Update Analytic rule for missing TTPs
This commit is contained in:
Родитель
48183cdeeb
Коммит
82d0448998
|
@ -12,6 +12,10 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- CredentialAccess
|
||||
relevantTechniques:
|
||||
- T1552
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where customProps_RuleId_s == "TRIS0001" and (priority_s == "P1" or priority_s == "P2")
|
||||
|
@ -29,5 +33,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,11 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
relevantTechniques:
|
||||
- T1213
|
||||
- T1530
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where customProps_RuleId_s == "TRIS0002" and (priority_s == "P1" or priority_s == "P2")
|
||||
|
@ -29,5 +34,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,11 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
relevantTechniques:
|
||||
- T1213
|
||||
- T1530
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where customProps_RuleId_s == "TRIS0003" and (priority_s == "P1" or priority_s == "P2")
|
||||
|
@ -29,5 +34,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,11 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
relevantTechniques:
|
||||
- T1213
|
||||
- T1530
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where customProps_RuleId_s == "TRIS0004" and (priority_s == "P1" or priority_s == "P2")
|
||||
|
@ -29,5 +34,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,11 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
relevantTechniques:
|
||||
- T1213
|
||||
- T1530
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where customProps_RuleId_s == "TRIS0005" and (priority_s == "P1" or priority_s == "P2")
|
||||
|
@ -29,5 +34,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,10 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
relevantTechniques:
|
||||
- T1119
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where ( customProps_RuleId_s == "TRIS0007" or customProps_RuleId_s == "TRIS0008" or
|
||||
|
@ -31,5 +35,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,11 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
relevantTechniques:
|
||||
- T1213
|
||||
- T1530
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where customProps_RuleId_s == "TRIS0012" and (priority_s == "P1" or priority_s == "P2")
|
||||
|
@ -29,5 +34,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,11 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
relevantTechniques:
|
||||
- T1213
|
||||
- T1530
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where customProps_RuleId_s == "TRIS0015" and (priority_s == "P1" or priority_s == "P2")
|
||||
|
@ -29,5 +34,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,11 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
relevantTechniques:
|
||||
- T1213
|
||||
- T1530
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where customProps_RuleId_s == "TRIS0018" and (priority_s == "P1" or priority_s == "P2")
|
||||
|
@ -29,5 +34,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,11 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
relevantTechniques:
|
||||
- T1213
|
||||
- T1530
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where customProps_RuleId_s == "TRIS0026" and (priority_s == "P1" or priority_s == "P2")
|
||||
|
@ -29,5 +34,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,11 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
relevantTechniques:
|
||||
- T1560
|
||||
- T1530
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where customProps_RuleId_s == "TRIS0032" and (priority_s == "P1" or priority_s == "P2")
|
||||
|
@ -29,5 +34,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,11 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
relevantTechniques:
|
||||
- T1560
|
||||
- T1530
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where customProps_RuleId_s == "TRIS0032" and (priority_s == "P1" or priority_s == "P2")
|
||||
|
@ -29,5 +34,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,13 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
- PrivilegeEscalation
|
||||
relevantTechniques:
|
||||
- T1560
|
||||
- T1530
|
||||
- T1078
