Files
splunk-security_content/docs/_pages/detections.md
T
2021-10-14 14:48:48 -04:00

104 KiB

title, layout, author_profile, permalink, classes, sidebar
title layout author_profile permalink classes sidebar
Detections categories false /detections/ wide
nav
detections
Name Technique Type
7zip CommandLine To SMB Share Path Archive via Utility Hunting
AWS Create Policy Version to allow all resources Cloud Accounts TTP
AWS CreateAccessKey Cloud Account Hunting
AWS CreateLoginProfile Cloud Account TTP
AWS Cross Account Activity From Previously Unseen Account None Anomaly
AWS Detect Users creating keys with encrypt policy without MFA Data Encrypted for Impact TTP
AWS Detect Users with KMS keys performing encryption S3 Data Encrypted for Impact Anomaly
AWS ECR Container Scanning Findings High Malicious Image TTP
AWS ECR Container Scanning Findings Low Informational Unknown Malicious Image Hunting
AWS ECR Container Scanning Findings Medium Malicious Image Anomaly
AWS ECR Container Upload Outside Business Hours Malicious Image Anomaly
AWS ECR Container Upload Unknown User Malicious Image Anomaly
AWS Excessive Security Scanning Cloud Service Discovery TTP
AWS IAM AccessDenied Discovery Events Cloud Infrastructure Discovery Anomaly
AWS IAM Assume Role Policy Brute Force Cloud Infrastructure Discovery, Brute Force TTP
AWS IAM Delete Policy Account Manipulation Hunting
AWS IAM Failure Group Deletion Account Manipulation Anomaly
AWS IAM Successful Group Deletion Cloud Groups, Account Manipulation Hunting
AWS Network Access Control List Created with All Open Ports Disable or Modify Cloud Firewall TTP
AWS Network Access Control List Deleted Disable or Modify Cloud Firewall Anomaly
AWS SAML Access by Provider User and Principal Valid Accounts Anomaly
AWS SAML Update identity provider Valid Accounts TTP
AWS SetDefaultPolicyVersion Cloud Accounts TTP
AWS UpdateLoginProfile Cloud Account TTP
Abnormally High Number Of Cloud Infrastructure API Calls Cloud Accounts Anomaly
Abnormally High Number Of Cloud Instances Destroyed Cloud Accounts Anomaly
Abnormally High Number Of Cloud Instances Launched Cloud Accounts Anomaly
Abnormally High Number Of Cloud Security Group API Calls Cloud Accounts Anomaly
Access LSASS Memory for Dump Creation LSASS Memory TTP
Account Discovery With Net App Domain Account TTP
Add DefaultUser And Password In Registry Credentials in Registry Anomaly
AdsiSearcher Account Discovery Domain Account TTP
Allow File And Printing Sharing In Firewall Disable or Modify Cloud Firewall TTP
Allow Inbound Traffic By Firewall Rule Registry Remote Desktop Protocol TTP
Allow Inbound Traffic In Firewall Rule Remote Desktop Protocol TTP
Allow Network Discovery In Firewall Disable or Modify Cloud Firewall TTP
Allow Operation with Consent Admin Abuse Elevation Control Mechanism TTP
Amazon EKS Kubernetes Pod scan detection Cloud Service Discovery Hunting
Amazon EKS Kubernetes cluster scan detection Cloud Service Discovery Hunting
Anomalous usage of 7zip Archive via Utility Anomaly
Any Powershell DownloadFile PowerShell TTP
Any Powershell DownloadString PowerShell TTP
Applying Stolen Credentials via Mimikatz modules Process Injection, Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation, Access Token Manipulation, Create or Modify System Process, Boot or Logon Autostart Execution, Abuse Elevation Control Mechanism, Compromise Client Software Binary, Modify Authentication Process, Steal or Forge Kerberos Tickets TTP
Applying Stolen Credentials via PowerSploit modules Process Injection, Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation, Access Token Manipulation, Create or Modify System Process, Boot or Logon Autostart Execution, Abuse Elevation Control Mechanism, Compromise Client Software Binary, Credentials from Password Stores, Steal or Forge Kerberos Tickets TTP
Assessment of Credential Strength via DSInternals modules Valid Accounts, Account Manipulation, Account Discovery, Password Policy Discovery, Unsecured Credentials, Credentials from Password Stores TTP
Attacker Tools On Endpoint Match Legitimate Name or Location, Active Scanning, OS Credential Dumping TTP
Attempt To Add Certificate To Untrusted Store Install Root Certificate TTP
Attempt To Disable Services Service Stop TTP
Attempt To Stop Security Service Disable or Modify Tools TTP
Attempt To delete Services Service Stop TTP
Attempted Credential Dump From Registry via Reg exe OS Credential Dumping TTP
Attempted Credential Dump From Registry via Reg exe Security Account Manager TTP
Auto Admin Logon Registry Entry Credentials in Registry TTP
BCDEdit Failure Recovery Modification Inhibit System Recovery TTP
BITS Job Persistence BITS Jobs TTP
BITSAdmin Download File BITS Jobs, Ingress Tool Transfer TTP
Batch File Write to System32 Malicious File TTP
Bcdedit Command Back To Normal Mode Boot Inhibit System Recovery TTP
CHCP Command Execution Command and Scripting Interpreter TTP
CMD Echo Pipe - Escalation Windows Command Shell, Windows Service TTP
CMLUA Or CMSTPLUA UAC Bypass CMSTP TTP
CertUtil Download With URLCache and Split Arguments Ingress Tool Transfer TTP
CertUtil Download With VerifyCtl and Split Arguments Ingress Tool Transfer TTP
CertUtil With Decode Argument Deobfuscate/Decode Files or Information TTP
Certutil exe certificate extraction None TTP
Change To Safe Mode With Network Config Inhibit System Recovery TTP
Check Elevated CMD using whoami System Owner/User Discovery TTP
Child Processes of Spoolsv exe Exploitation for Privilege Escalation TTP
Circle CI Disable Security Job Compromise Client Software Binary Anomaly
Circle CI Disable Security Step Compromise Client Software Binary Anomaly
