IP
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Okta Multiple Users Failing To Authenticate From Ip
|
|
- content: Suspicious writes to System Volume Information
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Detect new user AWS Console Login
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Detect AWS Console Login by New User
|
|
- content: Domain Account Discovery With Net App
|
|
removed_in_version: 5.2.0
|
|
reason: "This analytic was a TTP that looked only for commands that tries to query
|
|
info about the users via net user /do. This had a couple of issues, such as triggering
|
|
on creation of users via the /add flag etc..\nIt was deprecated in favor of a
|
|
more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122"
|
|
replacement_content:
|
|
- Windows User Discovery Via Net
|
|
- content: Detection of DNS Tunnels
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Detect DNS requests to Phishing Sites leveraging EvilGinx2
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Office Document Creating Schedule Task
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Office Product Loading Taskschd DLL
|
|
- content: Okta Account Locked Out
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Okta Multiple Accounts Locked Out
|
|
- content: Unsuccessful Netbackup backups
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Detect Mimikatz Via PowerShell And EventCode 4703
|
|
removed_in_version: 5.2.0
|
|
reason: Updated to a new detection name
|
|
replacement_content:
|
|
- Detect Mimikatz With PowerShell Script Block Logging
|
|
- content: Winword Spawning Cmd
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Office Product Spawned Uncommon Process
|
|
- content: GCP Kubernetes cluster scan detection
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Kubernetes Scanning by Unauthenticated IP Address
|
|
- content: Kubernetes GCP detect suspicious kubectl calls
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: gcp detect oauth token abuse
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Correlation by User and Risk
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the datamodel
|
|
replacement_content:
|
|
- Risk Rule for Dev Sec Ops by Repository
|
|
- content: Processes created by netsh
|
|
removed_in_version: 5.2.0
|
|
reason: Updated to a new detection name
|
|
replacement_content:
|
|
- Processes launching netsh
|
|
- content: Office Product Spawning Wmic
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Office Product Spawned Uncommon Process
|
|
- content: Extraction of Registry Hives
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Sensitive Registry Hive Dump Via CommandLine
|
|
- content: Attempt To Stop Security Service
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Attempt To Stop Security Service
|
|
- content: Windows MSIExec With Network Connections
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows HTTP Network Communication From MSIExec
|
|
- content: Windows Query Registry Reg Save
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Registry Entries Exported Via Reg
|
|
- content: Cloud Network Access Control List Deleted
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- AWS Network Access Control List Deleted
|
|
- content: O365 Suspicious Rights Delegation
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- O365 Elevated Mailbox Permission Assigned
|
|
- content: Abnormally High AWS Instances Launched by User - MLTK
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Reg exe used to hide files directories via registry keys
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Detect Long DNS TXT Record Response
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Password Policy Discovery with Net
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Password Policy Discovery with Net
|
|
- content: AWS Cloud Provisioning From Previously Unseen IP Address
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Cloud Provisioning Activity From Previously Unseen IP Address
|
|
- content: Network Connection Discovery With Net
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Network Connection Discovery Via Net
|
|
- content: Kubernetes Azure detect suspicious kubectl calls
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Kubernetes GCP detect sensitive role access
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Detect Webshell Exploit Behavior
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Suspicious Child Process Spawned From WebServer
|
|
- content: DNS record changed
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Unsigned Image Loaded by LSASS
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Detect USB device insertion
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Windows Network Share Interaction With Net
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Network Share Interaction Via Net
|
|
- content: Account Discovery With Net App
|
|
removed_in_version: 5.2.0
|
|
reason: This analytic was a TTP that focused on unrelated things and called account
|
|
discovery. Since there were other detection that overlapped with it. I choose
|
|
to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122
|
|
/ Windows Excessive Usage Of Net App.
