Files
splunk-security_content/docs/mitre-map/coverage.csv
T
2020-07-09 23:08:41 -04:00

26 KiB

1Technique IDDetection AvailableLinkscore
2T1568.001No-0
3T1218.010No-0
4T1213No-0
5T1519No-0
6T1021.002No-0
7T1027.002No-0
8T1020No-0
9T1158No-0
10T1164No-0
11T1003.003No-0
12T1201No-0
13T1578.003No-0
14T1049No-0
15T1547.011No-0
16T1185No-0
17T1564.005No-0
18T1119No-0
19T1037No-0
20T1055.005No-0
21T1199No-0
22T1547.003No-0
23T1069.003No-0
24T1537No-0
25T1192Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml1
26T1146No-0
27T1136.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml1
28T1069No-0
29T1044No-0
30T1505No-0
31T1114.002No-0
32T1542.001No-0
33T1514No-0
34T1552No-0
35T1052No-0
36T1556.003No-0
37T1563.001No-0
38T1499.002No-0
39T1574No-0
40T1563No-0
41T1055.014No-0
42T1134.005No-0
43T1558No-0
44T1542.002No-0
45T1077No-0
46T1121No-0
47T1059.006No-0
48T1048.003No-0
49T1574.002No-0
50T1079No-0
51T1213.001No-0
52T1504No-0
53T1090.001No-0
54T1083No-0
55T1552.001No-0
56T1134No-0
57T1144No-0
58T1078.003No-0
59T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml3
60T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml3
61T1530Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml3
62T1120No-0
63T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml2
64T1112Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml2
65T1546.011No-0
66T1550No-0
67T1547.004No-0
68T1218.003No-0
69T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml2
70T1068Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml2
71T1059.004No-0
72T1011.001No-0
73T1100No-0
74T1054No-0
75T1021No-0
76T1564No-0
77T1547.009No-0
78T1022No-0
79T1102.001No-0
80T1105No-0
81T1559.001No-0
82T1036.001No-0
83T1070.004No-0
84T1578.004No-0
85T1572No-0
86T1546.009No-0
87T1518No-0
88T1501No-0
89T1053.002No-0
90T1548.002No-0
91T1212No-0
92T1065No-0
93T1546.003No-0
94T1175No-0
95T1552.004No-0
96T1223No-0
97T1574.008No-0
98T1015Yeshttps://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml3
99T1015Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml3
100T1015Yeshttps://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml3
101T1567.002No-0
102T1218.002No-0
103T1023No-0
104T1183No-0
105T1125No-0
106T1200No-0
107T1108No-0
108T1578.001No-0
109T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml2
110T1136Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml2
111T1573.002No-0
112T1059.003No-0
113T1147No-0
114T1004No-0
115T1205No-0
116T1552.006No-0
117T1104No-0
118T1562.001No-0
119T1056No-0
120T1219No-0
121T1567.001No-0
122T1566.002No-0
123T1036.002No-0
124T1046No-0
125T1115No-0
126T1554No-0
127T1546.002No-0
128T1565.001No-0
129T1502No-0
130T1211No-0
131T1072Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
132T1080No-0
133T1560.003No-0
134T1180No-0
135T1070.005No-0
136T1542.003No-0
137T1555.001No-0
138T1052.001No-0
139T1056.004No-0
140T1094No-0
141T1001.003No-0
142T1076Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml2
143T1076Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml2
144T1215No-0
145T1218.007No-0
146T1178No-0
147T1171No-0
148T1140No-0
149T1025No-0
150T1136.003No-0
151T1547.007No-0
152T1552.003No-0
153T1213.002No-0
154T1001.001No-0
155T1195.002No-0
156T1053Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml4
157T1053Yeshttps://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml4
158T1053Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml4
159T1053Yeshttps://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml4
160T1209No-0
161T1069.001No-0
162T1193Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml2
163T1193Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml2
164T1179No-0
165T1098.003No-0
166T1505.002No-0
167T1059.002No-0
168T1078.001No-0
169T1562.004No-0
170T1563.002No-0
171T1558.003No-0
172T1099No-0
173T1059.001No-0
174T1195.001No-0
175T1497.001No-0
176T1536No-0
177T1058Yeshttps://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml1
178T1005No-0
179T1148No-0
180T1038No-0
181T1552.002No-0
182T1218.005No-0
183T1486No-0
184T1003.008No-0
185T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml22
186T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml22
187T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml22
188T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml22
189T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml22
190T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml22
191T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml22
192T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml22
193T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml22
194T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml22
195T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml22
196T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml22
197T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml22
198T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml22
199T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml22
200T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml22
201T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml22
202T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml22
203T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml22
204T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml22
205T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml22
206T1078Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml22
207T1053.001No-0
208T1557.001No-0
209T1500No-0
210T1170No-0
211T1166No-0
212T1051No-0
213T1498.001No-0
214T1210No-0
215T1074.002No-0
216T1202No-0
217T1495No-0
218T1561.002No-0
219T1102.003No-0
220T1574.009No-0
221T1190No-0
222T1095Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml1
223T1087.001No-0
224T1218.008No-0
225T1547.005No-0
226T1040No-0
227T1153No-0
228T1087.003No-0
229T1071No-0
230T1129No-0
231T1204.002No-0
232T1155No-0
