Files
splunk-security_content/docs/mitre-map/coverage.csv
2020-10-20 22:29:07 +00:00

7.7 MiB

1Technique IDDetection AvailableLinkscore
2T1502No-0
3T1531No-0
4T1124No-0
5T1578.004No-0
6T1574.008No-0
7T1008No-0
8T1040No-0
9T1573No-0
10T1194No-0
11T1191No-0
12T1131No-0
13T1036.004No-0
14T1157No-0
15T1027.002No-0
16T1088No-0
17T1574.005No-0
18T1542.001No-0
19T1519No-0
20T1214No-0
21T1114.003No-0
22T1070.006No-0
23T1101No-0
24T1546.004No-0
25T1018No-0
26T1098No-0
27T1070.003No-0
28T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
29T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
30T1560.003No-0
31T1574.007No-0
32T1218.007No-0
33T1494No-0
34T1003.004No-0
35T1547.009No-0
36T1069.001No-0
37T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
38T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
39T1121No-0
40T1198No-0
41T1055.009No-0
42T1069.003No-0
43T1166No-0
44T1087.004No-0
45T1045No-0
46T1505.001No-0
47T1569.001No-0
48T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
49T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
50T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
51T1028No-0
52T1552.004No-0
53T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
54T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
55T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
56T1134.004No-0
57T1548No-0
58T1073No-0
59T1167No-0
60T1206No-0
61T1208No-0
62T1001No-0
63T1134.001No-0
64T1148No-0
65T1498.001No-0
66T1563.002No-0
67T1564No-0
68T1561.002No-0
69T1518.001No-0
70T1219No-0
71T1149No-0
72T1574.001No-0
73T1074.001No-0
74T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
75T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
76T1141No-0
77T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
78T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
79T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
80T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
81T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
82T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
83T1039No-0
84T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
85T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
86T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
87T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
88T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
89T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
90T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
91T1546.003No-0
92T1547No-3
93T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
94T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
95T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
96T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
97T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
98T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
99T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
100T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
101T1568.002No-0
102T1193No-0
103T1548.001No-0
104T1107No-0
105T1553.002No-0
106T1505No-0
107T1480.001No-0
108T1161No-0
109T1568.003No-0
110T1013No-0
111T1556.002No-0
112T1021.004No-0
113T1027.003No-0
114T1056No-0
115T1547.003No-0
116T1094No-0
117T1162No-0
118T1074No-0
119T1030No-0
120T1564.006No-0
121T1564.001No-0
122T1053.001No-0
123T1204.001No-0
124T1567.001No-0
125T1113No-0
126T1202No-0
127T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
128T1023No-0
129T1090.002No-0
130T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
131T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
132T1578.003No-0
133T1178No-0
134T1056.001No-0
135T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
136T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
137T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
138T1565.002No-0
139T1038No-0
140T1096No-0
141T1538No-0
142T1488No-0
143T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
144T1127No-0
145T1506No-0
146T1010No-0
147T1048.001No-0
148T1493No-0
149T1207No-0
150T1102.003No-0
151T1492No-0
152T1036.003No-0
153T1543.002No-0
154T1059.007No-0
155T1055.012No-0
156T1136.002No-0
157T1111No-0
158T1213.002No-0
159T1495No-0
160T1186No-0
161T1559.002No-0
162T1151No-0
163T1154No-0
164T1098.002No-0
165T1026No-0
166T1036.002No-0
167T1499No-0
168T1574.004No-0
169T1059.005No-0
170T1056.003No-0
171T1222.002No-0
172T1001.002No-0
173T1218.003No-0
174T1578.001No-0
175T1565No-0
176T1547.004No-0
177T1547.006No-0
178T1527No-0
179T1213.001No-0
180T1037No-0
181T1087.001No-0
182T1069.002No-0
183T1195.002No-0
184T1548.003No-0
185T1547.010No-0
186T1183No-0
187T1137.003No-0
188T1514No-0
189T1122No-0
190T1563.001No-0
191T1552No-0
192T1550.003No-0
193T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
194T1536No-0
195T1080No-0
196T1037.003No-0
197T1558No-1
198T1138No-0
199T1127.001No-0
200T1574.011No-0
201T1218.004No-0
202T1087.003No-0
203T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
204T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
205T1553No-1
206T1546.010No-0
207T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
208T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
209T1567No-0
210T1482No-0
211T1564.003No-0
212T1216.001No-0
213T1174No-0
214T1064No-0
215T1217No-0
216T1110No-0
217T1546No-5
218T1102.001No-0
219T1558.002No-0
220T1032No-0
221T1145No-0
222T1543.004No-0
223T1037.004No-0
224T1552.003No-0
225T1574.012No-0
226T1043No-0
227T1044No-0
228T1063No-0
229T1216No-0
230T1550.001No-0
231T1173No-0
232T1192No-0
233T1152No-0
234T1119No-0
235T1546.014No-0
236T1164No-0
237T1197No-0
238T1135No-0
239T1098.004No-0
240T1055.013No-0
241T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
242T1550Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_get_session_token_abuse.yml2
243T1539No-0
244T1497No-0
245T1001.003No-0
246T1561.001No-0
247T1123No-0
248T1486No-0
249T1014No-0
250T1099No-0
251T1562.002No-0
252T1102.002No-0
253T1086No-0
254T1555.001No-0
255T1489No-0
256T1069No-0
257T1182No-0
258T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
259T1204No-1
260T1115No-0
261T1105No-0
262T1079No-0
263T1056.004No-0
264T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml5
265T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_gcp_storage_access_from_a_new_ip.yml5
266T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_gcp_storage_buckets.yml5
267T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml5
268T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml5
269T1137.001No-0
270T1137.002No-0
271T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
272T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
273T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
274T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
275T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
276T1133No-0
277T1017No-0
278T1487No-0
279T1501No-0
280T1031No-0
281T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml29
282T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_gcploit_framework.yml29
283T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml29
284T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_assume_role_abuse.yml29
285T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_permanent_key_creation.yml29
286T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml29
287T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_role_creation.yml29
288T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml29
289T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_attach_to_role_policy.yml29
290T1093No-0
291T1181No-0
292T1025No-0
293T1550.004No-0
294T1087.002No-0
295T1005No-0
296T1546.012No-0
297T1110.001No-0
298T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
299T1573.002No-0
300T1153No-0
301T1557.001No-0
302T1491No-0
303T1055.002No-0
304T1051No-0
305T1036.001No-0
306T1021.005No-0
307T1195No-0
308T1574.010No-0
309T1497.003No-0
310T1006No-0
311T1091No-0
312T1546.015No-0
313T1552.005No-0
314T1500No-0
315T1037.002No-0
316T1057No-0
317T1137.004No-0
318T1215No-0
319T1195.001No-0
320T1499.001No-0
321T1129No-0
322T1130No-0
323T1555.002No-0
324T1009No-0
325T1554No-0
326T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
327T1142No-0
328T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
329T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
330T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
331T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
332T1218.005No-0
333T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
334T1177No-0
335T1046No-0
336T1546.007No-0
