+Enterprise ATT&CK
---+Password Filter DLL Mitigation
---+Space after Filename Mitigation
---+HISTCONTROL Mitigation
---+Credentials in Files Mitigation
---+Exploitation for Credential Access Mitigation
---+Query Registry Mitigation
---+Login Item Mitigation
---+Setuid and Setgid Mitigation
---+Compiled HTML File Mitigation
---+Data Destruction Mitigation
---+Windows Management Instrumentation Event Subscription Mitigation
---+File System Permissions Weakness Mitigation
---+AppInit DLLs Mitigation
---+Launch Agent Mitigation
---+Network Intrusion Prevention
---+Regsvr32 Mitigation
---+Hidden Users Mitigation
---+Data from Information Repositories Mitigation
---+Exploitation of Remote Services Mitigation
---+Vulnerability Scanning
---+Domain Trust Discovery Mitigation
---+Third-party Software Mitigation
---+Binary Padding Mitigation
---+Audio Capture Mitigation
---+System Owner/User Discovery Mitigation
---+Peripheral Device Discovery Mitigation
---+Clipboard Data Mitigation
---+Gatekeeper Bypass Mitigation
---+Scheduled Transfer Mitigation
---+Browser Bookmark Discovery Mitigation
---+Port Monitors Mitigation
---+Limit Access to Resource Over Network
---+AppleScript Mitigation
---+Indirect Command Execution Mitigation
---+Network Share Discovery Mitigation
---+Remote Data Storage
---+Filter Network Traffic
---+Restrict Web-Based Content
---+Install Root Certificate Mitigation
---+Limit Software Installation
---+Sudo Mitigation
---+Multilayer Encryption Mitigation
---+Transmitted Data Manipulation Mitigation
---+Automated Exfiltration Mitigation
---+Application Window Discovery Mitigation
---+Application Developer Guidance
---+System Firmware Mitigation
---+Data Compressed Mitigation
---+Limit Hardware Installation
---+User Training
---+Data Encrypted Mitigation
---+File and Directory Discovery Mitigation
---+User Account Control
---+Hypervisor Mitigation
---+Plist Modification Mitigation
---+Operating System Configuration
---+Windows Admin Shares Mitigation
---+Winlogon Helper DLL Mitigation
---+Runtime Data Manipulation Mitigation
---+Image File Execution Options Injection Mitigation
---+Process Doppelgänging Mitigation
---+File Deletion Mitigation
---+Exploitation for Defense Evasion Mitigation
---+Email Collection Mitigation
---+Disabling Security Tools Mitigation
---+Data from Removable Media Mitigation
---+Standard Non-Application Layer Protocol Mitigation
---+Control Panel Items Mitigation
---+Pass the Ticket Mitigation
---+Domain Generation Algorithms Mitigation
---+Clear Command History Mitigation
---+Windows Remote Management Mitigation
---+Data Backup
---+Launch Daemon Mitigation
---+Service Stop Mitigation
---+SSH Hijacking Mitigation
---+Data Encrypted for Impact Mitigation
---+Data Staged Mitigation
---+Shared Webroot Mitigation
---+Kernel Modules and Extensions Mitigation
---+Credentials in Registry Mitigation
---+Masquerading Mitigation
---+Web Service Mitigation
---+Resource Hijacking Mitigation
---+Network Sniffing Mitigation
---+Execution Prevention
---+Password Policy Discovery Mitigation
---+Credential Access Protection
---+Brute Force Mitigation
---+Indicator Removal from Tools Mitigation
---+.bash_profile and .bashrc Mitigation
---+Signed Script Proxy Execution Mitigation
---+Multi-Stage Channels Mitigation
---+Fallback Channels Mitigation
---+Screen Capture Mitigation
---+Source Mitigation
---+Remote Desktop Protocol Mitigation
---+LLMNR/NBT-NS Poisoning Mitigation
---+User Execution Mitigation
---+Hardware Additions Mitigation
---+Keychain Mitigation
---+Scripting Mitigation
---+Code Signing
---+Timestomp Mitigation
---+Account Discovery Mitigation
---+Defacement Mitigation
---+Environment Variable Permissions
---+Re-opened Applications Mitigation
---+Netsh Helper DLL Mitigation
---+Domain Fronting Mitigation
---+Data Loss Prevention
---+Network Denial of Service Mitigation
---+Exploit Public-Facing Application Mitigation
---+Component Firmware Mitigation
---+System Network Configuration Discovery Mitigation
---+Indicator Removal on Host Mitigation
---+LC_MAIN Hijacking Mitigation
---+Forced Authentication Mitigation
---+Firmware Corruption Mitigation
---+Privileged Process Integrity
---+Multi-hop Proxy Mitigation
---+XSL Script Processing Mitigation
---+LC_LOAD_DYLIB Addition Mitigation
---+Do Not Mitigate
---+Pre-compromise
---+Trusted Relationship Mitigation
---+DLL Side-Loading Mitigation
---+Drive-by Compromise Mitigation
---+LSASS Driver Mitigation
---+Hooking Mitigation
---+SSL/TLS Inspection
---+Commonly Used Port Mitigation
---+Process Hollowing Mitigation
---+Boot Integrity
---+Data from Local System Mitigation
---+Trap Mitigation
---+Out-of-Band Communications Channel
---+Dynamic Data Exchange Mitigation
---+Endpoint Denial of Service Mitigation
---+System Time Discovery Mitigation
---+Code Signing Mitigation