Clear Unallocated Sector Using Cipher App File Deletion TTP
Clop Common Exec Parameter User Execution TTP
Clop Ransomware Known Service Name Create or Modify System Process TTP
Cloud API Calls From Previously Unseen User Roles Valid Accounts Anomaly
Cloud Compute Instance Created By Previously Unseen User Cloud Accounts Anomaly
Cloud Compute Instance Created In Previously Unused Region Unused/Unsupported Cloud Regions Anomaly
Cloud Compute Instance Created With Previously Unseen Image None Anomaly
Cloud Compute Instance Created With Previously Unseen Instance Type None Anomaly
Cloud Instance Modified By Previously Unseen User Cloud Accounts Anomaly
Cloud Provisioning Activity From Previously Unseen City Valid Accounts Anomaly
Cloud Provisioning Activity From Previously Unseen Country Valid Accounts Anomaly
Cloud Provisioning Activity From Previously Unseen IP Address Valid Accounts Anomaly
Cloud Provisioning Activity From Previously Unseen Region Valid Accounts Anomaly
Cmdline Tool Not Executed In CMD Shell JavaScript TTP
Cobalt Strike Named Pipes Process Injection TTP
Common Ransomware Extensions Data Destruction Hunting
Common Ransomware Notes Data Destruction Hunting
Conti Common Exec parameter User Execution TTP
Control Loading from World Writable Directory Control Panel TTP
Correlation by Repository and Risk Malicious Image Correlation
Correlation by User and Risk Malicious Image Correlation
Create Remote Thread In Shell Application Process Injection TTP
Create Remote Thread into LSASS LSASS Memory TTP
Create Service In Suspicious File Path Service Execution TTP
Create local admin accounts using net exe Local Account TTP
Create or delete windows shares using net exe Network Share Connection Removal TTP
Creation of Shadow Copy NTDS TTP
Creation of Shadow Copy with wmic and powershell NTDS TTP
Creation of lsass Dump with Taskmgr LSASS Memory TTP
Credential Dumping via Copy Command from Shadow Copy NTDS TTP
Credential Dumping via Symlink to Shadow Copy NTDS TTP
Credential Extraction indicative of FGDump and CacheDump with s option OS Credential Dumping TTP
Credential Extraction indicative of FGDump and CacheDump with v option OS Credential Dumping TTP
Credential Extraction indicative of Lazagne command line options OS Credential Dumping, Credentials from Password Stores TTP
Credential Extraction indicative of use of DSInternals credential conversion modules OS Credential Dumping TTP
Credential Extraction indicative of use of DSInternals modules OS Credential Dumping TTP
Credential Extraction indicative of use of Mimikatz modules OS Credential Dumping TTP
Credential Extraction indicative of use of PowerSploit modules OS Credential Dumping TTP
Credential Extraction native Microsoft debuggers peek into the kernel OS Credential Dumping TTP
Credential Extraction native Microsoft debuggers via z command line option OS Credential Dumping TTP
Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals OS Credential Dumping TTP
DLLHost with no Command Line Arguments with Network Process Injection TTP
DNS Exfiltration Using Nslookup App Exfiltration Over Alternative Protocol TTP
DNS Query Length Outliers - MLTK DNS Anomaly
DNS Query Length With High Standard Deviation Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol Anomaly
DSQuery Domain Discovery Domain Trust Discovery TTP
Delete A Net User Service Stop Anomaly
Delete ShadowCopy With PowerShell Inhibit System Recovery TTP
Deleting Of Net Users Account Access Removal TTP
Deleting Shadow Copies Inhibit System Recovery TTP
Deny Permission using Cacls Utility File and Directory Permissions Modification TTP
Detect ARP Poisoning Hardware Additions, Network Denial of Service, ARP Cache Poisoning TTP
Detect AWS Console Login by New User None Hunting
Detect AWS Console Login by User from New City Unused/Unsupported Cloud Regions Hunting
Detect AWS Console Login by User from New Country Unused/Unsupported Cloud Regions Hunting
Detect AWS Console Login by User from New Region Unused/Unsupported Cloud Regions Hunting
Detect Activity Related to Pass the Hash Attacks Pass the Hash TTP
Detect AzureHound Command-Line Arguments Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups TTP
Detect AzureHound File Modifications Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups TTP
Detect Baron Samedit CVE-2021-3156 Exploitation for Privilege Escalation TTP
Detect Baron Samedit CVE-2021-3156 Segfault Exploitation for Privilege Escalation TTP
Detect Baron Samedit CVE-2021-3156 via OSQuery Exploitation for Privilege Escalation TTP
Detect Computer Changed with Anonymous Account Exploitation of Remote Services Hunting
Detect Copy of ShadowCopy with Script Block Logging Security Account Manager TTP
Detect Credential Dumping through LSASS access LSASS Memory TTP
Detect Dump LSASS Memory using comsvcs NTDS TTP
Detect Empire with PowerShell Script Block Logging PowerShell TTP
Detect Excessive Account Lockouts From Endpoint Domain Accounts Anomaly
Detect Excessive User Account Lockouts Local Accounts Anomaly
Detect Exchange Web Shell Web Shell TTP
Detect F5 TMUI RCE CVE-2020-5902 Exploit Public-Facing Application TTP
Detect GCP Storage access from a new IP Data from Cloud Storage Object Anomaly
Detect HTML Help Renamed Compiled HTML File Hunting
Detect HTML Help Spawn Child Process Compiled HTML File TTP
Detect HTML Help URL in Command Line Compiled HTML File TTP
Detect HTML Help Using InfoTech Storage Handlers Compiled HTML File TTP
Detect IPv6 Network Infrastructure Threats Hardware Additions, Network Denial of Service, ARP Cache Poisoning TTP
