Files
splunk-security_content/docs/mitre-map/coverage.csv
T
2020-08-22 01:18:14 -04:00

7.1 MiB

1Technique IDDetection AvailableLinkscore
2T1568.001No-0
3T1218.010No-0
4T1213No-0
5T1519No-0
6T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
7T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
8T1027.002No-0
9T1020No-0
10T1158No-0
11T1164No-0
12T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml4
13T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml4
14T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml4
15T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml4
16T1201No-0
17T1578.003No-0
18T1049No-0
19T1547.011No-0
20T1185No-0
21T1564.005No-0
22T1119No-0
23T1037No-0
24T1055.005No-0
25T1199No-0
26T1547.003No-0
27T1069.003No-0
28T1537No-0
29T1192No-0
30T1146No-0
31T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
32T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
33T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
34T1069No-0
35T1044No-0
36T1505No-0
37T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
38T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
39T1542.001No-0
40T1514No-0
41T1552No-0
42T1052No-0
43T1556.003No-0
44T1563.001No-0
45T1499.002No-0
46T1574No-1
47T1563No-0
48T1055.014No-0
49T1134.005No-0
50T1558Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml2
51T1542.002No-0
52T1077No-0
53T1121No-0
54T1059.006No-0
55T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
56T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
57T1574.002No-0
58T1079No-0
59T1213.001No-0
60T1504No-0
61T1090.001No-0
62T1083No-0
63T1552.001No-0
64T1134No-0
65T1144No-0
66T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
67T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
68T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml3
69T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml3
70T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml3
71T1120No-0
72T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
73T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
74T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
75T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
76T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
77T1550No-1
78T1547.004No-0
79T1218.003No-0
80T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
81T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
82T1059.004No-0
83T1011.001No-0
84T1100No-0
85T1054No-0
86T1021Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml7
87T1564No-0
88T1547.009No-0
89T1022No-0
90T1102.001No-0
91T1105No-0
92T1559.001No-0
93T1036.001No-0
94T1070.004No-0
95T1578.004No-0
96T1572No-0
97T1546.009No-0
98T1518No-0
99T1501No-0
100T1053.002No-0
101T1548.002No-0
102T1212No-0
103T1065No-0
104T1546.003No-0
105T1175No-0
106T1552.004No-0
107T1223No-0
108T1574.008No-0
109T1015No-0
110T1567.002No-0
111T1218.002No-0
112T1023No-0
113T1183No-0
114T1125No-0
115T1200No-0
116T1108No-0
117T1578.001No-0
118T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
119T1573.002No-0
120T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
121T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
122T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
123T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
124T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
125T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
126T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
127T1147No-0
128T1004No-0
129T1205No-0
130T1552.006No-0
131T1104No-0
132T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
133T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
134T1056No-0
135T1219No-0
136T1567.001No-0
137T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
138T1036.002No-0
139T1046No-0
140T1115No-0
141T1554No-0
142T1546.002No-0
143T1565.001No-0
144T1502No-0
145T1211No-0
146T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
147T1080No-0
148T1560.003No-0
149T1180No-0
150T1070.005No-0
151T1542.003No-0
152T1555.001No-0
153T1052.001No-0
154T1056.004No-0
155T1094No-0
156T1001.003No-0
157T1076No-0
158T1215No-0
159T1218.007No-0
160T1178No-0
161T1171No-0
162T1140No-0
163T1025No-0
164T1136.003No-0
165T1547.007No-0
166T1552.003No-0
167T1213.002No-0
168T1001.001No-0
169T1195.002No-0
170T1053No-4
171T1209No-0
172T1069.001No-0
173T1193No-0
174T1179No-0
175T1098.003No-0
176T1505.002No-0
177T1059.002No-0
178T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
179T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
180T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
181T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
182T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
183T1563.002No-0
184T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
185T1099No-0
186T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
187T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
188T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
189T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
190T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
191T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
192T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
193T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
194T1195.001No-0
195T1497.001No-0
196T1536No-0
197T1058No-0
198T1005No-0
199T1148No-0
200T1038No-0
201T1552.002No-0
202T1218.005No-0
203T1486No-0
204T1003.008No-0
205T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml21
206T1053.001No-0
207T1557.001No-0
208T1500No-0
209T1170No-0
210T1166No-0
211T1051No-0
212T1498.001No-0
213T1210No-0
214T1074.002No-0
215T1202No-0
216T1495No-0
217T1561.002No-0
218T1102.003No-0
219T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
220T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml2
221T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml2
222T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
223T1087.001No-0
224T1218.008No-0
225T1547.005No-0
226T1040No-0
227T1153No-0
228T1087.003No-0
229T1071No-10
230T1129No-0
231T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
232T1155No-0
233T1085No-0
234T1177No-0
235T1021.004No-0
236T1042No-0
237T1090.003No-0
238T1134.004No-0
239T1053.004No-0
240T1221No-0
241T1557No-0
242T1003.007No-0
243T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
244T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
245T1555.003No-0
246T1132.002No-0
247T1113No-0
248T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml2
249T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml2
250T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
251T1208No-0
252T1499No-0
253T1561No-0
254T1497.003No-0
255T1009No-0
256T1496No-0
257T1216.001No-0
258T1011No-0
259T1548.004No-0
260T1127No-0
261T1562.006No-0
262T1124No-0
263T1126No-0
264T1055.004No-0
265T1098.002No-0
266T1505.003No-0
267T1031No-0
268T1574.007No-0
269T1137.002No-0
270T1491.002No-0
271T1548.003No-0
272T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
273T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
274T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
275T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
276T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
277T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
278T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
279T1021.003No-0
280T1048.002No-0
281T1196No-0
282T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
283T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
284T1169No-0
285T1128No-0
286T1548.001No-0
287T1172No-0
288T1149No-0
289T1543No-1
290T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
291T1182No-0
292T1547No-3
293T1059No-15
294T1093No-0
295T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
296T1037.002No-0
297T1098No-0
298T1527No-0
299T1220No-0
300T1034No-0
301T1141No-0
302T1116No-0
303T1003.005No-0
304T1041No-0
305T1055.002No-0
306T1522No-0
307T1074.001No-0
308T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
309T1111No-0
310T1546.005No-0
311T1050No-0
312T1574.001No-0
313T1055.011No-0
