Files
2020-09-18 23:39:37 +00:00

7.5 MiB

1Technique IDDetection AvailableLinkscore
2T1529No-0
3T1167No-0
4T1199No-0
5T1484No-0
6T1073No-0
7T1075No-0
8T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
9T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
10T1044No-0
11T1213No-0
12T1059.004No-0
13T1163No-0
14T1574.005No-0
15T1036.004No-0
16T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
17T1179No-0
18T1141No-0
19T1499.004No-0
20T1560.001No-0
21T1098No-0
22T1564.002No-0
23T1565.003No-0
24T1218.008No-0
25T1497.002No-0
26T1027.002No-0
27T1102No-0
28T1005No-0
29T1497No-0
30T1211No-0
31T1482No-0
32T1037.001No-0
33T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
34T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
35T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
36T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
37T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
38T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
39T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
40T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
41T1196No-0
42T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
43T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
44T1142No-0
45T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
46T1134No-0
47T1518No-0
48T1059.005No-0
49T1150No-0
50T1031No-0
51T1132.001No-0
52T1220No-0
53T1085No-0
54T1559.001No-0
55T1572No-0
56T1021.005No-0
57T1574.008No-0
58T1184No-0
59T1568.001No-0
60T1218.007No-0
61T1546.002No-0
62T1048.002No-0
63T1547.009No-0
64T1003No-12
65T1557.001No-0
66T1553.002No-0
67T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
68T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
69T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_zerologon_via_zeek.yml3
70T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml3
71T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml3
72T1560.002No-0
73T1144No-0
74T1177No-0
75T1135No-0
76T1032No-0
77T1563.002No-0
78T1115No-0
79T1137.003No-0
80T1546.005No-0
81T1137.002No-0
82T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
83T1134.001No-0
84T1558.001No-0
85T1499.002No-0
86T1496No-0
87T1137.004No-0
88T1074No-0
89T1188No-0
90T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
91T1223No-0
92T1170No-0
93T1003.005No-0
94T1556No-0
95T1218.010No-0
96T1195.003No-0
97T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
98T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
99T1514No-0
100T1564.004No-0
101T1001.003No-0
102T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
103T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
104T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
105T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
106T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
107T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
108T1036.006No-0
109T1027.001No-0
110T1049No-0
111T1185No-0
112T1070.004No-0
113T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_gcp_storage_buckets.yml5
114T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_gcp_storage_access_from_a_new_ip.yml5
115T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml5
116T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml5
117T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml5
118T1162No-0
119T1216No-0
120T1552No-0
121T1192No-0
122T1052.001No-0
123T1574.007No-0
124T1007No-0
125T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml2
126T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml2
127T1194No-0
128T1537No-0
129T1109No-0
130T1004No-0
131T1059No-15
132T1098.001No-0
133T1062No-0
134T1546.014No-0
135T1552.005No-0
136T1053.001No-0
137T1527No-0
138T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
139T1570No-0
140T1020No-0
141T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
142T1546.004No-0
143T1555.002No-0
144T1002No-0
145T1492No-0
146T1553.001No-0
147T1488No-0
148T1134.005No-0
149T1542.003No-0
150T1491No-0
151T1128No-0
152T1505.001No-0
153T1003.004No-0
154T1008No-0
155T1136.002No-0
156T1499.001No-0
157T1505.003No-0
158T1056.001No-0
159T1127.001No-0
160T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
161T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
162T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
163T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
164T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
165T1134.002No-0
166T1102.002No-0
167T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
168T1053.004No-0
169T1564No-0
170T1560.003No-0
171T1578No-0
172T1022No-0
173T1547.005No-0
174T1036.001No-0
175T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
176T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
177T1193No-0
178T1061No-0
179T1127No-0
180T1003.007No-0
181T1165No-0
182T1565.001No-0
183T1012No-0
184T1033No-0
185T1036.005No-0
186T1030No-0
187T1087.002No-0
188T1140No-0
189T1573No-0
190T1039No-0
191T1539No-0
192T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
193T1565No-0
194T1059.002No-0
195T1035No-0
196T1562.006No-0
197T1110.004No-0
198T1076No-0
199T1137.001No-0
200T1574.001No-0
201T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
202T1037No-0
203T1064No-0
204T1090.003No-0
205T1148No-0
206T1531No-0
207T1071.003No-0
208T1498.001No-0
209T1564.006No-0
210T1578.001No-0
211T1556.002No-0
212T1070.006No-0
213T1066No-0
214T1155No-0
215T1098.002No-0
216T1113No-0
217T1106No-0
218T1016No-0
219T1090No-0
220T1147No-0
221T1034No-0
222T1497.003No-0
223T1087.003No-0
224T1494No-0
225T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
226T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
227T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
228T1001No-0
229T1564.003No-0
230T1546No-5
231T1219No-0
232T1201No-0
233T1036.002No-0
234T1055.002No-0
235T1486No-0
236T1578.004No-0
237T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
238T1173No-0
239T1175No-0
240T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
241T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
242T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
243T1568No-0
244T1547.002No-0
245T1169No-0
246T1105No-0
247T1547.003No-0
248T1059.006No-0
249T1552.001No-0
250T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml3
251T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml3
252T1187No-0
253T1480.001No-0
254T1099No-0
255T1210Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml1
256T1489No-0
257T1132No-0
258T1152No-0
259T1119No-0
260T1205.001No-0
261T1567No-0
262T1550Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_get_session_token_abuse.yml2
263T1172No-0
264T1069No-0
265T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
266T1561.001No-0
267T1556.001No-0
268T1087.004No-0
269T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
270T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
271T1554No-0
272T1543No-1
273T1555.003No-0
274T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
275T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
276T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
277T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
278T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
279T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
280T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
281T1014No-0
282T1502No-0
283T1562.002No-0
284T1102.003No-0
285T1077No-0
286T1195.001No-0
287T1011.001No-0
288T1129No-0
289T1564.005No-0
290T1552.004No-0
291T1218.001No-0
292T1001.002No-0
293T1023No-0
294T1086No-0
295T1565.002No-0
296T1214No-0
297T1569No-1
298T1546.010No-0
299T1108No-0
300T1528No-0
301T1131No-0
302T1132.002No-0
303T1037.005No-0
304T1213.001No-0
305T1104No-0
306T1562.007No-0
307T1548No-0
308T1574.012No-0
309T1499No-0
310T1207No-0
311T1543.004No-0
312T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
313T1186No-0
314T1518.001No-0
315T1025No-0
316T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
317T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
318T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
319T1087No-0
320T1563No-0
321T1548.001No-0
322T1547.006No-0
323T1026No-0
324T1137.005No-0
325T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
326T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
327T1547.007No-0
328T1546.007No-0
329T1037.004No-0
330T1157No-0