Detect Kerberoasting Kerberoasting TTP
Detect Large Outbound ICMP Packets Non-Application Layer Protocol TTP
Detect MSHTA Url in Command Line Mshta TTP
Detect Mimikatz Using Loaded Images LSASS Memory TTP
Detect Mimikatz With PowerShell Script Block Logging OS Credential Dumping TTP
Detect New Local Admin account Local Account TTP
Detect New Login Attempts to Routers None TTP
Detect New Open GCP Storage Buckets Data from Cloud Storage Object TTP
Detect New Open S3 Buckets over AWS CLI Data from Cloud Storage Object TTP
Detect New Open S3 buckets Data from Cloud Storage Object TTP
Detect Outbound SMB Traffic File Transfer Protocols TTP
Detect Outlook exe writing a zip file Spearphishing Attachment TTP
Detect Pass the Hash Pass the Hash TTP
Detect Path Interception By Creation Of program exe Path Interception by Unquoted Path TTP
Detect Port Security Violation Hardware Additions, Network Denial of Service, ARP Cache Poisoning TTP
Detect Prohibited Applications Spawning cmd exe Windows Command Shell Hunting
Detect Prohibited Applications Spawning cmd exe Command and Scripting Interpreter TTP
Detect PsExec With accepteula Flag SMB/Windows Admin Shares TTP
Detect RClone Command-Line Usage Automated Exfiltration TTP
Detect Rare Executables None Anomaly
Detect Regasm Spawning a Process Regsvcs/Regasm TTP
Detect Regasm with Network Connection Regsvcs/Regasm TTP
Detect Regasm with no Command Line Arguments Regsvcs/Regasm TTP
Detect Regsvcs Spawning a Process Regsvcs/Regasm TTP
Detect Regsvcs with Network Connection Regsvcs/Regasm TTP
Detect Regsvcs with No Command Line Arguments Regsvcs/Regasm TTP
Detect Regsvr32 Application Control Bypass Regsvr32 TTP
Detect Renamed 7-Zip Archive via Utility Hunting
Detect Renamed PSExec Service Execution Hunting
Detect Renamed RClone Automated Exfiltration Hunting
Detect Renamed WinRAR Archive via Utility Hunting
Detect Rogue DHCP Server Hardware Additions, Network Denial of Service, Man-in-the-Middle TTP
Detect Rundll32 Application Control Bypass - advpack Rundll32 TTP
Detect Rundll32 Application Control Bypass - setupapi Rundll32 TTP
Detect Rundll32 Application Control Bypass - syssetup Rundll32 TTP
Detect Rundll32 Inline HTA Execution Mshta TTP
Detect S3 access from a new IP Data from Cloud Storage Object Anomaly
Detect SNICat SNI Exfiltration Exfiltration Over C2 Channel TTP
Detect SharpHound Command-Line Arguments Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups TTP
Detect SharpHound File Modifications Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups TTP
Detect SharpHound Usage Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups TTP
Detect Software Download To Network Device TFTP Boot TTP
Detect Spike in AWS Security Hub Alerts for EC2 Instance None Anomaly
Detect Spike in AWS Security Hub Alerts for User None Anomaly
Detect Spike in S3 Bucket deletion Data from Cloud Storage Object Anomaly
Detect Spike in blocked Outbound Traffic from your AWS None Anomaly
Detect Traffic Mirroring Hardware Additions, Network Denial of Service, Traffic Duplication TTP
Detect Unauthorized Assets by MAC address None TTP
Detect Use of cmd exe to Launch Script Interpreters Windows Command Shell TTP
Detect WMI Event Subscription Persistence Windows Management Instrumentation Event Subscription TTP
Detect Windows DNS SIGRed via Splunk Stream Exploitation for Client Execution TTP
Detect Windows DNS SIGRed via Zeek Exploitation for Client Execution TTP
Detect Zerologon via Zeek Exploit Public-Facing Application TTP
Detect attackers scanning for vulnerable JBoss servers System Information Discovery TTP
Detect hosts connecting to dynamic domain providers Drive-by Compromise TTP
Detect malicious requests to exploit JBoss servers None TTP
Detect mshta inline hta execution Mshta TTP
Detect mshta renamed Mshta Hunting
Detect processes used for System Network Configuration Discovery System Network Configuration Discovery TTP
Detect shared ec2 snapshot Transfer Data to Cloud Account TTP
Detection of tools built by NirSoft Software Deployment Tools TTP
Disable AMSI Through Registry Disable or Modify Tools TTP
Disable ETW Through Registry Disable or Modify Tools TTP
Disable Logs Using WevtUtil Clear Windows Event Logs TTP
Disable Net User Account Service Stop TTP
Disable Registry Tool Disable or Modify Tools TTP
Disable Show Hidden Files Hidden Files and Directories, Disable or Modify Tools TTP
Disable Windows App Hotkeys Disable or Modify Tools TTP
Disable Windows Behavior Monitoring Disable or Modify Tools TTP
Disable Windows SmartScreen Protection Disable or Modify Tools TTP
Disabling CMD Application Disable or Modify Tools TTP
Disabling ControlPanel Disable or Modify Tools TTP
Disabling Firewall with Netsh Disable or Modify Tools TTP
Disabling FolderOptions Windows Feature Disable or Modify Tools TTP
Disabling Net User Account Account Access Removal TTP
Disabling NoRun Windows App Disable or Modify Tools TTP
Disabling Remote User Account Control Bypass User Account Control TTP
Disabling SystemRestore In Registry Disable or Modify Tools TTP
Disabling Task Manager Disable or Modify Tools TTP
Domain Account Discovery With Net App Domain Account TTP
Domain Account Discovery with Dsquery Domain Account Hunting
Domain Account Discovery with Wmic Domain Account TTP
Domain Controller Discovery with Nltest Remote System Discovery TTP
Domain Controller Discovery with Wmic Remote System Discovery Hunting
Domain Group Discovery With Dsquery Domain Groups Hunting
Domain Group Discovery With Net Domain Groups Hunting
Domain Group Discovery With Wmic Domain Groups Hunting
Domain Group Discovery with Adsisearcher Domain Groups TTP
