Files
splunk-security_content/docs/mitre-map/coverage.csv
T
2020-07-15 21:14:02 +00:00

27 KiB

1Technique IDDetection AvailableLinkscore
2T1004No-0
3T1094No-0
4T1490No-0
5T1027.003No-0
6T1069No-0
7T1543No-0
8T1140No-0
9T1097No-0
10T1518.001No-0
11T1005No-0
12T1574.001No-0
13T1555.001No-0
14T1126No-0
15T1201No-0
16T1213No-0
17T1087.001No-0
18T1102.002No-0
19T1136.002No-0
20T1546.005No-0
21T1562.001No-0
22T1009No-0
23T1134.005No-0
24T1014No-0
25T1222No-0
26T1550.003No-0
27T1127.001No-0
28T1053.005No-0
29T1001.002No-0
30T1059.004No-0
31T1045No-0
32T1174No-0
33T1147No-0
34T1055.011No-0
35T1564No-0
36T1038No-0
37T1574.010No-0
38T1553.002No-0
39T1573.002No-0
40T1187No-0
41T1027.002No-0
42T1061No-0
43T1003.006No-0
44T1030No-0
45T1056No-0
46T1563.002No-0
47T1195.002No-0
48T1214No-0
49T1059.001No-0
50T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml1
51T1546.012No-0
52T1571No-0
53T1570No-0
54T1546.011No-0
55T1055.002No-0
56T1553No-0
57T1548.002No-0
58T1504No-0
59T1006No-0
60T1546.008No-0
61T1160No-0
62T1505.003No-0
63T1552No-0
64T1102.001No-0
65T1489No-0
66T1078.003No-0
67T1108No-0
68T1560No-0
69T1020No-0
70T1159No-0
71T1056.004No-0
72T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml5
73T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml5
74T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml5
75T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml5
76T1003.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml5
77T1565.002No-0
78T1003.004No-0
79T1033No-0
80T1056.002No-0
81T1037.003No-0
82T1553.004No-0
83T1221No-0
84T1144No-0
85T1074Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml2
86T1074Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml2
87T1150No-0
88T1578.004No-0
89T1001.003No-0
90T1548.003No-0
91T1137No-0
92T1522No-0
93T1059.006No-0
94T1574.002No-0
95T1497.002No-0
96T1063No-0
97T1027.005No-0
98T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml2
99T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml2
100T1062No-0
101T1104No-0
102T1091No-0
103T1035No-0
104T1546.007No-0
105T1198No-0
106T1143No-0
107T1134.001No-0
108T1184No-0
109T1213.001No-0
110T1036.002No-0
111T1048.002No-0
112T1128No-0
113T1115No-0
114T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml3
115T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml3
116T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
117T1491.002No-0
118T1011No-0
119T1197No-0
120T1546.002No-0
121T1547No-0
122T1026No-0
123T1127No-0
124T1216.001No-0
125T1547.005No-0
126T1566.002No-0
127T1060No-0
128T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml21
129T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml21
130T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml21
131T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml21
132T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml21
133T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml21
134T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml21
135T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml21
136T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml21
137T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml21
138T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml21
139T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml21
140T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml21
141T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml21
142T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml21
143T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml21
144T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml21
145T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml21
146T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml21
147T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml21
148T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml21
149T1534No-0
150T1087.002No-0
151T1041Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml1
152T1561No-0
153T1183No-0
154T1180No-0
155T1054No-0
156T1181No-0
157T1074.002No-0
158T1188No-0
159T1205No-0
160T1222.002No-0
161T1220No-0
162T1218.002No-0
163T1546.001No-0
164T1070.005No-0
165T1193Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml2
166T1193Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
167T1090.001No-0
168T1023No-0
169T1494No-0
170T1076Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml2
171T1076Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml2
172T1558.002No-0
173T1219No-0
174T1178No-0
175T1125No-0
176T1169No-0
177T1059.005No-0
178T1130No-0
179T1550.002No-0
180T1547.004No-0
181T1002No-0
182T1177No-0
183T1010No-0
184T1546.013No-0
185T1538No-0
186T1064Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml7
187T1064Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml7
188T1064Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml7
189T1064Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml7
190T1064Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml7
191T1064Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml7
192T1064Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
193T1051No-0
194T1487No-0
195T1148No-0
196T1486No-0
197T1502No-0
198T1132.001No-0
199T1149No-0
200T1537No-0
201T1138Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
202T1138Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
203T1138Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
204T1050Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml2
205T1050Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml2
206T1202No-0
207T1566.003No-0
208T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml7
209T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml7
210T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml7
211T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml7
