Files
splunk-security_content/docs/mitre-map/coverage.json
T
2022-08-16 16:22:49 +00:00

1237 lines
209 KiB
JSON

{
"version": "4.3",
"name": "Detection Coverage",
"description": "security_content detection coverage",
"domain": "mitre-enterprise",
"techniques": [
{
"techniqueID": "T1059",
"score": 47,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/detect_risky_spl_using_pretrained_ml_model.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_delete_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_risky_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_command_and_scripting_interpreter_risky_spl_mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_distinct_processes_from_windows_temp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/living_off_the_land.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/log4shell_cve_2021_44228_exploitation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/macos_lolbin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_and_scripting_interpreter_hunting_path_traversal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_and_scripting_interpreter_path_traversal_exec.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_identify_protocol_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/exchange_powershell_module_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml"
},
{
"techniqueID": "T1083",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/path_traversal_spl_injection.yml"
},
{
"techniqueID": "T1587.003",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_digital_certificates_infrastructure_version.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_digital_certificates_lack_of_encryption.yml"
},
{
"techniqueID": "T1498",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_dos_via_malformed_s2s_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_arp_poisoning.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_ipv6_network_infrastructure_threats.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_port_security_violation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_rogue_dhcp_server.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_traffic_mirroring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/large_volume_of_dns_any_queries.yml"
},
{
"techniqueID": "T1499",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_endpoint_denial_of_service_dos_zip_bomb.yml"
},
{
"techniqueID": "T1055",
"score": 20,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_process_injection_forwarder_bundle_downloads.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/loading_of_dynwrapx_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_process_with_namedpipe_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_rasautou_dll_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_assistance_spawning_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winhlp32_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"
},
{
"techniqueID": "T1001.003",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_protocol_impersonation_weak_encryption_configuration.yml"
},
{
"techniqueID": "T1588.004",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_protocol_impersonation_weak_encryption_selfsigned.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_protocol_impersonation_weak_encryption_simplerequest.yml"
},
{
"techniqueID": "T1078",
"score": 38,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_user_enumeration_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_powershell_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_activity_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_computer_account_name_change.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_kerberos_service_ticket_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_ticket_granting_ticket_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_account_lockout_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_failed_sso_attempts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_user_logins_from_multiple_cities.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_attach_to_role_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_permanent_key_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_role_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_sts_assume_role_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_detect_gcploit_framework.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unusual_number_of_computer_service_tickets_requested.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml"
},
{
"techniqueID": "T1189",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_xss_in_monitoring_console.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml"
},
{
"techniqueID": "T1078.004",
"score": 21,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_powershell_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_destroyed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_instances_launched.yml"
},
{
"techniqueID": "T1136.003",
"score": 6,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_new_federated_domain_added.yml"
},
{
"techniqueID": "T1136",
"score": 11,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_new_federated_domain_added.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___account_harvesting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_add_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml"
},
{
"techniqueID": "T1110.001",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_failed_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/high_number_of_login_failures_from_a_single_source.yml"
},
{
"techniqueID": "T1552",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_getpassworddata.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml"
},
{
"techniqueID": "T1110.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_credential_access_rds_password_reset.yml"
},
{
"techniqueID": "T1562.008",
"score": 6,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_impair_security_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_update_cloudtrail.yml"
},
{
"techniqueID": "T1562",
"score": 61,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_delete_cloudwatch_log_group.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_impair_security_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_putbucketlifecycle.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_stop_logging_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_defense_evasion_update_cloudtrail.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_iptables_firewall_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_for_service_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_excessive_disabled_services_event.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_registry_delete_task_sd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_terminating_lsass_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml"
},
{
"techniqueID": "T1486",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_diskcryptor_usage.yml"
},
{
"techniqueID": "T1204.003",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_high.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_medium.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_upload_unknown_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/correlation_by_repository_and_risk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/correlation_by_user_and_risk.yml"
},
{
"techniqueID": "T1204",
