Files
2020-08-04 21:37:21 +00:00

26 KiB

1Technique IDDetection AvailableLinkscore
2T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
3T1102No-0
4T1059.002No-0
5T1009No-0
6T1027.005No-0
7T1495No-0
8T1568No-0
9T1050No-0
10T1567No-0
11T1011.001No-0
12T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml1
13T1003.005No-0
14T1110.002No-0
15T1130No-0
16T1542.001No-0
17T1124No-0
18T1215No-0
19T1164No-0
20T1501No-0
21T1556No-0
22T1176No-0
23T1020No-0
24T1205No-0
25T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
26T1011No-0
27T1018No-0
28T1552.003No-0
29T1053.002No-0
30T1206No-0
31T1107No-0
32T1070.002No-0
33T1570No-0
34T1550.004No-0
35T1110.001No-0
36T1218.010No-0
37T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
38T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
39T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
40T1014No-0
41T1074.002No-0
42T1499.001No-0
43T1558.001No-0
44T1192No-0
45T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
46T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
47T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
48T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
49T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
50T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
51T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
52T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
53T1118No-0
54T1195No-0
55T1042No-0
56T1218.004No-0
57T1498No-0
58T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
59T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
60T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
61T1548.004No-0
62T1574.010No-0
63T1035No-0
64T1061No-0
65T1175No-0
66T1547.008No-0
67T1183No-0
68T1110.004No-0
69T1134.003No-0
70T1037.002No-0
71T1148No-0
72T1064No-0
73T1165No-0
74T1559No-0
75T1546No-0
76T1574No-0
77T1187No-0
78T1046No-0
79T1106No-0
80T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
81T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
82T1493No-0
83T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
84T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
85T1218.002No-0
86T1563.001No-0
87T1565No-0
88T1070.004No-0
89T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
90T1537No-0
91T1218.009No-0
92T1480No-0
93T1218.005No-0
94T1219No-0
95T1025No-0
96T1032No-0
97T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
98T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml1
99T1029No-0
100T1087No-0
101T1184No-0
102T1189No-0
103T1002No-0
104T1113No-0
105T1561.001No-0
106T1562.002No-0
107T1547.007No-0
108T1127No-0
109T1186No-0
110T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml1
111T1216No-0
112T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
113T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
114T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
115T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
116T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
117T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
118T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
119T1555.001No-0
120T1063No-0
121T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
122T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
123T1562.007No-0
124T1069.003No-0
125T1137No-0
126T1114.003No-0
127T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
128T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
129T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
130T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
131T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
132T1098.004No-0
133T1487No-0
134T1132.001No-0
135T1177No-0
136T1134No-0
137T1017No-0
138T1059.005No-0
139T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
140T1131No-0
141T1055.003No-0
142T1195.003No-0
143T1548No-0
144T1027.004No-0
145T1077No-0
146T1217No-0
147T1557.001No-0
148T1547.003No-0
149T1496No-0
150T1578.004No-0
151T1539No-0
152T1059.006No-0
153T1037.003No-0
154T1564.005No-0
155T1126No-0
156T1074No-0
157T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
158T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
159T1001No-0
160T1559.002No-0
161T1223No-0
162T1573.002No-0
163T1090.003No-0
164T1552.005No-0
165T1172No-0
166T1542.003No-0
167T1099No-0
168T1073No-0
169T1574.001No-0
170T1504No-0
171T1213No-0
172T1133No-0
173T1556.001No-0
174T1216.001No-0
175T1055.014No-0
176T1008No-0
177T1208No-0
178T1499.003No-0
179T1569.001No-0
180T1499.004No-0
181T1547.005No-0
182T1076No-0
183T1529No-0
184T1210No-0
185T1052.001No-0
186T1111No-0
187T1102.002No-0
188T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
189T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
190T1559.001No-0
191T1140No-0
192T1055.001No-0
193T1499.002No-0
194T1547.011No-0
195T1211No-0
196T1120No-0
197T1497.003No-0
198T1062No-0
199T1080No-0
200T1137.002No-0
201T1005No-0
202T1069.001No-0
203T1505.001No-0
204T1205.001No-0
205T1560.002No-0
206T1097No-0
207T1045No-0
208T1568.001No-0
209T1123No-0
210T1139No-0
211T1166No-0
212T1197No-0
213T1137.001No-0
214T1567.001No-0
215T1104No-0
216T1049No-0
217T1196No-0
218T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
219T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
220T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
221T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
222T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
223T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
224T1089No-0
225T1514No-0