|
|
replacement_content:
|
|
- Windows Excessive Usage Of Net App
|
|
- content: Change Default File Association
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows New Default File Association Value Set
|
|
- content: Windows Lateral Tool Transfer RemCom
|
|
removed_in_version: 5.2.0
|
|
reason: Updated to a new detection name
|
|
replacement_content:
|
|
- Windows Service Execution RemCom
|
|
- content: Office Document Executing Macro Code
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Office Product Loading VBE7 DLL
|
|
- content: Okta Account Lockout Events
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Okta Multiple Accounts Locked Out
|
|
- content: Abnormally High AWS Instances Launched by User
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Abnormally High Number Of Cloud Instances Launched
|
|
- content: EC2 Instance Modified With Previously Unseen User
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Cloud API Calls From Previously Unseen User Roles
|
|
- content: Windows Valid Account With Never Expires Password
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Set Account Password Policy To Unlimited Via Net
|
|
- content: Windows hosts file modification
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: MSHTML Module Load in Office Product
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Office Product Loaded MSHTML Module
|
|
- content: Abnormally High AWS Instances Terminated by User
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Abnormally High Number Of Cloud Instances Destroyed
|
|
- content: Web Fraud - Account Harvesting
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Office Spawning Control
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Office Product Spawned Control
|
|
- content: Detect Activity Related to Pass the Hash Attacks
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Deleting Of Net Users
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows User Deletion Via Net
|
|
- content: Suspicious File Write
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: AWS EKS Kubernetes cluster sensitive object access
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Kubernetes Abuse of Secret by Unusual Location
|
|
- content: Spectre and Meltdown Vulnerable Systems
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: EC2 Instance Started With Previously Unseen User
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Cloud Compute Instance Created By Previously Unseen User
|
|
- content: Office Product Spawning CertUtil
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Office Product Spawned Uncommon Process
|
|
- content: Kubernetes GCP detect RBAC authorizations by account
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Office Application Drop Executable
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Office Product Dropped Uncommon File
|
|
- content: Kubernetes Azure active service accounts by pod namespace
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Kubernetes Azure pod scan fingerprint
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Detect Spike in Network ACL Activity
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Abnormally High Number Of Cloud Infrastructure API Calls
|
|
- content: Suspicious Powershell Command-Line Arguments
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Malicious PowerShell Process - Encoded Command
|
|
- content: Office Application Spawn Regsvr32 process
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Windows Office Product Spawned Uncommon Process
|
|
- content: Detect API activity from users without MFA
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- AWS Successful Single-Factor Authentication
|
|
- content: Kubernetes Azure detect sensitive object access
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Web Fraud - Password Sharing Across Accounts
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Disabling Net User Account
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows User Disabled Via Net
|
|
- content: GCP Detect accounts with high risk roles by project
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Kubernetes GCP detect service accounts forbidden failure access
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Extended Period Without Successful Netbackup Backups
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Office Product Spawning Rundll32 with no DLL
|
|
removed_in_version: 5.2.0
|
|
reason: Renamed and updated logic
|
|
replacement_content:
|
|
- Windows Office Product Spawned Rundll32 With No DLL
|
|
- content: Okta ThreatInsight Suspected PasswordSpray Attack
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Okta ThreatInsight Threat Detected
|
|
- content: Net Localgroup Discovery
|
|
removed_in_version: 5.2.0
|
|
reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44
|
|
/ Windows Group Discovery Via Net
|
|
replacement_content:
|
|
- Windows Group Discovery Via Net
|
|
- content: Uncommon Processes On Endpoint
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Attacker Tools On Endpoint
|
|
- content: Dump LSASS via procdump Rename
|
|
removed_in_version: 5.2.0
|
|
reason: Updated to a new detection name
|
|
replacement_content:
|
|
- Dump LSASS via procdump
|
|
- content: Okta Two or More Rejected Okta Pushes
|
|
removed_in_version: 5.2.0
|
|
reason: Detections updated to use the new search logic and field names due to the
|
|
TA update
|
|
replacement_content:
|
|
- Okta Multiple Failed MFA Requests For User
|
|
- content: Windows Service Stop Via Net and SC Application
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Excel Spawning Windows Script Host
|
|
removed_in_version: 5.2.0
|
|
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
|
|
baselines:
|
|
- content: Previously Seen AWS Cross Account Activity
|
|
removed_in_version: 5.4.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Previously Seen AWS Cross Account Activity - Initial
|
|
removed_in_version: 5.4.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Previously Seen AWS Cross Account Activity - Update
|
|
removed_in_version: 5.4.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Add Prohibited Processes to Enterprise Security
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Baseline of API Calls per User ARN
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Baseline of Excessive AWS Instances Launched by User - MLTK
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Baseline of Excessive AWS Instances Terminated by User - MLTK
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Previously seen API call per user roles in CloudTrail
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Previously Seen AWS Provisioning Activity Sources
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Previously Seen EC2 AMIs
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Previously Seen EC2 Instance Types
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Previously Seen EC2 Launches By User
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Previously seen users in CloudTrail
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Update previously seen users in CloudTrail
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Monitor Successful Backups