337T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe___ssa.yml14
338T1042No-0
339T1546.002No-0
340T1499.004No-0
341T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
342T1059.004No-0
343T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml5
344T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dump_lsass_memory_using_comsvcs___ssa.yml5
345T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml5
346T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml5
347T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml5
348T1212No-0
349T1104No-0
350T1097No-0
351T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
352T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
353T1565.003No-0
354T1103No-0
355T1569No-1
356T1553.001No-0
357T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
358T1543.001No-0
359T1560No-0
360T1108No-0
361T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
362T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
363T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
364T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
365T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
366T1065No-0
367T1136.003No-0
368T1150No-0
369T1037.005No-0
370T1021No-6
371T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml5
372T1075No-0
373T1529No-0
374T1170No-0
375T1187No-0
376T1168No-0
377T1134No-0
378T1114No-3
379T1089No-0
380T1499.002No-0
381T1160No-0
382T1218.010No-0
383T1110.004No-0
384T1484No-0
385T1195.003No-0
386T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
387T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
388T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
389T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
390T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
391T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
392T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
393T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
394T1158No-0
395T1496No-0
396T1090.004No-0
397T1147No-0
398T1059.006No-0
399T1055.008No-0
400T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
401T1052No-0
402T1499.003No-0
403T1562.003No-0
404T1201No-0
405T1125No-0
406T1179No-0
407T1556.003No-0
408T1055.004No-0
409T1061No-0
410T1155No-0
411T1085No-0
412T1003.006No-0
413T1029No-0
414T1055.003No-0
415T1213No-0
416T1116No-0
417T1543No-1
418T1109No-0
419T1220No-0
420T1218.009No-0
421T1562No-3
422T1546.005No-0
423T1012No-0
424T1572No-0
425T1037.001No-0
426T1102No-0
427T1002No-0
428T1210Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml1
429T1020No-0
430T1083No-0
431T1081No-0
432T1171No-0
433T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
434T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
435T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
436T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
437T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
438T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
439T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
440T1106No-0
441T1574.002No-0
442T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml3
443T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml3
444T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_zerologon_via_zeek.yml3
445T1480No-0
446T1218.008No-0
447T1560.001No-0
448T1049No-0
449T1027.001No-0
450T1004No-0
451T1062No-0
452T1070.005No-0
453T1218.001No-0
454T1568No-0
455T1552.006No-0
456T1542.003No-0
457T1497.002No-0
458T1132.002No-0
459T1071.003No-0
460T1053No-4
461T1056.002No-0
462T1033No-0
463T1175No-0
464T1011No-0
465T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
466T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
467T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml3
468T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml3
469T1137No-0
470T1126No-0
471T1146No-0
472T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
473T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
474T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
475T1188No-0
476T1491.002No-0
477T1483No-0
478T1564.002No-0
479T1053.003No-0
480T1041No-0
481T1185No-0
482T1087No-0
483T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
484T1205No-0
485T1570No-0
486T1067No-0
487T1003.005No-0
488T1556.001No-0
489T1568.001No-0
490T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
491T1128No-0
492T1084No-0
493T1552.002No-0
494T1199No-0
495T1137.006No-0
496T1548.002No-0
497T1542No-0
498T1137.005No-0
499T1552.001No-0
500T1059No-15
501T1092No-0
502T1559No-0
503T1561No-0
504T1027.004No-0
505T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
506T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
507T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
508T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
509T1053.004No-0
510T1036.005No-0
511T1218.002No-0
512T1055.011No-0
513T1055.001No-0
514T1546.013No-0
515T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
516T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
517T1050No-0
518T1055.005No-0
519T1528No-0
520T1134.003No-0
521T1144No-0
522T1016No-0
523T1076No-0
524T1563No-0
525T1060No-0
526T1021.003No-0
527T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
528T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
529T1098.003No-0
530T1221No-0
531T1140No-0
532T1567.002No-0
533T1139No-0
534T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
535T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
536T1066No-0
537T1100No-0
538T1222No-1
539T1176No-0
540T1497.001No-0
541T1555.003No-0
542T1564.005No-0
543T1074.002No-0
544T1578.002No-0
545T1547.008No-0
546T1504No-0
547T1053.002No-0
548T1090.003No-0
549T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
550T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
551T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
552T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
553T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
554T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
555T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
556T1223No-0
557T1143No-0
558T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
559T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
560T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
561T1565.001No-0
562T1553.003No-0
563T1134.005No-0
564T1077No-0
565T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
566T1548.004No-0
567T1003.007No-0
568T1537No-0
569T1132.001No-0
570T1159No-0
571T1098.001No-0
572T1205.001No-0
573T1574No-1
574T1165No-0
575T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
576T1034No-0
577T1189No-0
578T1015No-0
579T1036.006No-0
580T1024No-0
581T1055.014No-0
582T1003.008No-0
583T1546.009No-0
584T1035No-0
585T1021.006No-0
586T1156No-0
587T1022No-0
588T1547.005No-0
589T1547.002No-0
590T1120No-0
591T1184No-0
592T1054No-0
593T1556No-0
594T1071No-10
595T1070.002No-0
596T1090No-0
597T1132No-0
598T1196No-0
599T1011.001No-0
600T1118No-0
601T1534No-0
602T1134.002No-0
603T1110.003No-0
604T1007No-0
605T1562.007No-0
606T1027.005No-0
607T1558.001No-0
608T1559.001No-0
609T1578No-0
610T1560.002No-0
611T1573.001No-0
612T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
613T1491.001No-0
614T1211No-0
615T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
616T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
617T1564.004No-0
618T1110.002No-0
619T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
620T1562.006No-0
621T1059.002No-0
622T1518No-0
623T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml3
624T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml3
625T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_information_discovery_detection.yml3
626T1163No-0
627T1505.002No-0
628T1547.011No-0
629T1090.001No-0
630T1180No-0
631T1490No-0
632T1058No-0
633T1001.001No-0
634T1542.002No-0
635T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
636T1019No-0
637T1055No-0
638T1574.006No-0
639T1048.002No-0
640T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml13
641T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml13
642T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml13
643T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml13
644T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml13
645T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml13
646T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml13
647T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml13
648T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml13