226T1560.001No-0
227T1115No-0
228T1528No-0
229T1056.004No-0
230T1218.007No-0
231T1546.010No-0
232T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
233T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
234T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
235T1066No-0
236T1531No-0
237T1110.003No-0
238T1218.001No-0
239T1548.001No-0
240T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
241T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
242T1574.007No-0
243T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml3
244T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml3
245T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml3
246T1505.002No-0
247T1213.001No-0
248T1105No-0
249T1546.005No-0
250T1546.004No-0
251T1055.009No-0
252T1007No-0
253T1564.001No-0
254T1003.008No-0
255T1491.002No-0
256T1546.003No-0
257T1146No-0
258T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
259T1101No-0
260T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
261T1574.002No-0
262T1169No-0
263T1546.012No-0
264T1021.003No-0
265T1209No-0
266T1547.010No-0
267T1167No-0
268T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
269T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
270T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
271T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
272T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
273T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
274T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
275T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
276T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
277T1056.002No-0
278T1564.006No-0
279T1574.011No-0
280T1573No-0
281T1490No-0
282T1037.005No-0
283T1542.002No-0
284T1188No-0
285T1142No-0
286T1039No-0
287T1543.002No-0
288T1553.002No-0
289T1556.003No-0
290T1547No-0
291T1578No-0
292T1578.001No-0
293T1053.003No-0
294T1561No-0
295T1074.001No-0
296T1151No-0
297T1034No-0
298T1134.005No-0
299T1055.004No-0
300T1543.001No-0
301T1027.003No-0
302T1550.003No-0
303T1564.003No-0
304T1013No-0
305T1518.001No-0
306T1505.003No-0
307T1572No-0
308T1534No-0
309T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
310T1036.002No-0
311T1483No-0
312T1022No-0
313T1574.004No-0
314T1558No-0
315T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
316T1546.009No-0
317T1574.012No-0
318T1218No-0
319T1558.002No-0
320T1036.003No-0
321T1552.004No-0
322T1560No-0
323T1564.002No-0
324T1562.003No-0
325T1135No-0
326T1212No-0
327T1555.003No-0
328T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
329T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml1
330T1546.015No-0
331T1505No-0
332T1059No-0
333T1003.006No-0
334T1114No-0
335T1555.002No-0
336T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
337T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
338T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
339T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
340T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
341T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
342T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
343T1128No-0
344T1060No-0
345T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
346T1134.004No-0
347T1553No-0
348T1547.004No-0
349T1056No-0
350T1001.003No-0
351T1083No-0
352T1498.001No-0
353T1553.003No-0
354T1093No-0
355T1198No-0
356T1094No-0
357T1218.008No-0
358T1199No-0
359T1090.004No-0
360T1087.003No-0
361T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
362T1055.012No-0
363T1001.002No-0
364T1182No-0
365T1562.006No-0
366T1040No-0
367T1574.006No-0
368T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml2
369T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml2
370T1043No-0
371T1174No-0
372T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml1
373T1090.001No-0
374T1546.013No-0
375T1003.007No-0
376T1564.004No-0
377T1168No-0
378T1552No-0
379T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
380T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
381T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
382T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
383T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml13
384T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml13
385T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml13
386T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml13
387T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml13
388T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml13
389T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml13
390T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml13
391T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml13
392T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml13
393T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml13
394T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml13
395T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml13
396T1059.007No-0
397T1162No-0
398T1546.006No-0
399T1087.004No-0
400T1117No-0
401T1087.001No-0
402T1218.003No-0
403T1547.006No-0
404T1055.005No-0
405T1156No-0
406T1001.001No-0
407T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
408T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
409T1087.002No-0
410T1491No-0
411T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
412T1053.004No-0
413T1143No-0
414T1037.001No-0
415T1055.011No-0
416T1021No-0
417T1222.002No-0
418T1030No-0
419T1054No-0
420T1568.003No-0
421T1053.001No-0
422T1132No-0