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Monitor Unsuccessful Backups
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Previously Seen AWS Regions
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Previously Seen EC2 Modifications By User
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
- content: Systems Ready for Spectre-Meltdown Windows Patch
|
|
removed_in_version: 5.2.0
|
|
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
|
|
investigations:
|
|
- content: All backup logs for host
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Amazon EKS Kubernetes activity by src ip
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: AWS Investigate Security Hub alerts by dest
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: AWS Investigate User Activities By AccessKeyId
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: AWS Investigate User Activities By ARN
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: AWS Network ACL Details from ID
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: AWS Network Interface details via resourceId
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: AWS S3 Bucket details via bucketName
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: GCP Kubernetes activity by src ip
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get All AWS Activity From City
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get All AWS Activity From Country
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get All AWS Activity From IP Address
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get All AWS Activity From Region
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Backup Logs For Endpoint
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Certificate logs for a domain
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get DNS Server History for a host
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get DNS traffic ratio
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get EC2 Instance Details by instanceId
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get EC2 Launch Details
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Email Info
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Emails From Specific Sender
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get First Occurrence and Last Occurrence of a MAC Address
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get History Of Email Sources
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Logon Rights Modifications For Endpoint
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Logon Rights Modifications For User
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Notable History
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Outbound Emails to Hidden Cobra Threat Actors
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Parent Process Info
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Process File Activity
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Process Info
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Process Information For Port Activity
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Process Responsible For The DNS Traffic
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Sysmon WMI Activity for Host
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Get Web Session Information via session id
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Investigate AWS activities via region name
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Investigate AWS User Activities by user field
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Investigate Failed Logins for Multiple Destinations
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Investigate Network Traffic From src ip
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Investigate Okta Activity by app
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Investigate Okta Activity by IP Address
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Investigate Pass the Hash Attempts
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Investigate Pass the Ticket Attempts
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Investigate Previous Unseen User
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Investigate Successful Remote Desktop Authentications
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Investigate Suspicious Strings in HTTP Header
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Investigate User Activities In Okta
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
- content: Investigate Web POSTs From src
|
|
removed_in_version: 5.2.0
|
|
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
|
|
stories:
|
|
- content: Nexus APT Threat Activity
|
|
removed_in_version: 5.4.0
|
|
reason: Analytic Story has been replaced by a new analytic story with a more specific name
|
|
replacement_content:
|
|
- China-Nexus Threat Activity
|
|
- content: Earth Estries
|
|
removed_in_version: 5.4.0
|
|
reason: Analytic Story has been replaced by a new analytic story with a more specific name
|
|
replacement_content:
|
|
- Salt Typhoon
|
|
- content: AWS Cross Account Activity
|
|
removed_in_version: 5.4.0
|
|
reason: All associated detections with this story have been deprecated
|
|
- content: AWS Cryptomining
|
|
removed_in_version: 5.2.0
|
|
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Cloud Cryptomining
|
|
- content: AWS Suspicious Provisioning Activities
|
|
removed_in_version: 5.2.0
|
|
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Suspicious Cloud Provisioning Activities
|
|
- content: Common Phishing Frameworks
|
|
removed_in_version: 5.2.0
|
|
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Container Implantation Monitoring and Investigation
|
|
removed_in_version: 5.2.0
|
|
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Kubernetes Security
|
|
- content: Host Redirection
|
|
removed_in_version: 5.2.0
|
|
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Kubernetes Sensitive Role Activity
|
|
removed_in_version: 5.2.0
|
|
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Kubernetes Security
|
|
- content: Lateral Movement
|
|
removed_in_version: 5.2.0
|
|
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Compromised User Account
|
|
- content: Monitor Backup Solution
|
|
removed_in_version: 5.2.0
|
|
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Monitor for Unauthorized Software
|
|
removed_in_version: 5.2.0
|
|
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Office 365 Detections
|
|
removed_in_version: 5.2.0
|
|
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Office 365 Account Takeover
|
|
- content: Spectre And Meltdown Vulnerabilities
|
|
removed_in_version: 5.2.0
|
|
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
|
- content: Suspicious AWS EC2 Activities
|
|
removed_in_version: 5.2.0
|
|
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Suspicious Cloud Instance Activities
|
|
- content: Unusual AWS EC2 Modifications
|
|
removed_in_version: 5.2.0
|
|
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
|
replacement_content:
|
|
- Suspicious Cloud Instance Activities
|
|
- content: Web Fraud Detection
|
|
removed_in_version: 5.2.0
|
|
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|