331T1195.002No-0
332T1212No-0
333T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
334T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
335T1136.003No-0
336T1567.002No-0
337T1027.004No-0
338T1149No-0
339T1083No-0
340T1159No-0
341T1103No-0
342T1037.003No-0
343T1218.005No-0
344T1001.001No-0
345T1051No-0
346T1063No-0
347T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
348T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
349T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
350T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
351T1204No-1
352T1546.013No-0
353T1045No-0
354T1222.002No-0
355T1519No-0
356T1038No-0
357T1569.001No-0
358T1154No-0
359T1074.001No-0
360T1110No-0
361T1120No-0
362T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml4
363T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml4
364T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml4
365T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml4
366T1094No-0
367T1054No-0
368T1546.009No-0
369T1542.002No-0
370T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
371T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
372T1217No-0
373T1027.003No-0
374T1573.002No-0
375T1218.003No-0
376T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
377T1538No-0
378T1501No-0
379T1180No-0
380T1183No-0
381T1218.002No-0
382T1137No-0
383T1493No-0
384T1151No-0
385T1205No-0
386T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
387T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
388T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
389T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
390T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
391T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
392T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
393T1208No-0
394T1100No-0
395T1145No-0
396T1574.011No-0
397T1055.003No-0
398T1522No-0
399T1558.002No-0
400T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
401T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
402T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
403T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
404T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
405T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
406T1130No-0
407T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
408T1491.001No-0
409T1548.004No-0
410T1122No-0
411T1490No-0
412T1578.003No-0
413T1156No-0
414T1069.001No-0
415T1055.011No-0
416T1080No-0
417T1574.010No-0
418T1546.012No-0
419T1019No-0
420T1056.002No-0
421T1053No-4
422T1055.008No-0
423T1055.012No-0
424T1561No-0
425T1160No-0
426T1043No-0
427T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
428T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
429T1090.001No-0
430T1102.001No-0
431T1090.004No-0
432T1560No-0
433T1087.001No-0
434T1499.003No-0
435T1010No-0
436T1017No-0
437T1050No-0
438T1559No-0
439T1543.001No-0
440T1134.003No-0
441T1111No-0
442T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
443T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
444T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
445T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
446T1567.001No-0
447T1568.003No-0
448T1505No-0
449T1503No-0
450T1018No-0
451T1536No-0
452T1133No-0
453T1216.001No-0
454T1564.001No-0
455T1081No-0
456T1495No-0
457T1213.002No-0
458T1098.004No-0
459T1563.001No-0
460T1562No-3
461T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
462T1561.002No-0
463T1547No-3
464T1553.003No-0
465T1550.001No-0
466T1134.004No-0
467T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
468T1048.001No-0
469T1218No-1
470T1202No-0
471T1055No-0
472T1021.004No-0
473T1548.002No-0
474T1548.003No-0
475T1067No-0
476T1092No-0
477T1166No-0
478T1546.006No-0
479T1041No-0
480T1171No-0
481T1029No-0
482T1550.003No-0
483T1056No-0
484T1534No-0
485T1003.008No-0
486T1497.001No-0
487T1084No-0
488T1124No-0
489T1222No-1
490T1542.001No-0
491T1036.003No-0
492T1056.003No-0
493T1191No-0
494T1543.002No-0
495T1021.006No-0
496T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
497T1559.002No-0
498T1555No-0
499T1555.001No-0
500T1573.001No-0
501T1074.002No-0
502T1547.011No-0
503T1042No-0
504T1547.010No-0
505T1071No-10
506T1552.003No-0
507T1055.009No-0
508T1578.002No-0
509T1547.004No-0
510T1110.003No-0
511T1107No-0
512T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
513T1060No-0
514T1204.001No-0
515T1487No-0
516T1070.003No-0
517T1552.002No-0
518T1090.002No-0
519T1126No-0
520T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
521T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
522T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
523T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
524T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
525T1125No-0
526T1114No-3
527T1164No-0
528T1546.015No-0
529T1138No-0
530T1158No-0
531T1574No-1
532T1218.004No-0
533T1024No-0
534T1181No-0
535T1505.002No-0
536T1056.004No-0
537T1053.003No-0
538T1215No-0
539T1198No-0
540T1178No-0
541T1143No-0
542T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_assume_role_abuse.yml26
543T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml26
544T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_attach_to_role_policy.yml26
545T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_role_creation.yml26
546T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_permanent_key_creation.yml26
547T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml26
548T1139No-0
549T1114.003No-0
550T1065No-0
551T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
552T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
553T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
554T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml3
555T1480No-0
556T1070.005No-0
557T1556.003No-0
558T1053.002No-0
559T1079No-0
560T1040No-0
561T1013No-0
562T1218.009No-0
563T1206No-0
564T1182No-0
565T1037.002No-0
566T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
567T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
568T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
569T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
570T1553No-1
571T1562.003No-0
572T1116No-0
573T1491.002No-0
574T1574.004No-0
575T1161No-0
576T1101No-0
577T1110.001No-0
578T1055.004No-0
579T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
580T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
581T1137.006No-0
582T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml5
583T1028No-0
584T1189No-0
585T1197No-0
586T1121No-0
587T1055.001No-0
588T1059.007No-0
589T1003.006No-0
590T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
591T1574.006No-0
592T1057No-0
593T1091No-0
594T1096No-0
595T1146No-0
596T1027.005No-0
597T1117No-0
598T1195No-0
599T1070.002No-0
600T1174No-0
601T1055.005No-0
602T1015No-0
603T1009No-0
604T1098.003No-0
605T1550.004No-0
606T1504No-0
607T1021No-6
608T1574.002No-0
609T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
610T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
611T1168No-0
612T1011No-0
613T1546.003No-0
614T1055.014No-0
615T1089No-0
616T1500No-0
617T1097No-0
618T1093No-0
619T1571No-0
620T1052No-0
621T1568.002No-0
622T1176No-0
623T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
624T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
625T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
626T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
627T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
628T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
629T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
630T1483No-0
631T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
632T1221No-0
633T1055.013No-0
634T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
635T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
636T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
637T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
638T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
639T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
640T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
641T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
642T1110.002No-0
643T1552.006No-0
644T1123No-0
645T1558No-1
646T1153No-0
647T1046No-0
648T1021.003No-0
649T1088No-0
650T1209No-0
651T1069.002No-0
652T1542No-0
