mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
1542 lines
88 KiB
Plaintext
1542 lines
88 KiB
Plaintext
|
|
[panel_group://workbench_panel_group_aws_cross_account_activity]
|
|
label = AWS Cross Account Activity
|
|
description = Track when a user assumes an IAM role in another AWS account to obtain cross-account access to services and resources in that account. Accessing new roles could be an indication of malicious activity.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_history", "panel://workbench_panel_aws_investigate_user_activities_by_accesskeyid", "panel://workbench_panel_aws_investigate_user_activities_by_source_user"]
|
|
|
|
[panel_group://workbench_panel_group_aws_cryptomining]
|
|
label = AWS Cryptomining
|
|
description = Monitor your AWS EC2 instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or EC2 instances started by previously unseen users are just a few examples of potentially malicious behavior.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_aws_investigate_user_activities_by_arn", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_investigate_aws_activities_via_region_name", "panel://workbench_panel_get_ec2_launch_details", "panel://workbench_panel_get_ec2_instance_details_by_instanceid"]
|
|
|
|
[panel_group://workbench_panel_group_aws_network_acl_activity]
|
|
label = AWS Network ACL Activity
|
|
description = Monitor your AWS network infrastructure for bad configurations and malicious activity. Investigative searches help you probe deeper, when the facts warrant it.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_all_aws_activity_from_ip_address", "panel://workbench_panel_aws_network_interface_details_via_resourceid", "panel://workbench_panel_get_notable_info", "panel://workbench_panel_aws_investigate_user_activities_by_arn", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_dns_traffic_ratio", "panel://workbench_panel_get_process_information_for_port_activity", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_dns_server_history_for_a_host", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info", "panel://workbench_panel_aws_network_acl_details_from_id"]
|
|
|
|
[panel_group://workbench_panel_group_aws_suspicious_provisioning_activities]
|
|
label = AWS Suspicious Provisioning Activities
|
|
description = Monitor your AWS provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your network.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_all_aws_activity_from_ip_address", "panel://workbench_panel_get_all_aws_activity_from_country", "panel://workbench_panel_get_all_aws_activity_from_region", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest", "panel://workbench_panel_get_all_aws_activity_from_city"]
|
|
|
|
[panel_group://workbench_panel_group_aws_user_monitoring]
|
|
label = AWS User Monitoring
|
|
description = Detect and investigate dormant user accounts for your AWS environment that have become active again. Because inactive and ad-hoc accounts are common attack targets, it's critical to enable governance within your environment.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_history", "panel://workbench_panel_investigate_aws_user_activities_by_user_field", "panel://workbench_panel_get_notable_info"]
|
|
|
|
[panel_group://workbench_panel_group_account_monitoring_and_controls]
|
|
label = Account Monitoring and Controls
|
|
description = A common attack technique is to leverage user accounts to gain unauthorized access to the target's network. This Analytic Story minimizes opportunities for attack by helping you actively manage creation/use/dormancy/deletion--the lifecycle of system and application accounts.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_logon_rights_modifications_for_endpoint", "panel://workbench_panel_get_logon_rights_modifications_for_user"]
|
|
|
|
[panel_group://workbench_panel_group_apache_struts_vulnerability]
|
|
label = Apache Struts Vulnerability
|
|
description = Detect and investigate activities--such as unusually long `Content-Type` length, suspicious java classes and web servers executing suspicious processes--consistent with attempts to exploit Apache Struts vulnerabilities.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_investigate_web_posts_from_src", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_investigate_suspicious_strings_in_http_header"]
|
|
|
|
[panel_group://workbench_panel_group_asset_tracking]
|
|
label = Asset Tracking
|
|
description = Keep a careful inventory of every asset on your network to make it easier to detect rogue devices. Unauthorized/unmanaged devices could be an indication of malicious behavior that should be investigated further.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_first_occurrence_and_last_occurrence_of_a_mac_address", "panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_notable_history"]
|
|
|
|
[panel_group://workbench_panel_group_brand_monitoring]
|
|
label = Brand Monitoring
|
|
description = Detect and investigate activity that may indicate that an adversary is using faux domains to mislead users into interacting with malicious infrastructure. Monitor DNS, email, and web traffic for permutations of your brand name.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_emails_from_specific_sender", "panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_email_info", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history"]
|
|
|
|
[panel_group://workbench_panel_group_cloud_cryptomining]
|
|
label = Cloud Cryptomining
|
|
description = Monitor your cloud compute instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or compute instances started by previously unseen users are just a few examples of potentially malicious behavior.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_aws_investigate_user_activities_by_arn", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest", "panel://workbench_panel_investigate_cloud_compute_instance_activities", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_investigate_user_activities_in_single_cloud_region", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_investigate_aws_activities_via_region_name", "panel://workbench_panel_get_ec2_launch_details", "panel://workbench_panel_investigate_user_activities_in_all_cloud_regions", "panel://workbench_panel_get_ec2_instance_details_by_instanceid"]
|
|
|
|
[panel_group://workbench_panel_group_coldroot_macos_rat]
|
|
label = ColdRoot MacOS RAT
|
|
description = Leverage searches that allow you to detect and investigate unusual activities that relate to the ColdRoot Remote Access Trojan that affects MacOS. An example of some of these activities are changing sensative binaries in the MacOS sub-system, detecting process names and executables associated with the RAT, detecting when a keyboard tab is installed on a MacOS machine and more.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_investigate_web_activity_from_src_ip", "panel://workbench_panel_investigate_network_traffic_from_src_ip", "panel://workbench_panel_get_vulnerability_logs_for_endpoint"]
|
|
|
|
[panel_group://workbench_panel_group_collection_and_staging]
|
|
label = Collection and Staging
|
|
description = Monitor for and investigate activities--such as suspicious writes to the Windows Recycling Bin or email servers sending high amounts of traffic to specific hosts, for example--that may indicate that an adversary is harvesting and exfiltrating sensitive data.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_command_and_control]
|
|
label = Command and Control
|
|
description = Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_all_aws_activity_from_ip_address", "panel://workbench_panel_aws_network_interface_details_via_resourceid", "panel://workbench_panel_get_notable_info", "panel://workbench_panel_aws_investigate_user_activities_by_arn", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_dns_traffic_ratio", "panel://workbench_panel_get_process_information_for_port_activity", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_dns_server_history_for_a_host", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info", "panel://workbench_panel_aws_network_acl_details_from_id"]
|
|
|
|
[panel_group://workbench_panel_group_common_phishing_frameworks]
|
|
label = Common Phishing Frameworks
|
|
description = Detect DNS and web requests to fake websites generated by the EvilGinx2 toolkit. These websites are designed to fool unwitting users who have clicked on a malicious link in a phishing email.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_certificate_logs_for_a_domain"]
|
|
|
|
[panel_group://workbench_panel_group_container_implantation_monitoring_and_investigation]
|
|
label = Container Implantation Monitoring and Investigation
|
|
description = Use the searches in this story to monitor your Kubernetes registry repositories for upload, and deployment of potentially vulnerable, backdoor, or implanted containers. These searches provide information on source users, destination path, container names and repository names. The searches provide context to address Mitre T1525 which refers to container implantation upload to a company's repository either in Amazon Elastic Container Registry, Google Container Registry and Azure Container Registry.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_investigate_aws_ecr_container_listing_activity"]
|
|
|
|
[panel_group://workbench_panel_group_credential_dumping]
|
|
label = Credential Dumping
|
|
description = Uncover activity consistent with credential dumping, a technique wherein attackers compromise systems and attempt to obtain and exfiltrate passwords. The threat actors use these pilfered credentials to further escalate privileges and spread throughout a target environment. The included searches in this Analytic Story are designed to identify attempts to credential dumping.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_investigate_failed_logins_for_multiple_destinations", "panel://workbench_panel_investigate_pass_the_ticket_attempts", "panel://workbench_panel_investigate_pass_the_hash_attempts", "panel://workbench_panel_investigate_previous_unseen_user"]
|
|
|
|
[panel_group://workbench_panel_group_dhs_report_ta18_074a]
|
|
label = DHS Report TA18-074A
|
|
description = Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA18-074A. Some of the activities that adversaries used in these compromises included spearfishing attacks, malware, watering-hole domains, many and more.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_process_file_activity", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_registry_activities", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info", "panel://workbench_panel_get_process_information_for_port_activity", "panel://workbench_panel_get_process_registry_activity", "panel://workbench_panel_get_vulnerability_logs_for_endpoint"]
|
|
|
|
[panel_group://workbench_panel_group_dns_amplification_attacks]
|
|
label = DNS Amplification Attacks
|
|
description = DNS poses a serious threat as a Denial of Service (DOS) amplifier, if it responds to `ANY` queries. This Analytic Story can help you detect attackers who may be abusing your company's DNS infrastructure to launch amplification attacks, causing Denial of Service to other victims.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_notable_info"]
|
|
|
|
[panel_group://workbench_panel_group_dns_hijacking]
|
|
label = DNS Hijacking
|
|
description = Secure your environment against DNS hijacks with searches that help you detect and investigate unauthorized changes to DNS records.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_dns_server_history_for_a_host"]
|
|
|
|
[panel_group://workbench_panel_group_data_protection]
|
|
label = Data Protection
|
|
description = Fortify your data-protection arsenal--while continuing to ensure data confidentiality and integrity--with searches that monitor for and help you investigate possible signs of data exfiltration.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_dns_traffic_ratio", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info", "panel://workbench_panel_get_dns_server_history_for_a_host"]
|
|
|
|
[panel_group://workbench_panel_group_disabling_security_tools]
|
|
label = Disabling Security Tools
|
|
description = Looks for activities and techniques associated with the disabling of security tools on a Windows system, such as suspicious `reg.exe` processes, processes launching netsh, and many others.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_dynamic_dns]
|
|
label = Dynamic DNS
|
|
description = Detect and investigate hosts in your environment that may be communicating with dynamic domain providers. Attackers may leverage these services to help them avoid firewall blocks and blacklists.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_dns_traffic_ratio", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_investigate_web_activity_from_src_ip", "panel://workbench_panel_get_dns_server_history_for_a_host"]
|
|
|
|
[panel_group://workbench_panel_group_emotet_malware__dhs_report_ta18_201a_]
|
|
label = Emotet Malware DHS Report TA18-201A
|
|
description = Detect rarely used executables, specific registry paths that may confer malware survivability and persistence, instances where cmd.exe is used to launch script interpreters, and other indicators that the Emotet financial malware has compromised your environment.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_update_logs_for_endpoint", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_registry_activities", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info", "panel://workbench_panel_get_process_information_for_port_activity", "panel://workbench_panel_get_vulnerability_logs_for_endpoint"]
|
|
|
|
[panel_group://workbench_panel_group_f5_tmui_rce_cve_2020_5902]
|
|
label = F5 TMUI RCE CVE-2020-5902
|
|
description = Uncover activity consistent with CVE-2020-5902. Discovered by Positive Technologies researchers, this vulnerability affects F5 BIG-IP, BIG-IQ. and Traffix SDC devices (vulnerable versions in F5 support link below). This vulnerability allows unauthenticated users, along with authenticated users, who have access to the configuration utility to execute system commands, create/delete files, disable services, and/or execute Java code. This vulnerability can result in full system compromise.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info"]
|
|
|
|
[panel_group://workbench_panel_group_hidden_cobra_malware]
|
|
label = Hidden Cobra Malware
|
|
description = Monitor for and investigate activities, including the creation or deletion of hidden shares and file writes, that may be evidence of infiltration by North Korean government-sponsored cybercriminals. Details of this activity were reported in DHS Report TA-18-149A.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_dns_traffic_ratio", "panel://workbench_panel_get_process_information_for_port_activity", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_investigate_successful_remote_desktop_authentications", "panel://workbench_panel_get_process_info", "panel://workbench_panel_get_dns_server_history_for_a_host", "panel://workbench_panel_get_vulnerability_logs_for_endpoint"]
|
|
|
|
[panel_group://workbench_panel_group_host_redirection]
|
|
label = Host Redirection
