Skip to content

Commit 95b6dd8

Browse files
authored
Merge PR #5381 from @david-syk - Update MITRE ATT&CK tags
chore: update multiple mitre att&ck tags
1 parent 6ded165 commit 95b6dd8

9 files changed

+11
-0
lines changed

rules/application/rpc_firewall/rpc_firewall_sharphound_recon_sessions.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@ author: Sagie Dulce, Dekel Paz
1111
date: 2022-01-01
1212
modified: 2022-01-01
1313
tags:
14+
- attack.discovery
1415
- attack.t1033
1516
logsource:
1617
product: rpc_firewall

rules/cloud/bitbucket/audit/bitbucket_audit_user_permissions_export_attempt_detected.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,8 @@ author: Muhammad Faisal (@faisalusuf)
99
date: 2024-02-25
1010
tags:
1111
- attack.reconnaissance
12+
- attack.collection
13+
- attack.discovery
1214
- attack.t1213
1315
- attack.t1082
1416
- attack.t1591.004

rules/windows/process_creation/proc_creation_win_hktl_sharpup.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,8 @@ date: 2022-08-20
99
modified: 2023-02-13
1010
tags:
1111
- attack.privilege-escalation
12+
- attack.discovery
13+
- attack.execution
1214
- attack.t1615
1315
- attack.t1569.002
1416
- attack.t1574.005

rules/windows/process_creation/proc_creation_win_hktl_winpeas.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@ date: 2022-09-19
1010
modified: 2023-03-23
1111
tags:
1212
- attack.privilege-escalation
13+
- attack.discovery
1314
- attack.t1082
1415
- attack.t1087
1516
- attack.t1046

rules/windows/process_creation/proc_creation_win_regedit_export_critical_keys.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@ date: 2020-10-12
1313
modified: 2024-03-13
1414
tags:
1515
- attack.exfiltration
16+
- attack.discovery
1617
- attack.t1012
1718
logsource:
1819
category: process_creation

rules/windows/process_creation/proc_creation_win_regedit_export_keys.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@ date: 2020-10-07
1313
modified: 2024-03-13
1414
tags:
1515
- attack.exfiltration
16+
- attack.discovery
1617
- attack.t1012
1718
logsource:
1819
category: process_creation

rules/windows/process_creation/proc_creation_win_webshell_chopper.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ author: Florian Roth (Nextron Systems), MSTI (query)
88
date: 2022-10-01
99
tags:
1010
- attack.persistence
11+
- attack.discovery
1112
- attack.t1505.003
1213
- attack.t1018
1314
- attack.t1033

rules/windows/process_creation/proc_creation_win_webshell_hacking.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@ date: 2022-03-17
1010
modified: 2023-11-09
1111
tags:
1212
- attack.persistence
13+
- attack.discovery
1314
- attack.t1505.003
1415
- attack.t1018
1516
- attack.t1033

rules/windows/process_creation/proc_creation_win_webshell_recon_commands_and_processes.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@ date: 2017-01-01
1111
modified: 2024-12-14
1212
tags:
1313
- attack.persistence
14+
- attack.discovery
1415
- attack.t1505.003
1516
- attack.t1018
1617
- attack.t1033

0 commit comments

Comments
 (0)