653T1069.003No-0
654T1058No-0
655T1506No-0
656T1547.008No-0
657T1006No-0
658T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml13
659T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml13
660T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml13
661T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml13
662T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml13
663T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml13
664T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml13
665T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml13
666T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml13
667T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml13
668T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml13
669T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml13
670T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml13
671T1118No-0
672T1529No-0
673T1167No-0
674T1199No-0
675T1484No-0
676T1073No-0
677T1075No-0
678T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
679T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
680T1044No-0
681T1213No-0
682T1059.004No-0
683T1163No-0
684T1574.005No-0
685T1036.004No-0
686T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
687T1179No-0
688T1141No-0
689T1499.004No-0
690T1560.001No-0
691T1098No-0
692T1564.002No-0
693T1565.003No-0
694T1218.008No-0
695T1497.002No-0
696T1027.002No-0
697T1102No-0
698T1005No-0
699T1497No-0
700T1211No-0
701T1482No-0
702T1037.001No-0
703T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
704T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
705T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
706T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
707T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
708T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
709T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
710T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
711T1196No-0
712T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
713T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
714T1142No-0
715T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
716T1134No-0
717T1518No-0
718T1059.005No-0
719T1150No-0
720T1031No-0
721T1132.001No-0
722T1220No-0
723T1085No-0
724T1559.001No-0
725T1572No-0
726T1021.005No-0
727T1574.008No-0
728T1184No-0
729T1568.001No-0
730T1218.007No-0
731T1546.002No-0
732T1048.002No-0
733T1547.009No-0
734T1003No-12
735T1557.001No-0
736T1553.002No-0
737T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
738T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
739T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_zerologon_via_zeek.yml3
740T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml3
741T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml3
742T1560.002No-0
743T1144No-0
744T1177No-0
745T1135No-0
746T1032No-0
747T1563.002No-0
748T1115No-0
749T1137.003No-0
750T1546.005No-0
751T1137.002No-0
752T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
753T1134.001No-0
754T1558.001No-0
755T1499.002No-0
756T1496No-0
757T1137.004No-0
758T1074No-0
759T1188No-0
760T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
761T1223No-0
762T1170No-0
763T1003.005No-0
764T1556No-0
765T1218.010No-0
766T1195.003No-0
767T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
768T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
769T1514No-0
770T1564.004No-0
771T1001.003No-0
772T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
773T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
774T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
775T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
776T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
777T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
778T1036.006No-0
779T1027.001No-0
780T1049No-0
781T1185No-0
782T1070.004No-0
783T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_gcp_storage_buckets.yml5
784T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_gcp_storage_access_from_a_new_ip.yml5
785T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml5
786T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml5
787T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml5
788T1162No-0
789T1216No-0
790T1552No-0
791T1192No-0
792T1052.001No-0
793T1574.007No-0
794T1007No-0
795T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml2
796T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml2
797T1194No-0
798T1537No-0
799T1109No-0
800T1004No-0
801T1059No-15
802T1098.001No-0
803T1062No-0
804T1546.014No-0
805T1552.005No-0
806T1053.001No-0
807T1527No-0
808T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
809T1570No-0
810T1020No-0
811T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
812T1546.004No-0
813T1555.002No-0
814T1002No-0
815T1492No-0
816T1553.001No-0
817T1488No-0
818T1134.005No-0
819T1542.003No-0
820T1491No-0
821T1128No-0
822T1505.001No-0
823T1003.004No-0
824T1008No-0
825T1136.002No-0
826T1499.001No-0
827T1505.003No-0
828T1056.001No-0
829T1127.001No-0
830T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
831T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
832T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
833T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
834T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
835T1134.002No-0
836T1102.002No-0
837T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
838T1053.004No-0
839T1564No-0
840T1560.003No-0
841T1578No-0
842T1022No-0
843T1547.005No-0
844T1036.001No-0
845T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
846T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
847T1193No-0
848T1061No-0
849T1127No-0
850T1003.007No-0
851T1165No-0
852T1565.001No-0
853T1012No-0
854T1033No-0
855T1036.005No-0
856T1030No-0
857T1087.002No-0
858T1140No-0
859T1573No-0
860T1039No-0
861T1539No-0
862T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
863T1565No-0
864T1059.002No-0
865T1035No-0
866T1562.006No-0
867T1110.004No-0
868T1076No-0
869T1137.001No-0
870T1574.001No-0
871T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
872T1037No-0
873T1064No-0
874T1090.003No-0
875T1148No-0
876T1531No-0
877T1071.003No-0
878T1498.001No-0
879T1564.006No-0
880T1578.001No-0
881T1556.002No-0
882T1070.006No-0
883T1066No-0
884T1155No-0
885T1098.002No-0
886T1113No-0
887T1106No-0
888T1016No-0
889T1090No-0
890T1147No-0
891T1034No-0
892T1497.003No-0
893T1087.003No-0
894T1494No-0
895T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
896T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
897T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
898T1001No-0
899T1564.003No-0
900T1546No-5
901T1219No-0
902T1201No-0
903T1036.002No-0
904T1055.002No-0
905T1486No-0
906T1578.004No-0
907T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
908T1173No-0
909T1175No-0
910T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
911T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
912T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
913T1568No-0
914T1547.002No-0
915T1169No-0
916T1105No-0
917T1547.003No-0
918T1059.006No-0
919T1552.001No-0
920T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml3
921T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml3
922T1187No-0
923T1480.001No-0
924T1099No-0
925T1210Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml1
926T1489No-0
927T1132No-0
928T1152No-0
929T1119No-0
930T1205.001No-0
931T1567No-0
932T1550Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_get_session_token_abuse.yml2
933T1172No-0
934T1069No-0
935T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
936T1561.001No-0
937T1556.001No-0
938T1087.004No-0
939T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
940T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
941T1554No-0
942T1543No-1
943T1555.003No-0
944T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
945T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
946T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
947T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
948T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
949T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
950T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
951T1014No-0
952T1502No-0
953T1562.002No-0
954T1102.003No-0
955T1077No-0
956T1195.001No-0
957T1011.001No-0