|
|
description = Detect evidence of tactics used to redirect traffic from a host to a destination other than the one intended--potentially one that is part of an adversary's attack infrastructure. An example is redirecting communications regarding patches and updates or misleading users into visiting a malicious website.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_dns_server_history_for_a_host"]
|
|
|
|
[panel_group://workbench_panel_group_jboss_vulnerability]
|
|
label = JBoss Vulnerability
|
|
description = In March of 2016, adversaries were seen using JexBoss--an open-source utility used for testing and exploiting JBoss application servers. These searches help detect evidence of these attacks, such as network connections to external resources or web services spawning atypical child processes, among others.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_vulnerability_logs_for_endpoint"]
|
|
|
|
[panel_group://workbench_panel_group_kubernetes_scanning_activity]
|
|
label = Kubernetes Scanning Activity
|
|
description = This story addresses detection against Kubernetes cluster fingerprint scan and attack by providing information on items such as source ip, user agent, cluster names.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_gcp_kubernetes_activity_by_src_ip", "panel://workbench_panel_amazon_eks_kubernetes_activity_by_src_ip"]
|
|
|
|
[panel_group://workbench_panel_group_kubernetes_sensitive_object_access_activity]
|
|
label = Kubernetes Sensitive Object Access Activity
|
|
description = This story addresses detection and response of accounts acccesing Kubernetes cluster sensitive objects such as configmaps or secrets providing information on items such as user user, group. object, namespace and authorization reason.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info"]
|
|
|
|
[panel_group://workbench_panel_group_kubernetes_sensitive_role_activity]
|
|
label = Kubernetes Sensitive Role Activity
|
|
description = This story addresses detection and response around Sensitive Role usage within a Kubernetes clusters against cluster resources and namespaces.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info"]
|
|
|
|
[panel_group://workbench_panel_group_lateral_movement]
|
|
label = Lateral Movement
|
|
description = Detect and investigate tactics, techniques, and procedures around how attackers move laterally within the enterprise. Because lateral movement can expose the adversary to detection, it should be an important focus for security analysts.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_investigate_successful_remote_desktop_authentications", "panel://workbench_panel_get_process_info", "panel://workbench_panel_get_process_information_for_port_activity"]
|
|
|
|
[panel_group://workbench_panel_group_malicious_powershell]
|
|
label = Malicious PowerShell
|
|
description = Attackers are finding stealthy ways "live off the land," leveraging utilities and tools that come standard on the endpoint--such as PowerShell--to achieve their goals without downloading binary files. These searches can help you detect and investigate PowerShell command-line options that may be indicative of malicious intent.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_monitor_backup_solution]
|
|
label = Monitor Backup Solution
|
|
description = Address common concerns when monitoring your backup processes. These searches can help you reduce risks from ransomware, device theft, or denial of physical access to a host by backing up data on endpoints.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_history", "panel://workbench_panel_all_backup_logs_for_host", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_risk_modifiers_for_endpoint"]
|
|
|
|
[panel_group://workbench_panel_group_monitor_for_unauthorized_software]
|
|
label = Monitor for Unauthorized Software
|
|
description = Identify and investigate prohibited/unauthorized software or processes that may be concealing malicious behavior within your environment.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_update_logs_for_endpoint", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info", "panel://workbench_panel_get_vulnerability_logs_for_endpoint"]
|
|
|
|
[panel_group://workbench_panel_group_monitor_for_updates]
|
|
label = Monitor for Updates
|
|
description = Monitor your enterprise to ensure that your endpoints are being patched and updated. Adversaries notoriously exploit known vulnerabilities that could be mitigated by applying routine security patches.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_notable_info"]
|
|
|
|
[panel_group://workbench_panel_group_netsh_abuse]
|
|
label = Netsh Abuse
|
|
description = Detect activities and various techniques associated with the abuse of `netsh.exe`, which can disable local firewall settings or set up a remote connection to a host from an infected system.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_orangeworm_attack_group]
|
|
label = Orangeworm Attack Group
|
|
description = Detect activities and various techniques associated with the Orangeworm Attack Group, a group that frequently targets the healthcare industry.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_phishing_payloads]
|
|
label = Phishing Payloads
|
|
description = Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_parent_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_possible_backdoor_activity_associated_with_mudcarp_espionage_campaigns]
|
|
label = Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
|
|
description = Monitor your environment for suspicious behaviors that resemble the techniques employed by the MUDCARP threat group.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_registry_activities", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_prohibited_traffic_allowed_or_protocol_mismatch]
|
|
label = Prohibited Traffic Allowed or Protocol Mismatch
|
|
description = Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_process_information_for_port_activity", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info", "panel://workbench_panel_get_dns_server_history_for_a_host"]
|
|
|
|
[panel_group://workbench_panel_group_ransomware]
|
|
label = Ransomware
|
|
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware--spikes in SMB traffic, suspicious wevtutil usage, the presence of common ransomware extensions, and system processes run from unexpected locations, and many others.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_update_logs_for_endpoint", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_registry_activities", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_sysmon_wmi_activity_for_host", "panel://workbench_panel_get_process_info", "panel://workbench_panel_get_process_information_for_port_activity", "panel://workbench_panel_get_backup_logs_for_endpoint", "panel://workbench_panel_get_vulnerability_logs_for_endpoint"]
|
|
|
|
[panel_group://workbench_panel_group_router_and_infrastructure_security]
|
|
label = Router and Infrastructure Security
|
|
description = Validate the security configuration of network infrastructure and verify that only authorized users and systems are accessing critical assets. Core routing and switching infrastructure are common strategic targets for attackers.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_notable_history"]
|
|
|
|
[panel_group://workbench_panel_group_sql_injection]
|
|
label = SQL Injection
|
|
description = Use the searches in this Analytic Story to help you detect structured query language (SQL) injection attempts characterized by long URLs that contain malicious parameters.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_notable_info"]
