Update Analytic rule for missing TTPs

This commit is contained in:
rahul0216 2024-07-25 00:20:49 +05:30
Родитель 48183cdeeb
Коммит 82d0448998
20 изменённых файлов: 222 добавлений и 20 удалений

Просмотреть файл

@ -12,6 +12,10 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- CredentialAccess
relevantTechniques:
- T1552
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0001" and (priority_s == "P1" or priority_s == "P2")
@ -29,5 +33,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,11 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
relevantTechniques:
- T1213
- T1530
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0002" and (priority_s == "P1" or priority_s == "P2")
@ -29,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,11 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
relevantTechniques:
- T1213
- T1530
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0003" and (priority_s == "P1" or priority_s == "P2")
@ -29,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,11 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
relevantTechniques:
- T1213
- T1530
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0004" and (priority_s == "P1" or priority_s == "P2")
@ -29,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,11 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
relevantTechniques:
- T1213
- T1530
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0005" and (priority_s == "P1" or priority_s == "P2")
@ -29,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,10 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
relevantTechniques:
- T1119
query: |
TheomAlerts_CL
| where ( customProps_RuleId_s == "TRIS0007" or customProps_RuleId_s == "TRIS0008" or
@ -31,5 +35,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,11 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
relevantTechniques:
- T1213
- T1530
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0012" and (priority_s == "P1" or priority_s == "P2")
@ -29,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,11 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
relevantTechniques:
- T1213
- T1530
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0015" and (priority_s == "P1" or priority_s == "P2")
@ -29,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,11 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
relevantTechniques:
- T1213
- T1530
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0018" and (priority_s == "P1" or priority_s == "P2")
@ -29,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,11 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
relevantTechniques:
- T1213
- T1530
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0026" and (priority_s == "P1" or priority_s == "P2")
@ -29,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,11 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
relevantTechniques:
- T1560
- T1530
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0032" and (priority_s == "P1" or priority_s == "P2")
@ -29,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,11 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
relevantTechniques:
- T1560
- T1530
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0032" and (priority_s == "P1" or priority_s == "P2")
@ -29,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,13 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
- PrivilegeEscalation
relevantTechniques:
- T1560
- T1530
- T1078
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0034" and (priority_s == "P1" or priority_s == "P2")
@ -29,5 +36,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,11 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
relevantTechniques:
- T1560
- T1530
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0035" and (priority_s == "P1" or priority_s == "P2")
@ -29,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,13 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
- PrivilegeEscalation
relevantTechniques:
- T1560
- T1530
- T1078
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0036" and (priority_s == "P1" or priority_s == "P2")
@ -29,5 +36,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,31 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
- CommandAndControl
- CredentialAccess
- DefenseEvasion
- Discovery
- Exfiltration
- Impact
- Reconnaissance
relevantTechniques:
- T1592
- T1589
- T1070
- T1552
- T1619
- T1119
- T1560
- T1530
- T1213
- T1001
- T1041
- T1537
- T1485
- T1486
- T1565
query: |
TheomAlerts_CL
| where priority_s == "P1"
@ -29,5 +54,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.2
version: 1.0.3
kind: Scheduled

Просмотреть файл

@ -12,6 +12,31 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
- CommandAndControl
- CredentialAccess
- DefenseEvasion
- Discovery
- Exfiltration
- Impact
- Reconnaissance
relevantTechniques:
- T1592
- T1589
- T1070
- T1552
- T1619
- T1119
- T1560
- T1530
- T1213
- T1001
- T1041
- T1537
- T1485
- T1486
- T1565
query: |
TheomAlerts_CL
| where priority_s == "P2"
@ -29,5 +54,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,31 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
- CommandAndControl
- CredentialAccess
- DefenseEvasion
- Discovery
- Exfiltration
- Impact
- Reconnaissance
relevantTechniques:
- T1592
- T1589
- T1070
- T1552
- T1619
- T1119
- T1560
- T1530
- T1213
- T1001
- T1041
- T1537
- T1485
- T1486
- T1565
query: |
TheomAlerts_CL
| where priority_s == "P5"
@ -29,5 +54,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,31 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
- CommandAndControl
- CredentialAccess
- DefenseEvasion
- Discovery
- Exfiltration
- Impact
- Reconnaissance
relevantTechniques:
- T1592
- T1589
- T1070
- T1552
- T1619
- T1119
- T1560
- T1530
- T1213
- T1001
- T1041
- T1537
- T1485
- T1486
- T1565
query: |
TheomAlerts_CL
| where priority_s == "P4"
@ -29,5 +54,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled

Просмотреть файл

@ -12,6 +12,31 @@ queryPeriod: 5m
queryFrequency: 5m
triggerOperator: gt
triggerThreshold: 0
tactics:
- Collection
- CommandAndControl
- CredentialAccess
- DefenseEvasion
- Discovery
- Exfiltration
- Impact
- Reconnaissance
relevantTechniques:
- T1592
- T1589
- T1070
- T1552
- T1619
- T1119
- T1560
- T1530
- T1213
- T1001
- T1041
- T1537
- T1485
- T1486
- T1565
query: |
TheomAlerts_CL
| where priority_s == "P3"
@ -29,5 +54,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: deepLink_s
version: 1.0.1
version: 1.0.2
kind: Scheduled