Files
splunk-security_content/docs/_pages/stories.md
2022-03-09 11:36:28 +01:00

6.4 KiB

title, layout, permalink, collection, classes, sidebar
title layout permalink collection classes sidebar
Analytic Stories collection /stories/ stories wide
nav
stories
Name Technique Tactic
AWS Cross Account Activity None None
AWS Cryptomining None None
AWS IAM Privilege Escalation None None
AWS Network ACL Activity None None
AWS Security Hub Alerts None None
AWS Suspicious Provisioning Activities None None
AWS User Monitoring None None
Active Directory Discovery None None
Active Directory Kerberos Attacks None None
Active Directory Lateral Movement None None
Active Directory Password Spraying None None
Apache Struts Vulnerability None None
Asset Tracking None None
BITS Jobs None None
Baron Samedit CVE-2021-3156 None None
BlackMatter Ransomware None None
Brand Monitoring None None
Clop Ransomware None None
Cloud Cryptomining None None
Cloud Federated Credential Abuse None None
Cobalt Strike None None
ColdRoot MacOS RAT None None
Collection and Staging None None
Command and Control None None
Common Phishing Frameworks None None
Container Implantation Monitoring and Investigation None None
Credential Dumping None None
DHS Report TA18-074A None None
DNS Amplification Attacks None None
DNS Hijacking None None
DarkSide Ransomware None None
Data Destruction None None
Data Exfiltration None None
Data Protection None None
Deobfuscate-Decode Files or Information None None
Detect Zerologon Attack None None
Dev Sec Ops None None
Disabling Security Tools None None
Domain Trust Discovery None None
Dynamic DNS None None
Emotet Malware DHS Report TA18-201A None None
F5 TMUI RCE CVE-2020-5902 None None
FIN7 None None
GCP Cross Account Activity None None
HAFNIUM Group None None
Hermetic Wiper None None
Hidden Cobra Malware None None
Host Redirection None None
IcedID None None
Information Sabotage None None
Ingress Tool Transfer None None
JBoss Vulnerability None None
Kubernetes Scanning Activity None None
Kubernetes Sensitive Object Access Activity None None
Kubernetes Sensitive Role Activity None None
Linux Persistence Techniques None None
Linux Post-Exploitation None None
Linux Privilege Escalation None None
Living Off The Land None None
Log4Shell CVE-2021-44228 None None
Malicious PowerShell None None
Masquerading - Rename System Utilities None None
Meterpreter None None
Microsoft MSHTML Remote Code Execution CVE-2021-40444 None None
Monitor Backup Solution None None
Monitor for Unauthorized Software None None
Monitor for Updates None None
NOBELIUM Group None None
Netsh Abuse None None
Network Discovery None None
Office 365 Detections None None
Orangeworm Attack Group None None
PetitPotam NTLM Relay on Active Directory Certificate Services None None
Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns None None
PrintNightmare CVE-2021-34527 None None
Prohibited Traffic Allowed or Protocol Mismatch None None
ProxyShell None None
Ransomware None None
Ransomware Cloud None None
Remcos None None
Revil Ransomware None None
Router and Infrastructure Security None None
Ryuk Ransomware None None
SQL Injection None None
SamSam Ransomware None None
Signed Binary Proxy Execution InstallUtil None None
Silver Sparrow None None
Spearphishing Attachments None None
Spectre And Meltdown Vulnerabilities None None
Splunk Enterprise Vulnerability None None
Splunk Enterprise Vulnerability CVE-2018-11409 None None
Suspicious AWS EC2 Activities None None
Suspicious AWS Login Activities None None
Suspicious AWS S3 Activities None None
Suspicious AWS Traffic None None
Suspicious Cloud Authentication Activities None None
Suspicious Cloud Instance Activities None None
Suspicious Cloud Provisioning Activities None None
Suspicious Cloud User Activities None None
Suspicious Command-Line Executions None None
Suspicious Compiled HTML Activity None None
Suspicious DNS Traffic None None
Suspicious Emails None None
Suspicious GCP Storage Activities None None
Suspicious MSHTA Activity None None
Suspicious Okta Activity None None
Suspicious Regsvcs Regasm Activity None None
Suspicious Regsvr32 Activity None None
Suspicious Rundll32 Activity None None
Suspicious WMI Use None None
Suspicious Windows Registry Activities None None
Suspicious Zoom Child Processes None None
Trickbot None None
Trusted Developer Utilities Proxy Execution None None
Trusted Developer Utilities Proxy Execution MSBuild None None
Unusual AWS EC2 Modifications None None
Unusual Processes None None
Use of Cleartext Protocols None None
Web Fraud Detection None None
WhisperGate None None
Windows DNS SIGRed CVE-2020-1350 None None
Windows Defense Evasion Tactics None None
Windows Discovery Techniques None None
Windows File Extension and Association Abuse None None
Windows Log Manipulation None None
Windows Persistence Techniques None None
Windows Privilege Escalation None None
Windows Service Abuse None None
XMRig None None
sAMAccountName Spoofing and Domain Controller Impersonation None None