---+Systemd Service Mitigation
---+Hidden Files and Directories Mitigation
---+Network Segmentation
---+Threat Intelligence Program
---+Input Prompt Mitigation
---+Registry Run Keys / Startup Folder Mitigation
---+Automated Collection Mitigation
---+Rundll32 Mitigation
---+Spearphishing Attachment Mitigation
---+File System Logical Offsets Mitigation
---+Password Policies
---+Behavior Prevention on Endpoint
---+Distributed Component Object Model Mitigation
---+CMSTP Mitigation
---+Exfiltration Over Command and Control Channel Mitigation
---+Exploitation for Privilege Escalation Mitigation
---+Service Registry Permissions Weakness Mitigation
---+User Account Management
---+Authentication Package Mitigation
---+Startup Items Mitigation
---+Network Share Connection Removal Mitigation
---+Man in the Browser Mitigation
---+AppCert DLLs Mitigation
---+Rootkit Mitigation
---+Bootkit Mitigation
---+DLL Search Order Hijacking Mitigation
---+Supply Chain Compromise Mitigation
---+Restrict File and Directory Permissions
---+Create Account Mitigation
---+Remote System Discovery Mitigation
---+Logon Scripts Mitigation
---+Privileged Account Management
---+Screensaver Mitigation
---+Security Support Provider Mitigation
---+Uncommonly Used Port Mitigation
---+Shortcut Modification Mitigation
---+Time Providers Mitigation
---+Restrict Registry Permissions
---+Kerberoasting Mitigation
---+Custom Cryptographic Protocol Mitigation
---+Antivirus/Antimalware
---+Standard Cryptographic Protocol Mitigation
---+Regsvcs/Regasm Mitigation
---+Exfiltration Over Other Network Medium Mitigation
---+Graphical User Interface Mitigation
---+NTFS File Attributes Mitigation
---+Bash History Mitigation
---+Spearphishing Link Mitigation
---+Compile After Delivery Mitigation
---+Credential Dumping Mitigation
---+Remote Access Tools Mitigation
---+Multi-factor Authentication
---+Browser Extensions Mitigation
---+Software Configuration
---+DCShadow Mitigation
---+New Service Mitigation
---+Communication Through Removable Media Mitigation
---+SID-History Injection Mitigation
---+Application Isolation and Sandboxing
---+Data Transfer Size Limits Mitigation
---+Inhibit System Recovery Mitigation
---+Web Shell Mitigation
---+Pass the Hash Mitigation
---+Security Software Discovery Mitigation
---+Bypass User Account Control Mitigation
---+Accessibility Features Mitigation
---+System Network Connections Discovery Mitigation
---+Rc.common Mitigation
---+Local Job Scheduling Mitigation
---+Environmental Keying Mitigation
---+Access Token Manipulation Mitigation
---+System Information Discovery Mitigation
---+Template Injection Mitigation
---+Spearphishing via Service Mitigation
---+Application Deployment Software Mitigation
---+Software Packing Mitigation
---+BITS Jobs Mitigation
---+Extra Window Memory Injection Mitigation
---+Audit
---+Remote File Copy Mitigation
---+Application Shimming Mitigation
---+Execution through Module Load Mitigation
---+Deobfuscate/Decode Files or Information Mitigation
---+PowerShell Mitigation
---+Data Obfuscation Mitigation
---+Network Service Scanning Mitigation
---+Exploit Protection
---+Mshta Mitigation
---+Valid Accounts Mitigation
---+External Remote Services Mitigation
---+Service Execution Mitigation
---+Change Default File Association Mitigation
---+System Service Discovery Mitigation
---+Data from Network Shared Drive Mitigation
---+Video Capture Mitigation
---+Multiband Communication Mitigation
---+Sudo Caching Mitigation
---+Dylib Hijacking Mitigation
---+Permission Groups Discovery Mitigation
---+Path Interception Mitigation
---+Launchctl Mitigation
---+Active Directory Configuration
---+Exfiltration Over Physical Medium Mitigation
---+Update Software
---+Restrict Library Loading
---+Two-Factor Authentication Interception Mitigation
---+Stored Data Manipulation Mitigation
---+Disable or Remove Feature or Program
---+InstallUtil Mitigation
---+Indicator Blocking Mitigation
---+Modify Registry Mitigation
---+SIP and Trust Provider Hijacking Mitigation
---+Replication Through Removable Media Mitigation
---+Taint Shared Content Mitigation
---+Private Keys Mitigation
---+Scheduled Task Mitigation
---+Exploitation for Client Execution Mitigation
---+Custom Command and Control Protocol Mitigation
---+Process Discovery Mitigation
---+Port Knocking Mitigation
---+Redundant Access Mitigation
---+Account Use Policies
---+Hidden Window Mitigation
---+Data Encoding Mitigation
---+Modify Existing Service Mitigation
---+Encrypt Sensitive Information
---+Component Object Model Hijacking Mitigation
---+Analytic 0110
---+Analytic 0613
---+Analytic 0769
---+Analytic 0068
---+Analytic 0887
---+Analytic 0061
---+Analytic 1421
---+Analytic 0295
---+Analytic 0534
---+Analytic 0010
---+Analytic 0491
---+Analytic 1104
---+Analytic 1112
---+Analytic 1532