958T1129No-0
959T1564.005No-0
960T1552.004No-0
961T1218.001No-0
962T1001.002No-0
963T1023No-0
964T1086No-0
965T1565.002No-0
966T1214No-0
967T1569No-1
968T1546.010No-0
969T1108No-0
970T1528No-0
971T1131No-0
972T1132.002No-0
973T1037.005No-0
974T1213.001No-0
975T1104No-0
976T1562.007No-0
977T1548No-0
978T1574.012No-0
979T1499No-0
980T1207No-0
981T1543.004No-0
982T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
983T1186No-0
984T1518.001No-0
985T1025No-0
986T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
987T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
988T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
989T1087No-0
990T1563No-0
991T1548.001No-0
992T1547.006No-0
993T1026No-0
994T1137.005No-0
995T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
996T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
997T1547.007No-0
998T1546.007No-0
999T1037.004No-0
1000T1157No-0
1001T1195.002No-0
1002T1212No-0
1003T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
1004T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
1005T1136.003No-0
1006T1567.002No-0
1007T1027.004No-0
1008T1149No-0
1009T1083No-0
1010T1159No-0
1011T1103No-0
1012T1037.003No-0
1013T1218.005No-0
1014T1001.001No-0
1015T1051No-0
1016T1063No-0
1017T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
1018T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
1019T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
1020T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
1021T1204No-1
1022T1546.013No-0
1023T1045No-0
1024T1222.002No-0
1025T1519No-0
1026T1038No-0
1027T1569.001No-0
1028T1154No-0
1029T1074.001No-0
1030T1110No-0
1031T1120No-0
1032T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml4
1033T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml4
1034T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml4
1035T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml4
1036T1094No-0
1037T1054No-0
1038T1546.009No-0
1039T1542.002No-0
1040T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
1041T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
1042T1217No-0
1043T1027.003No-0
1044T1573.002No-0
1045T1218.003No-0
1046T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
1047T1538No-0
1048T1501No-0
1049T1180No-0
1050T1183No-0
1051T1218.002No-0
1052T1137No-0
1053T1493No-0
1054T1151No-0
1055T1205No-0
1056T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
1057T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
1058T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
1059T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
1060T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
1061T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
1062T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
1063T1208No-0
1064T1100No-0
1065T1145No-0
1066T1574.011No-0
1067T1055.003No-0
1068T1522No-0
1069T1558.002No-0
1070T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
1071T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
1072T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
1073T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
1074T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
1075T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
1076T1130No-0
1077T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
1078T1491.001No-0
1079T1548.004No-0
1080T1122No-0
1081T1490No-0
1082T1578.003No-0
1083T1156No-0
1084T1069.001No-0
1085T1055.011No-0
1086T1080No-0
1087T1574.010No-0
1088T1546.012No-0
1089T1019No-0
1090T1056.002No-0
1091T1053No-4
1092T1055.008No-0
1093T1055.012No-0
1094T1561No-0
1095T1160No-0
1096T1043No-0
1097T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
1098T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
1099T1090.001No-0
1100T1102.001No-0
1101T1090.004No-0
1102T1560No-0
1103T1087.001No-0
1104T1499.003No-0
1105T1010No-0
1106T1017No-0
1107T1050No-0
1108T1559No-0
1109T1543.001No-0
1110T1134.003No-0
1111T1111No-0
1112T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
1113T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
1114T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
1115T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
1116T1567.001No-0
1117T1568.003No-0
1118T1505No-0
1119T1503No-0
1120T1018No-0
1121T1536No-0
1122T1133No-0
1123T1216.001No-0
1124T1564.001No-0
1125T1081No-0
1126T1495No-0
1127T1213.002No-0
1128T1098.004No-0
1129T1563.001No-0
1130T1562No-3
1131T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
1132T1561.002No-0
1133T1547No-3
1134T1553.003No-0
1135T1550.001No-0
1136T1134.004No-0
1137T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
1138T1048.001No-0
1139T1218No-1
1140T1202No-0
1141T1055No-0
1142T1021.004No-0
1143T1548.002No-0
1144T1548.003No-0
1145T1067No-0
1146T1092No-0
1147T1166No-0
1148T1546.006No-0
1149T1041No-0
1150T1171No-0
1151T1029No-0
1152T1550.003No-0
1153T1056No-0
1154T1534No-0
1155T1003.008No-0
1156T1497.001No-0
1157T1084No-0
1158T1124No-0
1159T1222No-1
1160T1542.001No-0
1161T1036.003No-0
1162T1056.003No-0
1163T1191No-0
1164T1543.002No-0
1165T1021.006No-0
1166T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
1167T1559.002No-0
1168T1555No-0
1169T1555.001No-0
1170T1573.001No-0
1171T1074.002No-0
1172T1547.011No-0
1173T1042No-0
1174T1547.010No-0
1175T1071No-10
1176T1552.003No-0
1177T1055.009No-0
1178T1578.002No-0
1179T1547.004No-0
1180T1110.003No-0
1181T1107No-0
1182T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
1183T1060No-0
1184T1204.001No-0
1185T1487No-0
1186T1070.003No-0
1187T1552.002No-0
1188T1090.002No-0
1189T1126No-0
1190T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
1191T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
1192T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
1193T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
1194T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
1195T1125No-0
1196T1114No-3
1197T1164No-0
1198T1546.015No-0
1199T1138No-0
1200T1158No-0
1201T1574No-1
1202T1218.004No-0
1203T1024No-0
1204T1181No-0
1205T1505.002No-0
1206T1056.004No-0
1207T1053.003No-0
1208T1215No-0
1209T1198No-0
1210T1178No-0
1211T1143No-0
1212T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_assume_role_abuse.yml26
1213T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml26
1214T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_attach_to_role_policy.yml26
1215T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_role_creation.yml26
1216T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_permanent_key_creation.yml26
1217T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml26
1218T1139No-0
1219T1114.003No-0
1220T1065No-0
1221T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
1222T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
1223T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
1224T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml3
1225T1480No-0
1226T1070.005No-0
1227T1556.003No-0
1228T1053.002No-0
1229T1079No-0
1230T1040No-0
1231T1013No-0
1232T1218.009No-0
1233T1206No-0
1234T1182No-0
1235T1037.002No-0
1236T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
1237T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
1238T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
1239T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
1240T1553No-1
1241T1562.003No-0
1242T1116No-0
1243T1491.002No-0
1244T1574.004No-0
1245T1161No-0
1246T1101No-0
1247T1110.001No-0
1248T1055.004No-0
1249T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
1250T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
1251T1137.006No-0
1252T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml5
1253T1028No-0
1254T1189No-0
1255T1197No-0
1256T1121No-0
1257T1055.001No-0
1258T1059.007No-0
1259T1003.006No-0
1260T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
1261T1574.006No-0
1262T1057No-0
1263T1091No-0
1264T1096No-0
1265T1146No-0
1266T1027.005No-0
1267T1117No-0
1268T1195No-0
1269T1070.002No-0
1270T1174No-0
1271T1055.005No-0
1272T1015No-0
1273T1009No-0
1274T1098.003No-0
1275T1550.004No-0
1276T1504No-0
1277T1021No-6
1278T1574.002No-0
1279T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
1280T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
1281T1168No-0
1282T1011No-0
1283T1546.003No-0
1284T1055.014No-0
1285T1089No-0
1286T1500No-0
1287T1097No-0