212T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml7
213T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml7
214T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml7
215T1559.001No-0
216T1573No-0
217T1155No-0
218T1132.002No-0
219T1556No-0
220T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
221T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
222T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
223T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
224T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
225T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
226T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
227T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
228T1031No-0
229T1543.001No-0
230T1179No-0
231T1022No-0
232T1157No-0
233T1573.001No-0
234T1216No-0
235T1018No-0
236T1093No-0
237T1175No-0
238T1574.009No-0
239T1536No-0
240T1067No-0
241T1562.003No-0
242T1572No-0
243T1499.004No-0
244T1087Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
245T1071.002No-0
246T1567No-0
247T1027.001No-0
248T1547.006No-0
249T1498.001No-0
250T1055.001No-0
251T1098.001No-0
252T1218.011No-0
253T1218.010No-0
254T1543.003No-0
255T1096No-0
256T1146No-0
257T1543.002No-0
258T1037No-0
259T1553.001No-0
260T1211No-0
261T1069.002No-0
262T1566.001No-0
263T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml3
264T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml3
265T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml3
266T1021.005No-0
267T1553.003No-0
268T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
269T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
270T1105No-0
271T1564.003No-0
272T1186No-0
273T1070.003No-0
274T1081No-0
275T1142No-0
276T1019No-0
277T1543.004No-0
278T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml4
279T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml4
280T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml4
281T1526Yeshttps://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml4
282T1503No-0
283T1079No-0
284T1027.004No-0
285T1562.004Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
286T1495No-0
287T1574.008No-0
288T1578.003No-0
289T1204.002No-0
290T1075Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
291T1578.002No-0
292T1204No-0
293T1101No-0
294T1092No-0
295T1565.003No-0
296T1090.003No-0
297T1084Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml3
298T1084Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml3
299T1084Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml3
300T1132No-0
301T1039No-0
302T1036.006No-0
303T1480No-0
304T1497.003No-0
305T1071.003No-0
306T1563No-0
307T1055.003No-0
308T1040No-0
309T1223No-0
310T1001.001No-0
311T1565No-0
312T1558.001No-0
313T1491No-0
314T1514No-0
315T1021.006No-0
316T1217No-0
317T1036.004No-0
318T1037.002No-0
319T1003.002Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml1
320T1546No-0
321T1562Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml1
322T1574.011No-0
323T1547.008No-0
324T1170No-0
325T1547.010No-0
326T1542.002No-0
327T1090.002No-0
328T1055.004No-0
329T1049No-0
330T1501No-0
331T1546.015No-0
332T1114.001No-0
333T1505No-0
334T1176No-0
335T1562.007No-0
336T1164No-0
337T1547.001No-0
338T1137.006No-0
339T1562.002No-0
340T1145No-0
341T1191No-0
342T1555.003No-0
343T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
344T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
345T1574No-0
346T1109No-0
347T1152No-0
348T1090No-0
349T1529No-0
350T1556.003No-0
351T1564.001No-0
352T1034No-0
353T1012No-0
354T1172No-0
355T1066No-0
356T1110.004No-0
357T1158No-0
358T1568.003No-0
359T1566No-0
360T1042Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml3
361T1042Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml3
362T1042Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml3
363T1569No-0
364T1564.002No-0
365T1069.001No-0
366T1482No-0
367T1021No-0
368T1208Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
369T1113No-0
370T1052.001No-0
371T1542.001No-0
372T1114.003No-0
373T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml1
374T1083No-0
375T1028No-0
376T1001No-0
377T1074.001No-0
378T1212No-0
379T1547.002No-0
380T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
381T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
382T1569.002No-0
383T1213.002No-0
384T1556.001No-0
385T1568.001No-0
386T1548No-0
387T1055.013No-0
388T1574.006No-0
389T1053.002No-0
390T1552.002No-0
391T1162No-0
392T1071.004No-0
393T1055.014No-0
394T1218.004No-0
395T1131Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml1
396T1056.003No-0
397T1168No-0
398T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml4
399T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml4
400T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml4
401T1003.003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml4
402T1218.001No-0
403T1087.004No-0
404T1070.001No-0
405T1518No-0
406T1137.001No-0
407T1161No-0
408T1560.003No-0
409T1547.003No-0
410T1003.007No-0
411T1059.002No-0
412T1563.001No-0
413T1036.005No-0
414T1505.002No-0
415T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
416T1057No-0
417T1137.005No-0
418T1110.002No-0
419T1098.003No-0
420T1554No-0
421T1166No-0
422T1218.005No-0
423T1555.002No-0
424T1557No-0
425T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml2
426T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml2
427T1048.003No-0
428T1016No-0
429T1078.002No-0
430T1134.002No-0
431T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml14
432T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml14
433T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml14
434T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml14
435T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml14
436T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml14