Download Files Using Telegram Ingress Tool Transfer TTP
Drop IcedID License dat Malicious File Hunting
Dump LSASS via comsvcs DLL LSASS Memory TTP
Dump LSASS via procdump LSASS Memory TTP
Elevated Group Discovery With Net Domain Groups TTP
Elevated Group Discovery With Wmic Domain Groups TTP
Elevated Group Discovery with PowerView Domain Groups Hunting
Email Attachments With Lots Of Spaces None Anomaly
Email files written outside of the Outlook directory Local Email Collection TTP
Email servers sending high volume traffic to hosts Remote Email Collection Anomaly
Enable RDP In Other Port Number Remote Services TTP
Enumerate Users Local Group Using Telegram Account Discovery TTP
Esentutl SAM Copy Security Account Manager Hunting
Eventvwr UAC Bypass Bypass User Account Control TTP
Excel Spawning PowerShell Security Account Manager TTP
Excel Spawning Windows Script Host Security Account Manager TTP
Excessive Attempt To Disable Services Service Stop Anomaly
Excessive DNS Failures DNS Anomaly
Excessive Service Stop Attempt Service Stop Anomaly
Excessive Usage Of Cacls App File and Directory Permissions Modification Anomaly
Excessive Usage Of Net App Account Access Removal Anomaly
Excessive Usage Of SC Service Utility Service Execution Anomaly
Excessive Usage Of Taskkill Disable or Modify Tools Anomaly
Excessive Usage of NSLOOKUP App Exfiltration Over Alternative Protocol Anomaly
Excessive number of distinct processes created in Windows Temp folder Command and Scripting Interpreter Anomaly
Excessive number of service control start as disabled Disable or Modify Tools Anomaly
Excessive number of taskhost processes System Owner/User Discovery Anomaly
Exchange PowerShell Abuse via SSRF Exploit Public-Facing Application TTP
Exchange PowerShell Module Usage PowerShell TTP
Executables Or Script Creation In Suspicious Path Masquerading TTP
Execute Javascript With Jscript COM CLSID Visual Basic TTP
Execution of File with Multiple Extensions Rename System Utilities TTP
Extraction of Registry Hives Security Account Manager TTP
File with Samsam Extension None TTP
First Time Seen Child Process of Zoom Exploitation for Privilege Escalation Anomaly
First Time Seen Running Windows Service Service Execution Anomaly
First time seen command line argument Command and Scripting Interpreter, Regsvr32, Indirect Command Execution Anomaly
FodHelper UAC Bypass Modify Registry, Bypass User Account Control TTP
Fsutil Zeroing File Indicator Removal on Host TTP
GCP Detect gcploit framework Valid Accounts TTP
GCP Kubernetes cluster pod scan detection Cloud Service Discovery Hunting
GPUpdate with no Command Line Arguments with Network Process Injection TTP
GSuite Email Suspicious Attachment Spearphishing Attachment Anomaly
Get ADDefaultDomainPasswordPolicy with Powershell Password Policy Discovery Hunting
Get ADDefaultDomainPasswordPolicy with Powershell Script Block Password Policy Discovery Hunting
Get ADUser with PowerShell Domain Account Hunting
Get ADUser with PowerShell Script Block Domain Account Hunting
Get ADUserResultantPasswordPolicy with Powershell Password Policy Discovery TTP
Get ADUserResultantPasswordPolicy with Powershell Script Block Password Policy Discovery TTP
Get DomainPolicy with Powershell Password Policy Discovery TTP
Get DomainPolicy with Powershell Script Block Password Policy Discovery TTP
Get DomainUser with PowerShell Domain Account TTP
Get DomainUser with PowerShell Script Block Domain Account TTP
Get WMIObject Group Discovery Local Groups Hunting
Get WMIObject Group Discovery with Script Block Logging Local Groups Hunting
Get-DomainTrust with PowerShell Domain Trust Discovery TTP
Get-DomainTrust with PowerShell Script Block Domain Trust Discovery TTP
Get-ForestTrust with PowerShell Domain Trust Discovery TTP
Get-ForestTrust with PowerShell Script Block Domain Trust Discovery TTP
GetAdComputer with PowerShell Remote System Discovery Hunting
GetAdComputer with PowerShell Script Block Remote System Discovery Hunting
GetAdGroup with PowerShell Domain Groups Hunting
GetAdGroup with PowerShell Script Block Domain Groups Hunting
GetCurrent User with PowerShell System Owner/User Discovery Hunting
GetCurrent User with PowerShell Script Block System Owner/User Discovery Hunting
GetDomainComputer with PowerShell Remote System Discovery TTP
GetDomainComputer with PowerShell Script Block Remote System Discovery TTP
GetDomainController with PowerShell Remote System Discovery Hunting
GetDomainController with PowerShell Script Block Remote System Discovery TTP
GetDomainGroup with PowerShell Domain Groups TTP
GetDomainGroup with PowerShell Script Block Domain Groups TTP
GetLocalUser with PowerShell Local Account Hunting
GetLocalUser with PowerShell Script Block Local Account Hunting
GetNetTcpconnection with PowerShell System Network Connections Discovery Hunting
GetNetTcpconnection with PowerShell Script Block System Network Connections Discovery Hunting
GetWmiObject DS User with PowerShell Domain Account TTP
GetWmiObject DS User with PowerShell Script Block Domain Account TTP
GetWmiObject Ds Computer with PowerShell Remote System Discovery TTP
GetWmiObject Ds Computer with PowerShell Script Block Remote System Discovery TTP
GetWmiObject Ds Group with PowerShell Domain Groups TTP
GetWmiObject Ds Group with PowerShell Script Block Domain Groups TTP
GetWmiObject User Account with PowerShell Local Account Hunting
GetWmiObject User Account with PowerShell Script Block Local Account Hunting
GitHub Dependabot Alert Compromise Software Dependencies and Development Tools Anomaly
GitHub Pull Request from Unknown User Compromise Software Dependencies and Development Tools Anomaly
