Azure-Sentinel/Hunting Queries/GitHub
Ajeet Prakash (MSTIC) 16fe6108dd Removed the deprecated MITRE techniques from hunting and detection queries and updating them with the latest ones that seem most appropriate.
TechniqueId      TechniqueName                                                    New
T1483                 Domain Generation Algorithms                         T1568
T1064                 Scripting                                                                  T1059
T1043                 Commonly Used Port                                            T1071
T1065                 Uncommonly Used Port                                       T1571
T1100                 Web Shell                                                                T1505
T1089                 Disabling Security Tools                                       T1562
T1035                 Service Execution                                                  ( Removed totally T1035 without replacement)
T1109                 Component Firmware                                          T1542
T10178                                                                                                T1078
2021-08-12 10:58:18 -07:00
..
First Time User Invite and Add Member to Org.yaml
Inactive or New Account Usage.yaml
Mass Deletion of Repositories .yaml
Oauth App Restrictions Disabled.yaml
Org Repositories Default Permissions Change.yaml
Repository Permission Switched to Public.yaml
Suspicious Fork Activity.yaml
Unusual Number of Repository Clones.yaml
User First Time Repository Delete Activity.yaml
User Grant Access and Grants Other Access.yaml