437T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml14
438T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml14
439T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml14
440T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml14
441T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml14
442T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml14
443T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml14
444T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml14
445T1564.004No-0
446T1090.004No-0
447T1117No-0
448T1007No-0
449T1136.003No-0
450T1099No-0
451T1519No-0
452T1055No-0
453T1163No-0
454T1078.001No-0
455T1080No-0
456T1102.003No-0
457T1574.005No-0
458T1071.001No-0
459T1552.006No-0
460T1071No-0
461T1037.005No-0
462T1073No-0
463T1209No-0
464T1078.004No-0
465T1546.004No-0
466T1564.005No-0
467T1121No-0
468T1561.002No-0
469T1011.001No-0
470T1003.005No-0
471T1195.003No-0
472T1087.003No-0
473T1194No-0
474T1485No-0
475T1089Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml4
476T1089Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml4
477T1089Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml4
478T1089Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml4
479T1015Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
480T1015Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml3
481T1015Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml3
482T1098.002No-0
483T1506No-0
484T1110.003No-0
485T1021.003No-0
486T1568.002No-0
487T1110No-0
488T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml2
489T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
490T1059.007No-0
491T1102Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml1
492T1555No-0
493T1505.001No-0
494T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml2
495T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml2
496T1199No-0
497T1124No-0
498T1548.001No-0
499T1499.003No-0
500T1218.003No-0
501T1564.006No-0
502T1568No-0
503T1167No-0
504T1153No-0
505T1055.008No-0
506T1560.002No-0
507T1070.002No-0
508T1069.003No-0
509T1025No-0
510T1122No-0
511T1036.001No-0
512T1206No-0
513T1134No-0
514T1552.001No-0
515T1499No-0
516T1556.002No-0
517T1546.009No-0
518T1032No-0
519T1037.001No-0
520T1120No-0
521T1013No-0
522T1546.003No-0
523T1141No-0
524T1218No-0
525T1546.014No-0
526T1190No-0
527T1557.001No-0
528T1137.002No-0
529T1165No-0
530T1195.001No-0
531T1542No-0
532T1139No-0
533T1548.004No-0
534T1151No-0
535T1103Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml1
536T1578.001No-0
537T1100No-0
538T1137.004No-0
539T1059.003No-0
540T1550.001No-0
541T1029No-0
542T1500No-0
543T1107No-0
544T1203No-0
545T1196No-0
546T1497.001No-0
547T1547.011No-0
548T1210No-0
549T1546.010No-0
550T1118No-0
551T1546.006No-0
552T1574.007No-0
553T1192Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
554T1182No-0
555T1499.001No-0
556T1480.001No-0
557T1046No-0
558T1003.008No-0
559T1567.001No-0
560T1070.006No-0
561T1218.009No-0
562T1542.003No-0
563T1552.005No-0
564T1497No-0
565T1565.001No-0
566T1156No-0
567T1085Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
568T1492No-0
569T1110.001No-0
570T1498.002No-0
571T1053.003No-0
572T1218.008No-0
573T1098.004No-0
574T1048.001No-0
575T1205.001No-0
576T1021.004No-0
577T1065No-0
578T1024No-0
579T1055.009No-0
580T1116No-0
581T1483No-0
582T1200No-0
583T1123No-0
584T1222.001No-0
585T1195No-0
586T1484No-0
587T1527No-0
588T1053.001No-0
589T1496No-0
590T1552.004No-0
591T1550No-0
592T1037.004No-0
593T1499.002No-0
594T1561.001No-0
595T1017No-0
596T1077No-0
597T1119No-0
598T1574.004No-0
599T1137.003No-0
600T1559.002No-0
601T1491.001No-0
602T1134.003No-0
603T1053Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
604T1053Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
605T1053Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
606T1053Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
607T1171No-0
608T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml2
609T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml2
610T1088No-0
611T1552.003No-0
612T1562.006No-0
613T1129No-0
614T1488No-0
615T1189No-0
616T1111No-0
617T1053.004No-0
618T1215No-0
619T1547.009No-0
620T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
621T1134.004No-0
622T1539No-0
623T1567.002No-0
624T1106No-0
625T1531No-0
626T1207No-0
627T1044No-0
628T1569.001No-0
629T1218.007No-0
630T1058Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml1
631T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml7
632T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml7
633T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml7
634T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml7
635T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml7
636T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml7
637T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
638T1547.007No-0
639T1135No-0
640T1098Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml1
641T1114Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
642T1114Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml2
643T1550.004No-0
644T1204.001No-0
645T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml6
646T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml6
647T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml6
648T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml6
649T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml6
650T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml6
651T1173No-0
652T1070.004No-0
653T1154No-0
654T1493No-0
655T1559No-0
656T1528No-0
657T1027No-0
658T1185No-0
659T1055.012No-0
660T1558No-0
661T1114.002No-0
662T1578No-0
663T1574.012No-0
664T1498No-0
665T1133No-0
666T1021.002No-0
667T1558.003No-0
668T1560.001No-0
669T1052No-0
670T1056.001No-0
671T1008No-0
672T1036.003No-0
673T1055.005No-0