314T1184No-0
315T1074No-0
316T1542No-0
317T1073No-0
318T1092No-0
319T1014No-0
320T1189No-0
321T1137.006No-0
322T1075No-0
323T1087.002No-0
324T1134.003No-0
325T1222.002No-0
326T1562.002No-0
327T1548No-0
328T1035No-0
329T1555No-0
330T1561.001No-0
331T1098.004No-0
332T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
333T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
334T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
335T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
336T1017No-0
337T1205.001No-0
338T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
339T1565.002No-0
340T1569No-1
341T1499.004No-0
342T1037.005No-0
343T1553.003No-0
344T1546.004No-0
345T1053.003No-0
346T1560No-0
347T1181No-0
348T1565No-0
349T1131No-0
350T1558.002No-0
351T1218.009No-0
352T1001.002No-0
353T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
354T1160No-0
355T1060No-0
356T1560.001No-0
357T1489No-0
358T1207No-0
359T1204No-1
360T1553.001No-0
361T1018No-0
362T1547.002No-0
363T1091No-0
364T1019No-0
365T1543.001No-0
366T1555.002No-0
367T1492No-0
368T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
369T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
370T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
371T1574.004No-0
372T1550.003No-0
373T1480No-0
374T1161No-0
375T1558.001No-0
376T1214No-0
377T1546.006No-0
378T1556No-0
379T1087No-0
380T1574.005No-0
381T1506No-0
382T1564.001No-0
383T1130No-0
384T1139No-0
385T1045No-0
386T1546.007No-0
387T1032No-0
388T1090No-0
389T1498No-1
390T1027.005No-0
391T1543.004No-0
392T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
393T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
394T1097No-0
395T1546No-5
396T1556.002No-0
397T1176No-0
398T1562No-3
399T1187No-0
400T1070.006No-0
401T1186No-0
402T1057No-0
403T1543.002No-0
404T1574.010No-0
405T1028No-0
406T1010No-0
407T1565.003No-0
408T1056.001No-0
409T1110.003No-0
410T1109No-0
411T1142No-0
412T1154No-0
413T1547.006No-0
414T1487No-0
415T1037.003No-0
416T1071.003No-0
417T1027.003No-0
418T1055.012No-0
419T1056.003No-0
420T1090.004No-0
421T1137No-0
422T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
423T1110.001No-0
424T1204.001No-0
425T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
426T1137.001No-0
427T1027.004No-0
428T1106No-0
429T1036.005No-0
430T1553.002No-0
431T1070.003No-0
432T1218.001No-0
433T1482No-0
434T1137.005No-0
435T1013No-0
436T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
437T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
438T1123No-0
439T1021.005No-0
440T1574.006No-0
441T1012No-0
442T1499.003No-0
443T1218.004No-0
444T1168No-0
445T1048.001No-0
446T1222No-1
447T1173No-0
448T1156No-0
449T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
450T1134.002No-0
451T1055.003No-0
452T1480.001No-0
453T1570No-0
454T1101No-0
455T1029No-0
456T1534No-0
457T1556.001No-0
458T1086No-0
459T1494No-0
460T1491.001No-0
461T1056.002No-0
462T1008No-0
463T1036.004No-0
464T1195.003No-0
465T1055No-0
466T1568.003No-0
467T1007No-0
468T1574.011No-0
469T1067No-0
470T1505.001No-0
471T1206No-0
472T1062No-0
473T1152No-0
474T1564.003No-0
475T1114.003No-0
476T1528No-0
477T1037.001No-0
478T1198No-0
479T1064No-0
480T1145No-0
481T1059.005No-0
482T1493No-0
483T1110.004No-0
484T1055.008No-0
485T1568No-0
486T1081No-0
487T1055.001No-0
488T1194No-0
489T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
490T1546.010No-0
491T1002No-0
492T1039No-0
493T1573.001No-0
494T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
495T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
496T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
497T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
498T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
499T1550.001No-0
500T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
501T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
502T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
503T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
504T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
505T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
506T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
507T1538No-0
508T1191No-0
509T1001No-0
510T1150No-0
511T1098.001No-0
512T1568.002No-0
513T1547.008No-0
514T1133No-0
515T1559.002No-0
516T1567No-0
517T1084No-0
518T1114No-3
519T1070.002No-0
520T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
521T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
522T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
523T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
524T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
525T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
526T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
527T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
528T1564.002No-0
529T1484No-0
530T1055.009No-0
531T1135No-0
532T1574.012No-0
533T1564.004No-0
534T1163No-0
535T1562.007No-0
536T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
537T1090.002No-0
538T1564.006No-0
539T1066No-0
540T1055.013No-0
541T1491No-0
542T1546.012No-0
543T1197No-0
544T1547.010No-0
545T1016No-0
546T1499.001No-0
547T1573No-0
548T1127.001No-0
549T1117No-0
550T1027.001No-0
551T1546.014No-0
552T1162No-0
553T1559No-0
554T1503No-0
555T1195No-0
556T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
557T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
558T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
559T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
560T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
561T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
562T1122No-0
563T1560.002No-0
564T1110.002No-0
565T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml5
566T1059.007No-0
567T1043No-0
568T1488No-0
569T1529No-0
570T1096No-0
571T1550.004No-0
572T1217No-0
573T1218No-1
574T1578No-0
575T1546.015No-0
576T1006No-0
577T1137.003No-0
578T1174No-0
579T1134.001No-0
580T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml3
581T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
582T1030No-0
583T1137.004No-0
584T1036.006No-0
585T1539No-0
586T1518.001No-0
587T1061No-0
588T1151No-0
589T1578.002No-0
590T1037.004No-0
591T1107No-0
592T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
593T1103No-0
594T1490No-0
595T1483No-0
596T1088No-0
597T1159No-0
598T1165No-0
599T1132.001No-0
600T1003.004No-0
601T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
602T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
603T1102No-0
604T1024No-0
605T1157No-0
606T1003No-12
607T1087.004No-0
608T1552.005No-0
609T1562.003No-0
610T1553No-1
611T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
612T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
613T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
614T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
615T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
616T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
617T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
618T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
619T1216No-0
620T1063No-0
621T1036.003No-0
622T1569.001No-0
623T1118No-0
624T1571No-0
625T1069.002No-0
626T1089No-0
627T1143No-0
628T1003.006No-0
629T1497.002No-0
630T1188No-0
631T1110No-0
632T1531No-0
633T1138No-0
634T1132No-0
635T1546.013No-0
636T1026No-0
637T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
638T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
639T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
640T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
641T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
642T1102.002No-0
643T1033No-0
644T1021.006No-0
645T1497No-0
646T1167No-0
647T1136.002No-0
648T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml13
649T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml13
650T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml13
651T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml13
652T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml13