423T1070.006No-0
424T1147No-0
425T1085No-0
426T1173No-0
427T1024No-0
428T1486No-0
429T1181No-0
430T1567.002No-0
431T1573.001No-0
432T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
433T1122No-0
434T1522No-0
435T1121No-0
436T1134.002No-0
437T1557No-0
438T1191No-0
439T1550No-0
440T1546.007No-0
441T1056.003No-0
442T1548.002No-0
443T1565.003No-0
444T1037.004No-0
445T1084No-0
446T1048.002No-0
447T1569No-0
448T1500No-0
449T1563.002No-0
450T1553.001No-0
451T1015No-0
452T1137.005No-0
453T1202No-0
454T1027.002No-0
455T1144No-0
456T1547.002No-0
457T1149No-0
458T1538No-0
459T1220No-0
460T1489No-0
461T1550.001No-0
462T1556.002No-0
463T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
464T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
465T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
466T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
467T1010No-0
468T1116No-0
469T1574.005No-0
470T1036.004No-0
471T1543.004No-0
472T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml4
473T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml4
474T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml4
475T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml4
476T1102.003No-0
477T1482No-0
478T1499No-0
479T1578.002No-0
480T1204.001No-0
481T1194No-0
482T1016No-0
483T1071.003No-0
484T1075No-0
485T1051No-0
486T1160No-0
487T1497.002No-0
488T1163No-0
489T1023No-0
490T1222No-0
491T1561.002No-0
492T1200No-0
493T1055.008No-0
494T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml2
495T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml2
496T1518No-0
497T1213.002No-0
498T1031No-0
499T1036.006No-0
500T1152No-0
501T1178No-0
502T1098.001No-0
503T1019No-0
504T1154No-0
505T1185No-0
506T1527No-0
507T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
508T1494No-0
509T1056.001No-0
510T1070.003No-0
511T1096No-0
512T1214No-0
513T1492No-0
514T1021.006No-0
515T1108No-0
516T1180No-0
517T1484No-0
518T1136.002No-0
519T1488No-0
520T1086No-0
521T1055.013No-0
522T1502No-0
523T1044No-0
524T1055No-0
525T1552.001No-0
526T1546.002No-0
527T1157No-0
528T1134.001No-0
529T1574.008No-0
530T1006No-0
531T1090.002No-0
532T1578.003No-0
533T1555No-0
534T1201No-0
535T1207No-0
536T1021.005No-0
537T1547.009No-0
538T1138No-0
539T1221No-0
540T1125No-0
541T1026No-0
542T1161No-0
543T1070.005No-0
544T1069.002No-0
545T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
546T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
547T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
548T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
549T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
550T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
551T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
552T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
553T1204No-0
554T1195.001No-0
555T1033No-0
556T1110No-0
557T1037No-0
558T1090No-0
559T1565.002No-0
560T1542No-0
561T1562No-0
562T1568.002No-0
563T1565.001No-0
564T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
565T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
566T1052No-0
567T1071No-0
568T1564No-0
569T1503No-0
570T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
571T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
572T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
573T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
574T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
575T1519No-0
576T1158No-0
577T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
578T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
579T1038No-0
580T1004No-0
581T1067No-0
582T1055.002No-0
583T1109No-0
584T1081No-0
585T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
586T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
587T1506No-0
588T1098.003No-0
589T1098.002No-0
590T1048.001No-0
591T1137.003No-0
592T1150No-0
593T1057No-0
594T1137.004No-0
595T1103No-0
596T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
597T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
598T1195.002No-0
599T1179No-0
600T1058No-0
601T1091No-0
602T1563No-0
603T1021.004No-0
604T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
605T1536No-0
606T1069No-0
607T1036.001No-0
608T1092No-0
609T1129No-0
610T1132.002No-0
611T1159No-0
612T1497.001No-0
613T1065No-0
614T1552.002No-0
615T1560.003No-0
616T1003No-0
617T1170No-0
618T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
619T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
620T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
621T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
622T1136.003No-0
623T1098No-0
624T1491.001No-0
625T1053No-0
626T1027.001No-0
627T1137.006No-0
628T1127.001No-0
629T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
630T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
631T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
632T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
633T1543No-0
634T1171No-0
635T1059.004No-0
636T1155No-0
637T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
638T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
639T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
640T1153No-0
641T1145No-0
642T1100No-0
643T1079No-0
644T1480.001No-0
645T1552.006No-0
646T1548.003No-0
647T1041No-0
648T1193No-0
649T1036.005No-0
650T1554No-0
651T1571No-0
652T1102.001No-0
653T1141No-0
654T1119No-0
655T1028No-0
656T1497No-0
657T1012No-0
658T1546.014No-0
659T1088No-0
660T1003.004No-0