Github Commit Changes In Master Trusted Relationship Anomaly
Github Commit In Develop Trusted Relationship Anomaly
Grant Permission Using Cacls Utility File and Directory Permissions Modification TTP
Gsuite Drive Share In External Email Exfiltration to Cloud Storage Anomaly
Gsuite Email Suspicious Subject With Attachment Spearphishing Attachment Anomaly
Gsuite Email With Known Abuse Web Service Link Spearphishing Attachment Anomaly
Gsuite Outbound Email With Attachment To External Domain Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol Anomaly
Gsuite Suspicious Shared File Name Spearphishing Attachment Anomaly
Hide User Account From Sign-In Screen Disable or Modify Tools TTP
Hiding Files And Directories With Attrib exe Windows File and Directory Permissions Modification TTP
High File Deletion Frequency Data Destruction Anomaly
High Number of Login Failures from a single source Password Guessing Anomaly
High Process Termination Frequency Data Encrypted for Impact Anomaly
Hosts receiving high volume of network traffic from email server Remote Email Collection Anomaly
ICACLS Grant Command File and Directory Permissions Modification TTP
Icacls Deny Command File and Directory Permissions Modification TTP
IcedID Exfiltrated Archived File Creation Archive via Utility Hunting
Illegal Access To User Content via PowerSploit modules Remote Services, Screen Capture, Audio Capture, Remote Service Session Hijacking TTP
Illegal Account Creation via PowerSploit modules Establish Accounts TTP
Illegal Deletion of Logs via Mimikatz modules Indicator Removal on Host TTP
Illegal Enabling or Disabling of Accounts via DSInternals modules Valid Accounts, Account Manipulation TTP
Illegal Management of Active Directory Elements and Policies via DSInternals modules Account Manipulation, Rogue Domain Controller, Domain Policy Modification TTP
Illegal Management of Computers and Active Directory Elements via PowerSploit modules Account Manipulation, Rogue Domain Controller, Domain Policy Modification TTP
Illegal Privilege Elevation and Persistence via PowerSploit modules Scheduled Task/Job, Access Token Manipulation, Abuse Elevation Control Mechanism TTP
Illegal Privilege Elevation via Mimikatz modules Access Token Manipulation, Abuse Elevation Control Mechanism TTP
Illegal Service and Process Control via Mimikatz modules Process Injection, Native API, System Services TTP
Illegal Service and Process Control via PowerSploit modules Process Injection, Native API, System Services TTP
Jscript Execution Using Cscript App JavaScript TTP
Kerberoasting spn request with RC4 encryption Kerberoasting TTP
Known Services Killed by Ransomware Inhibit System Recovery TTP
Kubernetes AWS detect suspicious kubectl calls None Hunting
Kubernetes Nginx Ingress LFI Exploitation for Credential Access TTP
Kubernetes Nginx Ingress RFI Exploitation for Credential Access TTP
Kubernetes Scanner Image Pulling Cloud Service Discovery TTP
Large Volume of DNS ANY Queries Reflection Amplification Anomaly
Local Account Discovery With Wmic Local Account Hunting
Local Account Discovery with Net Local Account Hunting
MS Scripting Process Loading Ldap Module JavaScript Anomaly
MS Scripting Process Loading WMI Module JavaScript Anomaly
MSHTML Module Load in Office Product Spearphishing Attachment TTP
MacOS - Re-opened Applications None TTP
Mailsniper Invoke functions Local Email Collection TTP
Malicious PowerShell Process - Connect To Internet With Hidden Window PowerShell Hunting
Malicious PowerShell Process - Encoded Command Obfuscated Files or Information Hunting
Malicious PowerShell Process - Execution Policy Bypass PowerShell TTP
Malicious PowerShell Process With Obfuscation Techniques PowerShell TTP
Malicious Powershell Executed As A Service Service Execution TTP
Modification Of Wallpaper Defacement TTP
Modify ACL permission To Files Or Folder File and Directory Permissions Modification TTP
Modify ACLs Permission Of Files Or Folders File and Directory Permissions Modification Anomaly
Monitor Email For Brand Abuse None TTP
Monitor Registry Keys for Print Monitors Port Monitors TTP
Monitor Web Traffic For Brand Abuse None TTP
More than usual number of LOLBAS applications in short time period Command and Scripting Interpreter, Scheduled Task/Job Anomaly
Mshta spawning Rundll32 OR Regsvr32 Process Mshta TTP
Msmpeng Application DLL Side Loading DLL Side-Loading TTP
Multiple Archive Files Http Post Traffic Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol TTP
Multiple Disabled Users Failing To Authenticate From Host Using Kerberos Password Spraying Anomaly
Multiple Invalid Users Failing To Authenticate From Host Using Kerberos Password Spraying Anomaly
Multiple Invalid Users Failing To Authenticate From Host Using NTLM Password Spraying Anomaly
Multiple Okta Users With Invalid Credentials From The Same IP Default Accounts TTP
Multiple Users Attempting To Authenticate Using Explicit Credentials Password Spraying Anomaly
Multiple Users Failing To Authenticate From Host Using Kerberos Password Spraying Anomaly
Multiple Users Failing To Authenticate From Host Using NTLM Password Spraying Anomaly
Multiple Users Failing To Authenticate From Process Password Spraying Anomaly
Multiple Users Remotely Failing To Authenticate From Host Password Spraying Anomaly
NET Profiler UAC bypass Bypass User Account Control TTP
NLTest Domain Trust Discovery Domain Trust Discovery TTP
Net Localgroup Discovery Local Groups Hunting
Network Connection Discovery With Arp System Network Connections Discovery Hunting
Network Connection Discovery With Net System Network Connections Discovery Hunting