"score": 15,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_high.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_scanning_findings_medium.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_ecr_container_upload_unknown_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_lambda_updatefunctioncode.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/correlation_by_repository_and_risk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/correlation_by_user_and_risk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clop_common_exec_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/conti_common_exec_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_common_exec_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml"
},
{
"techniqueID": "T1526",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_excessive_security_scanning.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_scanner_image_pulling.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/kubernetes_azure_scan_fingerprint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/amazon_eks_kubernetes_cluster_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/amazon_eks_kubernetes_pod_scan_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gcp_kubernetes_cluster_pod_scan_detection.yml"
},
{
"techniqueID": "T1580",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_accessdenied_discovery_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml"
},
{
"techniqueID": "T1110",
"score": 14,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_active_directory_high_risk_sign_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disabled_users_failing_to_authenticate_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_invalid_users_failed_authentication_via_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_users_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/high_number_of_login_failures_from_a_single_source.yml"
},
{
"techniqueID": "T1098",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_ssh_key_file_creation.yml"
},
{
"techniqueID": "T1069.003",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml"
},
{
"techniqueID": "T1069",
"score": 25,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml"
},
{
"techniqueID": "T1562.007",
"score": 6,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_network_access_control_list_deleted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_network_acl_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_network_discovery_in_firewall.yml"
},
{
"techniqueID": "T1110.003",
"score": 11,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/azure_active_directory_high_risk_sign_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_unusual_number_of_failed_authentications_from_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disabled_users_failing_to_authenticate_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_invalid_users_failed_authentication_via_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_users_authenticate_using_explicit_credentials.yml"
},
{
"techniqueID": "T1621",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_authentication_failed_during_mfa_challenge.yml"
},
{
"techniqueID": "T1003.002",
"score": 8,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/azure_ad_successful_single_factor_authentication.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml"
},
{
"techniqueID": "T1554",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/circle_ci_disable_security_job.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/circle_ci_disable_security_step.yml"
},
{
"techniqueID": "T1535",
"score": 8,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml"
},
{
"techniqueID": "T1530",
"score": 6,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_gcp_storage_access_from_a_new_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_gcp_storage_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_s3_access_from_a_new_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_spike_in_s3_bucket_deletion.yml"
},
{
"techniqueID": "T1537",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_shared_ec2_snapshot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_frequency_copy_of_files_in_network_share.yml"
},
{
"techniqueID": "T1195.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_actions_disable_security_workflow.yml"
},
{
"techniqueID": "T1195",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_actions_disable_security_workflow.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_dependabot_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_pull_request_from_unknown_user.yml"
},
{
"techniqueID": "T1199",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml"
},
{
"techniqueID": "T1195.001",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_dependabot_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_pull_request_from_unknown_user.yml"
},
{
"techniqueID": "T1567.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml"
},
{
"techniqueID": "T1567",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml"
},
{
"techniqueID": "T1566.001",
"score": 25,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_office_product_spawning_msdt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/suspicious_email_attachment_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml"
},
{
"techniqueID": "T1566",
"score": 29,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_office_product_spawning_msdt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/suspicious_email_attachment_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gdrive_suspicious_file_sharing.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_calendar_invite.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml"
},
{
"techniqueID": "T1048.003",
"score": 8,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/protocol_or_port_mismatch.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml"
},
{
"techniqueID": "T1048",
"score": 8,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dns_exfiltration_using_nslookup_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_nslookup_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/prohibited_network_traffic_allowed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/protocol_or_port_mismatch.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml"
},
{
"techniqueID": "T1212",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_nginx_ingress_lfi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/kubernetes_nginx_ingress_rfi.yml"
},
{
"techniqueID": "T1556",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_disable_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_sso_logon_errors.yml"
},
{
"techniqueID": "T1114",
"score": 8,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/email_files_written_outside_of_the_outlook_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml"
},
{
"techniqueID": "T1114.003",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml"
},
{
"techniqueID": "T1114.002",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml"
},
{
"techniqueID": "T1566.003",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml"
},
{
"techniqueID": "T1003.001",
"score": 13,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_non_system_account_targeting_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_possible_credential_dumping.yml"
},
{
"techniqueID": "T1071.001",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/tor_traffic.yml"
},
{
"techniqueID": "T1071.004",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_outliers___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/excessive_dns_failures.yml"
},
{
"techniqueID": "T1036.003",
"score": 10,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_copy_on_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_in_non_standard_path.yml"
},
{
"techniqueID": "T1059.001",
"score": 28,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_powershell_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_lateral_movement_powershell_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recon_using_wmi_class.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unloading_amsi_via_reflection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powershell_import_applocker_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/exchange_powershell_module_usage.yml"