649T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml13
650T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml13
651T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml13
652T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml13
653T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
654T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
655T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
656T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
657T1209No-0
658T1522No-0
659T1169No-0
660T1503No-0
661T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
662T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
663T1052.001No-0
664T1555No-0
665T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
666T1505.003No-0
667T1546.006No-0
668T1070.004No-0
669T1172No-0
670T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml3
671T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
672T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
673T1117No-0
674T1547.007No-0
675T1218No-1
676T1571No-0
677T1502No-0
678T1531No-0
679T1124No-0
680T1578.004No-0
681T1574.008No-0
682T1008No-0
683T1040No-0
684T1573No-0
685T1194No-0
686T1191No-0
687T1131No-0
688T1036.004No-0
689T1157No-0
690T1027.002No-0
691T1088No-0
692T1574.005No-0
693T1542.001No-0
694T1519No-0
695T1214No-0
696T1114.003No-0
697T1070.006No-0
698T1101No-0
699T1546.004No-0
700T1018No-0
701T1098No-0
702T1070.003No-0
703T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
704T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
705T1560.003No-0
706T1574.007No-0
707T1218.007No-0
708T1494No-0
709T1003.004No-0
710T1547.009No-0
711T1069.001No-0
712T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
713T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
714T1121No-0
715T1198No-0
716T1055.009No-0
717T1069.003No-0
718T1166No-0
719T1087.004No-0
720T1045No-0
721T1505.001No-0
722T1569.001No-0
723T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
724T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
725T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
726T1028No-0
727T1552.004No-0
728T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
729T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
730T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
731T1134.004No-0
732T1548No-0
733T1073No-0
734T1167No-0
735T1206No-0
736T1208No-0
737T1001No-0
738T1134.001No-0
739T1148No-0
740T1498.001No-0
741T1563.002No-0
742T1564No-0
743T1561.002No-0
744T1518.001No-0
745T1219No-0
746T1149No-0
747T1574.001No-0
748T1074.001No-0
749T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
750T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
751T1141No-0
752T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
753T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
754T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
755T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
756T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
757T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
758T1039No-0
759T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
760T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
761T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
762T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
763T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
764T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
765T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
766T1546.003No-0
767T1547No-3
768T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
769T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
770T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
771T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
772T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
773T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
774T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
775T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
776T1568.002No-0
777T1193No-0
778T1548.001No-0
779T1107No-0
780T1553.002No-0
781T1505No-0
782T1480.001No-0
783T1161No-0
784T1568.003No-0
785T1013No-0
786T1556.002No-0
787T1021.004No-0
788T1027.003No-0
789T1056No-0
790T1547.003No-0
791T1094No-0
792T1162No-0
793T1074No-0
794T1030No-0
795T1564.006No-0
796T1564.001No-0
797T1053.001No-0
798T1204.001No-0
799T1567.001No-0
800T1113No-0
801T1202No-0
802T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
803T1023No-0
804T1090.002No-0
805T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
806T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
807T1578.003No-0
808T1178No-0
809T1056.001No-0
810T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
811T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
812T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
813T1565.002No-0
814T1038No-0
815T1096No-0
816T1538No-0
817T1488No-0
818T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
819T1127No-0
820T1506No-0
821T1010No-0
822T1048.001No-0
823T1493No-0
824T1207No-0
825T1102.003No-0
826T1492No-0
827T1036.003No-0
828T1543.002No-0
829T1059.007No-0
830T1055.012No-0
831T1136.002No-0
832T1111No-0
833T1213.002No-0
834T1495No-0
835T1186No-0
836T1559.002No-0
837T1151No-0
838T1154No-0
839T1098.002No-0
840T1026No-0
841T1036.002No-0
842T1499No-0
843T1574.004No-0
844T1059.005No-0
845T1056.003No-0
846T1222.002No-0
847T1001.002No-0
848T1218.003No-0
849T1578.001No-0
850T1565No-0
851T1547.004No-0
852T1547.006No-0
853T1527No-0
854T1213.001No-0
855T1037No-0
856T1087.001No-0
857T1069.002No-0
858T1195.002No-0
859T1548.003No-0
860T1547.010No-0
861T1183No-0
862T1137.003No-0
863T1514No-0
864T1122No-0
865T1563.001No-0
866T1552No-0
867T1550.003No-0
868T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
869T1536No-0
870T1080No-0
871T1037.003No-0
872T1558No-1
873T1138No-0
874T1127.001No-0
875T1574.011No-0
876T1218.004No-0
877T1087.003No-0
878T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
879T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
880T1553No-1
881T1546.010No-0
882T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
883T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
884T1567No-0
885T1482No-0
886T1564.003No-0
887T1216.001No-0
888T1174No-0
889T1064No-0
890T1217No-0
891T1110No-0
892T1546No-5
893T1102.001No-0
894T1558.002No-0
895T1032No-0
896T1145No-0
897T1543.004No-0
898T1037.004No-0
899T1552.003No-0
900T1574.012No-0
901T1043No-0
902T1044No-0
903T1063No-0
904T1216No-0
905T1550.001No-0
906T1173No-0
907T1192No-0
908T1152No-0
909T1119No-0
910T1546.014No-0
911T1164No-0
912T1197No-0
913T1135No-0
914T1098.004No-0
915T1055.013No-0
916T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
917T1550Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_get_session_token_abuse.yml2
918T1539No-0
919T1497No-0
920T1001.003No-0
921T1561.001No-0
922T1123No-0
923T1486No-0
924T1014No-0
925T1099No-0
926T1562.002No-0
927T1102.002No-0
928T1086No-0
929T1555.001No-0
930T1489No-0
931T1069No-0
932T1182No-0
933T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
934T1204No-1
935T1115No-0
936T1105No-0
937T1079No-0
938T1056.004No-0
939T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml5
940T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_gcp_storage_access_from_a_new_ip.yml5
941T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_gcp_storage_buckets.yml5
942T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml5
943T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml5
944T1137.001No-0
945T1137.002No-0
946T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
947T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
948T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
949T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
950T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
951T1133No-0
952T1017No-0
953T1487No-0
954T1501No-0
955T1031No-0
956T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml29
957T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_gcploit_framework.yml29
958T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml29
959T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_assume_role_abuse.yml29
960T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_permanent_key_creation.yml29
961T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml29
962T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_role_creation.yml29
963T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml29
964T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_attach_to_role_policy.yml29
965T1093No-0
966T1181No-0
967T1025No-0