|
|
|
|
[panel_group://workbench_panel_group_samsam_ransomware]
|
|
label = SamSam Ransomware
|
|
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the SamSam ransomware, including looking for file writes associated with SamSam, RDP brute force attacks, the presence of files with SamSam ransomware extensions, suspicious psexec use, and more.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_update_logs_for_endpoint", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_investigate_successful_remote_desktop_authentications", "panel://workbench_panel_get_process_info", "panel://workbench_panel_get_process_information_for_port_activity", "panel://workbench_panel_get_backup_logs_for_endpoint", "panel://workbench_panel_get_vulnerability_logs_for_endpoint"]
|
|
|
|
[panel_group://workbench_panel_group_spectre_and_meltdown_vulnerabilities]
|
|
label = Spectre And Meltdown Vulnerabilities
|
|
description = Assess and mitigate your systems' vulnerability to Spectre and Meltdown exploitation with the searches in this Analytic Story.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_notable_history"]
|
|
|
|
[panel_group://workbench_panel_group_splunk_enterprise_vulnerability]
|
|
label = Splunk Enterprise Vulnerability
|
|
description = Keeping your Splunk deployment up to date is critical and may help you reduce the risk of CVE-2016-4859, an open-redirection vulnerability within some older versions of Splunk Enterprise. The detection search will help ensure that users are being properly authenticated and not being redirected to malicious domains.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_notable_info"]
|
|
|
|
[panel_group://workbench_panel_group_splunk_enterprise_vulnerability_cve_2018_11409]
|
|
label = Splunk Enterprise Vulnerability CVE-2018-11409
|
|
description = Reduce the risk of CVE-2018-11409, an information disclosure vulnerability within some older versions of Splunk Enterprise, with searches designed to help ensure that your Splunk system does not leak information to authenticated users.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_investigate_web_activity_from_src_ip", "panel://workbench_panel_investigate_network_traffic_from_src_ip"]
|
|
|
|
[panel_group://workbench_panel_group_suspicious_aws_ec2_activities]
|
|
label = Suspicious AWS EC2 Activities
|
|
description = Use the searches in this Analytic Story to monitor your AWS EC2 instances for evidence of anomalous activity and suspicious behaviors, such as EC2 instances that originate from unusual locations or those launched by previously unseen users (among others). Included investigative searches will help you probe more deeply, when the information warrants it.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_aws_investigate_user_activities_by_arn", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_investigate_aws_activities_via_region_name", "panel://workbench_panel_get_ec2_launch_details", "panel://workbench_panel_get_ec2_instance_details_by_instanceid"]
|
|
|
|
[panel_group://workbench_panel_group_suspicious_aws_login_activities]
|
|
label = Suspicious AWS Login Activities
|
|
description = Monitor your AWS authentication events using your CloudTrail logs. Searches within this Analytic Story will help you stay aware of and investigate suspicious logins.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn"]
|
|
|
|
[panel_group://workbench_panel_group_suspicious_aws_s3_activities]
|
|
label = Suspicious AWS S3 Activities
|
|
description = Use the searches in this Analytic Story to monitor your AWS S3 buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open S3 buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_all_aws_activity_from_ip_address", "panel://workbench_panel_get_notable_info", "panel://workbench_panel_aws_investigate_user_activities_by_arn", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_aws_s3_bucket_details_via_bucketname", "panel://workbench_panel_investigate_aws_activities_via_region_name"]
|
|
|
|
[panel_group://workbench_panel_group_suspicious_aws_traffic]
|
|
label = Suspicious AWS Traffic
|
|
description = Leverage these searches to monitor your AWS network traffic for evidence of anomalous activity and suspicious behaviors, such as a spike in blocked outbound traffic in your virtual private cloud (VPC).
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_all_aws_activity_from_ip_address", "panel://workbench_panel_aws_network_interface_details_via_resourceid", "panel://workbench_panel_get_notable_info", "panel://workbench_panel_aws_investigate_user_activities_by_arn", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_dns_traffic_ratio", "panel://workbench_panel_get_process_information_for_port_activity", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_dns_server_history_for_a_host", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info", "panel://workbench_panel_aws_network_acl_details_from_id"]
|
|
|
|
[panel_group://workbench_panel_group_suspicious_cloud_authentication_activities]
|
|
label = Suspicious Cloud Authentication Activities
|
|
description = Monitor your cloud authentication events. Searches within this Analytic Story leverage the recent cloud updates to the Authentication data model to help you stay aware of and investigate suspicious login activity.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_history", "panel://workbench_panel_investigate_aws_user_activities_by_user_field"]
|
|
|
|
[panel_group://workbench_panel_group_suspicious_command_line_executions]
|
|
label = Suspicious Command-Line Executions
|
|
description = Leveraging the Windows command-line interface (CLI) is one of the most common attack techniques--one that is also detailed in the MITRE ATT&CK framework. Use this Analytic Story to help you identify unusual or suspicious use of the CLI on Windows systems.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_registry_activities", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_suspicious_dns_traffic]
|
|
label = Suspicious DNS Traffic
|
|
description = Attackers often attempt to hide within or otherwise abuse the domain name system (DNS). You can thwart attempts to manipulate this omnipresent protocol by monitoring for these types of abuses.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_dns_traffic_ratio", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info", "panel://workbench_panel_get_dns_server_history_for_a_host"]
|
|
|
|
[panel_group://workbench_panel_group_suspicious_emails]
|
|
label = Suspicious Emails
|
|
description = Email remains one of the primary means for attackers to gain an initial foothold within the modern enterprise. Detect and investigate suspicious emails in your environment with the help of the searches in this Analytic Story.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_emails_from_specific_sender", "panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_email_info", "panel://workbench_panel_get_notable_history"]
|
|
|
|
[panel_group://workbench_panel_group_suspicious_mshta_activity]
|
|
label = Suspicious MSHTA Activity
|
|
description = Monitor and detect techniques used by attackers who leverage the mshta.exe process to execute malicious code.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_registry_activities", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_suspicious_okta_activity]
|
|
label = Suspicious Okta Activity
|
|