},
{
"techniqueID": "T1059.003",
"score": 9,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_started_forcefully.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_carry_out_string_command_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potentially_malicious_code_on_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml"
},
{
"techniqueID": "T1078.002",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_computer_account_name_change.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_kerberos_service_ticket_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_ticket_granting_ticket_request.yml"
},
{
"techniqueID": "T1562.004",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/firewall_allowed_program_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_iptables_firewall_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml"
},
{
"techniqueID": "T1564.001",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml"
},
{
"techniqueID": "T1053.005",
"score": 15,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_lateral_movement_powershell_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_scheduled_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/svchost_lolbas_execution_process_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_registry_delete_task_sd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_schtasks_create_run_as_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_windows_task_scheduler_event_action_started.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/randomly_generated_scheduled_task_name.yml"
},
{
"techniqueID": "T1546.001",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/change_default_file_association.yml"
},
{
"techniqueID": "T1218",
"score": 55,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/control_loading_from_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/verclsid_clsid_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_diskshadow_proxy_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_credential_theft.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_remote_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_uninstall_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_uninstall_option_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_rasautou_dll_execution.yml"
},
{
"techniqueID": "T1036",
"score": 14,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_kworker_process_in_writable_process_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_copy_on_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_in_non_standard_path.yml"
},
{
"techniqueID": "T1218.011",
"score": 16,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml"
},
{
"techniqueID": "T1204.002",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml"
},
{
"techniqueID": "T1560.001",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml"
},
{
"techniqueID": "T1560",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml"
},
{
"techniqueID": "T1003",
"score": 28,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_access_to_credential_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_hunting_system_account_targeting_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_non_system_account_targeting_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_possible_credential_dumping.yml"
},
{
"techniqueID": "T1087.002",
"score": 19,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml"
},
{
"techniqueID": "T1087",
"score": 27,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/splunk_account_discovery_drilldown_dashboard_disclosure.yml"
},
{
"techniqueID": "T1547.014",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/active_setup_registry_autostart.yml"
},
{
"techniqueID": "T1547",
"score": 15,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/active_setup_registry_autostart.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/monitor_registry_keys_for_print_monitors.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/print_spooler_adding_a_printer_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_spawning_rundll32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_loaded_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_writing_a_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/time_provider_persistence_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/print_processor_registry_autostart.yml"
},
{
"techniqueID": "T1552.002",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml"
},
{
"techniqueID": "T1562.001",
"score": 44,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_or_set_windows_defender_exclusion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_antivirus_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_blockatfirstseen_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_enhanced_notification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_mpengine_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_spynet_reporting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_defender_submit_samples_consent_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_defender_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remove_windows_defender_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_windows_defender_exclusion_commands.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_defender_exclusion_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dism_remove_defender.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_for_service_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_excessive_disabled_services_event.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_add_xml_applocker_rules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_context_menu.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_delete_win_defender_profile_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defense_deny_security_software_with_applocker.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_impair_defenses_disable_win_defender_auto_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raccine_scheduled_task_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_terminating_lsass_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_noninteractive_app_uninstallation.yml"
},
{
"techniqueID": "T1021.001",
"score": 9,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_remote_assistance.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_rdp_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_desktop_process_running_on_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/remote_desktop_network_bruteforce.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/remote_desktop_network_traffic.yml"
},
{
"techniqueID": "T1021",
"score": 24,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enable_rdp_in_other_port_number.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executable_file_written_in_administrative_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mmc_lolbas_execution_process_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_lateral_movement_powershell_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_service_rdpwinst_tool_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_rdp_in_firewall.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_allow_remote_assistance.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_services_rdp_enable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_desktop_process_running_on_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/remote_desktop_network_bruteforce.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/remote_desktop_network_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/smb_traffic_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/smb_traffic_spike___mltk.yml"