---+Analytic 0417
---+Analytic 0726
---+Analytic 0469
---+Analytic 0053
---+Analytic 0860
---+Analytic 0876
---+Analytic 0595
---+Analytic 0656
---+Analytic 1063
---+Analytic 1079
---+Analytic 1503
---+Analytic 0036
---+Analytic 0856
---+Analytic 0736
---+Analytic 0296
---+Analytic 1531
---+Analytic 1115
---+Analytic 0530
---+Analytic 1365
---+Analytic 0008
---+Analytic 1488
---+Analytic 1473
---+Analytic 0867
---+Analytic 1061
---+Analytic 0679
---+Analytic 0809
---+Analytic 0771
---+Analytic 1209
---+Analytic 0478
---+Analytic 1251
---+Analytic 0447
---+Analytic 1007
---+Analytic 0075
---+Analytic 0032
---+Analytic 0121
---+Analytic 1339
---+Analytic 0437
---+Analytic 1987
---+Analytic 0699
---+Analytic 1187
---+Analytic 1291
---+Analytic 0917
---+Analytic 0797
---+Analytic 0224
---+Analytic 0834
---+Analytic 1427
---+Analytic 1976
---+Analytic 1619
---+Analytic 1247
---+Analytic 1132
---+Analytic 0817
---+Analytic 0145
---+Analytic 0308
---+Analytic 0211
---+Analytic 1037
---+Analytic 1023
---+Analytic 1448
---+Analytic 1090
---+Analytic 0997
---+Analytic 1143
---+Analytic 0775
---+Analytic 0928
---+Analytic 1965
---+Analytic 1244
---+Analytic 1253
---+Analytic 1089
---+Analytic 0256
---+Analytic 1628
---+Analytic 2030
---+Analytic 0142
---+Analytic 0192
---+Analytic 0184
---+Analytic 0046
---+Analytic 1211
---+Analytic 0732
---+Analytic 1074
---+Analytic 0459
---+Analytic 1165
---+Analytic 0496
---+Analytic 0892
---+Analytic 0134
---+Analytic 0871
---+Analytic 0147
---+Analytic 0244
---+Analytic 1204
---+Analytic 1357
---+Analytic 1566
---+Analytic 0925
---+Analytic 1995
---+Analytic 0872
---+Analytic 0969
---+Analytic 0197
---+Analytic 0665
---+Analytic 0239
---+Analytic 1229
---+Analytic 0034
---+Analytic 0266
---+Analytic 0467
---+Analytic 1156
---+Analytic 1434
---+Analytic 1567
---+Analytic 0023
---+Analytic 1460
---+Analytic 0868
---+Analytic 0312
---+Analytic 0791
---+Analytic 1499
---+Analytic 1093
---+Analytic 1179
---+Analytic 0027
---+Analytic 0805
---+Analytic 2006
---+Analytic 0209
---+Analytic 1207
---+Analytic 1176
---+Analytic 1960
---+Analytic 1621
---+Analytic 0884
---+Analytic 0103
---+Analytic 0396
---+Analytic 0466
---+Analytic 0904
---+Analytic 0081
---+Analytic 0602
---+Analytic 0549
---+Analytic 1119
---+Analytic 0130
---+Analytic 1125
---+Analytic 1134
---+Analytic 0975
---+Analytic 0410
---+Analytic 0982
---+Analytic 1193
---+Analytic 0203
---+Analytic 0372
---+Analytic 1020
---+Analytic 0178
---+Analytic 1085
---+Analytic 0841
---+Analytic 0458
---+Analytic 0794
---+Analytic 0959
---+Analytic 0004
---+Analytic 1420
---+Analytic 0934
---+Analytic 1525
---+Analytic 0705
---+Analytic 0837
---+Analytic 1094
---+Analytic 0164
---+Analytic 0284
---+Analytic 1522
---+Analytic 1216
---+Analytic 1017
---+Analytic 0676
---+Analytic 0195
---+Analytic 1006
---+Analytic 0367
---+Analytic 0765
---+Analytic 1435
---+Analytic 1455
---+Analytic 0045
---+Analytic 1170
---+Analytic 0568
---+Analytic 0219
---+Analytic 0394
---+Analytic 2026
---+Analytic 1031
---+Analytic 1514
---+Analytic 0329
---+Analytic 1437
---+Analytic 0855
---+Analytic 0223
---+Analytic 0782
---+Analytic 0963
---+Analytic 1641
---+Analytic 1417
---+Analytic 0731
---+Analytic 0833
---+Analytic 1595
---+Analytic 0652
---+Analytic 1940
---+Analytic 1356
---+Analytic 0342
---+Analytic 1129
---+Analytic 0236
---+Analytic 0107
---+Analytic 0688
---+Analytic 1468
---+Analytic 1215
---+Analytic 1158
---+Analytic 0537
---+Analytic 0377
---+Analytic 2063
---+Analytic 1623
---+Analytic 1969
---+Analytic 1269
---+Analytic 0348
---+Analytic 0057
---+Analytic 1640
---+Analytic 1036
---+Analytic 1066
---+Analytic 1629
---+Analytic 1611
---+Analytic 1554
---+Analytic 0716
---+Analytic 1526
---+Analytic 1360
---+Analytic 1064
---+Analytic 0150
---+Analytic 0596
---+Analytic 0101
---+Analytic 0079
---+Analytic 1281
---+Analytic 1008
---+Analytic 1555
---+Analytic 0521
---+Analytic 1305
---+Analytic 1971
---+Analytic 0409
---+Analytic 1396
---+Analytic 0386
---+Analytic 0605
---+Analytic 0378
---+Analytic 1326
---+Analytic 0291
---+Analytic 1478
---+Analytic 0980
---+Analytic 1416
---+Analytic 0958
---+Analytic 0941
---+Analytic 1183
---+Analytic 1565
---+Analytic 0698
---+Analytic 0795
---+Analytic 0263
---+Analytic 1333
---+Analytic 1592
---+Analytic 0842
---+Analytic 0500
---+Analytic 1948
---+Analytic 1025
---+Analytic 0557
---+Analytic 1106
---+Analytic 2007
---+Analytic 1268
---+Analytic 0968
---+Analytic 1027
---+Analytic 1944
---+Analytic 1021
---+Analytic 0838
---+Analytic 0609
---+Analytic 1614
---+Analytic 0517
---+Analytic 1963
---+Analytic 1265
---+Analytic 0796
---+Analytic 0432
---+Analytic 0879
---+Analytic 2062
---+Analytic 1051
---+Analytic 0322
---+Analytic 0735
---+Analytic 1418
---+Analytic 1224
---+Analytic 1138
---+Analytic 0822
---+Analytic 1154
