Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add MITRE ATT&CK tags to various rules that were missing them #4392

Merged
merged 12 commits into from
Aug 28, 2023
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,8 @@ modified: 2023/05/08
tags:
- cve.2021.26858
- detection.emerging_threats
- attack.initial_access
- attack.t1190
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
category: webserver
detection:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,8 @@ modified: 2023/01/02
tags:
- cve.2021.40539
- detection.emerging_threats
- attack.initial_access
- attack.t1190
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
category: webserver
detection:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,10 @@ modified: 2022/12/25
tags:
- cve.2021.42287
- detection.emerging_threats
- attack.defense_evasion
- attack.persistence
- attack.t1036
nasbench marked this conversation as resolved.
Show resolved Hide resolved
- attack.t1098
logsource:
product: windows
service: security
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,13 @@ date: 2022/02/25
modified: 2023/02/08
tags:
- detection.emerging_threats
- attack.execution
- attack.defense_evasion
- attack..impact
nasbench marked this conversation as resolved.
Show resolved Hide resolved
- attack.t1485
nasbench marked this conversation as resolved.
Show resolved Hide resolved
- attack.t1498
- attack.t1059.001
- attack.t1140
logsource:
category: process_creation
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,8 @@ author: Sergio Palacios Dominguez, Nasreddine Bencherchali (Nextron Systems)
date: 2023/07/28
tags:
- cve.2023.27997
- attack.initial_access
- attack.t1190
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
category: webserver
detection:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,8 @@ modified: 2023/07/28
tags:
- cve.2023.34362
- detection.emerging_threats
- attack.persistence
- attack.t1505.003
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
category: webserver
detection:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,8 @@ author: Florian Roth (Nextron Systems), Nasreddine Bencherchali
date: 2023/01/21
tags:
- detection.emerging_threats
- attack.initial_access
- attack.t1190
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
category: process_creation
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ references:
author: Florian Roth (Nextron Systems)
date: 2021/10/16
modified: 2022/12/25
tags:
- attack.execution
- attack.t1059.004
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: linux
category: network_connection
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,9 @@ references:
- https://www.poolwatch.io/coin/monero
author: Florian Roth (Nextron Systems)
date: 2021/10/26
tags:
- attack.impact
- attack.t1496
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: linux
category: network_connection
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ references:
author: Florian Roth (Nextron Systems)
date: 2021/10/26
modified: 2022/12/25
tags:
- attack.impact
- attack.t1496
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: linux
category: process_creation
Expand Down
3 changes: 3 additions & 0 deletions rules/linux/process_creation/proc_creation_lnx_nohup.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,9 @@ references:
- https://www.computerhope.com/unix/unohup.htm
author: 'Christopher Peacock @SecurePeacock, SCYTHE @scythe_io'
date: 2022/06/06
tags:
- attack.execution
- attack.t1059.004
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: linux
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,9 @@ references:
- https://www.virustotal.com/gui/file/3e44c807a25a56f4068b5b8186eee5002eed6f26d665a8b791c472ad154585d1/detection
author: Joseliyo Sanchez, @Joseliyo_Jstnk
date: 2023/06/02
tags:
- attack.defense_evasion
- attack.t1036
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: linux
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,11 @@ references:
- Internal Research
author: Florian Roth (Nextron Systems)
date: 2022/03/14
tags:
- attack.execution
- attack.defense_evasion
- attack.t1059.004
nasbench marked this conversation as resolved.
Show resolved Hide resolved
- attack.t1036
logsource:
product: linux
category: process_creation
Expand Down
5 changes: 5 additions & 0 deletions rules/web/product/apache/web_apache_threading_error.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,11 @@ references:
author: Florian Roth (Nextron Systems)
date: 2019/01/22
modified: 2021/11/27
tags:
- attack.initial_access
- attack.lateral_movement
- attack.t1190
nasbench marked this conversation as resolved.