},
{
"techniqueID": "T1548",
"score": 27,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_operation_with_consent_admin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_uac_remote_restriction.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_awk_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_common_process_for_elevation_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_doas_conf_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_doas_tool_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_docker_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_node_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_persistence_and_privilege_escalation_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_access_to_sudoers_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_setuid_using_chmod_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_setuid_using_setcap_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_sudo_or_su_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_sudoers_tmp_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_visudo_utility_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/services_escalate_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml"
},
{
"techniqueID": "T1105",
"score": 17,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/curl_download_and_bash_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_curl_upload_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_ingress_tool_transfer_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_ingress_tool_transfer_with_curl.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/living_off_the_land.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/log4shell_cve_2021_44228_exploitation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wget_download_and_bash_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_curl_download_to_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_curl_upload_to_remote_destination.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_curl_network_connection.yml"
},
{
"techniqueID": "T1036.005",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml"
},
{
"techniqueID": "T1595",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml"
},
{
"techniqueID": "T1553.004",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_registry_certificate_added.yml"
},
{
"techniqueID": "T1553",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_registry_certificate_added.yml"
},
{
"techniqueID": "T1490",
"score": 10,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bcdedit_command_back_to_normal_mode_boot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/change_to_safe_mode_with_network_config.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/delete_shadowcopy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/known_services_killed_by_ransomware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/prevent_automatic_repair_mode_using_bcdedit.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbadmin_delete_system_backups.yml"
},
{
"techniqueID": "T1197",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml"
},
{
"techniqueID": "T1140",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml"
},
{
"techniqueID": "T1546",
"score": 12,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/change_default_file_association.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_file_creation_in_profile_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/screensaver_event_trigger_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml"
},
{
"techniqueID": "T1033",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml"
},
{
"techniqueID": "T1070.004",
"score": 10,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_cron_jobs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_init_daemon_script.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_ssl_certificate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml"
},
{
"techniqueID": "T1070",
"score": 18,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_cron_jobs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_init_daemon_script.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_ssl_certificate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml"
},
{
"techniqueID": "T1543",
"score": 15,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/services_lolbas_execution_process_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_create_kernel_mode_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_creation_on_remote_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/randomly_generated_windows_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_plistbuddy_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml"
},
{
"techniqueID": "T1543.003",
"score": 13,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_lateral_movement_powershell_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/services_lolbas_execution_process_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_krbrelayup_service_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_create_kernel_mode_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_creation_on_remote_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_initiation_on_remote_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/randomly_generated_windows_service_name.yml"
},
{
"techniqueID": "T1059.007",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml"
},
{
"techniqueID": "T1218.003",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml"
},
{
"techniqueID": "T1485",
"score": 17,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_file_deletion_in_windefender_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_account_manipulation_of_ssh_config_and_keys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_dd_file_overwrite.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deleting_critical_directory_using_rm_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_cron_jobs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_init_daemon_script.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_deletion_of_ssl_certificate.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_shred_overwrite_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdelete_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_memory_crash_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_file_without_extension_in_critical_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_high_file_deletion_frequency.yml"
},
{
"techniqueID": "T1218.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/control_loading_from_world_writable_directory.yml"
},
{
"techniqueID": "T1136.001",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_add_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml"
},
{
"techniqueID": "T1070.005",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml"
},
{
"techniqueID": "T1003.003",
"score": 6,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml"
},
{
"techniqueID": "T1027.004",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/csc_net_on_the_fly_compilation.yml"
},
{
"techniqueID": "T1027",
"score": 8,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/csc_net_on_the_fly_compilation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_decode_base64_to_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_obfuscated_files_or_information_base64_decode.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml"
},
{
"techniqueID": "T1531",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/deleting_of_net_users.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_net_app.yml"
},
{