1288T1093No-0
1289T1571No-0
1290T1052No-0
1291T1568.002No-0
1292T1176No-0
1293T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
1294T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
1295T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
1296T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
1297T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
1298T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
1299T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
1300T1483No-0
1301T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
1302T1221No-0
1303T1055.013No-0
1304T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
1305T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
1306T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
1307T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
1308T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
1309T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
1310T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
1311T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
1312T1110.002No-0
1313T1552.006No-0
1314T1123No-0
1315T1558No-1
1316T1153No-0
1317T1046No-0
1318T1021.003No-0
1319T1088No-0
1320T1209No-0
1321T1069.002No-0
1322T1542No-0
1323T1069.003No-0
1324T1058No-0
1325T1506No-0
1326T1547.008No-0
1327T1006No-0
1328T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml13
1329T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml13
1330T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml13
1331T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml13
1332T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml13
1333T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml13
1334T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml13
1335T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml13
1336T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml13
1337T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml13
1338T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml13
1339T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml13
1340T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml13
1341T1118No-0
1342T1529No-0
1343T1167No-0
1344T1199No-0
1345T1484No-0
1346T1073No-0
1347T1075No-0
1348T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
1349T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
1350T1044No-0
1351T1213No-0
1352T1059.004No-0
1353T1163No-0
1354T1574.005No-0
1355T1036.004No-0
1356T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
1357T1179No-0
1358T1141No-0
1359T1499.004No-0
1360T1560.001No-0
1361T1098No-0
1362T1564.002No-0
1363T1565.003No-0
1364T1218.008No-0
1365T1497.002No-0
1366T1027.002No-0
1367T1102No-0
1368T1005No-0
1369T1497No-0
1370T1211No-0
1371T1482No-0
1372T1037.001No-0
1373T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
1374T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
1375T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
1376T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
1377T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
1378T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
1379T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
1380T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
1381T1196No-0
1382T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
1383T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
1384T1142No-0
1385T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
1386T1134No-0
1387T1518No-0
1388T1059.005No-0
1389T1150No-0
1390T1031No-0
1391T1132.001No-0
1392T1220No-0
1393T1085No-0
1394T1559.001No-0
1395T1572No-0
1396T1021.005No-0
1397T1574.008No-0
1398T1184No-0
1399T1568.001No-0
1400T1218.007No-0
1401T1546.002No-0
1402T1048.002No-0
1403T1547.009No-0
1404T1003No-12
1405T1557.001No-0
1406T1553.002No-0
1407T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
1408T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
1409T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_zerologon_via_zeek.yml3
1410T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml3
1411T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml3
1412T1560.002No-0
1413T1144No-0
1414T1177No-0
1415T1135No-0
1416T1032No-0
1417T1563.002No-0
1418T1115No-0
1419T1137.003No-0
1420T1546.005No-0
1421T1137.002No-0
1422T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
1423T1134.001No-0
1424T1558.001No-0
1425T1499.002No-0
1426T1496No-0
1427T1137.004No-0
1428T1074No-0
1429T1188No-0
1430T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
1431T1223No-0
1432T1170No-0
1433T1003.005No-0
1434T1556No-0
1435T1218.010No-0
1436T1195.003No-0
1437T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
1438T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
1439T1514No-0
1440T1564.004No-0
1441T1001.003No-0
1442T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
1443T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
1444T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
1445T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
1446T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
1447T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
1448T1036.006No-0
1449T1027.001No-0
1450T1049No-0
1451T1185No-0
1452T1070.004No-0
1453T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_gcp_storage_buckets.yml5
1454T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_gcp_storage_access_from_a_new_ip.yml5
1455T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml5
1456T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml5
1457T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml5
1458T1162No-0
1459T1216No-0
1460T1552No-0
1461T1192No-0
1462T1052.001No-0
1463T1574.007No-0
1464T1007No-0
1465T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml2
1466T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml2
1467T1194No-0
1468T1537No-0
1469T1109No-0
1470T1004No-0
1471T1059No-15
1472T1098.001No-0
1473T1062No-0
1474T1546.014No-0
1475T1552.005No-0
1476T1053.001No-0
1477T1527No-0
1478T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
1479T1570No-0
1480T1020No-0
1481T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
1482T1546.004No-0
1483T1555.002No-0
1484T1002No-0
1485T1492No-0
1486T1553.001No-0
1487T1488No-0
1488T1134.005No-0
1489T1542.003No-0
1490T1491No-0
1491T1128No-0
1492T1505.001No-0
1493T1003.004No-0
1494T1008No-0
1495T1136.002No-0
1496T1499.001No-0
1497T1505.003No-0
1498T1056.001No-0
1499T1127.001No-0
1500T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
1501T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
1502T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
1503T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
1504T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
1505T1134.002No-0
1506T1102.002No-0
1507T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
1508T1053.004No-0
1509T1564No-0
1510T1560.003No-0
1511T1578No-0
1512T1022No-0
1513T1547.005No-0
1514T1036.001No-0
1515T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
1516T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
1517T1193No-0
1518T1061No-0
1519T1127No-0
1520T1003.007No-0
1521T1165No-0
1522T1565.001No-0
1523T1012No-0
1524T1033No-0
1525T1036.005No-0
1526T1030No-0
1527T1087.002No-0
1528T1140No-0
1529T1573No-0
1530T1039No-0
1531T1539No-0
1532T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
1533T1565No-0
1534T1059.002No-0
1535T1035No-0
1536T1562.006No-0
1537T1110.004No-0
1538T1076No-0
1539T1137.001No-0
1540T1574.001No-0
1541T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
1542T1037No-0
1543T1064No-0
1544T1090.003No-0
1545T1148No-0
1546T1531No-0
1547T1071.003No-0
1548T1498.001No-0
1549T1564.006No-0
1550T1578.001No-0
1551T1556.002No-0
1552T1070.006No-0
1553T1066No-0
1554T1155No-0
1555T1098.002No-0
1556T1113No-0
1557T1106No-0
1558T1016No-0
1559T1090No-0
1560T1147No-0
1561T1034No-0
1562T1497.003No-0
1563T1087.003No-0
1564T1494No-0
1565T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
1566T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
1567T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
1568T1001No-0
1569T1564.003No-0
1570T1546No-5
1571T1219No-0
1572T1201No-0
1573T1036.002No-0
1574T1055.002No-0
1575T1486No-0
1576T1578.004No-0
1577T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
1578T1173No-0
1579T1175No-0