653T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml13
654T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml13
655T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml13
656T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml13
657T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml13
658T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml13
659T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml13
660T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml13
661T1568.001No-0
662T1218.010No-0
663T1213No-0
664T1519No-0
665T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
666T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
667T1027.002No-0
668T1020No-0
669T1158No-0
670T1164No-0
671T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml4
672T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml4
673T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml4
674T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml4
675T1201No-0
676T1578.003No-0
677T1049No-0
678T1547.011No-0
679T1185No-0
680T1564.005No-0
681T1119No-0
682T1037No-0
683T1055.005No-0
684T1199No-0
685T1547.003No-0
686T1069.003No-0
687T1537No-0
688T1192No-0
689T1146No-0
690T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
691T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
692T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
693T1069No-0
694T1044No-0
695T1505No-0
696T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
697T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
698T1542.001No-0
699T1514No-0
700T1552No-0
701T1052No-0
702T1556.003No-0
703T1563.001No-0
704T1499.002No-0
705T1574No-1
706T1563No-0
707T1055.014No-0
708T1134.005No-0
709T1558Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml2
710T1542.002No-0
711T1077No-0
712T1121No-0
713T1059.006No-0
714T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
715T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
716T1574.002No-0
717T1079No-0
718T1213.001No-0
719T1504No-0
720T1090.001No-0
721T1083No-0
722T1552.001No-0
723T1134No-0
724T1144No-0
725T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
726T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
727T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml3
728T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml3
729T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml3
730T1120No-0
731T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
732T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
733T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
734T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
735T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
736T1550No-1
737T1547.004No-0
738T1218.003No-0
739T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
740T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
741T1059.004No-0
742T1011.001No-0
743T1100No-0
744T1054No-0
745T1021Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml7
746T1564No-0
747T1547.009No-0
748T1022No-0
749T1102.001No-0
750T1105No-0
751T1559.001No-0
752T1036.001No-0
753T1070.004No-0
754T1578.004No-0
755T1572No-0
756T1546.009No-0
757T1518No-0
758T1501No-0
759T1053.002No-0
760T1548.002No-0
761T1212No-0
762T1065No-0
763T1546.003No-0
764T1175No-0
765T1552.004No-0
766T1223No-0
767T1574.008No-0
768T1015No-0
769T1567.002No-0
770T1218.002No-0
771T1023No-0
772T1183No-0
773T1125No-0
774T1200No-0
775T1108No-0
776T1578.001No-0
777T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
778T1573.002No-0
779T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
780T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
781T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
782T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
783T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
784T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
785T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
786T1147No-0
787T1004No-0
788T1205No-0
789T1552.006No-0
790T1104No-0
791T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
792T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
793T1056No-0
794T1219No-0
795T1567.001No-0
796T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
797T1036.002No-0
798T1046No-0
799T1115No-0
800T1554No-0
801T1546.002No-0
802T1565.001No-0
803T1502No-0
804T1211No-0
805T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
806T1080No-0
807T1560.003No-0
808T1180No-0
809T1070.005No-0
810T1542.003No-0
811T1555.001No-0
812T1052.001No-0
813T1056.004No-0
814T1094No-0
815T1001.003No-0
816T1076No-0
817T1215No-0
818T1218.007No-0
819T1178No-0
820T1171No-0
821T1140No-0
822T1025No-0
823T1136.003No-0
824T1547.007No-0
825T1552.003No-0
826T1213.002No-0
827T1001.001No-0
828T1195.002No-0
829T1053No-4
830T1209No-0
831T1069.001No-0
832T1193No-0
833T1179No-0
834T1098.003No-0
835T1505.002No-0
836T1059.002No-0
837T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
838T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
839T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
840T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
841T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
842T1563.002No-0
843T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
844T1099No-0
845T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
846T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
847T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
848T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
849T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
850T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
851T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
852T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
853T1195.001No-0
854T1497.001No-0
855T1536No-0
856T1058No-0
857T1005No-0
858T1148No-0
859T1038No-0
860T1552.002No-0
861T1218.005No-0
862T1486No-0
863T1003.008No-0
864T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml21
865T1053.001No-0
866T1557.001No-0
867T1500No-0
868T1170No-0
869T1166No-0
870T1051No-0
871T1498.001No-0
872T1210No-0
873T1074.002No-0
874T1202No-0
875T1495No-0
876T1561.002No-0
877T1102.003No-0
878T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
879T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml2
880T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml2
881T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
882T1087.001No-0
883T1218.008No-0
884T1547.005No-0
885T1040No-0
886T1153No-0
887T1087.003No-0
888T1071No-10
889T1129No-0
890T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
891T1155No-0
892T1085No-0
893T1177No-0
894T1021.004No-0
895T1042No-0
896T1090.003No-0
897T1134.004No-0
898T1053.004No-0
899T1221No-0
900T1557No-0
901T1003.007No-0
902T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
903T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
904T1555.003No-0
905T1132.002No-0
906T1113No-0
907T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml2
908T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml2
909T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
910T1208No-0
911T1499No-0
912T1561No-0
913T1497.003No-0
914T1009No-0
915T1496No-0
916T1216.001No-0
917T1011No-0
918T1548.004No-0
919T1127No-0
920T1562.006No-0
921T1124No-0
922T1126No-0
923T1055.004No-0
924T1098.002No-0
925T1505.003No-0
926T1031No-0
927T1574.007No-0
928T1137.002No-0
929T1491.002No-0
930T1548.003No-0
931T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
932T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
933T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
934T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
935T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
936T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
937T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
938T1021.003No-0
939T1048.002No-0
940T1196No-0
941T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
942T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
943T1169No-0
944T1128No-0
945T1548.001No-0
946T1172No-0
947T1149No-0