968T1550.004No-0
969T1087.002No-0
970T1005No-0
971T1546.012No-0
972T1110.001No-0
973T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
974T1573.002No-0
975T1153No-0
976T1557.001No-0
977T1491No-0
978T1055.002No-0
979T1051No-0
980T1036.001No-0
981T1021.005No-0
982T1195No-0
983T1574.010No-0
984T1497.003No-0
985T1006No-0
986T1091No-0
987T1546.015No-0
988T1552.005No-0
989T1500No-0
990T1037.002No-0
991T1057No-0
992T1137.004No-0
993T1215No-0
994T1195.001No-0
995T1499.001No-0
996T1129No-0
997T1130No-0
998T1555.002No-0
999T1009No-0
1000T1554No-0
1001T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
1002T1142No-0
1003T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
1004T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
1005T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
1006T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
1007T1218.005No-0
1008T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
1009T1177No-0
1010T1046No-0
1011T1546.007No-0
1012T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe___ssa.yml14
1013T1042No-0
1014T1546.002No-0
1015T1499.004No-0
1016T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
1017T1059.004No-0
1018T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml5
1019T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dump_lsass_memory_using_comsvcs___ssa.yml5
1020T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml5
1021T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml5
1022T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml5
1023T1212No-0
1024T1104No-0
1025T1097No-0
1026T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
1027T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
1028T1565.003No-0
1029T1103No-0
1030T1569No-1
1031T1553.001No-0
1032T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
1033T1543.001No-0
1034T1560No-0
1035T1108No-0
1036T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
1037T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
1038T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
1039T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
1040T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
1041T1065No-0
1042T1136.003No-0
1043T1150No-0
1044T1037.005No-0
1045T1021No-6
1046T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml5
1047T1075No-0
1048T1529No-0
1049T1170No-0
1050T1187No-0
1051T1168No-0
1052T1134No-0
1053T1114No-3
1054T1089No-0
1055T1499.002No-0
1056T1160No-0
1057T1218.010No-0
1058T1110.004No-0
1059T1484No-0
1060T1195.003No-0
1061T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
1062T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
1063T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
1064T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
1065T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
1066T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
1067T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
1068T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
1069T1158No-0
1070T1496No-0
1071T1090.004No-0
1072T1147No-0
1073T1059.006No-0
1074T1055.008No-0
1075T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
1076T1052No-0
1077T1499.003No-0
1078T1562.003No-0
1079T1201No-0
1080T1125No-0
1081T1179No-0
1082T1556.003No-0
1083T1055.004No-0
1084T1061No-0
1085T1155No-0
1086T1085No-0
1087T1003.006No-0
1088T1029No-0
1089T1055.003No-0
1090T1213No-0
1091T1116No-0
1092T1543No-1
1093T1109No-0
1094T1220No-0
1095T1218.009No-0
1096T1562No-3
1097T1546.005No-0
1098T1012No-0
1099T1572No-0
1100T1037.001No-0
1101T1102No-0
1102T1002No-0
1103T1210Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml1
1104T1020No-0
1105T1083No-0
1106T1081No-0
1107T1171No-0
1108T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
1109T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
1110T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
1111T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
1112T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
1113T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
1114T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
1115T1106No-0
1116T1574.002No-0
1117T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml3
1118T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml3
1119T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_zerologon_via_zeek.yml3
1120T1480No-0
1121T1218.008No-0
1122T1560.001No-0
1123T1049No-0
1124T1027.001No-0
1125T1004No-0
1126T1062No-0
1127T1070.005No-0
1128T1218.001No-0
1129T1568No-0
1130T1552.006No-0
1131T1542.003No-0
1132T1497.002No-0
1133T1132.002No-0
1134T1071.003No-0
1135T1053No-4
1136T1056.002No-0
1137T1033No-0
1138T1175No-0
1139T1011No-0
1140T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
1141T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
1142T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml3
1143T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml3
1144T1137No-0
1145T1126No-0
1146T1146No-0
1147T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
1148T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
1149T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
1150T1188No-0
1151T1491.002No-0
1152T1483No-0
1153T1564.002No-0
1154T1053.003No-0
1155T1041No-0
1156T1185No-0
1157T1087No-0
1158T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
1159T1205No-0
1160T1570No-0
1161T1067No-0
1162T1003.005No-0
1163T1556.001No-0
1164T1568.001No-0
1165T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
1166T1128No-0
1167T1084No-0
1168T1552.002No-0
1169T1199No-0
1170T1137.006No-0
1171T1548.002No-0
1172T1542No-0
1173T1137.005No-0
1174T1552.001No-0
1175T1059No-15
1176T1092No-0
1177T1559No-0
1178T1561No-0
1179T1027.004No-0
1180T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
1181T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
1182T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
1183T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
1184T1053.004No-0
1185T1036.005No-0
1186T1218.002No-0
1187T1055.011No-0
1188T1055.001No-0
1189T1546.013No-0
1190T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
1191T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
1192T1050No-0
1193T1055.005No-0
1194T1528No-0
1195T1134.003No-0
1196T1144No-0
1197T1016No-0
1198T1076No-0
1199T1563No-0
1200T1060No-0
1201T1021.003No-0
1202T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
1203T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
1204T1098.003No-0
1205T1221No-0
1206T1140No-0
1207T1567.002No-0
1208T1139No-0
1209T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
1210T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
1211T1066No-0
1212T1100No-0
1213T1222No-1
1214T1176No-0
1215T1497.001No-0
1216T1555.003No-0
1217T1564.005No-0
1218T1074.002No-0
1219T1578.002No-0
1220T1547.008No-0
1221T1504No-0
1222T1053.002No-0
1223T1090.003No-0
1224T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
1225T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
1226T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
1227T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
1228T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
1229T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
1230T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
1231T1223No-0
1232T1143No-0
1233T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
1234T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
1235T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
1236T1565.001No-0
1237T1553.003No-0
1238T1134.005No-0
1239T1077No-0
1240T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
1241T1548.004No-0
1242T1003.007No-0
1243T1537No-0
1244T1132.001No-0
1245T1159No-0
1246T1098.001No-0
1247T1205.001No-0
1248T1574No-1
1249T1165No-0
1250T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
1251T1034No-0
1252T1189No-0
1253T1015No-0
1254T1036.006No-0
1255T1024No-0
1256T1055.014No-0
1257T1003.008No-0
1258T1546.009No-0
1259T1035No-0
1260T1021.006No-0
1261T1156No-0
1262T1022No-0
1263T1547.005No-0
1264T1547.002No-0
1265T1120No-0
1266T1184No-0
1267T1054No-0
1268T1556No-0
1269T1071No-10
1270T1070.002No-0
1271T1090No-0
1272T1132No-0
1273T1196No-0
1274T1011.001No-0
1275T1118No-0
1276T1534No-0
1277T1134.002No-0
1278T1110.003No-0
1279T1007No-0
1280T1562.007No-0
1281T1027.005No-0
1282T1558.001No-0
1283T1559.001No-0
1284T1578No-0
1285T1560.002No-0
1286T1573.001No-0
1287T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
1288T1491.001No-0
1289T1211No-0
1290T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
