Skip to content

Commit 1411dac

Browse files
authored
Merge branch 'develop' into cisco_slashn
2 parents f37ca5f + 45af4de commit 1411dac

12 files changed

+34
-36
lines changed

detections/endpoint/msi_module_loaded_by_non_system_binary.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: MSI Module Loaded by Non-System Binary
22
id: ccb98a66-5851-11ec-b91c-acde48001122
3-
version: 7
4-
date: '2025-02-10'
3+
version: 8
4+
date: '2025-04-22'
55
author: Michael Haag, Splunk
66
status: production
77
type: Hunting
@@ -38,7 +38,7 @@ tags:
3838
cve:
3939
- CVE-2021-41379
4040
mitre_attack_id:
41-
- T1574.002
41+
- T1574.001
4242
product:
4343
- Splunk Enterprise
4444
- Splunk Enterprise Security

detections/endpoint/msmpeng_application_dll_side_loading.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Msmpeng Application DLL Side Loading
22
id: 8bb3f280-dd9b-11eb-84d5-acde48001122
3-
version: 8
4-
date: '2025-02-10'
3+
version: 9
4+
date: '2025-04-22'
55
author: Teoderick Contreras, Splunk, Sanjay Govind
66
status: production
77
type: TTP
@@ -57,7 +57,7 @@ tags:
5757
- Revil Ransomware
5858
asset_type: Endpoint
5959
mitre_attack_id:
60-
- T1574.002
60+
- T1574.001
6161
product:
6262
- Splunk Enterprise
6363
- Splunk Enterprise Security

detections/endpoint/windows_dll_side_loading_in_calc.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows DLL Side-Loading In Calc
22
id: af01f6db-26ac-440e-8d89-2793e303f137
3-
version: 7
4-
date: '2025-04-16'
3+
version: 8
4+
date: '2025-04-22'
55
author: Teoderick Contreras, Splunk
66
status: production
77
type: TTP
@@ -59,7 +59,7 @@ tags:
5959
- Earth Alux
6060
asset_type: Endpoint
6161
mitre_attack_id:
62-
- T1574.002
62+
- T1574.001
6363
product:
6464
- Splunk Enterprise
6565
- Splunk Enterprise Security

detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows DLL Side-Loading Process Child Of Calc
22
id: 295ca9ed-e97b-4520-90f7-dfb6469902e1
3-
version: 7
4-
date: '2025-04-16'
3+
version: 8
4+
date: '2025-04-22'
55
author: Teoderick Contreras, Splunk
66
status: production
77
type: Anomaly
@@ -66,7 +66,7 @@ tags:
6666
- Earth Alux
6767
asset_type: Endpoint
6868
mitre_attack_id:
69-
- T1574.002
69+
- T1574.001
7070
product:
7171
- Splunk Enterprise
7272
- Splunk Enterprise Security

detections/endpoint/windows_known_abused_dll_created.yml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows Known Abused DLL Created
22
id: ea91651a-772a-4b02-ac3d-985b364a5f07
3-
version: 6
4-
date: '2025-02-10'
3+
version: 7
4+
date: '2025-04-22'
55
author: Steven Dick
66
status: production
77
type: Anomaly
@@ -79,7 +79,6 @@ tags:
7979
asset_type: Endpoint
8080
mitre_attack_id:
8181
- T1574.001
82-
- T1574.002
8382
product:
8483
- Splunk Enterprise
8584
- Splunk Enterprise Security

detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows Known Abused DLL Loaded Suspiciously
22
id: dd6d1f16-adc0-4e87-9c34-06189516b803
3-
version: 6
4-
date: '2025-02-10'
3+
version: 7
4+
date: '2025-04-22'
55
author: Steven Dick
66
status: production
77
type: TTP
@@ -65,7 +65,6 @@ tags:
6565
asset_type: Endpoint
6666
mitre_attack_id:
6767
- T1574.001
68-
- T1574.002
6968
product:
7069
- Splunk Enterprise
7170
- Splunk Enterprise Security

detections/endpoint/windows_known_graphicalproton_loaded_modules.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows Known GraphicalProton Loaded Modules
22
id: bf471c94-0324-4b19-a113-d02749b969bc
3-
version: 8
4-
date: '2025-04-17'
3+
version: 9
4+
date: '2025-04-22'
55
author: Teoderick Contreras, Splunk
66
status: production
77
type: Anomaly
@@ -57,7 +57,7 @@ tags:
5757
- Water Gamayun
5858
asset_type: Endpoint
5959
mitre_attack_id:
60-
- T1574.002
60+
- T1574.001
6161
product:
6262
- Splunk Enterprise
6363
- Splunk Enterprise Security

detections/endpoint/windows_masquerading_explorer_as_child_process.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows Masquerading Explorer As Child Process
22
id: 61490da9-52a1-4855-a0c5-28233c88c481
3-
version: 9
4-
date: '2025-04-17'
3+
version: 10
4+
date: '2025-04-22'
55
author: Teoderick Contreras, Splunk
66
status: production
77
type: TTP
@@ -68,7 +68,7 @@ tags:
6868
- Water Gamayun
6969
asset_type: Endpoint
7070
mitre_attack_id:
71-
- T1574.002
71+
- T1574.001
7272
product:
7373
- Splunk Enterprise
7474
- Splunk Enterprise Security

detections/endpoint/windows_sqlwriter_sqldumper_dll_sideload.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows SqlWriter SQLDumper DLL Sideload
22
id: 2ed89ba9-c6c7-46aa-9f08-a2a1c2955aa3
3-
version: 5
4-
date: '2024-11-13'
3+
version: 6
4+
date: '2025-04-22'
55
author: Michael Haag, Teoderick Contreras, Splunk
66
data_source:
77
- Sysmon EventID 7
@@ -69,7 +69,7 @@ tags:
6969
- Midnight Blizzard
7070
asset_type: Endpoint
7171
mitre_attack_id:
72-
- T1574.002
72+
- T1574.001
7373
product:
7474
- Splunk Enterprise
7575
- Splunk Enterprise Security

detections/endpoint/windows_unsigned_dll_side_loading.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows Unsigned DLL Side-Loading
22
id: 5a83ce44-8e0f-4786-a775-8249a525c879
3-
version: 10
4-
date: '2025-04-16'
3+
version: 11
4+
date: '2025-04-22'
55
author: Teoderick Contreras, Splunk
66
status: production
77
type: Anomaly
@@ -61,7 +61,7 @@ tags:
6161
- Earth Alux
6262
asset_type: Endpoint
6363
mitre_attack_id:
64-
- T1574.002
64+
- T1574.001
6565
product:
6666
- Splunk Enterprise
6767
- Splunk Enterprise Security

0 commit comments

Comments
 (0)