---+Analytic 0227
---+Analytic 0486
---+Analytic 0100
---+Analytic 0727
---+Analytic 0672
---+Analytic 1249
---+Analytic 1497
---+Analytic 1058
---+Analytic 1407
---+Analytic 0196
---+Analytic 0988
---+Analytic 1048
---+Analytic 1059
---+Analytic 0650
---+Analytic 0531
---+Analytic 1245
---+Analytic 0351
---+Analytic 0763
---+Analytic 2032
---+Analytic 0190
---+Analytic 1465
---+Analytic 2004
---+Analytic 0889
---+Analytic 1556
---+Analytic 1422
---+Analytic 0070
---+Analytic 1084
---+Analytic 0913
---+Analytic 1030
---+Analytic 1337
---+Analytic 2044
---+Analytic 0397
---+Analytic 0632
---+Analytic 1200
---+Analytic 0304
---+Analytic 0451
---+Analytic 1385
---+Analytic 0337
---+Analytic 0473
---+Analytic 1201
---+Analytic 0540
---+Analytic 1308
---+Analytic 0571
---+Analytic 1146
---+Analytic 0999
---+Analytic 0493
---+Analytic 0514
---+Analytic 0512
---+Analytic 0433
---+Analytic 0626
---+Analytic 0163
---+Analytic 1449
---+Analytic 2005
---+Analytic 1107
---+Analytic 0522
---+Analytic 0758
---+Analytic 0851
---+Analytic 1533
---+Analytic 0939
---+Analytic 1537
---+Analytic 1312
---+Analytic 0083
---+Analytic 1287
---+Analytic 0484
---+Analytic 0545
---+Analytic 0873
---+Analytic 1552
---+Analytic 0584
---+Analytic 0877
---+Analytic 1351
---+Analytic 0042
---+Analytic 0501
---+Analytic 0112
---+Analytic 0356
---+Analytic 1114
---+Analytic 1009
---+Analytic 0314
---+Analytic 1174
---+Analytic 0664
---+Analytic 0819
---+Analytic 0202
---+Analytic 0499
---+Analytic 1214
---+Analytic 0015
---+Analytic 0330
---+Analytic 0407
---+Analytic 0013
---+Analytic 2061
---+Analytic 0259
---+Analytic 1399
---+Analytic 0544
---+Analytic 1604
---+Analytic 1026
---+Analytic 0814
---+Analytic 0827
---+Analytic 0686
---+Analytic 0750
---+Analytic 0518
---+Analytic 0770
---+Analytic 0710
---+Analytic 1272
---+Analytic 0149
---+Analytic 0039
---+Analytic 0498
---+Analytic 1517
---+Analytic 1485
---+Analytic 0082
---+Analytic 1246
---+Analytic 1166
---+Analytic 0090
---+Analytic 2059
---+Analytic 0141
---+Analytic 0069
---+Analytic 1162
---+Analytic 0956
---+Analytic 0294
---+Analytic 1338
---+Analytic 1570
---+Analytic 0439
---+Analytic 1501
---+Analytic 0371
---+Analytic 0078
---+Analytic 0966
---+Analytic 1203
---+Analytic 1580
---+Analytic 0408
---+Analytic 0049
---+Analytic 1352
---+Analytic 1002
---+Analytic 1217
---+Analytic 1319
---+Analytic 0477
---+Analytic 0844
---+Analytic 0623
---+Analytic 0547
---+Analytic 1494
---+Analytic 1610
---+Analytic 1317
---+Analytic 0170
---+Analytic 0620
---+Analytic 0938
---+Analytic 0059
---+Analytic 0132
---+Analytic 1429
---+Analytic 0604
---+Analytic 0313
---+Analytic 1937
---+Analytic 1442
---+Analytic 1364
---+Analytic 0216
---+Analytic 2060
---+Analytic 0067
---+Analytic 0418
---+Analytic 1103
---+Analytic 1381
---+Analytic 0824
---+Analytic 1952
---+Analytic 1088
---+Analytic 0429
---+Analytic 0362
---+Analytic 0399
---+Analytic 1157
---+Analytic 0228
---+Analytic 1500
---+Analytic 1186
---+Analytic 1378
---+Analytic 1065
---+Analytic 0030
---+Analytic 0678
---+Analytic 0171
---+Analytic 0807
---+Analytic 0003
---+Analytic 1992
---+Analytic 0542
---+Analytic 0733
---+Analytic 1300
---+Analytic 0494
---+Analytic 1359
---+Analytic 1213
---+Analytic 0395
---+Analytic 0180
---+Analytic 1151
---+Analytic 1404
---+Analytic 1457
---+Analytic 1121
---+Analytic 0757
---+Analytic 0972
---+Analytic 2012
---+Analytic 0124
---+Analytic 0128
---+Analytic 0315
---+Analytic 0567
---+Analytic 1959
---+Analytic 0556
---+Analytic 0900
---+Analytic 1042
---+Analytic 1123
---+Analytic 0208
---+Analytic 0708
---+Analytic 1052
---+Analytic 0381
---+Analytic 0776
---+Analytic 1991
---+Analytic 1410
---+Analytic 0526
---+Analytic 1195
---+Analytic 2008
---+Analytic 1966
---+Analytic 1254
---+Analytic 0520
---+Analytic 1208
---+Analytic 1289
---+Analytic 0577
---+Analytic 0572
---+Analytic 1142
---+Analytic 1636
---+Analytic 1490
---+Analytic 1237
---+Analytic 1415
---+Analytic 1344
---+Analytic 0985
---+Analytic 0191
---+Analytic 0587
---+Analytic 1256
---+Analytic 1325
---+Analytic 1626
---+Analytic 1349
---+Analytic 0155
---+Analytic 0539
---+Analytic 1355
---+Analytic 2041
---+Analytic 0306
---+Analytic 0553
---+Analytic 1970
---+Analytic 0250
---+Analytic 0085
---+Analytic 1450
---+Analytic 0965
---+Analytic 1221
---+Analytic 1155
---+Analytic 1583
---+Analytic 1301
---+Analytic 1430
---+Analytic 0038
---+Analytic 1113
---+Analytic 1267
---+Analytic 0799
---+Analytic 0374
---+Analytic 0444
---+Analytic 1152
---+Analytic 1569
---+Analytic 0280
---+Analytic 0440
---+Analytic 1949
---+Analytic 1979
---+Analytic 0597
---+Analytic 0364
---+Analytic 1126
---+Analytic 0747
---+Analytic 0691
---+Analytic 0878
---+Analytic 0694
---+Analytic 0031
---+Analytic 0702
---+Analytic 0911
---+Analytic 0354
---+Analytic 0701
---+Analytic 0193