1291T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
1292T1564.004No-0
1293T1110.002No-0
1294T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
1295T1562.006No-0
1296T1059.002No-0
1297T1518No-0
1298T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml3
1299T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml3
1300T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_information_discovery_detection.yml3
1301T1163No-0
1302T1505.002No-0
1303T1547.011No-0
1304T1090.001No-0
1305T1180No-0
1306T1490No-0
1307T1058No-0
1308T1001.001No-0
1309T1542.002No-0
1310T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
1311T1019No-0
1312T1055No-0
1313T1574.006No-0
1314T1048.002No-0
1315T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml13
1316T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml13
1317T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml13
1318T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml13
1319T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml13
1320T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml13
1321T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml13
1322T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml13
1323T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml13
1324T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml13
1325T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml13
1326T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml13
1327T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml13
1328T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
1329T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
1330T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
1331T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
1332T1209No-0
1333T1522No-0
1334T1169No-0
1335T1503No-0
1336T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
1337T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
1338T1052.001No-0
1339T1555No-0
1340T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
1341T1505.003No-0
1342T1546.006No-0
1343T1070.004No-0
1344T1172No-0
1345T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml3
1346T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
1347T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
1348T1117No-0
1349T1547.007No-0
1350T1218No-1
1351T1571No-0
1352T1502No-0
1353T1531No-0
1354T1124No-0
1355T1578.004No-0
1356T1574.008No-0
1357T1008No-0
1358T1040No-0
1359T1573No-0
1360T1194No-0
1361T1191No-0
1362T1131No-0
1363T1036.004No-0
1364T1157No-0
1365T1027.002No-0
1366T1088No-0
1367T1574.005No-0
1368T1542.001No-0
1369T1519No-0
1370T1214No-0
1371T1114.003No-0
1372T1070.006No-0
1373T1101No-0
1374T1546.004No-0
1375T1018No-0
1376T1098No-0
1377T1070.003No-0
1378T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
1379T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
1380T1560.003No-0
1381T1574.007No-0
1382T1218.007No-0
1383T1494No-0
1384T1003.004No-0
1385T1547.009No-0
1386T1069.001No-0
1387T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
1388T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
1389T1121No-0
1390T1198No-0
1391T1055.009No-0
1392T1069.003No-0
1393T1166No-0
1394T1087.004No-0
1395T1045No-0
1396T1505.001No-0
1397T1569.001No-0
1398T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
1399T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
1400T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
1401T1028No-0
1402T1552.004No-0
1403T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
1404T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
1405T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
1406T1134.004No-0
1407T1548No-0
1408T1073No-0
1409T1167No-0
1410T1206No-0
1411T1208No-0
1412T1001No-0
1413T1134.001No-0
1414T1148No-0
1415T1498.001No-0
1416T1563.002No-0
1417T1564No-0
1418T1561.002No-0
1419T1518.001No-0
1420T1219No-0
1421T1149No-0
1422T1574.001No-0
1423T1074.001No-0
1424T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
1425T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
1426T1141No-0
1427T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
1428T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
1429T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
1430T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
1431T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
1432T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
1433T1039No-0
1434T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
1435T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
1436T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
1437T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
1438T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
1439T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
1440T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
1441T1546.003No-0
1442T1547No-3
1443T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
1444T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
1445T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
1446T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
1447T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
1448T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
1449T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
1450T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
1451T1568.002No-0
1452T1193No-0
1453T1548.001No-0
1454T1107No-0
1455T1553.002No-0
1456T1505No-0
1457T1480.001No-0
1458T1161No-0
1459T1568.003No-0
1460T1013No-0
1461T1556.002No-0
1462T1021.004No-0
1463T1027.003No-0
1464T1056No-0
1465T1547.003No-0
1466T1094No-0
1467T1162No-0
1468T1074No-0
1469T1030No-0
1470T1564.006No-0
1471T1564.001No-0
1472T1053.001No-0
1473T1204.001No-0
1474T1567.001No-0
1475T1113No-0
1476T1202No-0
1477T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
1478T1023No-0
1479T1090.002No-0
1480T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
1481T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
1482T1578.003No-0
1483T1178No-0
1484T1056.001No-0
1485T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
1486T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
1487T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
1488T1565.002No-0
1489T1038No-0
1490T1096No-0
1491T1538No-0
1492T1488No-0
1493T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
1494T1127No-0
1495T1506No-0
1496T1010No-0
1497T1048.001No-0
1498T1493No-0
1499T1207No-0
1500T1102.003No-0
1501T1492No-0
1502T1036.003No-0
1503T1543.002No-0
1504T1059.007No-0
1505T1055.012No-0
1506T1136.002No-0
1507T1111No-0
1508T1213.002No-0
1509T1495No-0
1510T1186No-0
1511T1559.002No-0
1512T1151No-0
1513T1154No-0
1514T1098.002No-0
1515T1026No-0
1516T1036.002No-0
1517T1499No-0
1518T1574.004No-0
1519T1059.005No-0
1520T1056.003No-0
1521T1222.002No-0
1522T1001.002No-0
1523T1218.003No-0
1524T1578.001No-0
1525T1565No-0
1526T1547.004No-0
1527T1547.006No-0
1528T1527No-0
1529T1213.001No-0
1530T1037No-0
1531T1087.001No-0
1532T1069.002No-0
1533T1195.002No-0
1534T1548.003No-0
1535T1547.010No-0
1536T1183No-0
1537T1137.003No-0
1538T1514No-0
1539T1122No-0
1540T1563.001No-0
1541T1552No-0
1542T1550.003No-0
1543T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
1544T1536No-0
1545T1080No-0
1546T1037.003No-0
1547T1558No-1
1548T1138No-0
1549T1127.001No-0
1550T1574.011No-0
1551T1218.004No-0
1552T1087.003No-0
1553T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
1554T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
1555T1553No-1
1556T1546.010No-0
1557T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
1558T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
1559T1567No-0
1560T1482No-0
1561T1564.003No-0
1562T1216.001No-0
1563T1174No-0
1564T1064No-0
1565T1217No-0
1566T1110No-0
1567T1546No-5
1568T1102.001No-0
1569T1558.002No-0
1570T1032No-0
1571T1145No-0
1572T1543.004No-0
1573T1037.004No-0
1574T1552.003No-0
1575T1574.012No-0
1576T1043No-0
1577T1044No-0
1578T1063No-0
1579T1216No-0
1580T1550.001No-0
1581T1173No-0
1582T1192No-0
1583T1152No-0
1584T1119No-0
1585T1546.014No-0
1586T1164No-0
1587T1197No-0
1588T1135No-0
1589T1098.004No-0
1590T1055.013No-0
1591T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
1592T1550Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_get_session_token_abuse.yml2
1593T1539No-0
1594T1497No-0
1595T1001.003No-0
1596T1561.001No-0
1597T1123No-0
1598T1486No-0
1599T1014No-0
1600T1099No-0
1601T1562.002No-0
1602T1102.002No-0
1603T1086No-0
1604T1555.001No-0
1605T1489No-0
1606T1069No-0
1607T1182No-0