948T1543No-1
949T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
950T1182No-0
951T1547No-3
952T1059No-15
953T1093No-0
954T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
955T1037.002No-0
956T1098No-0
957T1527No-0
958T1220No-0
959T1034No-0
960T1141No-0
961T1116No-0
962T1003.005No-0
963T1041No-0
964T1055.002No-0
965T1522No-0
966T1074.001No-0
967T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
968T1111No-0
969T1546.005No-0
970T1050No-0
971T1574.001No-0
972T1055.011No-0
973T1184No-0
974T1074No-0
975T1542No-0
976T1073No-0
977T1092No-0
978T1014No-0
979T1189No-0
980T1137.006No-0
981T1075No-0
982T1087.002No-0
983T1134.003No-0
984T1222.002No-0
985T1562.002No-0
986T1548No-0
987T1035No-0
988T1555No-0
989T1561.001No-0
990T1098.004No-0
991T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
992T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
993T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
994T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
995T1017No-0
996T1205.001No-0
997T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
998T1565.002No-0
999T1569No-1
1000T1499.004No-0
1001T1037.005No-0
1002T1553.003No-0
1003T1546.004No-0
1004T1053.003No-0
1005T1560No-0
1006T1181No-0
1007T1565No-0
1008T1131No-0
1009T1558.002No-0
1010T1218.009No-0
1011T1001.002No-0
1012T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
1013T1160No-0
1014T1060No-0
1015T1560.001No-0
1016T1489No-0
1017T1207No-0
1018T1204No-1
1019T1553.001No-0
1020T1018No-0
1021T1547.002No-0
1022T1091No-0
1023T1019No-0
1024T1543.001No-0
1025T1555.002No-0
1026T1492No-0
1027T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
1028T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
1029T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
1030T1574.004No-0
1031T1550.003No-0
1032T1480No-0
1033T1161No-0
1034T1558.001No-0
1035T1214No-0
1036T1546.006No-0
1037T1556No-0
1038T1087No-0
1039T1574.005No-0
1040T1506No-0
1041T1564.001No-0
1042T1130No-0
1043T1139No-0
1044T1045No-0
1045T1546.007No-0
1046T1032No-0
1047T1090No-0
1048T1498No-1
1049T1027.005No-0
1050T1543.004No-0
1051T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
1052T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
1053T1097No-0
1054T1546No-5
1055T1556.002No-0
1056T1176No-0
1057T1562No-3
1058T1187No-0
1059T1070.006No-0
1060T1186No-0
1061T1057No-0
1062T1543.002No-0
1063T1574.010No-0
1064T1028No-0
1065T1010No-0
1066T1565.003No-0
1067T1056.001No-0
1068T1110.003No-0
1069T1109No-0
1070T1142No-0
1071T1154No-0
1072T1547.006No-0
1073T1487No-0
1074T1037.003No-0
1075T1071.003No-0
1076T1027.003No-0
1077T1055.012No-0
1078T1056.003No-0
1079T1090.004No-0
1080T1137No-0
1081T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
1082T1110.001No-0
1083T1204.001No-0
1084T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
1085T1137.001No-0
1086T1027.004No-0
1087T1106No-0
1088T1036.005No-0
1089T1553.002No-0
1090T1070.003No-0
1091T1218.001No-0
1092T1482No-0
1093T1137.005No-0
1094T1013No-0
1095T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
1096T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
1097T1123No-0
1098T1021.005No-0
1099T1574.006No-0
1100T1012No-0
1101T1499.003No-0
1102T1218.004No-0
1103T1168No-0
1104T1048.001No-0
1105T1222No-1
1106T1173No-0
1107T1156No-0
1108T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
1109T1134.002No-0
1110T1055.003No-0
1111T1480.001No-0
1112T1570No-0
1113T1101No-0
1114T1029No-0
1115T1534No-0
1116T1556.001No-0
1117T1086No-0
1118T1494No-0
1119T1491.001No-0
1120T1056.002No-0
1121T1008No-0
1122T1036.004No-0
1123T1195.003No-0
1124T1055No-0
1125T1568.003No-0
1126T1007No-0
1127T1574.011No-0
1128T1067No-0
1129T1505.001No-0
1130T1206No-0
1131T1062No-0
1132T1152No-0
1133T1564.003No-0
1134T1114.003No-0
1135T1528No-0
1136T1037.001No-0
1137T1198No-0
1138T1064No-0
1139T1145No-0
1140T1059.005No-0
1141T1493No-0
1142T1110.004No-0
1143T1055.008No-0
1144T1568No-0
1145T1081No-0
1146T1055.001No-0
1147T1194No-0
1148T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
1149T1546.010No-0
1150T1002No-0
1151T1039No-0
1152T1573.001No-0
1153T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
1154T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
1155T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
1156T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
1157T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
1158T1550.001No-0
1159T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
1160T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
1161T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
1162T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
1163T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
1164T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
1165T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
1166T1538No-0
1167T1191No-0
1168T1001No-0
1169T1150No-0
1170T1098.001No-0
1171T1568.002No-0
1172T1547.008No-0
1173T1133No-0
1174T1559.002No-0
1175T1567No-0
1176T1084No-0
1177T1114No-3
1178T1070.002No-0
1179T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
1180T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
1181T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
1182T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
1183T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
1184T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
1185T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
1186T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
1187T1564.002No-0
1188T1484No-0
1189T1055.009No-0
1190T1135No-0
1191T1574.012No-0
1192T1564.004No-0
1193T1163No-0
1194T1562.007No-0
1195T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
1196T1090.002No-0
1197T1564.006No-0
1198T1066No-0
1199T1055.013No-0
1200T1491No-0
1201T1546.012No-0
1202T1197No-0
1203T1547.010No-0
1204T1016No-0
1205T1499.001No-0
1206T1573No-0
1207T1127.001No-0
1208T1117No-0
1209T1027.001No-0
1210T1546.014No-0
1211T1162No-0
1212T1559No-0
1213T1503No-0
1214T1195No-0
1215T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
1216T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
1217T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
1218T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
1219T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
1220T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
1221T1122No-0
1222T1560.002No-0
1223T1110.002No-0
1224T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml5
1225T1059.007No-0
1226T1043No-0
1227T1488No-0
1228T1529No-0
1229T1096No-0
1230T1550.004No-0
1231T1217No-0
1232T1218No-1
1233T1578No-0
1234T1546.015No-0
1235T1006No-0
1236T1137.003No-0
1237T1174No-0
1238T1134.001No-0
1239T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml3
1240T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
1241T1030No-0
1242T1137.004No-0
1243T1036.006No-0
1244T1539No-0
1245T1518.001No-0
1246T1061No-0
1247T1151No-0
1248T1578.002No-0
1249T1037.004No-0
1250T1107No-0
1251T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
1252T1103No-0
1253T1490No-0
1254T1483No-0
1255T1088No-0
1256T1159No-0
1257T1165No-0
1258T1132.001No-0
1259T1003.004No-0
1260T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
1261T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
1262T1102No-0
1263T1024No-0
1264T1157No-0
1265T1003No-12
1266T1087.004No-0
1267T1552.005No-0
1268T1562.003No-0
1269T1553No-1
1270T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
1271T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
1272T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
1273T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
1274T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
1275T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
1276T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
1277T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
1278T1216No-0
1279T1063No-0
1280T1036.003No-0
1281T1569.001No-0
1282T1118No-0
1283T1571No-0
1284T1069.002No-0
1285T1089No-0
1286T1143No-0
1287T1003.006No-0
1288T1497.002No-0