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where customProps_RuleId_s == "TRIS0034" and (priority_s == "P1" or priority_s == "P2")
|
||||
|
@ -29,5 +36,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,11 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
relevantTechniques:
|
||||
- T1560
|
||||
- T1530
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where customProps_RuleId_s == "TRIS0035" and (priority_s == "P1" or priority_s == "P2")
|
||||
|
@ -29,5 +34,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,13 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
- PrivilegeEscalation
|
||||
relevantTechniques:
|
||||
- T1560
|
||||
- T1530
|
||||
- T1078
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where customProps_RuleId_s == "TRIS0036" and (priority_s == "P1" or priority_s == "P2")
|
||||
|
@ -29,5 +36,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,31 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
- CommandAndControl
|
||||
- CredentialAccess
|
||||
- DefenseEvasion
|
||||
- Discovery
|
||||
- Exfiltration
|
||||
- Impact
|
||||
- Reconnaissance
|
||||
relevantTechniques:
|
||||
- T1592
|
||||
- T1589
|
||||
- T1070
|
||||
- T1552
|
||||
- T1619
|
||||
- T1119
|
||||
- T1560
|
||||
- T1530
|
||||
- T1213
|
||||
- T1001
|
||||
- T1041
|
||||
- T1537
|
||||
- T1485
|
||||
- T1486
|
||||
- T1565
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where priority_s == "P1"
|
||||
|
@ -29,5 +54,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.2
|
||||
version: 1.0.3
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,31 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
- CommandAndControl
|
||||
- CredentialAccess
|
||||
- DefenseEvasion
|
||||
- Discovery
|
||||
- Exfiltration
|
||||
- Impact
|
||||
- Reconnaissance
|
||||
relevantTechniques:
|
||||
- T1592
|
||||
- T1589
|
||||
- T1070
|
||||
- T1552
|
||||
- T1619
|
||||
- T1119
|
||||
- T1560
|
||||
- T1530
|
||||
- T1213
|
||||
- T1001
|
||||
- T1041
|
||||
- T1537
|
||||
- T1485
|
||||
- T1486
|
||||
- T1565
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where priority_s == "P2"
|
||||
|
@ -29,5 +54,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,31 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
- CommandAndControl
|
||||
- CredentialAccess
|
||||
- DefenseEvasion
|
||||
- Discovery
|
||||
- Exfiltration
|
||||
- Impact
|
||||
- Reconnaissance
|
||||
relevantTechniques:
|
||||
- T1592
|
||||
- T1589
|
||||
- T1070
|
||||
- T1552
|
||||
- T1619
|
||||
- T1119
|
||||
- T1560
|
||||
- T1530
|
||||
- T1213
|
||||
- T1001
|
||||
- T1041
|
||||
- T1537
|
||||
- T1485
|
||||
- T1486
|
||||
- T1565
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where priority_s == "P5"
|
||||
|
@ -29,5 +54,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,31 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
- CommandAndControl
|
||||
- CredentialAccess
|
||||
- DefenseEvasion
|
||||
- Discovery
|
||||
- Exfiltration
|
||||
- Impact
|
||||
- Reconnaissance
|
||||
relevantTechniques:
|
||||
- T1592
|
||||
- T1589
|
||||
- T1070
|
||||
- T1552
|
||||
- T1619
|
||||
- T1119
|
||||
- T1560
|
||||
- T1530
|
||||
- T1213
|
||||
- T1001
|
||||
- T1041
|
||||
- T1537
|
||||
- T1485
|
||||
- T1486
|
||||
- T1565
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where priority_s == "P4"
|
||||
|
@ -29,5 +54,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
|
@ -12,6 +12,31 @@ queryPeriod: 5m
|
|||
queryFrequency: 5m
|
||||
triggerOperator: gt
|
||||
triggerThreshold: 0
|
||||
tactics:
|
||||
- Collection
|
||||
- CommandAndControl
|
||||
- CredentialAccess
|
||||
- DefenseEvasion
|
||||
- Discovery
|
||||
- Exfiltration
|
||||
- Impact
|
||||
- Reconnaissance
|
||||
relevantTechniques:
|
||||
- T1592
|
||||
- T1589
|
||||
- T1070
|
||||
- T1552
|
||||
- T1619
|
||||
- T1119
|
||||
- T1560
|
||||
- T1530
|
||||
- T1213
|
||||
- T1001
|
||||
- T1041
|
||||
- T1537
|
||||
- T1485
|
||||
- T1486
|
||||
- T1565
|
||||
query: |
|
||||
TheomAlerts_CL
|
||||
| where priority_s == "P3"
|
||||
|
@ -29,5 +54,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: deepLink_s
|
||||
version: 1.0.1
|
||||
version: 1.0.2
|
||||
kind: Scheduled
|
||||
|
|
Загрузка…
Ссылка в новой задаче