---+Analytic 1014
---+Analytic 1986
---+Analytic 1549
---+Analytic 0343
---+Analytic 0636
---+Analytic 1994
---+Analytic 1235
---+Analytic 1389
---+Analytic 0787
---+Analytic 0091
---+Analytic 0953
---+Analytic 1330
---+Analytic 0749
---+Analytic 1956
---+Analytic 0108
---+Analytic 1309
---+Analytic 1292
---+Analytic 1321
---+Analytic 0973
---+Analytic 1071
---+Analytic 0457
---+Analytic 0237
---+Analytic 0703
---+Analytic 0403
---+Analytic 1572
---+Analytic 0629
---+Analytic 0785
---+Analytic 2002
---+Analytic 0324
---+Analytic 1320
---+Analytic 0136
---+Analytic 0054
---+Analytic 1538
---+Analytic 0056
---+Analytic 1521
---+Analytic 1578
---+Analytic 1083
---+Analytic 1411
---+Analytic 0402
---+Analytic 1523
---+Analytic 1431
---+Analytic 1573
---+Analytic 0828
---+Analytic 0902
---+Analytic 1548
---+Analytic 0639
---+Analytic 1034
---+Analytic 1401
---+Analytic 0680
---+Analytic 0697
---+Analytic 2037
---+Analytic 1452
---+Analytic 0996
---+Analytic 1000
---+Analytic 0783
---+Analytic 1529
---+Analytic 1466
---+Analytic 0272
---+Analytic 0630
---+Analytic 0127
---+Analytic 0936
---+Analytic 1510
---+Analytic 0158
---+Analytic 0253
---+Analytic 0724
---+Analytic 1322
---+Analytic 0167
---+Analytic 2000
---+Analytic 1982
---+Analytic 0508
---+Analytic 1383
---+Analytic 1199
---+Analytic 1491
---+Analytic 0829
---+Analytic 1560
---+Analytic 1519
---+Analytic 0606
---+Analytic 1953
---+Analytic 0113
---+Analytic 0790
---+Analytic 0865
---+Analytic 0647
---+Analytic 1210
---+Analytic 0174
---+Analytic 0102
---+Analytic 0096
---+Analytic 1117
---+Analytic 0275
---+Analytic 1161
---+Analytic 0214
---+Analytic 1189
---+Analytic 0648
---+Analytic 1181
---+Analytic 0515
---+Analytic 0480
---+Analytic 0325
---+Analytic 0619
---+Analytic 1484
---+Analytic 0475
---+Analytic 0122
---+Analytic 1222
---+Analytic 0213
---+Analytic 0187
---+Analytic 1182
---+Analytic 0443
---+Analytic 0820
---+Analytic 1942
---+Analytic 0268
---+Analytic 0419
---+Analytic 0793
---+Analytic 1588
---+Analytic 0502
---+Analytic 1602
---+Analytic 0254
---+Analytic 0420
---+Analytic 1372
---+Analytic 0690
---+Analytic 0286
---+Analytic 1615
---+Analytic 1060
---+Analytic 0384
---+Analytic 1467
---+Analytic 0413
---+Analytic 1406
---+Analytic 0111
---+Analytic 0151
---+Analytic 1534
---+Analytic 1379
---+Analytic 0993
---+Analytic 0188
---+Analytic 1092
---+Analytic 0347
---+Analytic 1336
---+Analytic 0981
---+Analytic 1506
---+Analytic 0586
---+Analytic 1078
---+Analytic 0874
---+Analytic 0510
---+Analytic 0077
---+Analytic 0234
---+Analytic 1001
---+Analytic 1581
---+Analytic 0578
---+Analytic 0427
---+Analytic 0983
---+Analytic 1400
---+Analytic 1240
---+Analytic 0503
---+Analytic 1520
---+Analytic 0267
---+Analytic 0580
---+Analytic 2065
---+Analytic 1609
---+Analytic 0185
---+Analytic 1172
---+Analytic 0139
---+Analytic 0673
---+Analytic 0095
---+Analytic 0784
---+Analytic 1062
---+Analytic 0166
---+Analytic 1019
---+Analytic 0309
---+Analytic 1627
---+Analytic 1004
---+Analytic 0905
---+Analytic 0026
---+Analytic 0978
---+Analytic 0246
---+Analytic 0780
---+Analytic 1180
---+Analytic 0668
---+Analytic 0931
---+Analytic 1472
---+Analytic 1483
---+Analytic 0162
---+Analytic 1981
---+Analytic 0779
---+Analytic 0756
---+Analytic 1553
---+Analytic 1508
---+Analytic 1316
---+Analytic 1955
---+Analytic 1462
---+Analytic 0778
---+Analytic 0210
---+Analytic 0899
---+Analytic 0319
---+Analytic 0541
---+Analytic 1108
---+Analytic 1069
---+Analytic 0160
---+Analytic 1147
---+Analytic 0349
---+Analytic 1622
---+Analytic 0616
---+Analytic 0311
---+Analytic 1574
---+Analytic 1443
---+Analytic 1413
---+Analytic 1258
---+Analytic 2024
---+Analytic 0989
---+Analytic 0358
---+Analytic 0660
---+Analytic 0198
---+Analytic 1040
---+Analytic 0560
---+Analytic 0060
---+Analytic 1477
---+Analytic 1540
---+Analytic 0094
---+Analytic 1498
---+Analytic 1219
---+Analytic 0850
---+Analytic 1335
---+Analytic 1544
---+Analytic 0199
---+Analytic 0285
---+Analytic 1190
---+Analytic 0746
---+Analytic 1033
---+Analytic 1375
---+Analytic 0608
---+Analytic 0920
---+Analytic 0916
---+Analytic 1984
---+Analytic 0248
---+Analytic 0274
---+Analytic 1487
---+Analytic 1438
---+Analytic 0846
---+Analytic 0588
---+Analytic 2043
---+Analytic 0400
---+Analytic 1341
---+Analytic 0535
---+Analytic 1997
---+Analytic 0897
---+Analytic 0532
---+Analytic 0944
---+Analytic 0328
---+Analytic 1424
---+Analytic 1951
---+Analytic 1591
---+Analytic 0465
---+Analytic 0225
---+Analytic 1218
---+Analytic 0137
---+Analytic 1145
---+Analytic 1277
---+Analytic 0350
---+Analytic 0093
---+Analytic 0255
---+Analytic 0086
---+Analytic 0368
---+Analytic 0269
---+Analytic 1943
---+Analytic 0554
---+Analytic 0005
---+Analytic 0591
---+Analytic 1299
---+Analytic 0825
---+Analytic 0573
---+Analytic 0281
---+Analytic 0685