description = Monitor your Okta environment for suspicious activities. Due to the Covid outbreak, many users are migrating over to leverage cloud services more and more. Okta is a popular tool to manage multiple users and the web-based applications they need to stay productive. The searches in this story will help monitor your Okta environment for suspicious activities and associated user behaviors.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_investigate_okta_activity_by_app", "panel://workbench_panel_investigate_user_activities_in_okta", "panel://workbench_panel_investigate_okta_activity_by_ip_address"]
|
|
|
|
[panel_group://workbench_panel_group_suspicious_wmi_use]
|
|
label = Suspicious WMI Use
|
|
description = Attackers are increasingly abusing Windows Management Instrumentation (WMI), a framework and associated utilities available on all modern Windows operating systems. Because WMI can be leveraged to manage both local and remote systems, it is important to identify the processes executed and the user context within which the activity occurred.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_sysmon_wmi_activity_for_host", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_suspicious_windows_registry_activities]
|
|
label = Suspicious Windows Registry Activities
|
|
description = Monitor and detect registry changes initiated from remote locations, which can be a sign that an attacker has infiltrated your system.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_registry_activities", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_suspicious_zoom_child_processes]
|
|
label = Suspicious Zoom Child Processes
|
|
description = Attackers are using Zoom as an vector to increase privileges on a sytems. This story detects new child processes of zoom and provides investigative actions for this detection.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_process_file_activity", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_process_registry_activity"]
|
|
|
|
[panel_group://workbench_panel_group_unusual_aws_ec2_modifications]
|
|
label = Unusual AWS EC2 Modifications
|
|
description = Identify unusual changes to your AWS EC2 instances that may indicate malicious activity. Modifications to your EC2 instances by previously unseen users is an example of an activity that may warrant further investigation.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_ec2_instance_details_by_instanceid", "panel://workbench_panel_aws_investigate_user_activities_by_arn"]
|
|
|
|
[panel_group://workbench_panel_group_unusual_processes]
|
|
label = Unusual Processes
|
|
description = Quickly identify systems running new or unusual processes in your environment that could be indicators of suspicious activity. Processes run from unusual locations, those with conspicuously long command lines, and rare executables are all examples of activities that may warrant deeper investigation.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_use_of_cleartext_protocols]
|
|
label = Use of Cleartext Protocols
|
|
description = Leverage searches that detect cleartext network protocols that may leak credentials or should otherwise be encrypted.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_information_for_port_activity"]
|
|
|
|
[panel_group://workbench_panel_group_web_fraud_detection]
|
|
label = Web Fraud Detection
|
|
description = Monitor your environment for activity consistent with common attack techniques bad actors use when attempting to compromise web servers or other web-related assets.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_emails_from_specific_sender", "panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_web_session_information_via_session_id"]
|
|
|
|
[panel_group://workbench_panel_group_windows_dns_sigred_cve_2020_1350]
|
|
label = Windows DNS SIGRed CVE-2020-1350
|
|
description = Uncover activity consistent with CVE-2020-1350, or SIGRed. Discovered by Checkpoint researchers, this vulnerability affects Windows 2003 to 2019, and is triggered by a malicious DNS response (only affects DNS over TCP). An attacker can use the malicious payload to cause a buffer overflow on the vulnerable system, leading to compromise. The included searches in this Analytic Story are designed to identify the large response payload for SIG and KEY DNS records which can be used for the exploit.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info"]
|
|
|
|
[panel_group://workbench_panel_group_windows_defense_evasion_tactics]
|
|
label = Windows Defense Evasion Tactics
|
|
description = Detect tactics used by malware to evade defenses on Windows endpoints. A few of these include suspicious `reg.exe` processes, files hidden with `attrib.exe` and disabling user-account control, among many others
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_registry_activities", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_windows_file_extension_and_association_abuse]
|
|
label = Windows File Extension and Association Abuse
|
|
description = Detect and investigate suspected abuse of file extensions and Windows file associations. Some of the malicious behaviors involved may include inserting spaces before file extensions or prepending the file extension with a different one, among other techniques.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_registry_activities", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_windows_log_manipulation]
|
|
label = Windows Log Manipulation
|
|
description = Adversaries often try to cover their tracks by manipulating Windows logs. Use these searches to help you monitor for suspicious activity surrounding log files--an essential component of an effective defense.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info", "panel://workbench_panel_get_vulnerability_logs_for_endpoint"]
|
|
|
|
[panel_group://workbench_panel_group_windows_persistence_techniques]
|
|
label = Windows Persistence Techniques
|
|
description = Monitor for activities and techniques associated with maintaining persistence on a Windows system--a sign that an adversary may have compromised your environment.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_registry_activities", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_windows_privilege_escalation]
|
|
label = Windows Privilege Escalation
|
|
description = Monitor for and investigate activities that may be associated with a Windows privilege-escalation attack, including unusual processes running on endpoints, modified registry keys, and more.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_investigate_web_activity_from_host", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_registry_activities", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
[panel_group://workbench_panel_group_windows_service_abuse]
|
|
label = Windows Service Abuse
|
|
description = Windows services are often used by attackers for persistence and the ability to load drivers or otherwise interact with the Windows kernel. This Analytic Story helps you monitor your environment for indications that Windows services are being modified or created in a suspicious manner.
|
|
disabled = 0
|
|
panels = ["panel://workbench_panel_get_notable_info", "panel://workbench_panel_get_risk_modifiers_for_user", "panel://workbench_panel_get_parent_process_info", "panel://workbench_panel_get_risk_modifiers_for_endpoint", "panel://workbench_panel_get_authentication_logs_for_endpoint", "panel://workbench_panel_get_user_information_from_identity_table", "panel://workbench_panel_get_notable_history", "panel://workbench_panel_get_process_info"]
|
|
|
|
|
|
|
|
[panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest]
|
|
label = AWS Investigate Security Hub alerts by dest
|
|
description = This search retrieves the all the alerts created by AWS Security Hub for a specific dest(instance_id).