"techniqueID": "T1550",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberos_tgt_request_using_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rubeus_command_line_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unknown_process_using_the_kerberos_protocol.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_sts_get_session_token_abuse.yml"
},
{
"techniqueID": "T1550.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml"
},
{
"techniqueID": "T1069.001",
"score": 11,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml"
},
{
"techniqueID": "T1482",
"score": 11,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml"
},
{
"techniqueID": "T1087.001",
"score": 11,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml"
},
{
"techniqueID": "T1069.002",
"score": 18,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml"
},
{
"techniqueID": "T1078.003",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/potential_password_in_username.yml"
},
{
"techniqueID": "T1505",
"score": 6,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/confluence_unauthenticated_remote_code_execution_cve_2022_26134.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/spring4shell_payload_url_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/web_jsp_request_via_url.yml"
},
{
"techniqueID": "T1505.003",
"score": 6,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/supernova_webshell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/spring4shell_payload_url_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/web_jsp_request_via_url.yml"
},
{
"techniqueID": "T1190",
"score": 27,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hunting_for_log4shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/java_class_file_download_by_java_user_agent.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/java_writing_jsp_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_java_spawning_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/living_off_the_land.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/log4shell_cve_2021_44228_exploitation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/outbound_network_connection_from_java_using_default_ports.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/exchange_powershell_abuse_via_ssrf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_java_spawning_shells.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winrm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_zerologon_via_zeek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/detect_f5_tmui_rce_cve_2020_5902.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/sql_injection_with_long_urls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_ldap_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/confluence_unauthenticated_remote_code_execution_cve_2022_26134.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/log4shell_jndi_payload_injection_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/log4shell_jndi_payload_injection_with_outbound_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/spring4shell_payload_url_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/vmware_server_side_template_injection_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/vmware_workspace_one_freemarker_server_side_template_injection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/web_jsp_request_via_url.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/web_spring4shell_http_request_class_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/web_spring_cloud_function_functionrouter.yml"
},
{
"techniqueID": "T1218.001",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml"
},
{
"techniqueID": "T1218.005",
"score": 8,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml"
},
{
"techniqueID": "T1574.009",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml"
},
{
"techniqueID": "T1574",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_preload_hijack_library_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/msi_module_loaded_by_non_system_binary.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml"
},
{
"techniqueID": "T1016",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_system_network_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_discovery_using_route_windows_app.yml"
},
{
"techniqueID": "T1021.002",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executable_file_written_in_administrative_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/smb_traffic_spike.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/smb_traffic_spike___mltk.yml"
},
{
"techniqueID": "T1020",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_traffic_mirroring.yml"
},
{
"techniqueID": "T1218.009",
"score": 6,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regasm_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regasm_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regasm_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvcs_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvcs_with_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvcs_with_no_command_line_arguments.yml"
},
{
"techniqueID": "T1218.010",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_inprocserver32_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/regsvr32_with_known_silent_switch_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml"
},
{
"techniqueID": "T1569",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_created_with_suspicious_service_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_running_windows_service.yml"
},
{
"techniqueID": "T1569.002",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_created_with_suspicious_service_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_running_windows_service.yml"
},
{
"techniqueID": "T1546.003",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_mof_event_triggered_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml"
},
{
"techniqueID": "T1070.001",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml"
},
{
"techniqueID": "T1112",
"score": 24,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_security_logs_using_minint_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_inprocserver32_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_client_registry_install_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_shimcache_flush.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_deleted_registry_by_a_non_critical_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_change_password_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_lock_workstation_feature_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_logoff_button_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_notification_center.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_shutdown_button_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disable_windows_group_policy_features_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_hide_notification_features_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_toast_notifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_win_defender_raw_write_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disable_windows_security_center_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disabling_wer_settings.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_disallow_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_regedit_silent_reg_import.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_registry_suppress_win_defender_notif.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_modify_show_compress_color_and_info_tip_registry.yml"
},
{
"techniqueID": "T1564",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml"
},
{
"techniqueID": "T1548.002",
"score": 11,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_uac_remote_restriction.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml"
},
{
"techniqueID": "T1558",