Network Connection Discovery With Netstat System Network Connections Discovery Hunting
New container uploaded to AWS ECR Implant Internal Image Hunting
Nishang PowershellTCPOneLine PowerShell TTP
No Windows Updates in a time frame None Hunting
Non Chrome Process Accessing Chrome Default Dir Credentials from Web Browsers Anomaly
Non Firefox Process Access Firefox Profile Dir Credentials from Web Browsers Anomaly
Ntdsutil Export NTDS NTDS TTP
O365 Add App Role Assignment Grant User Cloud Account TTP
O365 Added Service Principal Cloud Account TTP
O365 Bypass MFA via Trusted IP Disable or Modify Cloud Firewall TTP
O365 Disable MFA Modify Authentication Process TTP
O365 Excessive Authentication Failures Alert Brute Force Anomaly
O365 Excessive SSO logon errors Modify Authentication Process Anomaly
O365 New Federated Domain Added Cloud Account TTP
O365 PST export alert Email Collection TTP
O365 Suspicious Admin Email Forwarding Email Forwarding Rule Anomaly
O365 Suspicious Rights Delegation Remote Email Collection TTP
O365 Suspicious User Email Forwarding Email Forwarding Rule Anomaly
Office Application Drop Executable Spearphishing Attachment TTP
Office Application Spawn Regsvr32 process Spearphishing Attachment TTP
Office Application Spawn rundll32 process Spearphishing Attachment TTP
Office Document Creating Schedule Task Spearphishing Attachment TTP
Office Document Executing Macro Code Spearphishing Attachment TTP
Office Document Spawned Child Process To Download Spearphishing Attachment TTP
Office Product Spawn CMD Process Mshta TTP
Office Product Spawning BITSAdmin Spearphishing Attachment TTP
Office Product Spawning CertUtil Spearphishing Attachment TTP
Office Product Spawning MSHTA Spearphishing Attachment TTP
Office Product Spawning Rundll32 with no DLL Spearphishing Attachment TTP
Office Product Spawning Wmic Spearphishing Attachment TTP
Office Product Writing cab or inf Spearphishing Attachment TTP
Office Spawning Control Spearphishing Attachment TTP
Okta Account Lockout Events Default Accounts Anomaly
Okta Failed SSO Attempts Default Accounts Anomaly
Okta User Logins From Multiple Cities Default Accounts Anomaly
Overwriting Accessibility Binaries Accessibility Features TTP
Password Policy Discovery with Net Password Policy Discovery Hunting
Permission Modification using Takeown App File and Directory Permissions Modification TTP
PetitPotam Network Share Access Request Forced Authentication TTP
PetitPotam Suspicious Kerberos TGT Request OS Credential Dumping TTP
Phishing Email Detection by Machine Learning Method - SSA Phishing Anomaly
Plain HTTP POST Exfiltrated Data Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol TTP
Potential Pass the Token or Hash Observed at the Destination Device Pass the Hash TTP
Potential Pass the Token or Hash Observed by an Event Collecting Device Pass the Hash TTP
PowerShell 4104 Hunting PowerShell Hunting
PowerShell Domain Enumeration PowerShell TTP
PowerShell Get LocalGroup Discovery Local Groups Hunting
PowerShell Loading DotNET into Memory via System Reflection Assembly PowerShell TTP
PowerShell Start-BitsTransfer BITS Jobs TTP
Powershell Creating Thread Mutex Indicator Removal from Tools TTP
Powershell Disable Security Monitoring Disable or Modify Tools TTP
Powershell Enable SMB1Protocol Feature Indicator Removal from Tools TTP
Powershell Execute COM Object Component Object Model Hijacking TTP
Powershell Fileless Process Injection via GetProcAddress Process Injection, PowerShell TTP
Powershell Fileless Script Contains Base64 Encoded Content Obfuscated Files or Information, PowerShell TTP
Powershell Get LocalGroup Discovery with Script Block Logging Local Groups Hunting
Powershell Processing Stream Of Data PowerShell TTP
Powershell Remote Thread To Known Windows Process Process Injection TTP
Powershell Using memory As Backing Store Deobfuscate/Decode Files or Information TTP
Prevent Automatic Repair Mode using Bcdedit Inhibit System Recovery TTP
Print Spooler Adding A Printer Driver Print Processors TTP
Print Spooler Failed to Load a Plug-in Print Processors TTP
Probing Access with Stolen Credentials via PowerSploit modules Valid Accounts, Account Manipulation TTP
Process Creating LNK file in Suspicious Location Spearphishing Link TTP
Process Deleting Its Process File Path Indicator Removal on Host TTP
Process Execution via WMI Windows Management Instrumentation TTP
Process Kill Base On File Path Disable or Modify Tools TTP
Processes Tapping Keyboard Events None TTP
Processes launching netsh Disable or Modify System Firewall TTP
Prohibited Network Traffic Allowed Exfiltration Over Alternative Protocol TTP
Protocol or Port Mismatch Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol Anomaly
Protocols passing authentication in cleartext None TTP
Ransomware Notes bulk creation Data Encrypted for Impact Anomaly
Rare Parent-Child Process Relationship Exploitation for Client Execution, Command and Scripting Interpreter, Scheduled Task/Job, Software Deployment Tools Anomaly
Recon AVProduct Through Pwh or WMI Gather Victim Host Information TTP
Recon Using WMI Class Gather Victim Host Information TTP
Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules Valid Accounts, Account Discovery, Domain Policy Modification TTP
Reconnaissance and Access to Accounts and Groups via Mimikatz modules Valid Accounts, Account Discovery, Domain Policy Modification TTP
Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit modules Trusted Relationship, Domain Trust Discovery, Gather Victim Network Information, Gather Victim Org Information, Active Scanning TTP
