Files
2020-07-10 01:35:55 -04:00

17 KiB

1Technique IDDetection AvailableLinkscore
2T1193Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml49
3T1193Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml49
4T1566.001No-51
5T1204.002No-50
6T1027No-48
7T1059.001No-44
8T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml38
9T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml38
10T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml38
11T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml38
12T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml38
13T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml38
14T1059.003No-41
15T1105No-40
16T1060No-38
17T1547.001No-38
18T1071.001No-34
19T1070.004No-30
20T1107No-30
21T1053.005No-28
22T1003.001No-27
23T1059.005No-26
24T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml23
25T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml23
26T1192Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml23
27T1566.002No-24
28T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml2
29T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml2
30T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml2
31T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml2
32T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml2
33T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml2
34T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml2
35T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml2
36T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml2
37T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml2
38T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml2
39T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml2
40T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml2
41T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml2
42T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml2
43T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml2
44T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
45T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml2
46T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml2
47T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml2
48T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
49T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml2
50T1083No-23
51T1203No-23
52T1005No-22
53T1057No-22
54T1016No-22
55T1076Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml18
56T1076Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml18
57T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml19
58T1056.001No-20
59T1140No-19
60T1018No-19
61T1204.001No-19
62T1036.005No-19
63T1033No-18
64T1189No-17
65T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml10
66T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml10
67T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml10
68T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml10
69T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml10
70T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml10
71T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml10
72T1560.001No-16
73T1543.003No-16
74T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml2
75T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
76T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
77T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
78T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
79T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml2
80T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml2
81T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml2
82T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml2
83T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml2
84T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
85T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml2
86T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
87T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml2
88T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml13
89T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml13
90T1555.003No-15
91T1503No-15
92T1049No-14
93T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml13
94T1087.001No-14
95T1116No-14
96T1074.001No-14
97T1553.002No-14
98T1046No-13
99T1027.002No-12
100T1113No-12
101T1041Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml11
102T1045No-12
103T1021.002No-11
104T1574.002No-11
105T1085Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml10
106T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml3
107T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml3
108T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml3
109T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
110T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml3
111T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml3
112T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml3
113T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml3
114T1073No-11
115T1218.011No-11
116T1133No-11
117T1518.001No-11
118T1063No-11
119T1571No-11
120T1100No-10
121T1505.003No-10
122T1087.002No-10
123T1055No-10
124T1136.002No-10
125T1119No-9
126T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml7
127T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml7
128T1562.001No-9
129T1560No-9
130T1173No-9
131T1564.003No-9
132T1559.002No-9
133T1090.002No-9
134T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml-3