1580T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
1581T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
1582T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
1583T1568No-0
1584T1547.002No-0
1585T1169No-0
1586T1105No-0
1587T1547.003No-0
1588T1059.006No-0
1589T1552.001No-0
1590T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml3
1591T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml3
1592T1187No-0
1593T1480.001No-0
1594T1099No-0
1595T1210Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml1
1596T1489No-0
1597T1132No-0
1598T1152No-0
1599T1119No-0
1600T1205.001No-0
1601T1567No-0
1602T1550Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_get_session_token_abuse.yml2
1603T1172No-0
1604T1069No-0
1605T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
1606T1561.001No-0
1607T1556.001No-0
1608T1087.004No-0
1609T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
1610T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
1611T1554No-0
1612T1543No-1
1613T1555.003No-0
1614T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
1615T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
1616T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
1617T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
1618T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
1619T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
1620T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
1621T1014No-0
1622T1502No-0
1623T1562.002No-0
1624T1102.003No-0
1625T1077No-0
1626T1195.001No-0
1627T1011.001No-0
1628T1129No-0
1629T1564.005No-0
1630T1552.004No-0
1631T1218.001No-0
1632T1001.002No-0
1633T1023No-0
1634T1086No-0
1635T1565.002No-0
1636T1214No-0
1637T1569No-1
1638T1546.010No-0
1639T1108No-0
1640T1528No-0
1641T1131No-0
1642T1132.002No-0
1643T1037.005No-0
1644T1213.001No-0
1645T1104No-0
1646T1562.007No-0
1647T1548No-0
1648T1574.012No-0
1649T1499No-0
1650T1207No-0
1651T1543.004No-0
1652T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
1653T1186No-0
1654T1518.001No-0
1655T1025No-0
1656T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
1657T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
1658T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
1659T1087No-0
1660T1563No-0
1661T1548.001No-0
1662T1547.006No-0
1663T1026No-0
1664T1137.005No-0
1665T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
1666T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
1667T1547.007No-0
1668T1546.007No-0
1669T1037.004No-0
1670T1157No-0
1671T1195.002No-0
1672T1212No-0
1673T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
1674T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
1675T1136.003No-0
1676T1567.002No-0
1677T1027.004No-0
1678T1149No-0
1679T1083No-0
1680T1159No-0
1681T1103No-0
1682T1037.003No-0
1683T1218.005No-0
1684T1001.001No-0
1685T1051No-0
1686T1063No-0
1687T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
1688T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
1689T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
1690T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
1691T1204No-1
1692T1546.013No-0
1693T1045No-0
1694T1222.002No-0
1695T1519No-0
1696T1038No-0
1697T1569.001No-0
1698T1154No-0
1699T1074.001No-0
1700T1110No-0
1701T1120No-0
1702T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml4
1703T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml4
1704T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml4
1705T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml4
1706T1094No-0
1707T1054No-0
1708T1546.009No-0
1709T1542.002No-0
1710T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
1711T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
1712T1217No-0
1713T1027.003No-0
1714T1573.002No-0
1715T1218.003No-0
1716T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
1717T1538No-0
1718T1501No-0
1719T1180No-0
1720T1183No-0
1721T1218.002No-0
1722T1137No-0
1723T1493No-0
1724T1151No-0
1725T1205No-0
1726T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
1727T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
1728T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
1729T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
1730T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
1731T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
1732T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
1733T1208No-0
1734T1100No-0
1735T1145No-0
1736T1574.011No-0
1737T1055.003No-0
1738T1522No-0
1739T1558.002No-0
1740T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
1741T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
1742T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
1743T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
1744T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
1745T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
1746T1130No-0
1747T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
1748T1491.001No-0
1749T1548.004No-0
1750T1122No-0
1751T1490No-0
1752T1578.003No-0
1753T1156No-0
1754T1069.001No-0
1755T1055.011No-0
1756T1080No-0
1757T1574.010No-0
1758T1546.012No-0
1759T1019No-0
1760T1056.002No-0
1761T1053No-4
1762T1055.008No-0
1763T1055.012No-0
1764T1561No-0
1765T1160No-0
1766T1043No-0
1767T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
1768T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
1769T1090.001No-0
1770T1102.001No-0
1771T1090.004No-0
1772T1560No-0
1773T1087.001No-0
1774T1499.003No-0
1775T1010No-0
1776T1017No-0
1777T1050No-0
1778T1559No-0
1779T1543.001No-0
1780T1134.003No-0
1781T1111No-0
1782T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
1783T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
1784T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
1785T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
1786T1567.001No-0
1787T1568.003No-0
1788T1505No-0
1789T1503No-0
1790T1018No-0
1791T1536No-0
1792T1133No-0
1793T1216.001No-0
1794T1564.001No-0
1795T1081No-0
1796T1495No-0
1797T1213.002No-0
1798T1098.004No-0
1799T1563.001No-0
1800T1562No-3
1801T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
1802T1561.002No-0
1803T1547No-3
1804T1553.003No-0
1805T1550.001No-0
1806T1134.004No-0
1807T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
1808T1048.001No-0
1809T1218No-1
1810T1202No-0
1811T1055No-0
1812T1021.004No-0
1813T1548.002No-0
1814T1548.003No-0
1815T1067No-0
1816T1092No-0
1817T1166No-0
1818T1546.006No-0
1819T1041No-0
1820T1171No-0
1821T1029No-0
1822T1550.003No-0
1823T1056No-0
1824T1534No-0
1825T1003.008No-0
1826T1497.001No-0
1827T1084No-0
1828T1124No-0
1829T1222No-1
1830T1542.001No-0
1831T1036.003No-0
1832T1056.003No-0
1833T1191No-0
1834T1543.002No-0
1835T1021.006No-0
1836T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
1837T1559.002No-0
1838T1555No-0
1839T1555.001No-0
1840T1573.001No-0
1841T1074.002No-0
1842T1547.011No-0
1843T1042No-0
1844T1547.010No-0
1845T1071No-10
1846T1552.003No-0
1847T1055.009No-0
1848T1578.002No-0
1849T1547.004No-0
1850T1110.003No-0
1851T1107No-0
1852T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
1853T1060No-0
1854T1204.001No-0
1855T1487No-0
1856T1070.003No-0
1857T1552.002No-0
1858T1090.002No-0
1859T1126No-0
1860T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
1861T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
1862T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
1863T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
1864T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
1865T1125No-0
1866T1114No-3
1867T1164No-0
1868T1546.015No-0
1869T1138No-0
1870T1158No-0
1871T1574No-1
1872T1218.004No-0
1873T1024No-0
1874T1181No-0
1875T1505.002No-0
1876T1056.004No-0
1877T1053.003No-0
1878T1215No-0
1879T1198No-0
1880T1178No-0
1881T1143No-0
1882T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_assume_role_abuse.yml26
1883T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml26
1884T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_attach_to_role_policy.yml26
1885T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_role_creation.yml26
1886T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_permanent_key_creation.yml26
1887T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml26
1888T1139No-0
1889T1114.003No-0
1890T1065No-0
1891T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
1892T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
