Files
2020-07-10 01:35:55 -04:00

394 lines
17 KiB
CSV

Technique ID,Detection Available,Link,score
T1193,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,49
T1193,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,49
T1566.001,No,-,51
T1204.002,No,-,50
T1027,No,-,48
T1059.001,No,-,44
T1086,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,38
T1086,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,38
T1086,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,38
T1086,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,38
T1086,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,38
T1086,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,38
T1059.003,No,-,41
T1105,No,-,40
T1060,No,-,38
T1547.001,No,-,38
T1071.001,No,-,34
T1070.004,No,-,30
T1107,No,-,30
T1053.005,No,-,28
T1003.001,No,-,27
T1059.005,No,-,26
T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,23
T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,23
T1192,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,23
T1566.002,No,-,24
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2
T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,2
T1083,No,-,23
T1203,No,-,23
T1005,No,-,22
T1057,No,-,22
T1016,No,-,22
T1076,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,18
T1076,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,18
T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,19
T1056.001,No,-,20
T1140,No,-,19
T1018,No,-,19
T1204.001,No,-,19
T1036.005,No,-,19
T1033,No,-,18
T1189,No,-,17
T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,10
T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,10
T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,10
T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,10
T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,10
T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,10
T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,10
T1560.001,No,-,16
T1543.003,No,-,16
T1043,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,2
T1043,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2
T1043,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2
T1043,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2
T1043,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2
T1043,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,2
T1043,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,2
T1043,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,2
T1043,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,2
T1043,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,2
T1043,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2
T1043,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2
T1043,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2
T1043,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,2
T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,13
T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,13
T1555.003,No,-,15
T1503,No,-,15
T1049,No,-,14
T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,13
T1087.001,No,-,14
T1116,No,-,14
T1074.001,No,-,14
T1553.002,No,-,14
T1046,No,-,13
T1027.002,No,-,12
T1113,No,-,12
T1041,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,11
T1045,No,-,12
T1021.002,No,-,11
T1574.002,No,-,11
T1085,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,10
T1059,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,3
T1059,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,3
T1059,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,3
T1059,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3
T1059,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,3
T1059,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,3
T1059,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,3
T1059,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,3
T1073,No,-,11
T1218.011,No,-,11
T1133,No,-,11
T1518.001,No,-,11
T1063,No,-,11
T1571,No,-,11
T1100,No,-,10
T1505.003,No,-,10
T1087.002,No,-,10
T1055,No,-,10
T1136.002,No,-,10
T1119,No,-,9
T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,7
T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,7
T1562.001,No,-,9
T1560,No,-,9
T1173,No,-,9
T1564.003,No,-,9
T1559.002,No,-,9
T1090.002,No,-,9
T1003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,-3
T1003,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,-3
T1003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,-3
T1003,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,-3
T1003,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,-3
T1003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,-3
T1003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,-3
T1003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,-3
T1003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,-3
T1003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,-3