1608T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
1609T1204No-1
1610T1115No-0
1611T1105No-0
1612T1079No-0
1613T1056.004No-0
1614T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml5
1615T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_gcp_storage_access_from_a_new_ip.yml5
1616T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_gcp_storage_buckets.yml5
1617T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml5
1618T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml5
1619T1137.001No-0
1620T1137.002No-0
1621T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
1622T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
1623T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
1624T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
1625T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
1626T1133No-0
1627T1017No-0
1628T1487No-0
1629T1501No-0
1630T1031No-0
1631T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml29
1632T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_gcploit_framework.yml29
1633T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml29
1634T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_assume_role_abuse.yml29
1635T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_permanent_key_creation.yml29
1636T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml29
1637T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_role_creation.yml29
1638T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml29
1639T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_attach_to_role_policy.yml29
1640T1093No-0
1641T1181No-0
1642T1025No-0
1643T1550.004No-0
1644T1087.002No-0
1645T1005No-0
1646T1546.012No-0
1647T1110.001No-0
1648T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
1649T1573.002No-0
1650T1153No-0
1651T1557.001No-0
1652T1491No-0
1653T1055.002No-0
1654T1051No-0
1655T1036.001No-0
1656T1021.005No-0
1657T1195No-0
1658T1574.010No-0
1659T1497.003No-0
1660T1006No-0
1661T1091No-0
1662T1546.015No-0
1663T1552.005No-0
1664T1500No-0
1665T1037.002No-0
1666T1057No-0
1667T1137.004No-0
1668T1215No-0
1669T1195.001No-0
1670T1499.001No-0
1671T1129No-0
1672T1130No-0
1673T1555.002No-0
1674T1009No-0
1675T1554No-0
1676T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
1677T1142No-0
1678T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
1679T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
1680T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
1681T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
1682T1218.005No-0
1683T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
1684T1177No-0
1685T1046No-0
1686T1546.007No-0
1687T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe___ssa.yml14
1688T1042No-0
1689T1546.002No-0
1690T1499.004No-0
1691T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
1692T1059.004No-0
1693T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml5
1694T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dump_lsass_memory_using_comsvcs___ssa.yml5
1695T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml5
1696T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml5
1697T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml5
1698T1212No-0
1699T1104No-0
1700T1097No-0
1701T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
1702T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
1703T1565.003No-0
1704T1103No-0
1705T1569No-1
1706T1553.001No-0
1707T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
1708T1543.001No-0
1709T1560No-0
1710T1108No-0
1711T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
1712T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
1713T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
1714T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
1715T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
1716T1065No-0
1717T1136.003No-0
1718T1150No-0
1719T1037.005No-0
1720T1021No-6
1721T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml5
1722T1075No-0
1723T1529No-0
1724T1170No-0
1725T1187No-0
1726T1168No-0
1727T1134No-0
1728T1114No-3
1729T1089No-0
1730T1499.002No-0
1731T1160No-0
1732T1218.010No-0
1733T1110.004No-0
1734T1484No-0
1735T1195.003No-0
1736T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
1737T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
1738T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
1739T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
1740T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
1741T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
1742T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
1743T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
1744T1158No-0
1745T1496No-0
1746T1090.004No-0
1747T1147No-0
1748T1059.006No-0
1749T1055.008No-0
1750T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
1751T1052No-0
1752T1499.003No-0
1753T1562.003No-0
1754T1201No-0
1755T1125No-0
1756T1179No-0
1757T1556.003No-0
1758T1055.004No-0
1759T1061No-0
1760T1155No-0
1761T1085No-0
1762T1003.006No-0
1763T1029No-0
1764T1055.003No-0
1765T1213No-0
1766T1116No-0
1767T1543No-1
1768T1109No-0
1769T1220No-0
1770T1218.009No-0
1771T1562No-3
1772T1546.005No-0
1773T1012No-0
1774T1572No-0
1775T1037.001No-0
1776T1102No-0
1777T1002No-0
1778T1210Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml1
1779T1020No-0
1780T1083No-0
1781T1081No-0
1782T1171No-0
1783T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
1784T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
1785T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
1786T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
1787T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
1788T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
1789T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
1790T1106No-0
1791T1574.002No-0
1792T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml3
1793T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml3
1794T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_zerologon_via_zeek.yml3
1795T1480No-0
1796T1218.008No-0
1797T1560.001No-0
1798T1049No-0
1799T1027.001No-0
1800T1004No-0
1801T1062No-0
1802T1070.005No-0
1803T1218.001No-0
1804T1568No-0
1805T1552.006No-0
1806T1542.003No-0
1807T1497.002No-0
1808T1132.002No-0
1809T1071.003No-0
1810T1053No-4
1811T1056.002No-0
1812T1033No-0
1813T1175No-0
1814T1011No-0
1815T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
1816T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
1817T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml3
1818T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml3
1819T1137No-0
1820T1126No-0
1821T1146No-0
1822T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
1823T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
1824T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
1825T1188No-0
1826T1491.002No-0
1827T1483No-0
1828T1564.002No-0
1829T1053.003No-0
1830T1041No-0
1831T1185No-0
1832T1087No-0
1833T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
1834T1205No-0
1835T1570No-0
1836T1067No-0
1837T1003.005No-0
1838T1556.001No-0
1839T1568.001No-0
1840T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
1841T1128No-0
1842T1084No-0
1843T1552.002No-0
1844T1199No-0
1845T1137.006No-0
1846T1548.002No-0
1847T1542No-0
1848T1137.005No-0
1849T1552.001No-0
1850T1059No-15
1851T1092No-0
1852T1559No-0
1853T1561No-0
1854T1027.004No-0
1855T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
1856T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
1857T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
1858T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
1859T1053.004No-0
1860T1036.005No-0
1861T1218.002No-0
1862T1055.011No-0
1863T1055.001No-0
1864T1546.013No-0
1865T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
1866T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
1867T1050No-0
1868T1055.005No-0
1869T1528No-0
1870T1134.003No-0
1871T1144No-0
1872T1016No-0
1873T1076No-0
1874T1563No-0
1875T1060No-0
1876T1021.003No-0
1877T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
1878T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
1879T1098.003No-0
1880T1221No-0
1881T1140No-0
1882T1567.002No-0
1883T1139No-0
1884T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
1885T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
1886T1066No-0
1887T1100No-0
1888T1222No-1
1889T1176No-0
1890T1497.001No-0
1891T1555.003No-0
1892T1564.005No-0
1893T1074.002No-0
1894T1578.002No-0
1895T1547.008No-0
1896T1504No-0
1897T1053.002No-0
1898T1090.003No-0