1893T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
1894T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml3
1895T1480No-0
1896T1070.005No-0
1897T1556.003No-0
1898T1053.002No-0
1899T1079No-0
1900T1040No-0
1901T1013No-0
1902T1218.009No-0
1903T1206No-0
1904T1182No-0
1905T1037.002No-0
1906T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
1907T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
1908T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
1909T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
1910T1553No-1
1911T1562.003No-0
1912T1116No-0
1913T1491.002No-0
1914T1574.004No-0
1915T1161No-0
1916T1101No-0
1917T1110.001No-0
1918T1055.004No-0
1919T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
1920T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
1921T1137.006No-0
1922T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml5
1923T1028No-0
1924T1189No-0
1925T1197No-0
1926T1121No-0
1927T1055.001No-0
1928T1059.007No-0
1929T1003.006No-0
1930T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
1931T1574.006No-0
1932T1057No-0
1933T1091No-0
1934T1096No-0
1935T1146No-0
1936T1027.005No-0
1937T1117No-0
1938T1195No-0
1939T1070.002No-0
1940T1174No-0
1941T1055.005No-0
1942T1015No-0
1943T1009No-0
1944T1098.003No-0
1945T1550.004No-0
1946T1504No-0
1947T1021No-6
1948T1574.002No-0
1949T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
1950T1557Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
1951T1168No-0
1952T1011No-0
1953T1546.003No-0
1954T1055.014No-0
1955T1089No-0
1956T1500No-0
1957T1097No-0
1958T1093No-0
1959T1571No-0
1960T1052No-0
1961T1568.002No-0
1962T1176No-0
1963T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
1964T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
1965T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
1966T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
1967T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
1968T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
1969T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
1970T1483No-0
1971T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
1972T1221No-0
1973T1055.013No-0
1974T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
1975T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
1976T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
1977T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
1978T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
1979T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
1980T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
1981T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
1982T1110.002No-0
1983T1552.006No-0
1984T1123No-0
1985T1558No-1
1986T1153No-0
1987T1046No-0
1988T1021.003No-0
1989T1088No-0
1990T1209No-0
1991T1069.002No-0
1992T1542No-0
1993T1069.003No-0
1994T1058No-0
1995T1506No-0
1996T1547.008No-0
1997T1006No-0
1998T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml13
1999T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml13
2000T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml13
2001T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml13
2002T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml13
2003T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml13
2004T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml13
2005T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml13
2006T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml13
2007T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml13
2008T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml13
2009T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml13
2010T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml13
2011T1118No-0
2012T1529No-0
2013T1167No-0
2014T1199No-0
2015T1484No-0
2016T1073No-0
2017T1075No-0
2018T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
2019T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
2020T1044No-0
2021T1213No-0
2022T1059.004No-0
2023T1163No-0
2024T1574.005No-0
2025T1036.004No-0
2026T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
2027T1179No-0
2028T1141No-0
2029T1499.004No-0
2030T1560.001No-0
2031T1098No-0
2032T1564.002No-0
2033T1565.003No-0
2034T1218.008No-0
2035T1497.002No-0
2036T1027.002No-0
2037T1102No-0
2038T1005No-0
2039T1497No-0
2040T1211No-0
2041T1482No-0
2042T1037.001No-0
2043T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
2044T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
2045T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
2046T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
2047T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
2048T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
2049T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
2050T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
2051T1196No-0
2052T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
2053T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
2054T1142No-0
2055T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
2056T1134No-0
2057T1518No-0
2058T1059.005No-0
2059T1150No-0
2060T1031No-0
2061T1132.001No-0
2062T1220No-0
2063T1085No-0
2064T1559.001No-0
2065T1572No-0
2066T1021.005No-0
2067T1574.008No-0
2068T1184No-0
2069T1568.001No-0
2070T1218.007No-0
2071T1546.002No-0
2072T1048.002No-0
2073T1547.009No-0
2074T1003No-12
2075T1557.001No-0
2076T1553.002No-0
2077T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
2078T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
2079T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_zerologon_via_zeek.yml3
2080T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml3
2081T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml3
2082T1560.002No-0
2083T1144No-0
2084T1177No-0
2085T1135No-0
2086T1032No-0
2087T1563.002No-0
2088T1115No-0
2089T1137.003No-0
2090T1546.005No-0
2091T1137.002No-0
2092T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
2093T1134.001No-0
2094T1558.001No-0
2095T1499.002No-0
2096T1496No-0
2097T1137.004No-0
2098T1074No-0
2099T1188No-0
2100T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
2101T1223No-0
2102T1170No-0
2103T1003.005No-0
2104T1556No-0
2105T1218.010No-0
2106T1195.003No-0
2107T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
2108T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
2109T1514No-0
2110T1564.004No-0
2111T1001.003No-0
2112T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
2113T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
2114T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
2115T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
2116T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
2117T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
2118T1036.006No-0
2119T1027.001No-0
2120T1049No-0
2121T1185No-0
2122T1070.004No-0
2123T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_gcp_storage_buckets.yml5
2124T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_gcp_storage_access_from_a_new_ip.yml5
2125T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml5
2126T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml5
2127T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml5
2128T1162No-0
2129T1216No-0
2130T1552No-0
2131T1192No-0
2132T1052.001No-0
2133T1574.007No-0
2134T1007No-0
2135T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml2
2136T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml2
2137T1194No-0
2138T1537No-0
2139T1109No-0
2140T1004No-0
2141T1059No-15
2142T1098.001No-0
2143T1062No-0
2144T1546.014No-0
2145T1552.005No-0
2146T1053.001No-0
2147T1527No-0
2148T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
2149T1570No-0
2150T1020No-0
2151T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
2152T1546.004No-0
2153T1555.002No-0
2154T1002No-0
2155T1492No-0
2156T1553.001No-0
2157T1488No-0
2158T1134.005No-0
2159T1542.003No-0
2160T1491No-0
2161T1128No-0
2162T1505.001No-0
2163T1003.004No-0
2164T1008No-0
2165T1136.002No-0
2166T1499.001No-0
2167T1505.003No-0
2168T1056.001No-0
2169T1127.001No-0
2170T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
2171T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
2172T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
2173T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
2174T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