T1003,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,-3
T1003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,-3
T1143,No,-,9
T1218.010,No,-,8
T1548.002,No,-,8
T1065,No,-,8
T1219,No,-,8
T1190,No,-,8
T1071.004,No,-,8
T1035,No,-,8
T1569.002,No,-,8
T1135,No,-,8
T1117,No,-,8
T1132.001,No,-,8
T1003.004,No,-,8
T1102.002,No,-,8
T1552.001,No,-,7
T1547.009,No,-,7
T1023,No,-,7
T1021.004,No,-,7
T1221,No,-,7
T1070.001,No,-,7
T1555,No,-,7
T1027.005,No,-,7
T1106,No,-,7
T1012,No,-,7
T1007,No,-,7
T1573.001,No,-,7
T1066,No,-,7
T1059.007,No,-,7
T1069.002,No,-,7
T1114.002,No,-,6
T1048.003,No,-,6
T1009,No,-,6
T1036.004,No,-,6
T1003.002,No,-,6
T1027.001,No,-,6
T1158,No,-,5
T1059.006,No,-,5
T1120,No,-,5
T1102.001,No,-,5
T1546.003,No,-,5
T1223,No,-,5
T1015,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,2
T1015,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,2
T1015,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,2
T1573.002,No,-,5
T1562.004,No,-,5
T1099,No,-,5
T1218.005,No,-,5
T1170,No,-,5
T1074.002,No,-,5
T1040,No,-,5
T1546.008,No,-,5
T1075,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,4
T1001.002,No,-,5
T1564.001,No,-,5
T1090,No,-,5
T1566.003,No,-,5
T1070.006,No,-,5
T1027.003,No,-,5
T1218.001,No,-,5
T1055.001,No,-,5
T1194,No,-,5
T1084,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,2
T1084,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,2
T1084,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,2
T1550.002,No,-,5
T1110,No,-,5
T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,4
T1078.003,No,-,4
T1036.002,No,-,4
T1560.003,No,-,4
T1094,No,-,4
T1025,No,-,4
T1038,No,-,4
T1561.002,No,-,4
T1496,No,-,4
T1124,No,-,4
T1093,No,-,4
T1003.005,No,-,4
T1071.002,No,-,4
T1574.001,No,-,4
T1014,No,-,4
T1487,No,-,4
T1055.012,No,-,4
T1570,No,-,4
T1102,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,3
T1036.003,No,-,4
T1020,No,-,3
T1572,No,-,3
T1518,No,-,3
T1053.002,No,-,3
T1104,No,-,3
T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,2
T1542.003,No,-,3
T1069.001,No,-,3
T1486,No,-,3
T1500,No,-,3
T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,2
T1071,No,-,3
T1090.003,No,-,3
T1098,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,2
T1078.002,No,-,3
T1091,No,-,3
T1550.003,No,-,3
T1097,No,-,3
T1110.003,No,-,3
T1071.003,No,-,3
T1485,No,-,3
T1027.004,No,-,3
T1008,No,-,3
T1067,No,-,3
T1039,No,-,3
T1197,No,-,3
T1110.002,No,-,3
T1529,No,-,3
T1188,No,-,3
T1003.003,No,-,2
T1201,No,-,2
T1564.005,No,-,2
T1199,No,-,2
T1069,No,-,2
T1542.002,No,-,2
T1090.001,No,-,2
T1547.004,No,-,2
T1218.003,No,-,2
T1059.004,No,-,2
T1559.001,No,-,2
T1567.002,No,-,2
T1125,No,-,2
T1004,No,-,2
T1115,No,-,2
T1565.001,No,-,2
T1080,No,-,2
T1218.007,No,-,2
T1213.002,No,-,2
T1195.002,No,-,2
T1210,No,-,2
T1087.003,No,-,2
T1055.002,No,-,2
T1222.002,No,-,2
T1492,No,-,2
T1032,No,-,2
T1176,No,-,2
T1187,No,-,2
T1109,No,-,2
T1137,No,-,2
T1134.002,No,-,2
T1480.001,No,-,2
T1037.001,No,-,2
T1191,No,-,2
T1560.002,No,-,2
T1114.001,No,-,2
T1568.001,No,-,1
T1213,No,-,1
T1037,No,-,1
T1146,No,-,1
T1504,No,-,1
T1134,No,-,1
T1546.011,No,-,1
T1036.001,No,-,1
T1546.009,No,-,1
T1501,No,-,1
T1552.004,No,-,1
T1183,No,-,1
T1200,No,-,1
T1552.006,No,-,1
T1211,No,-,1
T1070.005,No,-,1
T1052.001,No,-,1
T1056.004,No,-,1
T1001.003,No,-,1
T1001.001,No,-,1
T1497.001,No,-,1
T1552.002,No,-,1
T1102.003,No,-,1
T1218.008,No,-,1
T1042,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2
T1042,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2
T1042,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,-2
T1216.001,No,-,1
T1126,No,-,1
T1098.002,No,-,1
T1137.002,No,-,1
T1172,No,-,1
T1182,No,-,1
T1527,No,-,1
T1220,No,-,1
T1074,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,-1
T1074,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,-1
T1092,No,-,1
T1137.006,No,-,1
T1562.002,No,-,1
T1561.001,No,-,1
T1565.002,No,-,1
T1053.003,No,-,1
T1489,No,-,1
T1558.001,No,-,1
T1214,No,-,1
T1556.002,No,-,1
T1186,No,-,1
T1543.002,No,-,1
T1028,No,-,1
T1010,No,-,1
T1565.003,No,-,1
T1090.004,No,-,1
T1137.001,No,-,1
T1070.003,No,-,1
T1482,No,-,1
T1123,No,-,1
T1021.005,No,-,1
T1574.006,No,-,1
T1534,No,-,1
T1494,No,-,1
T1491.001,No,-,1
T1056.002,No,-,1
T1568.003,No,-,1
T1528,No,-,1
T1145,No,-,1
T1493,No,-,1
T1546.001,No,-,1
T1550.001,No,-,1
T1001,No,-,1
T1568.002,No,-,1
T1070.002,No,-,1
T1574.012,No,-,1
T1564.004,No,-,1
T1055.013,No,-,1
T1546.012,No,-,1
T1573,No,-,1
T1127.001,No,-,1
T1195,No,-,1
T1122,No,-,1
T1488,No,-,1
T1096,No,-,1
T1546.015,No,-,1
T1174,No,-,1
T1134.001,No,-,1
T1030,No,-,1
T1137.004,No,-,1
T1483,No,-,1
T1497.002,No,-,1
T1138,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,-2
T1138,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,-2
T1138,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,-2
T1546.013,No,-,1
T1026,No,-,1
T1021.006,No,-,1
T1078.004,No,-,1