Show resolved Hide resolved
- attack.t1210
logsource:
service: apache
definition: 'Requirements: Must be able to collect the error.log file'
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,8 @@ modified: 2023/01/19
tags:
- cve.2022.26134
- cve.2021.26084
- attack.initial_access
- attack.t1190
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
category: webserver
detection:
Expand Down
5 changes: 4 additions & 1 deletion rules/web/webserver_generic/web_jndi_exploit.yml
Original file line number Diff line number Diff line change
@@ -1,13 +1,16 @@
title: JNDIExploit Pattern
id: 412d55bc-7737-4d25-9542-5b396867ce55
status: test
description: Detects exploitation attempt using the JDNIExploiit Kit
description: Detects exploitation attempt using the JNDI-Exploit-Kit
references:
- https://github.com/pimps/JNDI-Exploit-Kit
- https://githubmemory.com/repo/FunctFan/JNDIExploit
author: Florian Roth (Nextron Systems)
date: 2021/12/12
modified: 2022/12/25
tags:
- attack.initial_access
- attack.t1190
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
category: webserver
detection:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,9 @@ references:
author: Saw Win Naung, Nasreddine Bencherchali (Nextron Systems)
date: 2020/02/22
modified: 2022/07/25
tags:
- attack.initial_access
- attack.t1190
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
category: webserver
detection:
Expand Down
3 changes: 3 additions & 0 deletions rules/web/webserver_generic/web_ssti_in_access_logs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ references:
- https://github.com/payloadbox/ssti-payloads
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022/06/14
tags:
- attack.defense_evasion
- attack.t1221
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
category: webserver
detection:
Expand Down
3 changes: 3 additions & 0 deletions rules/web/webserver_generic/web_xss_in_access_logs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,9 @@ references:
author: Saw Win Naung, Nasreddine Bencherchali
date: 2021/08/15
modified: 2022/06/14
tags:
- attack.initial_access
- attack.t1189
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
category: webserver
detection:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ references:
author: frack113
date: 2022/02/19
modified: 2023/04/21
tags:
- attack.defense_evasion
- attack.t1562.004
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: windows
service: firewall-as
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,9 @@ references:
author: frack113
date: 2023/02/26
modified: 2023/05/30
tags:
- attack.defense_evasion
- attack.t1562.004
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: windows
service: firewall-as
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ references:
author: frack113
date: 2022/02/19
modified: 2023/04/21
tags:
- attack.defense_evasion
- attack.t1562.004
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: windows
service: firewall-as
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ references:
author: frack113, Nasreddine Bencherchali (Nextron Systems)
date: 2023/01/17
modified: 2023/04/21
tags:
- attack.defense_evasion
- attack.t1562.004
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: windows
service: firewall-as
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ references:
author: frack113
date: 2022/02/19
modified: 2023/06/12
tags:
- attack.defense_evasion
- attack.t1562.004
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: windows
service: firewall-as
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ references:
author: frack113
date: 2022/02/19
modified: 2023/01/17
tags:
- attack.defense_evasion
- attack.t1562.004
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: windows
service: firewall-as
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ references:
author: frack113
date: 2022/02/19
modified: 2023/04/21
tags:
- attack.defense_evasion
- attack.t1562.004
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: windows
service: firewall-as
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ references:
author: frack113, Nasreddine Bencherchali (Nextron Systems)
date: 2022/02/19
modified: 2023/04/21
tags:
- attack.defense_evasion
- attack.t1562.004
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: windows
service: firewall-as
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@ references:
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=632
author: Alexandr Yampolskyi, SOC Prime
date: 2023/04/26
tags:
- attack.persistence
- attack.t1098
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: windows
service: security
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@ references:
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=633
author: Alexandr Yampolskyi, SOC Prime
date: 2023/04/26
tags:
- attack.persistence
- attack.t1098
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: windows
service: security
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@ references:
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=634
author: Alexandr Yampolskyi, SOC Prime
date: 2023/04/26
tags:
- attack.persistence
- attack.t1098
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: windows
service: security
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,10 @@ references:
- https://go.recordedfuture.com/hubfs/reports/mtp-2021-0914.pdf
author: Max Altgelt (Nextron Systems)
date: 2022/04/06
tags:
- attack.defense_evasion
- attack.lateral_movement
- attack.t1550
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: windows
service: security
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,9 @@ references:
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4743
author: frack113
date: 2022/10/14
tags:
- attack.defense_evasion
- attack.t1207
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
service: security
product: windows
Expand Down
7 changes: 7 additions & 0 deletions rules/windows/builtin/security/win_security_admin_logon.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,13 @@ references:
author: frack113
date: 2022/10/14
modified: 2022/10/22
tags:
- attack.defense_evasion
- attack.lateral_movement
- attack.credential_access
- attack.t1558
nasbench marked this conversation as resolved.
Show resolved Hide resolved
- attack.t1649
- attack.t1550
logsource:
service: security
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ references:
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-6423
author: frack113
date: 2022/10/14
tags:
- attack.initial_access
nasbench marked this conversation as resolved.
Show resolved Hide resolved
- attack.t1200
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
service: security
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ references:
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4649
author: frack113
date: 2022/10/14
tags:
- attack.credential_access
- attack.t1558
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
service: security
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,9 @@ references:
- https://twitter.com/sbousseaden/status/1523383197513379841
author: Florian Roth (Nextron Systems)
date: 2022/05/09
tags:
- attack.defense_evasion
- attack.t1027
nasbench marked this conversation as resolved.
Show resolved Hide resolved
logsource:
product: windows
service: security
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,12 @@ references:
- https://twitter.com/sbousseaden/status/1523383197513379841
author: Florian Roth (Nextron Systems)
date: 2022/05/09
tags:
- attack.command_and_control
- attack.defense_evasion
- attack.t1027
nasbench marked this conversation as resolved.
Show resolved Hide resolved
- attack.t1105
- attack.t1036
logsource:
product: windows
service: security
Expand Down
Loading
Loading