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_aws_investigate_user_activities_by_arn]
|
|
label = AWS Investigate User Activities By ARN
|
|
description = This search lists all the logged CloudTrail activities by a specific user ARN and will create a table containing the source of the user, the region of the activity, the name and type of the event, the action taken, and all the user's identity information.
|
|
disabled = 0
|
|
tokens = {\
|
|
"user": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "identity",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_aws_investigate_user_activities_by_accesskeyid]
|
|
label = AWS Investigate User Activities By AccessKeyId
|
|
description = This search retrieves the times, ARN, source IPs, AWS regions, event names, and the result of the event for specific credentials.
|
|
disabled = 0
|
|
tokens = {\
|
|
"accessKeyId": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_aws_investigate_user_activities_by_source_user]
|
|
label = AWS Investigate User Activities By Source User
|
|
description = This search retrieves the times, ARN, source IPs, AWS regions, event names, and the result of the event for specific ARNs.
|
|
disabled = 0
|
|
tokens = {\
|
|
"src_user": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_aws_network_acl_details_from_id]
|
|
label = AWS Network ACL Details from ID
|
|
description = This search queries AWS description logs and returns all the information about a specific network ACL via network ACL ID
|
|
disabled = 0
|
|
tokens = {\
|
|
"networkAclId": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_aws_network_interface_details_via_resourceid]
|
|
label = AWS Network Interface details via resourceId
|
|
description = This search queries AWS configuration logs and returns the information about a specific network interface via network interface ID. The information will include the ARN of the network interface, its relationships with other AWS resources, the public and the private IP associated with the network interface.
|
|
disabled = 0
|
|
tokens = {\
|
|
"resourceId": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_aws_s3_bucket_details_via_bucketname]
|
|
label = AWS S3 Bucket details via bucketName
|
|
description = This search queries AWS configuration logs and returns the information about a specific S3 bucket. The information returned includes the time the S3 bucket was created, the resource ID, the region it belongs to, the value of action performed, AWS account ID, and configuration values of the access-control lists associated with the bucket.
|
|
disabled = 0
|
|
tokens = {\
|
|
"bucketName": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_all_backup_logs_for_host]
|
|
label = All backup logs for host
|
|
description = Retrieve the backup logs for the last 2 weeks for a specific host in order to investigate why backups are not completing successfully.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_amazon_eks_kubernetes_activity_by_src_ip]
|
|
label = Amazon EKS Kubernetes activity by src ip
|
|
description = This search provides investigation data about requests via user agent, authentication request URI, verb and cluster name data against Kubernetes cluster from a specific IP address
|
|
disabled = 0
|
|
tokens = {\
|
|
"src_ip": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_gcp_kubernetes_activity_by_src_ip]
|
|
label = GCP Kubernetes activity by src ip
|
|
description = This search provides investigation data about requests via user agent, authentication request URI, resource path and cluster name data against Kubernetes cluster from a specific IP address
|
|
disabled = 0
|
|
tokens = {\
|
|
"src_user": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_all_aws_activity_from_city]
|
|
label = Get All AWS Activity From City
|
|
description = This search retrieves all the activity from a specific city and will create a table containing the time, city, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful.
|
|
disabled = 0
|
|
tokens = {\
|
|
"City": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_all_aws_activity_from_country]
|
|
label = Get All AWS Activity From Country
|
|
description = This search retrieves all the activity from a specific country and will create a table containing the time, country, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful.
|
|
disabled = 0
|
|
tokens = {\
|
|
"Country": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_all_aws_activity_from_ip_address]
|
|
label = Get All AWS Activity From IP Address
|
|
description = This search retrieves all the activity from a specific IP address and will create a table containing the time, ARN, username, the type of user, the IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful.
|
|
disabled = 0
|
|
tokens = {\
|
|
"src_ip": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_all_aws_activity_from_region]
|
|
label = Get All AWS Activity From Region
|
|
description = This search retrieves all the activity from a specific geographic region and will create a table containing the time, geographic region, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful.
|
|
disabled = 0
|
|
tokens = {\
|
|
"Region": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_authentication_logs_for_endpoint]
|
|
label = Get Authentication Logs For Endpoint
|
|
description = This search returns all users that have attempted to access a particular endpoint.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_backup_logs_for_endpoint]
|
|
label = Get Backup Logs For Endpoint
|
|
description = This search will tell you the backup status from your netbackup_logs of a specific endpoint for the last week.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_certificate_logs_for_a_domain]
|
|
label = Get Certificate logs for a domain
|
|
description = This search queries the Certificates datamodel and give you all the information for a specific domain. Please note that the certificates issued by "Let's Encrypt" are widely used by attackers.
|
|
disabled = 0
|
|
tokens = {\
|
|
"domain": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_dns_server_history_for_a_host]
|
|
label = Get DNS Server History for a host
|
|
description = While investigating any detections it is important to understand which and how many DNS servers a host has connected to in the past. This search uses data that is tagged as DNS and gives you a count and list of DNS servers that a particular host has connected to the previous 24 hours.
|
|
disabled = 0
|
|
tokens = {\
|
|
"src_ip": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_dns_traffic_ratio]
|
|
label = Get DNS traffic ratio
|
|
description = This search calculates the ratio of DNS traffic originating and coming from a host to a list of DNS servers over the last 24 hours. A high value of this ratio could be very useful to quickly understand if a src_ip (host) is sending a high volume of data out via port 53, could be an indicator of data exfiltration via DNS.
|
|
disabled = 0
|
|
tokens = {\
|
|
"src_ip": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
},\
|
|
"dest_ip": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_ec2_instance_details_by_instanceid]
|
|
label = Get EC2 Instance Details by instanceId
|
|
description = This search queries AWS description logs and returns all the information about a specific instance via the instanceId field
|
|
disabled = 0
|
|
tokens = {\
|
|
"instanceId": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_ec2_launch_details]
|
|
label = Get EC2 Launch Details
|
|
description = This search returns some of the launch details for a EC2 instance.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_email_info]
|
|
label = Get Email Info
|
|
description = This search returns all the information Splunk might have collected a specific email message over the last 2 hours.