"score": 14,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rubeus_command_line_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_computer_account_created_by_computer_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_computer_account_requesting_kerberos_ticket.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_computer_account_with_spn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_kerberos_local_successful_logon.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powerview_spn_discovery.yml"
},
{
"techniqueID": "T1558.004",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_get_aduser.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabled_kerberos_pre_authentication_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberos_pre_authentication_flag_disabled_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rubeus_command_line_parameters.yml"
},
{
"techniqueID": "T1018",
"score": 18,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_adfind_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_get_adcomputer_unconstrained_delegation_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powerview_constrained_delegation_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powerview_unconstrained_delegation_discovery.yml"
},
{
"techniqueID": "T1562.006",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml"
},
{
"techniqueID": "T1127",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/etw_registry_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml"
},
{
"techniqueID": "T1489",
"score": 8,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_stop_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_processes_killed_by_industroyer2_malware.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_stop_by_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_valid_account_with_never_expires_password.yml"
},
{
"techniqueID": "T1222",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_cacls_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_deny_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/icacls_grant_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/modify_acl_permission_to_files_or_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/permission_modification_using_takeown_app.yml"
},
{
"techniqueID": "T1059.005",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_process_with_discord_dns_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/vbscript_execution_using_wscript_app.yml"
},
{
"techniqueID": "T1201",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml"
},
{
"techniqueID": "T1049",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_with_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_with_netstat.yml"
},
{
"techniqueID": "T1222.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml"
},
{
"techniqueID": "T1021.003",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mmc_lolbas_execution_process_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_lateral_movement_powershell_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block.yml"
},
{
"techniqueID": "T1047",
"score": 12,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_lateral_movement_powershell_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi_and_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_wmi_process_call_create.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmiprsve_lolbas_execution_process_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_temporary_event_subscription.yml"
},
{
"techniqueID": "T1021.006",
"score": 6,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/interactive_session_on_remote_endpoint_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_lateral_movement_powershell_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_winrm_and_winrs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsmprovhost_lolbas_execution_process_spawn.yml"
},
{
"techniqueID": "T1558.003",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rubeus_command_line_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/serviceprincipalnames_discovery_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unusual_number_of_kerberos_service_tickets_requested.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powerview_kerberos_service_ticket_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_powerview_spn_discovery.yml"
},
{
"techniqueID": "T1558.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberos_service_ticket_request_using_rc4_encryption.yml"
},
{
"techniqueID": "T1589",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberos_user_enumeration.yml"
},
{
"techniqueID": "T1589.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberos_user_enumeration.yml"
},
{
"techniqueID": "T1053.003",
"score": 6,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_add_files_in_known_crontab_directories.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_adding_crontab_using_list_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_at_allow_config_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_edit_cron_table_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml"
},
{
"techniqueID": "T1053",
"score": 26,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_add_files_in_known_crontab_directories.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_adding_crontab_using_list_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_at_allow_config_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_at_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_edit_cron_table_parameter.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_append_cronjob_entry_on_existing_cronjob_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_cronjob_modification_with_editor.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_service_file_created_in_systemd_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_service_restarted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_service_started_or_enabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schedule_task_with_http_command_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schedule_task_with_rundll32_command_trigger.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_run_task_on_demand.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/svchost_lolbas_execution_process_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_hidden_schedule_task_settings.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_schtasks_create_run_as_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/randomly_generated_scheduled_task_name.yml"
},
{
"techniqueID": "T1053.002",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_at_application_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_append_command_to_at_allow_config_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml"
},
{
"techniqueID": "T1548.003",
"score": 10,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_awk_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_doas_conf_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_doas_tool_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_docker_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_node_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_access_to_sudoers_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_sudo_or_su_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_sudoers_tmp_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_visudo_utility_execution.yml"
},
{
"techniqueID": "T1222.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_change_file_owner_to_root.yml"
},
{
"techniqueID": "T1115",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_clipboard_data_copy.yml"
},
{
"techniqueID": "T1548.001",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_common_process_for_elevation_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_setuid_using_chmod_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_setuid_using_setcap_utility.yml"
