Skip to content

Commit

Permalink
Merge PR #4718 from @qasimqlf - Update ATT&CK Mapping For Some Rules
Browse files Browse the repository at this point in the history
chore: update ATT&CK tagging for multiple rules
 
---------

Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
  • Loading branch information
qasimqlf and nasbench authored Feb 26, 2024
1 parent 4eccac5 commit 1fb3ce5
Show file tree
Hide file tree
Showing 25 changed files with 27 additions and 23 deletions.
2 changes: 1 addition & 1 deletion deprecated/windows/proc_creation_win_wuauclt_execution.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ date: 2020/10/17
modified: 2023/11/11
tags:
- attack.command_and_control
- attack.execution
- attack.defense_evasion
- attack.t1105
- attack.t1218
logsource:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ author: '@41thexplorer'
date: 2018/11/20
modified: 2023/02/20
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218.011
- detection.emerging_threats
logsource:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ author: Florian Roth (Nextron Systems), @41thexplorer
date: 2018/11/20
modified: 2023/03/08
tags:
- attack.defense_evasion
- attack.execution
- attack.t1218.011
- detection.emerging_threats
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ references:
author: Nasreddine Bencherchali (Nextron Systems), NCSC (Idea)
date: 2023/05/15
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
- detection.emerging_threats
logsource:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,8 +19,9 @@ references:
author: Harjot Singh @cyb3rjy0t
date: 2023/09/15
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
- attack.execution
- detection.threat_hunting
logsource:
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -21,8 +21,9 @@ author: Ivan Dyachkov, oscd.community
date: 2020/10/07
modified: 2023/09/14
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
- attack.execution
- detection.threat_hunting
logsource:
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ references:
author: Joseliyo Sanchez, @Joseliyo_Jstnk
date: 2024/02/05
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
- detection.threat_hunting
logsource:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ references:
author: Andreas Braathen (mnemonic.io), Nasreddine Bencherchali (Nextron Systems)
date: 2023/10/17
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
- detection.threat_hunting
logsource:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ references:
author: Andreas Braathen (mnemonic.io)
date: 2023/10/17
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
- detection.threat_hunting
logsource:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ author: Stamatis Chatzimangou
date: 2022/10/23
modified: 2022/10/23
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
- attack.t1218.007
logsource:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ references:
author: Joseliyo Sanchez, @Joseliyo_Jstnk
date: 2024/02/05
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
logsource:
category: file_event
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ references:
author: Joseliyo Sanchez, @Joseliyo_Jstnk
date: 2024/02/05
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
logsource:
product: windows
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ author: Sreeman, Nasreddine Bencherchali (Nextron Systems)
date: 2020/01/13
modified: 2024/02/17
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
- attack.command_and_control
- attack.t1105
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ author: Nasreddine Bencherchali (Nextron Systems)
date: 2022/07/12
modified: 2023/05/15
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
logsource:
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ references:
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023/09/15
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
logsource:
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ references:
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023/09/15
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
logsource:
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ references:
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023/09/15
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
logsource:
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ author: Nasreddine Bencherchali (Nextron Systems)
date: 2022/06/20
modified: 2023/02/04
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
logsource:
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ author: Nasreddine Bencherchali (Nextron Systems)
date: 2022/06/20
modified: 2023/02/04
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
logsource:
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ author: Bhabesh Raj, X__Junior (Nextron Systems)
date: 2021/07/30
modified: 2023/11/02
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
logsource:
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ references:
author: Joseliyo Sanchez, @Joseliyo_Jstnk, Nasreddine Bencherchali (Nextron Systems)
date: 2024/02/05
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
logsource:
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ author: Beyu Denis, oscd.community
date: 2020/10/18
modified: 2023/02/04
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
logsource:
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ author: Beyu Denis, oscd.community
date: 2020/10/18
modified: 2021/11/27
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
logsource:
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ author: Nasreddine Bencherchali (Nextron Systems)
date: 2022/07/12
modified: 2023/04/11
tags:
- attack.execution
- attack.defense_evasion
- attack.t1218
logsource:
category: process_creation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ author: 'Agro (@agro_sev) oscd.community'
date: 2020/10/13
modified: 2021/11/27
tags:
- attack.defense_evasion
- attack.t1218
logsource:
category: process_creation
Expand Down

0 comments on commit 1fb3ce5

Please sign in to comment.