|
|
disabled = 0
|
|
tokens = {\
|
|
"message_id": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_emails_from_specific_sender]
|
|
label = Get Emails From Specific Sender
|
|
description = This search returns all the emails from a specific sender over the last 24 and next hours.
|
|
disabled = 0
|
|
tokens = {\
|
|
"src_user": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_first_occurrence_and_last_occurrence_of_a_mac_address]
|
|
label = Get First Occurrence and Last Occurrence of a MAC Address
|
|
description = This search allows you to gather more context around a notable which has detected a new device connecting to your network. Use this search to determine the first and last occurrences of the suspicious device attempting to connect with your network.
|
|
disabled = 0
|
|
tokens = {\
|
|
"src_mac": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_history_of_email_sources]
|
|
label = Get History Of Email Sources
|
|
description = This search returns a list of all email sources seen in the 48 hours prior to the notable event to 24 hours after, and the number of emails from each source.
|
|
disabled = 0
|
|
tokens = {\
|
|
"src": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_logon_rights_modifications_for_endpoint]
|
|
label = Get Logon Rights Modifications For Endpoint
|
|
description = This search allows you to retrieve any modifications to logon rights associated with a specific host.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_logon_rights_modifications_for_user]
|
|
label = Get Logon Rights Modifications For User
|
|
description = This search allows you to retrieve any modifications to logon rights for a specific user account.
|
|
disabled = 0
|
|
tokens = {\
|
|
"user": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "identity",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_notable_history]
|
|
label = Get Notable History
|
|
description = This search queries the notable index and returns all the Notable Events for the particular destination host, giving the analyst an overview of the incidents that may have occurred with the host under investigation.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_notable_info]
|
|
label = Get Notable Info
|
|
description = This search queries the notable index to retrieve detailed information captured within the notable. Every notable has a unique ID associated with it, which is used to point us directly to the notable event under investigation.
|
|
disabled = 0
|
|
tokens = {\
|
|
"event_id": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_outbound_emails_to_hidden_cobra_threat_actors]
|
|
label = Get Outbound Emails to Hidden Cobra Threat Actors
|
|
description = This search returns the information of the users that sent emails to the accounts controlled by the Hidden Cobra Threat Actors: specifically to `misswang8107@gmail.com`, and from `redhat@gmail.com`.
|
|
disabled = 0
|
|
tokens = {\
|
|
"src_user": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
},\
|
|
"recipient": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_parent_process_info]
|
|
label = Get Parent Process Info
|
|
description = This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest
|
|
disabled = 0
|
|
tokens = {\
|
|
"process_name": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
},\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_process_file_activity]
|
|
label = Get Process File Activity
|
|
description = This search returns the file activity for a specific process on a specific endpoint
|
|
disabled = 0
|
|
tokens = {\
|
|
"process_id": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
},\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_process_info]
|
|
label = Get Process Info
|
|
description = This search queries the Endpoint data model to give you details about the process running on a host which is under investigation. To gather the process info, enter the values for the process name in question and the destination IP address.
|
|
disabled = 0
|
|
tokens = {\
|
|
"process_name": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
},\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_process_information_for_port_activity]
|
|
label = Get Process Information For Port Activity
|
|
description = This search will return information about the process associated with observed network traffic to a specific destination port from a specific host.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest_port": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
},\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_process_registry_activity]
|
|
label = Get Process Registry Activity
|
|
description = This search returns the registry activity for a specific process on a specific endpoint
|
|
disabled = 0
|
|
tokens = {\
|
|
"process_id": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
},\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_process_responsible_for_the_dns_traffic]
|
|
label = Get Process Responsible For The DNS Traffic
|
|
description = While investigating, an analyst will want to know what process and parent_process is responsible for generating suspicious DNS traffic. Use the following search and enter the value of `dest` in the search to get specific details on the process responsible for creating the DNS traffic.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_registry_activities]
|
|
label = Get Registry Activities
|
|
description = This search queries the Endpoint Datamodel to give you details of the latest registry values for a specific destination computer.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_risk_modifiers_for_endpoint]
|
|
label = Get Risk Modifiers For Endpoint
|
|
description = For the last 7 days, the search will query the Risk data model in Splunk Enterprise Security and calculate the count, sum of the risk\_scores, names of the correlation searches that contributed to create a risk score for a specific endpoint(machine\_name)
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_risk_modifiers_for_user]
|
|
label = Get Risk Modifiers For User
|
|
description = For the last 7 days, the search will query the Risk data model in Splunk Enterprise Security and calculate the count, sum of the risk_scores, names of the correlation searches that contributed to create a risk score for a specific user
|
|
disabled = 0
|
|
tokens = {\
|
|
"user": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "identity",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_sysmon_wmi_activity_for_host]
|
|
label = Get Sysmon WMI Activity for Host
|
|
description = This search queries Sysmon WMI events for the host of interest.
|
|
disabled = 0
|
|
tokens = {\
|
|
"process": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
},\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_update_logs_for_endpoint]
|
|
label = Get Update Logs For Endpoint
|
|
description = This search will tell you give you the update logs for a specific endpoint for the last week.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_user_information_from_identity_table]
|
|
label = Get User Information from Identity Table
|
|
description = Gather more information about the user identified in the Notable Event.
|
|
disabled = 0
|
|
tokens = {\
|
|
"user": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "identity",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_vulnerability_logs_for_endpoint]
|
|
label = Get Vulnerability Logs For Endpoint
|
|
description = This search will show you any vulnerabilities noted for a specific endpoint for the last week.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_get_web_session_information_via_session_id]
|
|
label = Get Web Session Information via session id
|
|
description = This search helps an analyst investigate a notable event to find out more about a specific web session. The search looks for a specific web session ID in the HTTP web traffic and outputs the URL and user agents, grouped by source IP address and HTTP status code.
