mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
845 lines
30 KiB
JSON
845 lines
30 KiB
JSON
{
|
|
"version": "3.0",
|
|
"name": "Detection Coverage",
|
|
"description": "security-content detection coverage",
|
|
"domain": "mitre-enterprise",
|
|
"techniques": [
|
|
{
|
|
"techniqueID": "T1218.011",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1078",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1204.002",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1485",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml"
|
|
},
|
|
{
|
|
"techniqueID": "T1114.002",
|
|
"score": 2,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1535",
|
|
"score": 8,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1546.011",
|
|
"score": 3,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1071.001",
|
|
"score": 2,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml"
|
|
},
|
|
{},
|
|
{
|
|
"techniqueID": "T1021.002",
|
|
"score": 2,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1027",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1546.001",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml"
|
|
},
|
|
{
|
|
"techniqueID": "T1566",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1070",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml"
|
|
},
|
|
{},
|
|
{
|
|
"techniqueID": "T1059.003",
|
|
"score": 7,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1569.002",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml"
|
|
},
|
|
{
|
|
"techniqueID": "T1566.003",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1526",
|
|
"score": 5,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1072",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1048.003",
|
|
"score": 2,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1068",
|
|
"score": 2,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1047",
|
|
"score": 6,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1136.001",
|
|
"score": 3,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1095",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml"
|
|
},
|
|
{
|
|
"techniqueID": "T1550.002",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml"
|
|
},
|
|
{},
|
|
{
|
|
"techniqueID": "T1530",
|
|
"score": 3,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1558.003",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml"
|
|
},
|
|
{},
|
|
{
|
|
"techniqueID": "T1553.004",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1071.004",
|
|
"score": 7,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml"
|
|
},
|
|
{
|
|
"techniqueID": "T1203",
|
|
"score": 2,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1114.001",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1222.001",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1071.002",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml"
|
|
},
|
|
{
|
|
"techniqueID": "T1136",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1003.001",
|
|
"score": 7,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1574.009",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1546.008",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1190",
|
|
"score": 2,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1048",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1547.001",
|
|
"score": 3,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml"
|
|
},
|
|
{
|
|
"techniqueID": "T1566.002",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml"
|
|
},
|
|
{
|
|
"techniqueID": "T1078.004",
|
|
"score": 13,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1070.001",
|
|
"score": 2,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1543.003",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1003.002",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1021.001",
|
|
"score": 4,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1003.003",
|
|
"score": 4,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1082",
|
|
"score": 2,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1078.002",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1059.001",
|
|
"score": 8,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1566.001",
|
|
"score": 2,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1036",
|
|
"score": 5,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1112",
|
|
"score": 2,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1525",
|
|
"score": 2,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1078.003",
|
|
"score": 2,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1498.002",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1053.005",
|
|
"score": 4,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1078.001",
|
|
"score": 4,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{
|
|
"techniqueID": "T1562.001",
|
|
"score": 2,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml"
|
|
},
|
|
{
|
|
"techniqueID": "T1562.004",
|
|
"score": 1,
|
|
"comment": "https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml"
|
|
},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{},
|
|
{}
|
|
],
|
|
"gradient": {
|
|
"colors": [
|
|
"##ffffff",
|
|
"#8ec843"
|
|
],
|
|
"minValue": 0,
|
|
"maxValue": 0
|
|
},
|
|
"filters": {
|
|
"platforms": [
|
|
"Windows",
|
|
"Linux",
|
|
"macOS",
|
|
"AWS",
|
|
"GCP",
|
|
"Azure",
|
|
"Office 365",
|
|
"SaaS"
|
|
]
|
|
},
|
|
"legendItems": [
|
|
{
|
|
"label": "NO available detections",
|
|
"color": "#ffffff"
|
|
},
|
|
{
|
|
"label": "Available detections",
|
|
"color": "#8ec843"
|
|
}
|
|
],
|
|
"showTacticRowBackground": true,
|
|
"tacticRowBackground": "#dddddd",
|
|
"sorting": 3
|
|
} |