Skip to content

Commit

Permalink
Merge PR #4512 from @frack113 - Add Missing Emerging Threats Tag
Browse files Browse the repository at this point in the history
chore: add missing tag `detection.emerging_threats` for emerging threats rules
  • Loading branch information
frack113 authored Oct 26, 2023
1 parent 86d5b64 commit 1584787
Show file tree
Hide file tree
Showing 31 changed files with 32 additions and 0 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ tags:
- attack.persistence
- attack.g0064
- attack.t1543.003
- detection.emerging_threats
logsource:
product: windows
service: system
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ tags:
- attack.g0010
- attack.execution
- attack.t1106
- detection.emerging_threats
logsource:
product: windows
category: pipe_created
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ tags:
- attack.persistence
- attack.g0010
- attack.t1543.003
- detection.emerging_threats
logsource:
product: windows
service: system
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ tags:
- attack.persistence
- attack.g0010
- attack.t1543.003
- detection.emerging_threats
logsource:
product: windows
service: system
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,8 @@ modified: 2022/12/25
tags:
- attack.initial_access
- attack.t1190
- cve.2020.0688
- detection.emerging_threats
logsource:
product: windows
service: application
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ tags:
- attack.credential_access
- attack.command_and_control
- attack.t1071
- detection.emerging_threats
logsource:
product: windows
service: dns-server-analytic
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ tags:
- attack.resource_development
- attack.t1587
- cve.2021.1675
- detection.emerging_threats
logsource:
category: file_event
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ tags:
- attack.t1203
- attack.execution
- cve.2021.26858
- detection.emerging_threats
logsource:
category: file_event
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ modified: 2023/06/22
tags:
- attack.resource_development
- attack.t1587
- detection.emerging_threats
logsource:
product: windows
category: file_event
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ modified: 2022/12/25
tags:
- attack.privilege_escalation
- attack.t1068
- detection.emerging_threats
logsource:
category: file_event
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ modified: 2022/07/12
tags:
- attack.initial_access
- attack.t1190
- detection.emerging_threats
logsource:
product: windows
service: application
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ date: 2022/06/06
tags:
- attack.execution
- cve.2021.44077
- detection.emerging_threats
logsource:
category: file_event
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ tags:
- attack.t1203
- cve.2021.33771
- cve.2021.31979
- detection.emerging_threats
# - threat_group.Sourgum
logsource:
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ modified: 2022/07/12
tags:
- attack.lateral_movement
- attack.t1210
- detection.emerging_threats
logsource:
product: windows
service: msexchange-management
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ tags:
- attack.privilege_escalation
- attack.t1059.001
- cve.2022.24527
- detection.emerging_threats
logsource:
category: file_event
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ date: 2023/05/23
tags:
- attack.impact
- attack.t1486
- detection.emerging_threats
logsource:
product: windows
service: security
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ modified: 2022/10/09
tags:
- attack.persistence
- attack.t1546
- detection.emerging_threats
logsource:
product: windows
service: application
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ date: 2023/10/20
tags:
- attack.privilege_escalation
- attack.initial_access
- detection.emerging_threats
logsource:
product: cisco
service: syslog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ tags:
- attack.persistence
- attack.t1505.001
- cve.2023.27363
- detection.emerging_threats
logsource:
product: windows
category: file_event
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ tags:
- cve.2023.27997
- attack.initial_access
- attack.t1190
- detection.emerging_threats
logsource:
category: webserver
detection:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ tags:
- attack.persistence
- attack.defense_evasion
- cve.2023.36884
- detection.emerging_threats
logsource:
category: file_event
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ date: 2023/07/12
tags:
- attack.command_and_control
- cve.2023.36884
- detection.emerging_threats
logsource:
category: proxy
detection:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ date: 2023/07/12
tags:
- attack.command_and_control
- cve.2023.36884
- detection.emerging_threats
logsource:
category: proxy
detection:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ date: 2023/07/12
tags:
- attack.command_and_control
- cve.2023.36884
- detection.emerging_threats
logsource:
category: proxy
detection:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ date: 2023/07/12
tags:
- attack.command_and_control
- cve.2023.36884
- detection.emerging_threats
logsource:
category: proxy
detection:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ date: 2023/07/13
tags:
- attack.command_and_control
- cve.2023.36884
- detection.emerging_threats
logsource:
product: windows
service: security
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ author: Nasreddine Bencherchali (Nextron Systems)
date: 2023/04/21
tags:
- attack.execution
- detection.emerging_threats
logsource:
product: windows
service: application
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ tags:
- attack.execution
- attack.t1105
- attack.t1059
- detection.emerging_threats
logsource:
category: file_event
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ date: 2023/10/15
tags:
- attack.execution
- attack.t1059
- detection.emerging_threats
logsource:
category: process_creation
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ modified: 2023/10/15
tags:
- attack.persistence
- attack.t1136.001
- detection.emerging_threats
logsource:
category: process_creation
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ date: 2023/02/23
tags:
- attack.command_and_control
- attack.t1219
- detection.emerging_threats
logsource:
product: windows
category: dns_query
Expand Down

0 comments on commit 1584787

Please sign in to comment.