1899T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
1900T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
1901T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
1902T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
1903T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
1904T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
1905T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
1906T1223No-0
1907T1143No-0
1908T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
1909T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
1910T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
1911T1565.001No-0
1912T1553.003No-0
1913T1134.005No-0
1914T1077No-0
1915T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
1916T1548.004No-0
1917T1003.007No-0
1918T1537No-0
1919T1132.001No-0
1920T1159No-0
1921T1098.001No-0
1922T1205.001No-0
1923T1574No-1
1924T1165No-0
1925T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
1926T1034No-0
1927T1189No-0
1928T1015No-0
1929T1036.006No-0
1930T1024No-0
1931T1055.014No-0
1932T1003.008No-0
1933T1546.009No-0
1934T1035No-0
1935T1021.006No-0
1936T1156No-0
1937T1022No-0
1938T1547.005No-0
1939T1547.002No-0
1940T1120No-0
1941T1184No-0
1942T1054No-0
1943T1556No-0
1944T1071No-10
1945T1070.002No-0
1946T1090No-0
1947T1132No-0
1948T1196No-0
1949T1011.001No-0
1950T1118No-0
1951T1534No-0
1952T1134.002No-0
1953T1110.003No-0
1954T1007No-0
1955T1562.007No-0
1956T1027.005No-0
1957T1558.001No-0
1958T1559.001No-0
1959T1578No-0
1960T1560.002No-0
1961T1573.001No-0
1962T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
1963T1491.001No-0
1964T1211No-0
1965T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
1966T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
1967T1564.004No-0
1968T1110.002No-0
1969T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
1970T1562.006No-0
1971T1059.002No-0
1972T1518No-0
1973T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml3
1974T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml3
1975T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_information_discovery_detection.yml3
1976T1163No-0
1977T1505.002No-0
1978T1547.011No-0
1979T1090.001No-0
1980T1180No-0
1981T1490No-0
1982T1058No-0
1983T1001.001No-0
1984T1542.002No-0
1985T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
1986T1019No-0
1987T1055No-0
1988T1574.006No-0
1989T1048.002No-0
1990T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml13
1991T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml13
1992T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml13
1993T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml13
1994T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml13
1995T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml13
1996T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml13
1997T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml13
1998T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml13
1999T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml13
2000T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml13
2001T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml13
2002T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml13
2003T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
2004T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
2005T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
2006T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
2007T1209No-0
2008T1522No-0
2009T1169No-0
2010T1503No-0
2011T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
2012T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
2013T1052.001No-0
2014T1555No-0
2015T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
2016T1505.003No-0
2017T1546.006No-0
2018T1070.004No-0
2019T1172No-0
2020T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml3
2021T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
2022T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
2023T1117No-0
2024T1547.007No-0
2025T1218No-1
2026T1571No-0
2027T1502No-0
2028T1531No-0
2029T1124No-0
2030T1578.004No-0
2031T1574.008No-0
2032T1008No-0
2033T1040No-0
2034T1573No-0
2035T1194No-0
2036T1191No-0
2037T1131No-0
2038T1036.004No-0
2039T1157No-0
2040T1027.002No-0
2041T1088No-0
2042T1574.005No-0
2043T1542.001No-0
2044T1519No-0
2045T1214No-0
2046T1114.003No-0
2047T1070.006No-0
2048T1101No-0
2049T1546.004No-0
2050T1018No-0
2051T1098No-0
2052T1070.003No-0
2053T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
2054T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
2055T1560.003No-0
2056T1574.007No-0
2057T1218.007No-0
2058T1494No-0
2059T1003.004No-0
2060T1547.009No-0
2061T1069.001No-0
2062T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
2063T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
2064T1121No-0
2065T1198No-0
2066T1055.009No-0
2067T1069.003No-0
2068T1166No-0
2069T1087.004No-0
2070T1045No-0
2071T1505.001No-0
2072T1569.001No-0
2073T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
2074T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
2075T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
2076T1028No-0
2077T1552.004No-0
2078T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
2079T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
2080T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
2081T1134.004No-0
2082T1548No-0
2083T1073No-0
2084T1167No-0
2085T1206No-0
2086T1208No-0
2087T1001No-0
2088T1134.001No-0
2089T1148No-0
2090T1498.001No-0
2091T1563.002No-0
2092T1564No-0
2093T1561.002No-0
2094T1518.001No-0
2095T1219No-0
2096T1149No-0
2097T1574.001No-0
2098T1074.001No-0
2099T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
2100T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
2101T1141No-0
2102T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
2103T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
2104T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
2105T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
2106T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
2107T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
2108T1039No-0
2109T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
2110T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
2111T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
2112T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
2113T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
2114T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
2115T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
2116T1546.003No-0
2117T1547No-3
2118T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
2119T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
2120T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
2121T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
2122T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
2123T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
2124T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
2125T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
2126T1568.002No-0
2127T1193No-0
2128T1548.001No-0
2129T1107No-0
2130T1553.002No-0
2131T1505No-0
2132T1480.001No-0
2133T1161No-0
2134T1568.003No-0
2135T1013No-0
2136T1556.002No-0
2137T1021.004No-0
2138T1027.003No-0
2139T1056No-0
2140T1547.003No-0
2141T1094No-0
2142T1162No-0
2143T1074No-0
2144T1030No-0
2145T1564.006No-0
2146T1564.001No-0
2147T1053.001No-0
2148T1204.001No-0
2149T1567.001No-0
2150T1113No-0
2151T1202No-0
2152T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
2153T1023No-0
2154T1090.002No-0
2155T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
2156T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
2157T1578.003No-0
2158T1178No-0
2159T1056.001No-0
2160T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
2161T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
2162T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
2163T1565.002No-0
2164T1038No-0
2165T1096No-0
2166T1538No-0
2167T1488No-0
2168T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
2169T1127No-0
2170T1506No-0
2171T1010No-0
2172T1048.001No-0
2173T1493No-0
2174T1207No-0
2175T1102.003No-0
2176T1492No-0
2177T1036.003No-0
2178T1543.002No-0
2179T1059.007No-0
2180T1055.012No-0
2181T1136.002No-0
2182T1111No-0
2183T1213.002No-0
2184T1495No-0
2185T1186No-0
2186T1559.002No-0
2187T1151No-0
2188T1154No-0
2189T1098.002No-0
2190T1026No-0
2191T1036.002No-0
2192T1499No-0
2193T1574.004No-0
2194T1059.005No-0
2195T1056.003No-0
2196T1222.002No-0
2197T1001.002No-0
2198T1218.003No-0