|
|
disabled = 0
|
|
tokens = {\
|
|
"session_id": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_aws_ecr_container_listing_activity]
|
|
label = Investigate AWS ECR container listing activity
|
|
description = This search lists all the users performing a list image operation on AWS Elastic Container Registry. Listing source user, image id, source IP, user type, http user agent. This search also gives counts of unique user agents per listing source.
|
|
disabled = 0
|
|
tokens = {\
|
|
"Compute.event_name": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_aws_user_activities_by_user_field]
|
|
label = Investigate AWS User Activities by user field
|
|
description = This search lists all the logged CloudTrail activities by a specific user and will create a table containing the source of the user, the region of the activity, the name and type of the event, the action taken, and the user's identity information.
|
|
disabled = 0
|
|
tokens = {\
|
|
"user": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "identity",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_aws_activities_via_region_name]
|
|
label = Investigate AWS activities via region name
|
|
description = This search lists all the user activities logged by CloudTrail for a specific region in question and will create a table of the values of parameters requested, the type of the event and the response from the AWS API by each user
|
|
disabled = 0
|
|
tokens = {\
|
|
"awsRegion": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_cloud_compute_instance_activities]
|
|
label = Investigate Cloud Compute Instance Activities
|
|
description = This search returns a logs of events that operated on the compute instance.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_failed_logins_for_multiple_destinations]
|
|
label = Investigate Failed Logins for Multiple Destinations
|
|
description = This search returns failed logins to multiple destinations by user.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_network_traffic_from_src_ip]
|
|
label = Investigate Network Traffic From src ip
|
|
description = This search allows you to find all the network traffic from a specific IP address.
|
|
disabled = 0
|
|
tokens = {\
|
|
"src_ip": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_okta_activity_by_ip_address]
|
|
label = Investigate Okta Activity by IP Address
|
|
description = This search returns all okta events from a specific IP address.
|
|
disabled = 0
|
|
tokens = {\
|
|
"user": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "identity",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_okta_activity_by_app]
|
|
label = Investigate Okta Activity by app
|
|
description = This search returns all okta events associated with a specific app
|
|
disabled = 0
|
|
tokens = {\
|
|
"app": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_pass_the_hash_attempts]
|
|
label = Investigate Pass the Hash Attempts
|
|
description = This search hunts for dumped NTLM hashes used for pass the hash.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_pass_the_ticket_attempts]
|
|
label = Investigate Pass the Ticket Attempts
|
|
description = This search hunts for dumped kerberos ticket from LSASS memory.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_previous_unseen_user]
|
|
label = Investigate Previous Unseen User
|
|
description = This search returns previous unseen user, which didn't log in for 30 days.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_successful_remote_desktop_authentications]
|
|
label = Investigate Successful Remote Desktop Authentications
|
|
description = This search returns the source, destination, and user for all successful remote-desktop authentications. A successful authentication after a brute-force attack on a destination machine is suspicious behavior.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_suspicious_strings_in_http_header]
|
|
label = Investigate Suspicious Strings in HTTP Header
|
|
description = This search helps an analyst investigate a notable event related to a potential Apache Struts exploitation. To investigate, we will want to isolate and analyze the "payload" or the commands that were passed to the vulnerable hosts by creating a few regular expressions to carve out the commands focusing on common keywords from the payload, such as cmd.exe, /bin/bash and whois. The search returns these suspicious strings found in the HTTP logs of the system of interest.
|
|
disabled = 0
|
|
tokens = {\
|
|
"src_ip": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
},\
|
|
"dest_ip": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_user_activities_in_all_cloud_regions]
|
|
label = Investigate User Activities In All Cloud Regions
|
|
description = This search lists all the logged cloud infrastructure activities by a specific cloud user
|
|
disabled = 0
|
|
tokens = {\
|
|
"region": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
},\
|
|
"src_user": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_user_activities_in_okta]
|
|
label = Investigate User Activities In Okta
|
|
description = This search returns all okta events by a specific user
|
|
disabled = 0
|
|
tokens = {\
|
|
"user": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "identity",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_user_activities_in_single_cloud_region]
|
|
label = Investigate User Activities In Single Cloud Region
|
|
description = This search lists all the logged cloud infrastructure activities by a specific cloud user in a specific cloud region
|
|
disabled = 0
|
|
tokens = {\
|
|
"region": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
},\
|
|
"src_user": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_web_activity_from_host]
|
|
label = Investigate Web Activity From Host
|
|
description = This search allows you to find all the web activity from a specific host. During an investigation, it is important to profile web activity to characterize user or host activity.
|
|
disabled = 0
|
|
tokens = {\
|
|
"dest": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_web_activity_from_src_ip]
|
|
label = Investigate Web Activity From src ip
|
|
description = This search searches for all web activity from a specific host. During an investigation, it is important to profile web activity to characterize user or host activity.
|
|
disabled = 0
|
|
tokens = {\
|
|
"src_ip": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_investigate_web_posts_from_src]
|
|
label = Investigate Web POSTs From src
|
|
description = This investigative search retrieves POST requests from a specified source IP or hostname. Identifying the POST requests, as well as their associated destination URLs and user agent(s), may help you scope and characterize the suspicious traffic.
|
|
disabled = 0
|
|
tokens = {\
|
|
"src": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|
|
[panel://workbench_panel_process_chain_analysis]
|
|
label = Process Chain Analysis
|
|
description = Analyze the Process Chain and identify the malicious file. By analyzing the parent process guid and searching for the process guid, the spawning process chain can be identified.
|
|
disabled = 0
|
|
tokens = {\
|
|
"process_guid": {\
|
|
"valuePrefix": "",\
|
|
"valueSuffix": "",\
|
|
"delimiter": " OR ",\
|
|
"valueType": "primitive",\
|
|
"value": "asset",\
|
|
"default": "_1!=1"\
|
|
}\
|
|
}\
|
|
|
|
|