2175T1134.002No-0
2176T1102.002No-0
2177T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
2178T1053.004No-0
2179T1564No-0
2180T1560.003No-0
2181T1578No-0
2182T1022No-0
2183T1547.005No-0
2184T1036.001No-0
2185T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
2186T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
2187T1193No-0
2188T1061No-0
2189T1127No-0
2190T1003.007No-0
2191T1165No-0
2192T1565.001No-0
2193T1012No-0
2194T1033No-0
2195T1036.005No-0
2196T1030No-0
2197T1087.002No-0
2198T1140No-0
2199T1573No-0
2200T1039No-0
2201T1539No-0
2202T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
2203T1565No-0
2204T1059.002No-0
2205T1035No-0
2206T1562.006No-0
2207T1110.004No-0
2208T1076No-0
2209T1137.001No-0
2210T1574.001No-0
2211T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
2212T1037No-0
2213T1064No-0
2214T1090.003No-0
2215T1148No-0
2216T1531No-0
2217T1071.003No-0
2218T1498.001No-0
2219T1564.006No-0
2220T1578.001No-0
2221T1556.002No-0
2222T1070.006No-0
2223T1066No-0
2224T1155No-0
2225T1098.002No-0
2226T1113No-0
2227T1106No-0
2228T1016No-0
2229T1090No-0
2230T1147No-0
2231T1034No-0
2232T1497.003No-0
2233T1087.003No-0
2234T1494No-0
2235T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
2236T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
2237T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
2238T1001No-0
2239T1564.003No-0
2240T1546No-5
2241T1219No-0
2242T1201No-0
2243T1036.002No-0
2244T1055.002No-0
2245T1486No-0
2246T1578.004No-0
2247T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
2248T1173No-0
2249T1175No-0
2250T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
2251T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
2252T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
2253T1568No-0
2254T1547.002No-0
2255T1169No-0
2256T1105No-0
2257T1547.003No-0
2258T1059.006No-0
2259T1552.001No-0
2260T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml3
2261T1498Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml3
2262T1187No-0
2263T1480.001No-0
2264T1099No-0
2265T1210Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_computer_changed_with_anonymous_account.yml1
2266T1489No-0
2267T1132No-0
2268T1152No-0
2269T1119No-0
2270T1205.001No-0
2271T1567No-0
2272T1550Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_detect_sts_get_session_token_abuse.yml2
2273T1172No-0
2274T1069No-0
2275T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
2276T1561.001No-0
2277T1556.001No-0
2278T1087.004No-0
2279T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
2280T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
2281T1554No-0
2282T1543No-1
2283T1555.003No-0
2284T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
2285T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
2286T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
2287T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
2288T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
2289T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
2290T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
2291T1014No-0
2292T1502No-0
2293T1562.002No-0
2294T1102.003No-0
2295T1077No-0
2296T1195.001No-0
2297T1011.001No-0
2298T1129No-0
2299T1564.005No-0
2300T1552.004No-0
2301T1218.001No-0
2302T1001.002No-0
2303T1023No-0
2304T1086No-0
2305T1565.002No-0
2306T1214No-0
2307T1569No-1
2308T1546.010No-0
2309T1108No-0
2310T1528No-0
2311T1131No-0
2312T1132.002No-0
2313T1037.005No-0
2314T1213.001No-0
2315T1104No-0
2316T1562.007No-0
2317T1548No-0
2318T1574.012No-0
2319T1499No-0
2320T1207No-0
2321T1543.004No-0
2322T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
2323T1186No-0
2324T1518.001No-0
2325T1025No-0
2326T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
2327T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
2328T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
2329T1087No-0
2330T1563No-0
2331T1548.001No-0
2332T1547.006No-0
2333T1026No-0
2334T1137.005No-0
2335T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
2336T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
2337T1547.007No-0
2338T1546.007No-0
2339T1037.004No-0
2340T1157No-0
2341T1195.002No-0
2342T1212No-0
2343T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_arp_poisoning.yml2
2344T1200Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_rogue_dhcp_server.yml2
2345T1136.003No-0
2346T1567.002No-0
2347T1027.004No-0
2348T1149No-0
2349T1083No-0
2350T1159No-0
2351T1103No-0
2352T1037.003No-0
2353T1218.005No-0
2354T1001.001No-0
2355T1051No-0
2356T1063No-0
2357T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
2358T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
2359T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
2360T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
2361T1204No-1
2362T1546.013No-0
2363T1045No-0
2364T1222.002No-0
2365T1519No-0
2366T1038No-0
2367T1569.001No-0
2368T1154No-0
2369T1074.001No-0
2370T1110No-0
2371T1120No-0
2372T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml4
2373T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml4
2374T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml4
2375T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml4
2376T1094No-0
2377T1054No-0
2378T1546.009No-0
2379T1542.002No-0
2380T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
2381T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
2382T1217No-0
2383T1027.003No-0
2384T1573.002No-0
2385T1218.003No-0
2386T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
2387T1538No-0
2388T1501No-0
2389T1180No-0
2390T1183No-0
2391T1218.002No-0
2392T1137No-0
2393T1493No-0
2394T1151No-0
2395T1205No-0
2396T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
2397T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
2398T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
2399T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
2400T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
2401T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
2402T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
2403T1208No-0
2404T1100No-0
2405T1145No-0
2406T1574.011No-0
2407T1055.003No-0
2408T1522No-0
2409T1558.002No-0
2410T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
2411T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
2412T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
2413T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
2414T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
2415T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
2416T1130No-0
2417T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
2418T1491.001No-0
2419T1548.004No-0
2420T1122No-0
2421T1490No-0
2422T1578.003No-0
2423T1156No-0
2424T1069.001No-0
2425T1055.011No-0
2426T1080No-0
2427T1574.010No-0
2428T1546.012No-0
2429T1019No-0
2430T1056.002No-0
2431T1053No-4
2432T1055.008No-0
2433T1055.012No-0
2434T1561No-0
2435T1160No-0
2436T1043No-0
2437T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
2438T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
2439T1090.001No-0
2440T1102.001No-0
2441T1090.004No-0
2442T1560No-0
2443T1087.001No-0
2444T1499.003No-0
2445T1010No-0
2446T1017No-0
2447T1050No-0
2448T1559No-0
2449T1543.001No-0
2450T1134.003No-0
2451T1111No-0
2452T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
2453T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
2454T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
2455T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
2456T1567.001No-0
2457T1568.003No-0
2458T1505No-0
2459T1503No-0
2460T1018No-0
2461T1536No-0
2462T1133No-0
2463T1216.001No-0
2464T1564.001No-0
2465T1081No-0
2466T1495No-0
2467T1213.002No-0
2468T1098.004No-0
2469T1563.001No-0
2470T1562No-3
2471T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
2472T1561.002No-0
2473T1547No-3
2474T1553.003No-0
2475T1550.001No-0
2476T1134.004No-0
2477T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
2478T1048.001No-0
2479T1218No-1
2480T1202No-0
2481T1055No-0
2482T1021.004No-0
2483T1548.002No-0
2484T1548.003No-0
2485T1067No-0
2486T1092No-0
2487T1166No-0
2488T1546.006No-0
2489T1041No-0
2490T1171No-0
2491T1029No-0
2492T1550.003No-0
2493T1056No-0
2494T1534No-0
2495T1003.008No-0
2496T1497.001No-0
2497T1084No-0
2498T1124No-0
2499T1222No-1
2500T1542.001No-0
The file is too large to be shown. View Raw