2199T1578.001No-0
2200T1565No-0
2201T1547.004No-0
2202T1547.006No-0
2203T1527No-0
2204T1213.001No-0
2205T1037No-0
2206T1087.001No-0
2207T1069.002No-0
2208T1195.002No-0
2209T1548.003No-0
2210T1547.010No-0
2211T1183No-0
2212T1137.003No-0
2213T1514No-0
2214T1122No-0
2215T1563.001No-0
2216T1552No-0
2217T1550.003No-0
2218T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
2219T1536No-0
2220T1080No-0
2221T1037.003No-0
2222T1558No-1
2223T1138No-0
2224T1127.001No-0
2225T1574.011No-0
2226T1218.004No-0
2227T1087.003No-0
2228T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
2229T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
2230T1553No-1
2231T1546.010No-0
2232T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
2233T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
2234T1567No-0
2235T1482No-0
2236T1564.003No-0
2237T1216.001No-0
2238T1174No-0
2239T1064No-0
2240T1217No-0
2241T1110No-0
2242T1546No-5
2243T1102.001No-0
2244T1558.002No-0
2245T1032No-0
2246T1145No-0
2247T1543.004No-0
2248T1037.004No-0
2249T1552.003No-0
2250T1574.012No-0
2251T1043No-0
2252T1044No-0
2253T1063No-0
2254T1216No-0
2255T1550.001No-0
2256T1173No-0
2257T1192No-0
2258T1152No-0
2259T1119No-0
2260T1546.014No-0
2261T1164No-0
2262T1197No-0
2263T1135No-0
2264T1098.004No-0
2265T1055.013No-0
2266T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
2267T1550Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_get_session_token_abuse.yml2
2268T1539No-0
2269T1497No-0
2270T1001.003No-0
2271T1561.001No-0
2272T1123No-0
2273T1486No-0
2274T1014No-0
2275T1099No-0
2276T1562.002No-0
2277T1102.002No-0
2278T1086No-0
2279T1555.001No-0
2280T1489No-0
2281T1069No-0
2282T1182No-0
2283T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
2284T1204No-1
2285T1115No-0
2286T1105No-0
2287T1079No-0
2288T1056.004No-0
2289T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml5
2290T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_gcp_storage_access_from_a_new_ip.yml5
2291T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_gcp_storage_buckets.yml5
2292T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml5
2293T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml5
2294T1137.001No-0
2295T1137.002No-0
2296T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
2297T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
2298T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
2299T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
2300T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
2301T1133No-0
2302T1017No-0
2303T1487No-0
2304T1501No-0
2305T1031No-0
2306T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml29
2307T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_gcploit_framework.yml29
2308T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml29
2309T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_assume_role_abuse.yml29
2310T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_permanent_key_creation.yml29
2311T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml29
2312T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_role_creation.yml29
2313T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml29
2314T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_attach_to_role_policy.yml29
2315T1093No-0
2316T1181No-0
2317T1025No-0
2318T1550.004No-0
2319T1087.002No-0
2320T1005No-0
2321T1546.012No-0
2322T1110.001No-0
2323T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
2324T1573.002No-0
2325T1153No-0
2326T1557.001No-0
2327T1491No-0
2328T1055.002No-0
2329T1051No-0
2330T1036.001No-0
2331T1021.005No-0
2332T1195No-0
2333T1574.010No-0
2334T1497.003No-0
2335T1006No-0
2336T1091No-0
2337T1546.015No-0
2338T1552.005No-0
2339T1500No-0
2340T1037.002No-0
2341T1057No-0
2342T1137.004No-0
2343T1215No-0
2344T1195.001No-0
2345T1499.001No-0
2346T1129No-0
2347T1130No-0
2348T1555.002No-0
2349T1009No-0
2350T1554No-0
2351T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
2352T1142No-0
2353T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
2354T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
2355T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
2356T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
2357T1218.005No-0
2358T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
2359T1177No-0
2360T1046No-0
2361T1546.007No-0
2362T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe___ssa.yml14
2363T1042No-0
2364T1546.002No-0
2365T1499.004No-0
2366T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
2367T1059.004No-0
2368T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml5
2369T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dump_lsass_memory_using_comsvcs___ssa.yml5
2370T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml5
2371T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml5
2372T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml5
2373T1212No-0
2374T1104No-0
2375T1097No-0
2376T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
2377T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
2378T1565.003No-0
2379T1103No-0
2380T1569No-1
2381T1553.001No-0
2382T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
2383T1543.001No-0
2384T1560No-0
2385T1108No-0
2386T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
2387T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
2388T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
2389T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
2390T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
2391T1065No-0
2392T1136.003No-0
2393T1150No-0
2394T1037.005No-0
2395T1021No-6
2396T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml5
2397T1075No-0
2398T1529No-0
2399T1170No-0
2400T1187No-0
2401T1168No-0
2402T1134No-0
2403T1114No-3
2404T1089No-0
2405T1499.002No-0
2406T1160No-0
2407T1218.010No-0
2408T1110.004No-0
2409T1484No-0
2410T1195.003No-0
2411T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
2412T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
2413T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
2414T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
2415T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
2416T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
2417T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
2418T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
2419T1158No-0
2420T1496No-0
2421T1090.004No-0
2422T1147No-0
2423T1059.006No-0
2424T1055.008No-0
2425T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
2426T1052No-0
2427T1499.003No-0
2428T1562.003No-0
2429T1201No-0
2430T1125No-0
2431T1179No-0
2432T1556.003No-0
2433T1055.004No-0
2434T1061No-0
2435T1155No-0
2436T1085No-0
2437T1003.006No-0
2438T1029No-0
2439T1055.003No-0
2440T1213No-0
2441T1116No-0
2442T1543No-1
2443T1109No-0
2444T1220No-0
2445T1218.009No-0
2446T1562No-3
2447T1546.005No-0
2448T1012No-0
2449T1572No-0
2450T1037.001No-0
2451T1102No-0
2452T1002No-0
2453T1210Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml1
2454T1020No-0
2455T1083No-0
2456T1081No-0
2457T1171No-0
2458T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
2459T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
2460T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
2461T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
2462T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
2463T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
2464T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
2465T1106No-0
2466T1574.002No-0
2467T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml3
2468T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml3
2469T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_zerologon_via_zeek.yml3
2470T1480No-0
2471T1218.008No-0
2472T1560.001No-0
2473T1049No-0
2474T1027.001No-0
2475T1004No-0
2476T1062No-0
2477T1070.005No-0
2478T1218.001No-0
2479T1568No-0
2480T1552.006No-0
2481T1542.003No-0
2482T1497.002No-0
2483T1132.002No-0
2484T1071.003No-0
2485T1053No-4
2486T1056.002No-0
2487T1033No-0
2488T1175No-0
2489T1011No-0
2490T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
2491T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
2492T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml3
2493T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml3
2494T1137No-0
2495T1126No-0
2496T1146No-0
2497T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
2498T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
2499T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
2500T1188No-0
The file is too large to be shown. View Raw