---+Analytic 0200
---+Analytic 0154
---+Analytic 0722
---+Analytic 0767
---+Analytic 0316
---+Analytic 2022
---+Analytic 0813
---+Analytic 0416
---+Analytic 1559
---+Analytic 1382
---+Analytic 0288
---+Analytic 0715
---+Analytic 0812
---+Analytic 1482
---+Analytic 1637
---+Analytic 1550
---+Analytic 1290
---+Analytic 0947
---+Analytic 0382
---+Analytic 1447
---+Analytic 0635
---+Analytic 0919
---+Analytic 0471
---+Analytic 1423
---+Analytic 1252
---+Analytic 0720
---+Analytic 0229
---+Analytic 0317
---+Analytic 0411
---+Analytic 0745
---+Analytic 0243
---+Analytic 1607
---+Analytic 1118
---+Analytic 0942
---+Analytic 0910
---+Analytic 0561
---+Analytic 0144
---+Analytic 1070
---+Analytic 0283
---+Analytic 1283
---+Analytic 0682
---+Analytic 1493
---+Analytic 0657
---+Analytic 1463
---+Analytic 1471
---+Analytic 0607
---+Analytic 1492
---+Analytic 1613
---+Analytic 0479
---+Analytic 0692
---+Analytic 0847
---+Analytic 0663
---+Analytic 0485
---+Analytic 1096
---+Analytic 1131
---+Analytic 0843
---+Analytic 0373
---+Analytic 1346
---+Analytic 0895
---+Analytic 0504
---+Analytic 0040
---+Analytic 0109
---+Analytic 0334
---+Analytic 0742
---+Analytic 1255
---+Analytic 0017
---+Analytic 0689
---+Analytic 0492
---+Analytic 1160
---+Analytic 0098
---+Analytic 1496
---+Analytic 0326
---+Analytic 1177
---+Analytic 1331
---+Analytic 1010
---+Analytic 0357
---+Analytic 2038
---+Analytic 0428
---+Analytic 0361
---+Analytic 0194
---+Analytic 0293
---+Analytic 1486
---+Analytic 0205
---+Analytic 1369
---+Analytic 0957
---+Analytic 0857
---+Analytic 1459
---+Analytic 0454
---+Analytic 0896
---+Analytic 1551
---+Analytic 0097
---+Analytic 0880
---+Analytic 0761
---+Analytic 1585
---+Analytic 0654
---+Analytic 2018
---+Analytic 0816
---+Analytic 0182
---+Analytic 0759
---+Analytic 0072
---+Analytic 2017
---+Analytic 0687
---+Analytic 0218
---+Analytic 0287
---+Analytic 1511
---+Analytic 0548
---+Analytic 0186
---+Analytic 0115
---+Analytic 0614
---+Analytic 1968
---+Analytic 1329
---+Analytic 0450
---+Analytic 1273
---+Analytic 0627
---+Analytic 0649
---+Analytic 0426
---+Analytic 1446
---+Analytic 1297
---+Analytic 0422
---+Analytic 1120
---+Analytic 0992
---+Analytic 0412
---+Analytic 0114
---+Analytic 0231
---+Analytic 1057
---+Analytic 0265
---+Analytic 0126
---+Analytic 1288
---+Analytic 0558
---+Analytic 1476
---+Analytic 1454
---+Analytic 1436
---+Analytic 0773
---+Analytic 0006
---+Analytic 1967
---+Analytic 0345
---+Analytic 1599
---+Analytic 0552
---+Analytic 0226
---+Analytic 1168
---+Analytic 0482
---+Analytic 2013
---+Analytic 0864
---+Analytic 0575
---+Analytic 0441
---+Analytic 0063
---+Analytic 1481
---+Analytic 1055
---+Analytic 1950
---+Analytic 0393
---+Analytic 1586
---+Analytic 0143
---+Analytic 1941
---+Analytic 1635
---+Analytic 0951
---+Analytic 0675
---+Analytic 1194
---+Analytic 1386
---+Analytic 0589
---+Analytic 0832
---+Analytic 0340
---+Analytic 0389
---+Analytic 1332
---+Analytic 0513
---+Analytic 0754
---+Analytic 1512
---+Analytic 1989
---+Analytic 0806
---+Analytic 0628
---+Analytic 2003
---+Analytic 0230
---+Analytic 1035
---+Analytic 0489
---+Analytic 0264
---+Analytic 1077
---+Analytic 0401
---+Analytic 0235
---+Analytic 0962
---+Analytic 0260
---+Analytic 0743
---+Analytic 1307
---+Analytic 0601
---+Analytic 0201
---+Analytic 1280
---+Analytic 0181
---+Analytic 1271
---+Analytic 0370
---+Analytic 0802
---+Analytic 0744
---+Analytic 1479
---+Analytic 1558
---+Analytic 0363
---+Analytic 1327
---+Analytic 0599
---+Analytic 0707
---+Analytic 0387
---+Analytic 0921
---+Analytic 0051
---+Analytic 1192
---+Analytic 0505
---+Analytic 0346
---+Analytic 1225
---+Analytic 0976
---+Analytic 0748
---+Analytic 0366
---+Analytic 0908
---+Analytic 0960
---+Analytic 1405
---+Analytic 1557
---+Analytic 0468
---+Analytic 2025
---+Analytic 1603
---+Analytic 1489
---+Analytic 0594
---+Analytic 0669
---+Analytic 0025
---+Analytic 1983
---+Analytic 1148
---+Analytic 0241
---+Analytic 0421
---+Analytic 1642
---+Analytic 0024
---+Analytic 1248
---+Analytic 0667
---+Analytic 0156
---+Analytic 0979
---+Analytic 1050
---+Analytic 0625
---+Analytic 0404
---+Analytic 1263
---+Analytic 0592
---+Analytic 0804
---+Analytic 0529
---+Analytic 1475
---+Analytic 0644
---+Analytic 2027
---+Analytic 1286
---+Analytic 0998
---+Analytic 0723
---+Analytic 1067
---+Analytic 1985
---+Analytic 0543
---+Analytic 1978
---+Analytic 1368
---+Analytic 0028
---+Analytic 2035
---+Analytic 2010
---+Analytic 1226
---+Analytic 1631
---+Analytic 0436
---+Analytic 0945
---+Analytic 0462
---+Analytic 0700
---+Analytic 0729
---+Analytic 0658
---+Analytic 0738
---+Analytic 0434
---+Analytic 0922
---+Analytic 1408
---+Analytic 1039
---+Analytic 0923
---+Analytic 0483
---+Analytic 1575
---+Analytic 1632
---+Analytic 1576
---+Analytic 1412
---+Analytic 0138
---+Analytic 0950