1289T1188No-0
1290T1110No-0
1291T1531No-0
1292T1138No-0
1293T1132No-0
1294T1546.013No-0
1295T1026No-0
1296T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
1297T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
1298T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
1299T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
1300T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
1301T1102.002No-0
1302T1033No-0
1303T1021.006No-0
1304T1497No-0
1305T1167No-0
1306T1136.002No-0
1307T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml13
1308T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml13
1309T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml13
1310T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml13
1311T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml13
1312T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml13
1313T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml13
1314T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml13
1315T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml13
1316T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml13
1317T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml13
1318T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml13
1319T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml13
1320T1568.001No-0
1321T1218.010No-0
1322T1213No-0
1323T1519No-0
1324T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
1325T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
1326T1027.002No-0
1327T1020No-0
1328T1158No-0
1329T1164No-0
1330T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml4
1331T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml4
1332T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml4
1333T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml4
1334T1201No-0
1335T1578.003No-0
1336T1049No-0
1337T1547.011No-0
1338T1185No-0
1339T1564.005No-0
1340T1119No-0
1341T1037No-0
1342T1055.005No-0
1343T1199No-0
1344T1547.003No-0
1345T1069.003No-0
1346T1537No-0
1347T1192No-0
1348T1146No-0
1349T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
1350T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
1351T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
1352T1069No-0
1353T1044No-0
1354T1505No-0
1355T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
1356T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
1357T1542.001No-0
1358T1514No-0
1359T1552No-0
1360T1052No-0
1361T1556.003No-0
1362T1563.001No-0
1363T1499.002No-0
1364T1574No-1
1365T1563No-0
1366T1055.014No-0
1367T1134.005No-0
1368T1558Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml2
1369T1542.002No-0
1370T1077No-0
1371T1121No-0
1372T1059.006No-0
1373T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
1374T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
1375T1574.002No-0
1376T1079No-0
1377T1213.001No-0
1378T1504No-0
1379T1090.001No-0
1380T1083No-0
1381T1552.001No-0
1382T1134No-0
1383T1144No-0
1384T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
1385T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
1386T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml3
1387T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml3
1388T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml3
1389T1120No-0
1390T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
1391T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
1392T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
1393T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
1394T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
1395T1550No-1
1396T1547.004No-0
1397T1218.003No-0
1398T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
1399T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
1400T1059.004No-0
1401T1011.001No-0
1402T1100No-0
1403T1054No-0
1404T1021Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml7
1405T1564No-0
1406T1547.009No-0
1407T1022No-0
1408T1102.001No-0
1409T1105No-0
1410T1559.001No-0
1411T1036.001No-0
1412T1070.004No-0
1413T1578.004No-0
1414T1572No-0
1415T1546.009No-0
1416T1518No-0
1417T1501No-0
1418T1053.002No-0
1419T1548.002No-0
1420T1212No-0
1421T1065No-0
1422T1546.003No-0
1423T1175No-0
1424T1552.004No-0
1425T1223No-0
1426T1574.008No-0
1427T1015No-0
1428T1567.002No-0
1429T1218.002No-0
1430T1023No-0
1431T1183No-0
1432T1125No-0
1433T1200No-0
1434T1108No-0
1435T1578.001No-0
1436T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
1437T1573.002No-0
1438T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
1439T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
1440T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
1441T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
1442T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
1443T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
1444T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
1445T1147No-0
1446T1004No-0
1447T1205No-0
1448T1552.006No-0
1449T1104No-0
1450T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
1451T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
1452T1056No-0
1453T1219No-0
1454T1567.001No-0
1455T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
1456T1036.002No-0
1457T1046No-0
1458T1115No-0
1459T1554No-0
1460T1546.002No-0
1461T1565.001No-0
1462T1502No-0
1463T1211No-0
1464T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
1465T1080No-0
1466T1560.003No-0
1467T1180No-0
1468T1070.005No-0
1469T1542.003No-0
1470T1555.001No-0
1471T1052.001No-0
1472T1056.004No-0
1473T1094No-0
1474T1001.003No-0
1475T1076No-0
1476T1215No-0
1477T1218.007No-0
1478T1178No-0
1479T1171No-0
1480T1140No-0
1481T1025No-0
1482T1136.003No-0
1483T1547.007No-0
1484T1552.003No-0
1485T1213.002No-0
1486T1001.001No-0
1487T1195.002No-0
1488T1053No-4
1489T1209No-0
1490T1069.001No-0
1491T1193No-0
1492T1179No-0
1493T1098.003No-0
1494T1505.002No-0
1495T1059.002No-0
1496T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
1497T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
1498T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
1499T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
1500T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
1501T1563.002No-0
1502T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
1503T1099No-0
1504T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
1505T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
1506T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
1507T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
1508T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
1509T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
1510T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
1511T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
1512T1195.001No-0
1513T1497.001No-0
1514T1536No-0
1515T1058No-0
1516T1005No-0
1517T1148No-0
1518T1038No-0
1519T1552.002No-0
1520T1218.005No-0
1521T1486No-0
1522T1003.008No-0
1523T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml21
1524T1053.001No-0
1525T1557.001No-0
1526T1500No-0
1527T1170No-0
1528T1166No-0
1529T1051No-0
1530T1498.001No-0
1531T1210No-0
1532T1074.002No-0
1533T1202No-0
1534T1495No-0
1535T1561.002No-0
1536T1102.003No-0
1537T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
1538T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml2
1539T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml2
1540T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
1541T1087.001No-0
1542T1218.008No-0
1543T1547.005No-0
1544T1040No-0
1545T1153No-0
1546T1087.003No-0
1547T1071No-10
1548T1129No-0
1549T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
1550T1155No-0
1551T1085No-0
1552T1177No-0
1553T1021.004No-0
1554T1042No-0
1555T1090.003No-0
1556T1134.004No-0
1557T1053.004No-0
1558T1221No-0
1559T1557No-0
1560T1003.007No-0
1561T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
1562T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
1563T1555.003No-0
1564T1132.002No-0
1565T1113No-0
1566T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml2
1567T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml2