233T1085Yeshttps://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml1
234T1177No-0
235T1021.004No-0
236T1042Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml3
237T1042Yeshttps://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml3
238T1042Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml3
239T1090.003No-0
240T1134.004No-0
241T1053.004No-0
242T1221No-0
243T1557No-0
244T1003.007No-0
245T1070.001No-0
246T1555.003No-0
247T1132.002No-0
248T1113No-0
249T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml2
250T1082Yeshttps://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml2
251T1546.008No-0
252T1208Yeshttps://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml1
253T1499No-0
254T1561No-0
255T1497.003No-0
256T1009No-0
257T1496No-0
258T1216.001No-0
259T1011No-0
260T1548.004No-0
261T1127No-0
262T1562.006No-0
263T1124No-0
264T1126No-0
265T1055.004No-0
266T1098.002No-0
267T1505.003No-0
268T1031No-0
269T1574.007No-0
270T1137.002No-0
271T1491.002No-0
272T1548.003No-0
273T1071.004No-0
274T1021.003No-0
275T1048.002No-0
276T1196No-0
277T1071.001No-0
278T1169No-0
279T1128No-0
280T1548.001No-0
281T1172No-0
282T1149No-0
283T1543No-0
284T1498.002No-0
285T1182No-0
286T1547No-0
287T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml8
288T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml8
289T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml8
290T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml8
291T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml8
292T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml8
293T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml8
294T1059Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml8
295T1093No-0
296T1553.004No-0
297T1037.002No-0
298T1098Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml1
299T1527No-0
300T1220No-0
301T1034No-0
302T1141No-0
303T1116No-0
304T1003.005No-0
305T1041Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml1
306T1055.002No-0
307T1522No-0
308T1074.001No-0
309T1071.002No-0
310T1111No-0
311T1546.005No-0
312T1050Yeshttps://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml2
313T1050Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml2
314T1574.001No-0
315T1055.011No-0
316T1184No-0
317T1074Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml2
318T1074Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml2
319T1542No-0
320T1073No-0
321T1092No-0
322T1014No-0
323T1189No-0
324T1137.006No-0
325T1075Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml1
326T1087.002No-0
327T1134.003No-0
328T1222.002No-0
329T1562.002No-0
330T1548No-0
331T1035No-0
332T1555No-0
333T1561.001No-0
334T1098.004No-0
335T1021.001Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml1
336T1017No-0
337T1205.001No-0
338T1569.002No-0
339T1565.002No-0
340T1569No-0
341T1499.004No-0
342T1037.005No-0
343T1553.003No-0
344T1546.004No-0
345T1053.003No-0
346T1560No-0
347T1181No-0
348T1565No-0
349T1131Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml1
350T1558.002No-0
351T1218.009No-0
352T1001.002No-0
353T1078.002No-0
354T1160No-0
355T1060No-0
356T1560.001No-0
357T1489No-0
358T1207No-0
359T1204No-0
360T1553.001No-0
361T1018No-0
362T1547.002No-0
363T1091No-0
364T1019No-0
365T1543.001No-0
366T1555.002No-0
367T1492No-0
368T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml3
369T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml3
370T1048Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml3
371T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml2
372T1525Yeshttps://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml2
373T1574.004No-0
374T1550.003No-0
375T1480No-0
376T1161No-0
377T1558.001No-0
378T1214No-0
379T1546.006No-0
380T1556No-0
381T1087Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml1
382T1574.005No-0
383T1506No-0
384T1564.001No-0
385T1130No-0
386T1139No-0
387T1045No-0
388T1546.007No-0
389T1032No-0
390T1090No-0
391T1498No-0
392T1027.005No-0
393T1543.004No-0
394T1027No-0
395T1566.003No-0
396T1097No-0
397T1546No-0
398T1556.002No-0
399T1176No-0
400T1562No-0
401T1187No-0
402T1070.006No-0
403T1186No-0
404T1057No-0
405T1543.002No-0
406T1574.010No-0
407T1028No-0
408T1010No-0
409T1565.003No-0
410T1056.001No-0
411T1110.003No-0
412T1109No-0
413T1142No-0
414T1154No-0
415T1547.006No-0
416T1487No-0
417T1037.003No-0
418T1071.003No-0
419T1027.003No-0
420T1055.012No-0
421T1056.003No-0
422T1090.004No-0
423T1137No-0
424T1485No-0
425T1110.001No-0
426T1204.001No-0
427T1222.001No-0
428T1137.001No-0
429T1027.004No-0
430T1106No-0
431T1036.005No-0
432T1553.002No-0
433T1070.003No-0
434T1218.001No-0
435T1482No-0
436T1137.005No-0
437T1013No-0
438T1203No-0
439T1123No-0
440T1021.005No-0
441T1574.006No-0
442T1012No-0
443T1499.003No-0
444T1218.004No-0
445T1168No-0
446T1048.001No-0
447T1222No-0
448T1173No-0
449T1156No-0
450T1543.003No-0
451T1134.002No-0
452T1055.003No-0
453T1480.001No-0
454T1570No-0
455T1101No-0
456T1029No-0
457T1534No-0
458T1556.001No-0
459T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml6
460T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml6
461T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml6
462T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml6
463T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml6
464T1086Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml6
465T1494No-0
466T1491.001No-0
467T1056.002No-0
468T1008No-0
469T1036.004No-0
470T1195.003No-0
471T1055No-0
472T1568.003No-0
473T1007No-0
474T1574.011No-0
475T1067No-0
476T1505.001No-0
477T1206No-0
478T1062No-0
479T1152No-0
480T1564.003No-0
481T1114.003No-0
482T1528No-0
483T1037.001No-0
484T1198No-0
485T1064Yeshttps://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml7
486T1064Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml7
487T1064Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml7
488T1064Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml7