---+Analytic 1403
---+Analytic 1137
---+Analytic 0859
---+Analytic 1173
---+Analytic 1542
---+Analytic 1639
---+Analytic 0940
---+Analytic 0617
---+Analytic 1150
---+Analytic 1954
---+Analytic 1605
---+Analytic 0050
---+Analytic 0618
---+Analytic 1313
---+Analytic 2040
---+Analytic 1432
---+Analytic 0157
---+Analytic 0064
---+Analytic 1109
---+Analytic 0022
---+Analytic 1371
---+Analytic 1171
---+Analytic 0415
---+Analytic 0633
---+Analytic 2019
---+Analytic 0088
---+Analytic 2023
---+Analytic 0021
---+Analytic 0431
---+Analytic 0576
---+Analytic 0615
---+Analytic 1303
---+Analytic 0536
---+Analytic 1298
---+Analytic 1972
---+Analytic 1425
---+Analytic 1095
---+Analytic 0258
---+Analytic 1130
---+Analytic 0551
---+Analytic 0376
---+Analytic 0810
---+Analytic 0474
---+Analytic 1279
---+Analytic 1102
---+Analytic 0435
---+Analytic 1414
---+Analytic 1212
---+Analytic 1260
---+Analytic 0380
---+Analytic 0273
---+Analytic 2064
---+Analytic 0751
---+Analytic 0298
---+Analytic 1005
---+Analytic 1387
---+Analytic 1296
---+Analytic 1072
---+Analytic 0220
---+Analytic 1377
---+Analytic 0772
---+Analytic 0058
---+Analytic 0222
---+Analytic 1220
---+Analytic 0257
---+Analytic 1028
---+Analytic 1388
---+Analytic 0318
---+Analytic 2016
---+Analytic 0153
---+Analytic 0881
---+Analytic 1164
---+Analytic 1024
---+Analytic 1480
---+Analytic 1315
---+Analytic 1571
---+Analytic 0331
---+Analytic 0801
---+Analytic 0741
---+Analytic 1233
---+Analytic 0894
---+Analytic 0645
---+Analytic 0948
---+Analytic 0971
---+Analytic 1285
---+Analytic 0481
---+Analytic 0335
---+Analytic 0970
---+Analytic 0176
---+Analytic 1353
---+Analytic 0538
---+Analytic 1939
---+Analytic 1099
---+Analytic 0764
---+Analytic 1546
---+Analytic 1015
---+Analytic 1433
---+Analytic 1231
---+Analytic 1587
---+Analytic 1043
---+Analytic 0161
---+Analytic 1111
---+Analytic 0177
---+Analytic 1993
---+Analytic 0967
---+Analytic 1029
---+Analytic 1239
---+Analytic 1505
---+Analytic 1998
---+Analytic 0891
---+Analytic 1451
---+Analytic 0344
---+Analytic 2031
---+Analytic 0964
---+Analytic 0424
---+Analytic 0336
---+Analytic 1167
---+Analytic 0984
---+Analytic 1105
---+Analytic 0932
---+Analytic 1958
---+Analytic 1311
---+Analytic 0455
---+Analytic 1358
---+Analytic 0379
---+Analytic 0734
---+Analytic 0339
---+Analytic 0674
---+Analytic 1380
---+Analytic 1625
---+Analytic 0175
---+Analytic 1191
---+Analytic 1419
---+Analytic 0661
---+Analytic 0084
---+Analytic 1946
---+Analytic 0129
---+Analytic 0300
---+Analytic 0961
---+Analytic 0392
---+Analytic 0011
---+Analytic 0721
---+Analytic 0603
---+Analytic 1470
---+Analytic 1278
---+Analytic 0247
---+Analytic 0875
---+Analytic 0670
---+Analytic 0798
---+Analytic 0360
---+Analytic 0523
---+Analytic 0278
---+Analytic 1495
---+Analytic 0566
---+Analytic 1439
---+Analytic 0125
---+Analytic 1041
---+Analytic 0974
---+Analytic 1596
---+Analytic 0883
---+Analytic 1964
---+Analytic 1350
---+Analytic 0148
---+Analytic 0643
---+Analytic 0425
---+Analytic 1568
---+Analytic 0800
---+Analytic 0863
---+Analytic 1579
---+Analytic 2029
---+Analytic 1324
---+Analytic 1238
---+Analytic 0585
---+Analytic 0391
---+Analytic 1561
---+Analytic 0506
---+Analytic 0087
---+Analytic 0927
---+Analytic 1242
---+Analytic 0762
---+Analytic 1230
---+Analytic 1022
---+Analytic 0681
---+Analytic 0943
---+Analytic 1366
---+Analytic 1310
---+Analytic 0994
---+Analytic 0338
---+Analytic 1980
---+Analytic 1159
---+Analytic 0310
---+Analytic 0495
---+Analytic 0826
---+Analytic 0249
---+Analytic 0696
---+Analytic 0290
---+Analytic 0624
---+Analytic 0009
---+Analytic 0179
---+Analytic 1302
---+Analytic 0926
---+Analytic 1391
---+Analytic 0173
---+Analytic 1076
---+Analytic 1638
---+Analytic 1294
---+Analytic 0456
---+Analytic 0430
---+Analytic 0666
---+Analytic 0014
---+Analytic 1370
---+Analytic 1016
---+Analytic 0929
---+Analytic 0574
---+Analytic 1594
---+Analytic 0848
---+Analytic 1044
---+Analytic 1620
---+Analytic 1169
---+Analytic 0818
---+Analytic 0152
---+Analytic 1293
---+Analytic 0089
---+Analytic 1241
---+Analytic 1202
---+Analytic 1962
---+Analytic 0232
---+Analytic 0390
---+Analytic 0383
---+Analytic 1474
---+Analytic 1097
---+Analytic 1445
---+Analytic 1100
---+Analytic 1444
---+Analytic 1056
---+Analytic 1101
---+Analytic 0525
---+Analytic 0823
---+Analytic 0463
---+Analytic 0207
---+Analytic 1243
---+Analytic 0341
---+Analytic 0037
---+Analytic 1306
---+Analytic 1227
---+Analytic 0693
---+Analytic 1340
---+Analytic 1398
---+Analytic 0016
---+Analytic 0092
---+Analytic 0131
---+Analytic 0671
---+Analytic 1197
---+Analytic 0768
---+Analytic 1617
---+Analytic 1343
---+Analytic 0786
---+Analytic 0105
---+Analytic 1441
---+Analytic 1228
---+Analytic 0684
---+Analytic 1348
---+Analytic 0369
---+Analytic 1630
---+Analytic 1081
---+Analytic 0725
---+Analytic 0189
---+Analytic 0206