1568T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
1569T1208No-0
1570T1499No-0
1571T1561No-0
1572T1497.003No-0
1573T1009No-0
1574T1496No-0
1575T1216.001No-0
1576T1011No-0
1577T1548.004No-0
1578T1127No-0
1579T1562.006No-0
1580T1124No-0
1581T1126No-0
1582T1055.004No-0
1583T1098.002No-0
1584T1505.003No-0
1585T1031No-0
1586T1574.007No-0
1587T1137.002No-0
1588T1491.002No-0
1589T1548.003No-0
1590T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
1591T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
1592T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
1593T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
1594T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
1595T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
1596T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
1597T1021.003No-0
1598T1048.002No-0
1599T1196No-0
1600T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
1601T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
1602T1169No-0
1603T1128No-0
1604T1548.001No-0
1605T1172No-0
1606T1149No-0
1607T1543No-1
1608T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
1609T1182No-0
1610T1547No-3
1611T1059No-15
1612T1093No-0
1613T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
1614T1037.002No-0
1615T1098No-0
1616T1527No-0
1617T1220No-0
1618T1034No-0
1619T1141No-0
1620T1116No-0
1621T1003.005No-0
1622T1041No-0
1623T1055.002No-0
1624T1522No-0
1625T1074.001No-0
1626T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
1627T1111No-0
1628T1546.005No-0
1629T1050No-0
1630T1574.001No-0
1631T1055.011No-0
1632T1184No-0
1633T1074No-0
1634T1542No-0
1635T1073No-0
1636T1092No-0
1637T1014No-0
1638T1189No-0
1639T1137.006No-0
1640T1075No-0
1641T1087.002No-0
1642T1134.003No-0
1643T1222.002No-0
1644T1562.002No-0
1645T1548No-0
1646T1035No-0
1647T1555No-0
1648T1561.001No-0
1649T1098.004No-0
1650T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
1651T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
1652T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
1653T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
1654T1017No-0
1655T1205.001No-0
1656T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
1657T1565.002No-0
1658T1569No-1
1659T1499.004No-0
1660T1037.005No-0
1661T1553.003No-0
1662T1546.004No-0
1663T1053.003No-0
1664T1560No-0
1665T1181No-0
1666T1565No-0
1667T1131No-0
1668T1558.002No-0
1669T1218.009No-0
1670T1001.002No-0
1671T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
1672T1160No-0
1673T1060No-0
1674T1560.001No-0
1675T1489No-0
1676T1207No-0
1677T1204No-1
1678T1553.001No-0
1679T1018No-0
1680T1547.002No-0
1681T1091No-0
1682T1019No-0
1683T1543.001No-0
1684T1555.002No-0
1685T1492No-0
1686T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
1687T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
1688T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
1689T1574.004No-0
1690T1550.003No-0
1691T1480No-0
1692T1161No-0
1693T1558.001No-0
1694T1214No-0
1695T1546.006No-0
1696T1556No-0
1697T1087No-0
1698T1574.005No-0
1699T1506No-0
1700T1564.001No-0
1701T1130No-0
1702T1139No-0
1703T1045No-0
1704T1546.007No-0
1705T1032No-0
1706T1090No-0
1707T1498No-1
1708T1027.005No-0
1709T1543.004No-0
1710T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
1711T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
1712T1097No-0
1713T1546No-5
1714T1556.002No-0
1715T1176No-0
1716T1562No-3
1717T1187No-0
1718T1070.006No-0
1719T1186No-0
1720T1057No-0
1721T1543.002No-0
1722T1574.010No-0
1723T1028No-0
1724T1010No-0
1725T1565.003No-0
1726T1056.001No-0
1727T1110.003No-0
1728T1109No-0
1729T1142No-0
1730T1154No-0
1731T1547.006No-0
1732T1487No-0
1733T1037.003No-0
1734T1071.003No-0
1735T1027.003No-0
1736T1055.012No-0
1737T1056.003No-0
1738T1090.004No-0
1739T1137No-0
1740T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
1741T1110.001No-0
1742T1204.001No-0
1743T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
1744T1137.001No-0
1745T1027.004No-0
1746T1106No-0
1747T1036.005No-0
1748T1553.002No-0
1749T1070.003No-0
1750T1218.001No-0
1751T1482No-0
1752T1137.005No-0
1753T1013No-0
1754T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
1755T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
1756T1123No-0
1757T1021.005No-0
1758T1574.006No-0
1759T1012No-0
1760T1499.003No-0
1761T1218.004No-0
1762T1168No-0
1763T1048.001No-0
1764T1222No-1
1765T1173No-0
1766T1156No-0
1767T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
1768T1134.002No-0
1769T1055.003No-0
1770T1480.001No-0
1771T1570No-0
1772T1101No-0
1773T1029No-0
1774T1534No-0
1775T1556.001No-0
1776T1086No-0
1777T1494No-0
1778T1491.001No-0
1779T1056.002No-0
1780T1008No-0
1781T1036.004No-0
1782T1195.003No-0
1783T1055No-0
1784T1568.003No-0
1785T1007No-0
1786T1574.011No-0
1787T1067No-0
1788T1505.001No-0
1789T1206No-0
1790T1062No-0
1791T1152No-0
1792T1564.003No-0
1793T1114.003No-0
1794T1528No-0
1795T1037.001No-0
1796T1198No-0
1797T1064No-0
1798T1145No-0
1799T1059.005No-0
1800T1493No-0
1801T1110.004No-0
1802T1055.008No-0
1803T1568No-0
1804T1081No-0
1805T1055.001No-0
1806T1194No-0
1807T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
1808T1546.010No-0
1809T1002No-0
1810T1039No-0
1811T1573.001No-0
1812T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
1813T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
1814T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
1815T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
1816T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
1817T1550.001No-0
1818T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
1819T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
1820T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
1821T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
1822T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
1823T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
1824T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
1825T1538No-0
1826T1191No-0
1827T1001No-0
1828T1150No-0
1829T1098.001No-0
1830T1568.002No-0
1831T1547.008No-0
1832T1133No-0
1833T1559.002No-0
1834T1567No-0
1835T1084No-0
1836T1114No-3
1837T1070.002No-0
1838T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
1839T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
1840T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
1841T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
1842T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
1843T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
1844T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
1845T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
1846T1564.002No-0
1847T1484No-0
1848T1055.009No-0
1849T1135No-0
1850T1574.012No-0
1851T1564.004No-0
1852T1163No-0
1853T1562.007No-0
1854T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
1855T1090.002No-0
1856T1564.006No-0
1857T1066No-0
1858T1055.013No-0
1859T1491No-0
1860T1546.012No-0
1861T1197No-0
1862T1547.010No-0
1863T1016No-0
1864T1499.001No-0
1865T1573No-0
1866T1127.001No-0
1867T1117No-0
1868T1027.001No-0
1869T1546.014No-0
1870T1162No-0
1871T1559No-0
1872T1503No-0
1873T1195No-0
1874T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml6
1875T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml6
1876T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml6
1877T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml6
1878T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml6
1879T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml6
1880T1122No-0
1881T1560.002No-0
1882T1110.002No-0
1883T1566Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml5
1884T1059.007No-0
1885T1043No-0
1886T1488No-0
1887T1529No-0
1888T1096No-0
1889T1550.004No-0
1890T1217No-0
1891T1218No-1
1892T1578No-0
1893T1546.015No-0
1894T1006No-0
1895T1137.003No-0
1896T1174No-0
1897T1134.001No-0
1898T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml3
1899T1550.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
1900T1030No-0
1901T1137.004No-0
1902T1036.006No-0
1903T1539No-0