489T1064Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml7
490T1064Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml7
491T1064Yeshttps://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml7
492T1145No-0
493T1059.005No-0
494T1493No-0
495T1110.004No-0
496T1055.008No-0
497T1568No-0
498T1081No-0
499T1055.001No-0
500T1194No-0
501T1218.011No-0
502T1546.010No-0
503T1002No-0
504T1039No-0
505T1573.001No-0
506T1053.005No-0
507T1546.001No-0
508T1550.001No-0
509T1003.001No-0
510T1538No-0
511T1191No-0
512T1001No-0
513T1150No-0
514T1098.001No-0
515T1568.002No-0
516T1547.008No-0
517T1133No-0
518T1559.002No-0
519T1567No-0
520T1084Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml3
521T1084Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml3
522T1084Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml3
523T1114Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml2
524T1114Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml2
525T1070.002No-0
526T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml8
527T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml8
528T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml8
529T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml8
530T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml8
531T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml8
532T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml8
533T1535Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml8
534T1564.002No-0
535T1484No-0
536T1055.009No-0
537T1135No-0
538T1574.012No-0
539T1564.004No-0
540T1163No-0
541T1562.007No-0
542T1003.002No-0
543T1090.002No-0
544T1564.006No-0
545T1066No-0
546T1055.013No-0
547T1491No-0
548T1546.012No-0
549T1197No-0
550T1547.010No-0
551T1016No-0
552T1499.001No-0
553T1573No-0
554T1127.001No-0
555T1117No-0
556T1027.001No-0
557T1546.014No-0
558T1162No-0
559T1559No-0
560T1503No-0
561T1195No-0
562T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml7
563T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml7
564T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml7
565T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml7
566T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml7
567T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml7
568T1047Yeshttps://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml7
569T1122No-0
570T1560.002No-0
571T1110.002No-0
572T1566No-0
573T1059.007No-0
574T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml14
575T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml14
576T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml14
577T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml14
578T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml14
579T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml14
580T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml14
581T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml14
582T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml14
583T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml14
584T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml14
585T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml14
586T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml14
587T1043Yeshttps://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml14
588T1488No-0
589T1529No-0
590T1096No-0
591T1550.004No-0
592T1217No-0
593T1218No-0
594T1578No-0
595T1546.015No-0
596T1006No-0
597T1137.003No-0
598T1174No-0
599T1134.001No-0
600T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml2
601T1070Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml2
602T1550.002No-0
603T1030No-0
604T1137.004No-0
605T1036.006No-0
606T1539No-0
607T1518.001No-0
608T1061No-0
609T1151No-0
610T1578.002No-0
611T1037.004No-0
612T1107No-0
613T1114.001No-0
614T1103Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml1
615T1490No-0
616T1483No-0
617T1088No-0
618T1159No-0
619T1165No-0
620T1132.001No-0
621T1003.004No-0
622T1566.001No-0
623T1102Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml1
624T1024No-0
625T1157No-0
626T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml12
627T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml12
628T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml12
629T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml12
630T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml12
631T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml12
632T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml12
633T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml12
634T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml12
635T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml12
636T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml12
637T1003Yeshttps://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml12
638T1087.004No-0
639T1552.005No-0
640T1562.003No-0
641T1553No-0
642T1547.001No-0
643T1526No-0
644T1216No-0
645T1063No-0
646T1036.003No-0
647T1569.001No-0
648T1118No-0
649T1571No-0
650T1069.002No-0
651T1089Yeshttps://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml5
652T1089Yeshttps://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml5
653T1089Yeshttps://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml5
654T1089Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml5
655T1089Yeshttps://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml5
656T1143No-0
657T1003.006No-0
658T1497.002No-0
659T1188No-0
660T1110No-0
661T1531No-0
662T1138Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml3
663T1138Yeshttps://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml3
664T1138Yeshttps://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml3
665T1132No-0
666T1546.013No-0
667T1026No-0
668T1036Yeshttps://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml1
669T1102.002No-0
670T1033No-0
671T1021.006No-0
672T1497No-0
673T1167No-0
674T1136.002No-0
675T1078.004No-0