Reconnaissance and Access to Computers and Domains via PowerSploit modules Gather Victim Host Information, Gather Victim Network Information, Account Discovery TTP
Reconnaissance and Access to Computers via Mimikatz modules Gather Victim Host Information TTP
Reconnaissance and Access to Operating System Elements via PowerSploit modules System Service Discovery, Query Registry, Network Service Scanning, Windows Management Instrumentation, Process Discovery, File and Directory Discovery, Software Discovery, Software TTP
Reconnaissance and Access to Processes and Services via Mimikatz modules System Service Discovery, Network Service Scanning, Process Discovery TTP
Reconnaissance and Access to Shared Resources via Mimikatz modules SMB/Windows Admin Shares, Network Share Discovery, Data from Network Shared Drive TTP
Reconnaissance and Access to Shared Resources via PowerSploit modules SMB/Windows Admin Shares, Network Share Discovery, Data from Network Shared Drive TTP
Reconnaissance of Access and Persistence Opportunities via PowerSploit modules Scheduled Task/Job, Exploitation for Privilege Escalation, Valid Accounts, Create or Modify System Process, Boot or Logon Autostart Execution, Hijack Execution Flow TTP
Reconnaissance of Connectivity via PowerSploit modules SMB/Windows Admin Shares, Network Share Discovery, Data from Network Shared Drive TTP
Reconnaissance of Credential Stores and Services via Mimikatz modules Credentials, Domain Properties, Network Trust Dependencies, Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation TTP
Reconnaissance of Defensive Tools via PowerSploit modules Vulnerability Scanning, Software TTP
Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation TTP
Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules Create or Modify System Process, Process Injection, Hijack Execution Flow TTP
Recursive Delete of Directory In Batch CMD File Deletion TTP
Reg exe Manipulating Windows Services Registry Keys Services Registry Permissions Weakness TTP
Registry Keys Used For Persistence Registry Run Keys / Startup Folder TTP
Registry Keys Used For Privilege Escalation Image File Execution Options Injection TTP
Registry Keys for Creating SHIM Databases Application Shimming TTP
Remcos RAT File Creation in Remcos Folder Screen Capture TTP
Remcos client registry install entry Modify Registry TTP
Remote Desktop Network Bruteforce Remote Desktop Protocol TTP
Remote Desktop Network Traffic Remote Desktop Protocol Anomaly
Remote Desktop Process Running On System Remote Desktop Protocol Hunting
Remote Process Instantiation via WMI Windows Management Instrumentation TTP
Remote System Discovery with Adsisearcher Remote System Discovery TTP
Remote System Discovery with Dsquery Remote System Discovery Hunting
Remote System Discovery with Net Remote System Discovery Hunting
Remote System Discovery with Wmic Remote System Discovery TTP
Remote WMI Command Attempt Windows Management Instrumentation TTP
Resize ShadowStorage volume Inhibit System Recovery TTP
Resize Shadowstorage Volume Service Stop TTP
Revil Common Exec Parameter User Execution TTP
Revil Registry Entry Modify Registry TTP
RunDLL Loading DLL By Ordinal Rundll32 TTP
Rundll32 Control RunDLL Hunt Rundll32 Hunting
Rundll32 Control RunDLL World Writable Directory Rundll32 TTP
Rundll32 Create Remote Thread To A Process Process Injection TTP
Rundll32 CreateRemoteThread In Browser Process Injection TTP
Rundll32 DNSQuery Rundll32 TTP
Rundll32 Process Creating Exe Dll Files Rundll32 TTP
Rundll32 with no Command Line Arguments with Network Rundll32 TTP
Ryuk Test Files Detected Data Encrypted for Impact TTP
Ryuk Wake on LAN Command Windows Command Shell TTP
SAM Database File Access Attempt Security Account Manager Hunting
SLUI RunAs Elevated Bypass User Account Control TTP
SLUI Spawning a Process Bypass User Account Control TTP
SMB Traffic Spike SMB/Windows Admin Shares Anomaly
SMB Traffic Spike - MLTK SMB/Windows Admin Shares Anomaly
SQL Injection with Long URLs Exploit Public-Facing Application TTP
Samsam Test File Write Data Encrypted for Impact TTP
Sc exe Manipulating Windows Services Windows Service TTP
SchCache Change By App Connect And Create ADSI Object Domain Account Anomaly
Schedule Task with HTTP Command Arguments Scheduled Task/Job TTP
Schedule Task with Rundll32 Command Trigger Scheduled Task/Job TTP
Scheduled Task Deleted Or Created via CMD Scheduled Task TTP
Schtasks Run Task On Demand Scheduled Task/Job TTP
Schtasks scheduling job on remote system Scheduled Task TTP
Schtasks used for forcing a reboot Scheduled Task TTP
Script Execution via WMI Windows Management Instrumentation TTP
Sdclt UAC Bypass Bypass User Account Control TTP
SearchProtocolHost with no Command Line with Network Process Injection TTP
SecretDumps Offline NTDS Dumping Tool NTDS TTP
Services Escalate Exe Abuse Elevation Control Mechanism TTP
Set Default PowerShell Execution Policy To Unrestricted or Bypass PowerShell TTP
Setting Credentials via DSInternals modules Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation TTP
Setting Credentials via Mimikatz modules Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation TTP
Setting Credentials via PowerSploit modules Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation TTP
Shim Database File Creation Application Shimming TTP
Shim Database Installation With Suspicious Parameters Application Shimming TTP
Short Lived Windows Accounts Local Account TTP
SilentCleanup UAC Bypass Bypass User Account Control TTP
Single Letter Process On Endpoint Malicious File TTP
Spike in File Writes None Anomaly