1904T1518.001No-0
1905T1061No-0
1906T1151No-0
1907T1578.002No-0
1908T1037.004No-0
1909T1107No-0
1910T1114.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml1
1911T1103No-0
1912T1490No-0
1913T1483No-0
1914T1088No-0
1915T1159No-0
1916T1165No-0
1917T1132.001No-0
1918T1003.004No-0
1919T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
1920T1566.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml2
1921T1102No-0
1922T1024No-0
1923T1157No-0
1924T1003No-12
1925T1087.004No-0
1926T1552.005No-0
1927T1562.003No-0
1928T1553No-1
1929T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml3
1930T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
1931T1547.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml3
1932T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml5
1933T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml5
1934T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml5
1935T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml5
1936T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml5
1937T1216No-0
1938T1063No-0
1939T1036.003No-0
1940T1569.001No-0
1941T1118No-0
1942T1571No-0
1943T1069.002No-0
1944T1089No-0
1945T1143No-0
1946T1003.006No-0
1947T1497.002No-0
1948T1188No-0
1949T1110No-0
1950T1531No-0
1951T1138No-0
1952T1132No-0
1953T1546.013No-0
1954T1026No-0
1955T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml5
1956T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml5
1957T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml5
1958T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml5
1959T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml5
1960T1102.002No-0
1961T1033No-0
1962T1021.006No-0
1963T1497No-0
1964T1167No-0
1965T1136.002No-0
1966T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml13
1967T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml13
1968T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml13
1969T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml13
1970T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml13
1971T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml13
1972T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml13
1973T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml13
1974T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml13
1975T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml13
1976T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml13
1977T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml13
1978T1078.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml13
1979T1568.001No-0
1980T1218.010No-0
1981T1213No-0
1982T1519No-0
1983T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml2
1984T1021.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml2
1985T1027.002No-0
1986T1020No-0
1987T1158No-0
1988T1164No-0
1989T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml4
1990T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml4
1991T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml4
1992T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml4
1993T1201No-0
1994T1578.003No-0
1995T1049No-0
1996T1547.011No-0
1997T1185No-0
1998T1564.005No-0
1999T1119No-0
2000T1037No-0
2001T1055.005No-0
2002T1199No-0
2003T1547.003No-0
2004T1069.003No-0
2005T1537No-0
2006T1192No-0
2007T1146No-0
2008T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml3
2009T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml3
2010T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml3
2011T1069No-0
2012T1044No-0
2013T1505No-0
2014T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml2
2015T1114.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
2016T1542.001No-0
2017T1514No-0
2018T1552No-0
2019T1052No-0
2020T1556.003No-0
2021T1563.001No-0
2022T1499.002No-0
2023T1574No-1
2024T1563No-0
2025T1055.014No-0
2026T1134.005No-0
2027T1558Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml2
2028T1542.002No-0
2029T1077No-0
2030T1121No-0
2031T1059.006No-0
2032T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml2
2033T1048.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml2
2034T1574.002No-0
2035T1079No-0
2036T1213.001No-0
2037T1504No-0
2038T1090.001No-0
2039T1083No-0
2040T1552.001No-0
2041T1134No-0
2042T1144No-0
2043T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml2
2044T1078.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml2
2045T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml3
2046T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml3
2047T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml3
2048T1120No-0
2049T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
2050T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
2051T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
2052T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
2053T1546.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
2054T1550No-1
2055T1547.004No-0
2056T1218.003No-0
2057T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
2058T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
2059T1059.004No-0
2060T1011.001No-0
2061T1100No-0
2062T1054No-0
2063T1021Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml7
2064T1564No-0
2065T1547.009No-0
2066T1022No-0
2067T1102.001No-0
2068T1105No-0
2069T1559.001No-0
2070T1036.001No-0
2071T1070.004No-0
2072T1578.004No-0
2073T1572No-0
2074T1546.009No-0
2075T1518No-0
2076T1501No-0
2077T1053.002No-0
2078T1548.002No-0
2079T1212No-0
2080T1065No-0
2081T1546.003No-0
2082T1175No-0
2083T1552.004No-0
2084T1223No-0
2085T1574.008No-0
2086T1015No-0
2087T1567.002No-0
2088T1218.002No-0
2089T1023No-0
2090T1183No-0
2091T1125No-0
2092T1200No-0
2093T1108No-0
2094T1578.001No-0
2095T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml4
2096T1573.002No-0
2097T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
2098T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
2099T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
2100T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
2101T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
2102T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml7
2103T1059.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
2104T1147No-0
2105T1004No-0
2106T1205No-0
2107T1552.006No-0
2108T1104No-0
2109T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml2
2110T1562.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml2
2111T1056No-0
2112T1219No-0
2113T1567.001No-0
2114T1566.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml1
2115T1036.002No-0
2116T1046No-0
2117T1115No-0
2118T1554No-0
2119T1546.002No-0
2120T1565.001No-0
2121T1502No-0
2122T1211No-0
2123T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
2124T1080No-0
2125T1560.003No-0
2126T1180No-0
2127T1070.005No-0
2128T1542.003No-0
2129T1555.001No-0
2130T1052.001No-0
2131T1056.004No-0
2132T1094No-0
2133T1001.003No-0
2134T1076No-0
2135T1215No-0
2136T1218.007No-0
2137T1178No-0
2138T1171No-0
2139T1140No-0
2140T1025No-0
2141T1136.003No-0
2142T1547.007No-0
2143T1552.003No-0
2144T1213.002No-0
2145T1001.001No-0
2146T1195.002No-0
2147T1053No-4
2148T1209No-0
2149T1069.001No-0
2150T1193No-0
2151T1179No-0
2152T1098.003No-0
2153T1505.002No-0
2154T1059.002No-0
2155T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml4
2156T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml4
2157T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml4
2158T1078.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml4
2159T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
2160T1563.002No-0
2161T1558.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
2162T1099No-0
2163T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
2164T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml8
2165T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml8
2166T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml8
2167T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
2168T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml8
2169T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml8