},
{
"techniqueID": "T1059.004",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_decode_base64_to_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/macos_lolbin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_linux_discovery_commands.yml"
},
{
"techniqueID": "T1547.006",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_file_created_in_kernel_driver_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_insert_kernel_module_using_insmod_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_install_kernel_module_using_modprobe_utility.yml"
},
{
"techniqueID": "T1037.004",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_file_creation_in_init_boot_directory.yml"
},
{
"techniqueID": "T1037",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_file_creation_in_init_boot_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/logon_script_event_trigger_execution.yml"
},
{
"techniqueID": "T1546.004",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_file_creation_in_profile_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_append_command_to_profile_config_file.yml"
},
{
"techniqueID": "T1082",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_kernel_module_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/web_servers_executing_suspicious_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web/detect_attackers_scanning_for_vulnerable_jboss_servers.yml"
},
{
"techniqueID": "T1014",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_kernel_module_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_driver_load_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_drivers_loaded_by_signature.yml"
},
{
"techniqueID": "T1036.004",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_kworker_process_in_writable_process_path.yml"
},
{
"techniqueID": "T1068",
"score": 10,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_pkexec_privilege_escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_drivers_loaded_by_signature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_create_kernel_mode_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_file_on_disk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/child_processes_of_spoolsv_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_baron_samedit_cve_2021_3156.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml"
},
{
"techniqueID": "T1098.004",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_access_or_modification_of_sshd_config_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_ssh_key_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_ssh_authorized_keys_modification.yml"
},
{
"techniqueID": "T1003.008",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_possible_access_to_credential_files.yml"
},
{
"techniqueID": "T1574.006",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_preload_hijack_library_calls.yml"
},
{
"techniqueID": "T1090",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_proxy_socks_curl.yml"
},
{
"techniqueID": "T1095",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_proxy_socks_curl.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_large_outbound_icmp_packets.yml"
},
{
"techniqueID": "T1053.006",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_service_file_created_in_systemd_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_service_restarted.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_service_started_or_enabled.yml"
},
{
"techniqueID": "T1021.004",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/linux_ssh_remote_services_script_execute.yml"
},
{
"techniqueID": "T1055.001",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/loading_of_dynwrapx_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_rasautou_dll_execution.yml"
},
{
"techniqueID": "T1037.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/logon_script_event_trigger_execution.yml"
},
{
"techniqueID": "T1647",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/macos_plutil.yml"
},
{
"techniqueID": "T1114.001",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/email_files_written_outside_of_the_outlook_directory.yml"
},
{
"techniqueID": "T1550.003",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mimikatz_passtheticket_commandline_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rubeus_command_line_parameters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rubeus_kerberos_ticket_exports_through_winlogon_access.yml"
},
{
"techniqueID": "T1218.014",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mmc_lolbas_execution_process_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_lateral_movement_powershell_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml"
},
{
"techniqueID": "T1491",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/modification_of_wallpaper.yml"
},
{
"techniqueID": "T1547.010",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/monitor_registry_keys_for_print_monitors.yml"
},
{
"techniqueID": "T1127.001",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml"
},
{
"techniqueID": "T1574.002",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msi_module_loaded_by_non_system_binary.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml"
},
{
"techniqueID": "T1016.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_discovery_using_route_windows_app.yml"
},
{
"techniqueID": "T1555",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_browser_pass_view_parameter.yml"
},
{
"techniqueID": "T1555.003",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/possible_browser_pass_view_parameter.yml"
},
{
"techniqueID": "T1546.008",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml"
},
{
"techniqueID": "T1187",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml"
},
{
"techniqueID": "T1497",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ping_sleep_batch_command.yml"
},
{
"techniqueID": "T1497.003",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ping_sleep_batch_command.yml"
},
{
"techniqueID": "T1552.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/potential_password_in_username.yml"
},
{
"techniqueID": "T1027.005",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml"
},
{
"techniqueID": "T1546.015",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml"
},
{
"techniqueID": "T1547.012",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/print_spooler_adding_a_printer_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_spawning_rundll32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_loaded_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_writing_a_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/print_processor_registry_autostart.yml"
},
{
"techniqueID": "T1566.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml"
},
{
"techniqueID": "T1559.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_writing_dynamicwrapperx.yml"
},
{
"techniqueID": "T1592",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/recon_using_wmi_class.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_info_gathering_using_dxdiag_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_gather_victim_host_information_camera.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_recon_running_process_or_services.yml"
},
{
"techniqueID": "T1574.011",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_service_creation_using_registry_entry.yml"
},
{
"techniqueID": "T1546.011",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml"
},
{
"techniqueID": "T1547.001",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_registry_modification_for_safe_mode_persistence.yml"
},
{
"techniqueID": "T1546.012",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml"
},
{
"techniqueID": "T1113",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml"
},
{