Spoolsv Spawning Rundll32 Print Processors TTP
Spoolsv Suspicious Loaded Modules Print Processors TTP
Spoolsv Suspicious Process Access Exploitation for Privilege Escalation TTP
Spoolsv Writing a DLL Print Processors TTP
Spoolsv Writing a DLL - Sysmon Print Processors TTP
Sqlite Module In Temp Folder Data from Local System TTP
Start Up During Safe Mode Boot Registry Run Keys / Startup Folder TTP
Sunburst Correlation DLL and Network Event Exploitation for Client Execution TTP
Supernova Webshell Web Shell TTP
Suspicious Curl Network Connection Ingress Tool Transfer TTP
Suspicious DLLHost no Command Line Arguments Process Injection TTP
Suspicious Driver Loaded Path Windows Service TTP
Suspicious Email Attachment Extensions Spearphishing Attachment Anomaly
Suspicious Event Log Service Behavior Clear Windows Event Logs TTP
Suspicious GPUpdate no Command Line Arguments Process Injection TTP
Suspicious IcedID Regsvr32 Cmdline Regsvr32 TTP
Suspicious IcedID Rundll32 Cmdline Rundll32 TTP
Suspicious Image Creation In Appdata Folder Screen Capture TTP
Suspicious Java Classes None Anomaly
Suspicious MSBuild Rename MSBuild, Rename System Utilities TTP
Suspicious MSBuild Spawn MSBuild TTP
Suspicious PlistBuddy Usage Launch Agent TTP
Suspicious PlistBuddy Usage via OSquery Launch Agent TTP
Suspicious Process File Path Create or Modify System Process TTP
Suspicious Reg exe Process Modify Registry TTP
Suspicious Regsvr32 Register Suspicious Path Regsvr32 TTP
Suspicious Rundll32 PluginInit Rundll32 TTP
Suspicious Rundll32 Rename Rundll32, Rename System Utilities Hunting
Suspicious Rundll32 StartW Rundll32 TTP
Suspicious Rundll32 dllregisterserver Rundll32 TTP
Suspicious Rundll32 no Command Line Arguments Rundll32 TTP
Suspicious SQLite3 LSQuarantine Behavior Data Staged TTP
Suspicious Scheduled Task from Public Directory Scheduled Task Anomaly
Suspicious SearchProtocolHost no Command Line Arguments Process Injection TTP
Suspicious WAV file in Appdata Folder Screen Capture TTP
Suspicious microsoft workflow compiler rename Trusted Developer Utilities Proxy Execution, Rename System Utilities Hunting
Suspicious microsoft workflow compiler usage Trusted Developer Utilities Proxy Execution TTP
Suspicious msbuild path MSBuild, Rename System Utilities TTP
Suspicious mshta child process Mshta TTP
Suspicious mshta spawn Mshta TTP
Suspicious wevtutil Usage Clear Windows Event Logs TTP
Suspicious writes to windows Recycle Bin Masquerading TTP
System Information Discovery Detection System Information Discovery TTP
System Process Running from Unexpected Location Masquerading Anomaly
System Processes Run From Unexpected Locations Rename System Utilities TTP
System User Discovery With Query System Owner/User Discovery Hunting
System User Discovery With Whoami System Owner/User Discovery Hunting
TOR Traffic Web Protocols TTP
Trickbot Named Pipe Process Injection TTP
UAC Bypass MMC Load Unsigned Dll Bypass User Account Control TTP
UAC Bypass With Colorui COM Object CMSTP TTP
USN Journal Deletion Indicator Removal on Host TTP
Unified Messaging Service Spawning a Process Exploit Public-Facing Application TTP
Uninstall App Using MsiExec Msiexec TTP
Unload Sysmon Filter Driver Disable or Modify Tools TTP
Unloading AMSI via Reflection Impair Defenses TTP
Unusually Long Command Line None Anomaly
Unusually Long Command Line None Anomaly
Unusually Long Command Line - MLTK None Anomaly
Unusually Long Content-Type Length None Anomaly
User Discovery With Env Vars PowerShell System Owner/User Discovery Hunting
User Discovery With Env Vars PowerShell Script Block System Owner/User Discovery Hunting
W3WP Spawning Shell Web Shell TTP
WBAdmin Delete System Backups Inhibit System Recovery TTP
WMI Permanent Event Subscription Windows Management Instrumentation TTP
WMI Permanent Event Subscription - Sysmon Windows Management Instrumentation Event Subscription TTP
WMI Recon Running Process Or Services Gather Victim Host Information TTP
WMI Temporary Event Subscription Windows Management Instrumentation TTP
WSReset UAC Bypass Bypass User Account Control TTP
Wbemprox COM Object Execution CMSTP TTP
Web Servers Executing Suspicious Processes System Information Discovery TTP
Wermgr Process Connecting To IP Check Web Services IP Addresses TTP
Wermgr Process Create Executable File Obfuscated Files or Information TTP
Wermgr Process Spawned CMD Or Powershell Process Command and Scripting Interpreter TTP
WevtUtil Usage To Clear Logs Clear Windows Event Logs TTP
Wevtutil Usage To Disable Logs Clear Windows Event Logs TTP
WinEvent Scheduled Task Created Within Public Path Scheduled Task TTP
WinEvent Scheduled Task Created to Spawn Shell Scheduled Task TTP
WinRM Spawning a Process Exploit Public-Facing Application TTP
Windows AdFind Exe Remote System Discovery TTP
Windows DisableAntiSpyware Registry Disable or Modify Tools TTP
Windows Event Log Cleared Clear Windows Event Logs TTP
Windows Security Account Manager Stopped Service Stop TTP
Winword Spawning Cmd Spearphishing Attachment TTP
Winword Spawning PowerShell Spearphishing Attachment TTP
Winword Spawning Windows Script Host Spearphishing Attachment TTP
Wmic Group Discovery Local Groups Hunting
Write Executable in SMB Share SMB/Windows Admin Shares TTP
XMRIG Driver Loaded Windows Service TTP
XSL Script Execution With WMIC XSL Script Processing TTP
aws detect attach to role policy Valid Accounts Hunting
aws detect permanent key creation Valid Accounts Hunting
aws detect role creation Valid Accounts Hunting
aws detect sts assume role abuse Valid Accounts Hunting
aws detect sts get session token abuse Use Alternate Authentication Material Hunting