2170T1059.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
2171T1195.001No-0
2172T1497.001No-0
2173T1536No-0
2174T1058No-0
2175T1005No-0
2176T1148No-0
2177T1038No-0
2178T1552.002No-0
2179T1218.005No-0
2180T1486No-0
2181T1003.008No-0
2182T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml21
2183T1053.001No-0
2184T1557.001No-0
2185T1500No-0
2186T1170No-0
2187T1166No-0
2188T1051No-0
2189T1498.001No-0
2190T1210No-0
2191T1074.002No-0
2192T1202No-0
2193T1495No-0
2194T1561.002No-0
2195T1102.003No-0
2196T1574.009Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml1
2197T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml2
2198T1190Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml2
2199T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
2200T1087.001No-0
2201T1218.008No-0
2202T1547.005No-0
2203T1040No-0
2204T1153No-0
2205T1087.003No-0
2206T1071No-10
2207T1129No-0
2208T1204.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml1
2209T1155No-0
2210T1085No-0
2211T1177No-0
2212T1021.004No-0
2213T1042No-0
2214T1090.003No-0
2215T1134.004No-0
2216T1053.004No-0
2217T1221No-0
2218T1557No-0
2219T1003.007No-0
2220T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml2
2221T1070.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
2222T1555.003No-0
2223T1132.002No-0
2224T1113No-0
2225T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml2
2226T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml2
2227T1546.008Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml1
2228T1208No-0
2229T1499No-0
2230T1561No-0
2231T1497.003No-0
2232T1009No-0
2233T1496No-0
2234T1216.001No-0
2235T1011No-0
2236T1548.004No-0
2237T1127No-0
2238T1562.006No-0
2239T1124No-0
2240T1126No-0
2241T1055.004No-0
2242T1098.002No-0
2243T1505.003No-0
2244T1031No-0
2245T1574.007No-0
2246T1137.002No-0
2247T1491.002No-0
2248T1548.003No-0
2249T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml7
2250T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml7
2251T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml7
2252T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml7
2253T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml7
2254T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml7
2255T1071.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml7
2256T1021.003No-0
2257T1048.002No-0
2258T1196No-0
2259T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml2
2260T1071.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml2
2261T1169No-0
2262T1128No-0
2263T1548.001No-0
2264T1172No-0
2265T1149No-0
2266T1543No-1
2267T1498.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml1
2268T1182No-0
2269T1547No-3
2270T1059No-15
2271T1093No-0
2272T1553.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml1
2273T1037.002No-0
2274T1098No-0
2275T1527No-0
2276T1220No-0
2277T1034No-0
2278T1141No-0
2279T1116No-0
2280T1003.005No-0
2281T1041No-0
2282T1055.002No-0
2283T1522No-0
2284T1074.001No-0
2285T1071.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml1
2286T1111No-0
2287T1546.005No-0
2288T1050No-0
2289T1574.001No-0
2290T1055.011No-0
2291T1184No-0
2292T1074No-0
2293T1542No-0
2294T1073No-0
2295T1092No-0
2296T1014No-0
2297T1189No-0
2298T1137.006No-0
2299T1075No-0
2300T1087.002No-0
2301T1134.003No-0
2302T1222.002No-0
2303T1562.002No-0
2304T1548No-0
2305T1035No-0
2306T1555No-0
2307T1561.001No-0
2308T1098.004No-0
2309T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml4
2310T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml4
2311T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml4
2312T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml4
2313T1017No-0
2314T1205.001No-0
2315T1569.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml1
2316T1565.002No-0
2317T1569No-1
2318T1499.004No-0
2319T1037.005No-0
2320T1553.003No-0
2321T1546.004No-0
2322T1053.003No-0
2323T1560No-0
2324T1181No-0
2325T1565No-0
2326T1131No-0
2327T1558.002No-0
2328T1218.009No-0
2329T1001.002No-0
2330T1078.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml1
2331T1160No-0
2332T1060No-0
2333T1560.001No-0
2334T1489No-0
2335T1207No-0
2336T1204No-1
2337T1553.001No-0
2338T1018No-0
2339T1547.002No-0
2340T1091No-0
2341T1019No-0
2342T1543.001No-0
2343T1555.002No-0
2344T1492No-0
2345T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
2346T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
2347T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
2348T1574.004No-0
2349T1550.003No-0
2350T1480No-0
2351T1161No-0
2352T1558.001No-0
2353T1214No-0
2354T1546.006No-0
2355T1556No-0
2356T1087No-0
2357T1574.005No-0
2358T1506No-0
2359T1564.001No-0
2360T1130No-0
2361T1139No-0
2362T1045No-0
2363T1546.007No-0
2364T1032No-0
2365T1090No-0
2366T1498No-1
2367T1027.005No-0
2368T1543.004No-0
2369T1027Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml1
2370T1566.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
2371T1097No-0
2372T1546No-5
2373T1556.002No-0
2374T1176No-0
2375T1562No-3
2376T1187No-0
2377T1070.006No-0
2378T1186No-0
2379T1057No-0
2380T1543.002No-0
2381T1574.010No-0
2382T1028No-0
2383T1010No-0
2384T1565.003No-0
2385T1056.001No-0
2386T1110.003No-0
2387T1109No-0
2388T1142No-0
2389T1154No-0
2390T1547.006No-0
2391T1487No-0
2392T1037.003No-0
2393T1071.003No-0
2394T1027.003No-0
2395T1055.012No-0
2396T1056.003No-0
2397T1090.004No-0
2398T1137No-0
2399T1485Yeshttps://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml1
2400T1110.001No-0
2401T1204.001No-0
2402T1222.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml1
2403T1137.001No-0
2404T1027.004No-0
2405T1106No-0
2406T1036.005No-0
2407T1553.002No-0
2408T1070.003No-0
2409T1218.001No-0
2410T1482No-0
2411T1137.005No-0
2412T1013No-0
2413T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml2
2414T1203Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml2
2415T1123No-0
2416T1021.005No-0
2417T1574.006No-0
2418T1012No-0
2419T1499.003No-0
2420T1218.004No-0
2421T1168No-0
2422T1048.001No-0
2423T1222No-1
2424T1173No-0
2425T1156No-0
2426T1543.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml1
2427T1134.002No-0
2428T1055.003No-0
2429T1480.001No-0
2430T1570No-0
2431T1101No-0
2432T1029No-0
2433T1534No-0
2434T1556.001No-0
2435T1086No-0
2436T1494No-0
2437T1491.001No-0
2438T1056.002No-0
2439T1008No-0
2440T1036.004No-0
2441T1195.003No-0
2442T1055No-0
2443T1568.003No-0
2444T1007No-0
2445T1574.011No-0
2446T1067No-0
2447T1505.001No-0
2448T1206No-0
2449T1062No-0
2450T1152No-0
2451T1564.003No-0
2452T1114.003No-0
2453T1528No-0
2454T1037.001No-0
2455T1198No-0
2456T1064No-0
2457T1145No-0
2458T1059.005No-0
2459T1493No-0
2460T1110.004No-0
2461T1055.008No-0
2462T1568No-0
2463T1081No-0
2464T1055.001No-0
2465T1194No-0
2466T1218.011Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
2467T1546.010No-0
2468T1002No-0
2469T1039No-0
2470T1573.001No-0
2471T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
2472T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
2473T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
2474T1053.005Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
2475T1546.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml1
2476T1550.001No-0
2477T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml7
2478T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml7
2479T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml7
2480T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml7
2481T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml7
2482T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml7
2483T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml7
2484T1538No-0
2485T1191No-0
2486T1001No-0
2487T1150No-0
2488T1098.001No-0
2489T1568.002No-0
2490T1547.008No-0
2491T1133No-0
2492T1559.002No-0
2493T1567No-0
2494T1084No-0
2495T1114No-3
2496T1070.002No-0
2497T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
2498T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
2499T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
2500T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
The file is too large to be shown. View Raw