135T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml-3
136T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml-3
137T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml-3
138T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml-3
139T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml-3
140T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml-3
141T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml-3
142T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml-3
143T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml-3
144T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml-3
145T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml-3
146T1143No-9
147T1218.010No-8
148T1548.002No-8
149T1065No-8
150T1219No-8
151T1190No-8
152T1071.004No-8
153T1035No-8
154T1569.002No-8
155T1135No-8
156T1117No-8
157T1132.001No-8
158T1003.004No-8
159T1102.002No-8
160T1552.001No-7
161T1547.009No-7
162T1023No-7
163T1021.004No-7
164T1221No-7
165T1070.001No-7
166T1555No-7
167T1027.005No-7
168T1106No-7
169T1012No-7
170T1007No-7
171T1573.001No-7
172T1066No-7
173T1059.007No-7
174T1069.002No-7
175T1114.002No-6
176T1048.003No-6
177T1009No-6
178T1036.004No-6
179T1003.002No-6
180T1027.001No-6
181T1158No-5
182T1059.006No-5
183T1120No-5
184T1102.001No-5
185T1546.003No-5
186T1223No-5
187T1015Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml2
188T1015Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml2
189T1015Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml2
190T1573.002No-5
191T1562.004No-5
192T1099No-5
193T1218.005No-5
194T1170No-5
195T1074.002No-5
196T1040No-5
197T1546.008No-5
198T1075Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml4
199T1001.002No-5
200T1564.001No-5
201T1090No-5
202T1566.003No-5
203T1070.006No-5
204T1027.003No-5
205T1218.001No-5
206T1055.001No-5
207T1194No-5
208T1084Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml2
209T1084Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml2
210T1084Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml2
211T1550.002No-5
212T1110No-5
213T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml4
214T1078.003No-4
215T1036.002No-4
216T1560.003No-4
217T1094No-4
218T1025No-4
219T1038No-4
220T1561.002No-4
221T1496No-4
222T1124No-4
223T1093No-4
224T1003.005No-4
225T1071.002No-4
226T1574.001No-4
227T1014No-4
228T1487No-4
229T1055.012No-4
230T1570No-4
231T1102Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml3
232T1036.003No-4
233T1020No-3
234T1572No-3
235T1518No-3
236T1053.002No-3
237T1104No-3
238T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml2
239T1542.003No-3
240T1069.001No-3
241T1486No-3
242T1500No-3
243T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml2
244T1071No-3
245T1090.003No-3
246T1098Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml2
247T1078.002No-3
248T1091No-3
249T1550.003No-3
250T1097No-3
251T1110.003No-3
252T1071.003No-3
253T1485No-3
254T1027.004No-3
255T1008No-3
256T1067No-3
257T1039No-3
258T1197No-3
259T1110.002No-3
260T1529No-3
261T1188No-3
262T1003.003No-2
263T1201No-2
264T1564.005No-2
265T1199No-2
266T1069No-2
267T1542.002No-2
268T1090.001No-2
269T1547.004No-2
270T1218.003No-2
271T1059.004No-2
272T1559.001No-2
273T1567.002No-2
274T1125No-2
275T1004No-2
276T1115No-2
277T1565.001No-2
278T1080No-2
279T1218.007No-2
280T1213.002No-2
281T1195.002No-2
282T1210No-2
283T1087.003No-2
284T1055.002No-2
285T1222.002No-2
286T1492No-2
287T1032No-2
288T1176No-2
289T1187No-2
290T1109No-2
291T1137No-2
292T1134.002No-2
293T1480.001No-2
294T1037.001No-2
295T1191No-2
296T1560.002No-2
297T1114.001No-2
298T1568.001No-1
299T1213No-1
300T1037No-1
301T1146No-1
302T1504No-1
303T1134No-1
304T1546.011No-1
305T1036.001No-1
306T1546.009No-1
307T1501No-1
308T1552.004No-1
309T1183No-1
310T1200No-1
311T1552.006No-1
312T1211No-1
313T1070.005No-1
314T1052.001No-1
315T1056.004No-1
316T1001.003No-1
317T1001.001No-1
318T1497.001No-1
319T1552.002No-1
320T1102.003No-1
321T1218.008No-1
322T1042Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml-2
323T1042Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml-2
324T1042Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml-2
325T1216.001No-1
326T1126No-1
327T1098.002No-1
328T1137.002No-1
329T1172No-1
330T1182No-1
331T1527No-1
332T1220No-1
333T1074Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml-1
334T1074Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml-1
335T1092No-1
336T1137.006No-1
337T1562.002No-1
338T1561.001No-1
339T1565.002No-1
340T1053.003No-1
341T1489No-1
342T1558.001No-1
343T1214No-1
344T1556.002No-1
345T1186No-1
346T1543.002No-1
347T1028No-1
348T1010No-1
349T1565.003No-1
350T1090.004No-1
351T1137.001No-1
352T1070.003No-1
353T1482No-1
354T1123No-1
355T1021.005No-1
356T1574.006No-1
357T1534No-1
358T1494No-1
359T1491.001No-1
360T1056.002No-1
361T1568.003No-1
362T1528No-1
363T1145No-1
364T1493No-1
365T1546.001No-1
366T1550.001No-1
367T1001No-1
368T1568.002No-1
369T1070.002No-1
370T1574.012No-1
371T1564.004No-1
372T1055.013No-1
373T1546.012No-1
374T1573No-1
375T1127.001No-1
376T1195No-1
377T1122No-1
378T1488No-1
379T1096No-1
380T1546.015No-1
381T1174No-1
382T1134.001No-1
383T1030No-1
384T1137.004No-1
385T1483No-1
386T1497.002No-1
387T1138Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml-2
388T1138Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml-2
389T1138Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml-2
390T1546.013No-1
391T1026No-1
392T1021.006No-1
393T1078.004No-1