"techniqueID": "T1134",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/runas_execution_in_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"
},
{
"techniqueID": "T1134.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/runas_execution_in_commandline.yml"
},
{
"techniqueID": "T1546.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/screensaver_event_trigger_execution.yml"
},
{
"techniqueID": "T1005",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml"
},
{
"techniqueID": "T1547.003",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/time_provider_persistence_registry.yml"
},
{
"techniqueID": "T1218.007",
"score": 6,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_remote_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_spawn_discovery_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_unregister_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_msiexec_with_network_connections.yml"
},
{
"techniqueID": "T1218.012",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/verclsid_clsid_execution.yml"
},
{
"techniqueID": "T1590",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml"
},
{
"techniqueID": "T1590.005",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_gather_victim_network_info_through_ip_check_web_services.yml"
},
{
"techniqueID": "T1071",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_application_layer_protocol_rms_radmin_tool_namedpipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_smb_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_outliers___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/excessive_dns_failures.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/tor_traffic.yml"
},
{
"techniqueID": "T1218.013",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_binary_proxy_execution_mavinject_dll_injection.yml"
},
{
"techniqueID": "T1574.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dll_search_order_hijacking_with_iscsicpl.yml"
},
{
"techniqueID": "T1218.004",
"score": 7,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_credential_theft.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_in_non_standard_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_remote_network_connection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_uninstall_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_uninstall_option_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_installutil_url_in_command_line.yml"
},
{
"techniqueID": "T1592.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_gather_victim_host_information_camera.yml"
},
{
"techniqueID": "T1202",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_indirect_command_execution_via_forfiles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_indirect_command_execution_via_pcalua.yml"
},
{
"techniqueID": "T1204.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_iso_lnk_file_creation.yml"
},
{
"techniqueID": "T1588.002",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_nirsoft_advancedrun.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_nirsoft_utilities.yml"
},
{
"techniqueID": "T1218.008",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_odbcconf_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_odbcconf_load_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_odbcconf_load_response_file.yml"
},
{
"techniqueID": "T1561.002",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml"
},
{
"techniqueID": "T1561",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml"
},
{
"techniqueID": "T1219",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_remote_access_software_rms_registry.yml"
},
{
"techniqueID": "T1529",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_logoff_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_reboot_commandline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_shutdown_commandline.yml"
},
{
"techniqueID": "T1124",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_time_discovery_w32tm_delay.yml"
},
{
"techniqueID": "T1220",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_xsl_execution_via_url.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml"
},
{
"techniqueID": "T1134.004",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"
},
{
"techniqueID": "T1078.001",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/multiple_okta_users_with_invalid_credentials_from_the_same_ip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_account_lockout_events.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_failed_sso_attempts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/application/okta_user_logins_from_multiple_cities.yml"
},
{
"techniqueID": "T1210",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml"
},
{
"techniqueID": "T1072",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detection_of_tools_built_by_nirsoft.yml"
},
{
"techniqueID": "T1203",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sunburst_correlation_dll_and_network_event.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_windows_dns_sigred_via_splunk_stream.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_windows_dns_sigred_via_zeek.yml"
},
{
"techniqueID": "T1543.001",
"score": 2,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_plistbuddy_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_plistbuddy_usage_via_osquery.yml"
},
{
"techniqueID": "T1074",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_sqlite3_lsquarantine_behavior.yml"
},
{
"techniqueID": "T1200",
"score": 5,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_arp_poisoning.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_ipv6_network_infrastructure_threats.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_port_security_violation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_rogue_dhcp_server.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_traffic_mirroring.yml"
},
{
"techniqueID": "T1557",
"score": 4,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_arp_poisoning.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_ipv6_network_infrastructure_threats.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_port_security_violation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_rogue_dhcp_server.yml"
},
{
"techniqueID": "T1557.002",
"score": 3,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_arp_poisoning.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_ipv6_network_infrastructure_threats.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/detect_port_security_violation.yml"
},
{
"techniqueID": "T1071.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_outbound_smb_traffic.yml"
},
{
"techniqueID": "T1041",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_snicat_sni_exfiltration.yml"
},
{
"techniqueID": "T1542.005",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_software_download_to_network_device.yml"
},
{
"techniqueID": "T1542",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_software_download_to_network_device.yml"
},
{
"techniqueID": "T1020.001",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_traffic_mirroring.yml"
},
{
"techniqueID": "T1498.002",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/network/large_volume_of_dns_any_queries.yml"
},
{
"techniqueID": "T1040",
"score": 1,
"comment": "https://github.com/splunk/security_content/blob/develop/detections/network/splunk_identified_ssl_tls_certificates.yml"
}
],
"gradient": {
"colors": [
"#ffffff",
"#66b1ff",
"#096ed7"
],
"minValue": 0,
"maxValue": 61
},
"filters": {
"platforms": [
"Windows",
"Linux",
"macOS",
"AWS",
"GCP",
"Azure",
"Office 365",
"SaaS"
]
},
"legendItems": [
{
"label": "NO available detections",
"color": "#ffffff"
},
{
"label": "Some detections available",
"color": "#66b1ff"
}
],
"showTacticRowBackground": true,
"tacticRowBackground": "#dddddd",
"sorting": 3
}