---+Analytic 0907
---+Analytic 1562
---+Analytic 0080
---+Analytic 0116
---+Analytic 0414
---+Analytic 2039
---+Analytic 0712
---+Analytic 1149
---+Analytic 1988
---+Analytic 1961
---+Analytic 0271
---+Analytic 0590
---+Analytic 0490
---+Analytic 1047
---+Analytic 0307
---+Analytic 1284
---+Analytic 0320
---+Analytic 1259
---+Analytic 0019
---+Analytic 0918
---+Analytic 0808
---+Analytic 1354
---+Analytic 0183
---+Analytic 0169
---+Analytic 1590
---+Analytic 0472
---+Analytic 1598
---+Analytic 1624
---+Analytic 0986
---+Analytic 0861
---+Analytic 2001
---+Analytic 0204
---+Analytic 0497
---+Analytic 0683
---+Analytic 1003
---+Analytic 1395
---+Analytic 1257
---+Analytic 1616
---+Analytic 0305
---+Analytic 0562
---+Analytic 0076
---+Analytic 1276
---+Analytic 0052
---+Analytic 1122
---+Analytic 2011
---+Analytic 0739
---+Analytic 0119
---+Analytic 0924
---+Analytic 0641
---+Analytic 1323
---+Analytic 0516
---+Analytic 1282
---+Analytic 1363
---+Analytic 0251
---+Analytic 0276
---+Analytic 1012
---+Analytic 0212
---+Analytic 1938
---+Analytic 2009
---+Analytic 0789
---+Analytic 0301
---+Analytic 0839
---+Analytic 1266
---+Analytic 1342
---+Analytic 0135
---+Analytic 0662
---+Analytic 0120
---+Analytic 1545
---+Analytic 1541
---+Analytic 0546
---+Analytic 0048
---+Analytic 0885
---+Analytic 0598
---+Analytic 0507
---+Analytic 0987
---+Analytic 0470
---+Analytic 0882
---+Analytic 1144
---+Analytic 1038
---+Analytic 0718
---+Analytic 1582
---+Analytic 0869
---+Analytic 0527
---+Analytic 0261
---+Analytic 0423
---+Analytic 0890
---+Analytic 1295
---+Analytic 1530
---+Analytic 0292
---+Analytic 0849
---+Analytic 0303
---+Analytic 0033
---+Analytic 0811
---+Analytic 0583
---+Analytic 1011
---+Analytic 0906
---+Analytic 0385
---+Analytic 1513
---+Analytic 1601
---+Analytic 1223
---+Analytic 2015
---+Analytic 1509
---+Analytic 1196
---+Analytic 0104
---+Analytic 1045
---+Analytic 0352
---+Analytic 1234
---+Analytic 1139
---+Analytic 1456
---+Analytic 0912
---+Analytic 0488
---+Analytic 1608
---+Analytic 0460
---+Analytic 0133
---+Analytic 1392
---+Analytic 1153
---+Analytic 0903
---+Analytic 0323
---+Analytic 1518
---+Analytic 0438
---+Analytic 0297
---+Analytic 1618
---+Analytic 0677
---+Analytic 1390
---+Analytic 0977
---+Analytic 1232
---+Analytic 1502
---+Analytic 0029
---+Analytic 0252
---+Analytic 1367
---+Analytic 0461
---+Analytic 1393
---+Analytic 0830
---+Analytic 1328
---+Analytic 0579
---+Analytic 1250
---+Analytic 0870
---+Analytic 1597
---+Analytic 2014
---+Analytic 0245
---+Analytic 1426
---+Analytic 0704
---+Analytic 0840
---+Analytic 1593
---+Analytic 2020
---+Analytic 0570
---+Analytic 0123
---+Analytic 1275
---+Analytic 1990
---+Analytic 0655
---+Analytic 0600
---+Analytic 0634
---+Analytic 1206
---+Analytic 0240
---+Analytic 1547
---+Analytic 0071
---+Analytic 0159
---+Analytic 1091
---+Analytic 0550
---+Analytic 1973
---+Analytic 0893
---+Analytic 0146
---+Analytic 1049
---+Analytic 1314
---+Analytic 1402
---+Analytic 0788
---+Analytic 0282
---+Analytic 0221
---+Analytic 1606
---+Analytic 0737
---+Analytic 0946
---+Analytic 1643
---+Analytic 1270
---+Analytic 1198
---+Analytic 1304
---+Analytic 0711
---+Analytic 0781
---+Analytic 1977
---+Analytic 1564
---+Analytic 0990
---+Analytic 0933
---+Analytic 0406
---+Analytic 0858
---+Analytic 0476
---+Analytic 0753
---+Analytic 0528
---+Analytic 1073
---+Analytic 0740
---+Analytic 1384
---+Analytic 0565
---+Analytic 0299
---+Analytic 0555
---+Analytic 0642
---+Analytic 0821
---+Analytic 0815
---+Analytic 0106
---+Analytic 1075
---+Analytic 0898
---+Analytic 1345
---+Analytic 0446
---+Analytic 2021
---+Analytic 0610
---+Analytic 0442
---+Analytic 1535
---+Analytic 0752
---+Analytic 0835
---+Analytic 0774
---+Analytic 1128
---+Analytic 1098
---+Analytic 0949
---+Analytic 1264
---+Analytic 0935
---+Analytic 0713
---+Analytic 0375
---+Analytic 0452
---+Analytic 1184
---+Analytic 1175
---+Analytic 0242
---+Analytic 0355
---+Analytic 0862
---+Analytic 1262
---+Analytic 0792
---+Analytic 0803
---+Analytic 1947
---+Analytic 1046
---+Analytic 1974
---+Analytic 0233
---+Analytic 0937
---+Analytic 0930
---+Analytic 1374
---+Analytic 0836
---+Analytic 1612
---+Analytic 0044
---+Analytic 1110
---+Analytic 0262
---+Analytic 0353
---+Analytic 1633
---+Analytic 0564
---+Analytic 0638
---+Analytic 1397
---+Analytic 0901
---+Analytic 0995
---+Analytic 0043
---+Analytic 1116
---+Analytic 0777
---+Analytic 2028
---+Analytic 0066
---+Analytic 0852
---+Analytic 0464
---+Analytic 1394
---+Analytic 0622
---+Analytic 1318
---+Analytic 0659
---+Analytic 1464
---+Analytic 1205
---+Analytic 0055
---+Analytic 0651
---+Analytic 0954
---+Analytic 0563
---+Analytic 2034
---+Analytic 1600
---+Analytic 1133
---+Analytic 0007
---+Analytic 1032
---+Analytic 1536
---+Analytic 0640
---+Analytic 0611
---+Analytic 1469
---+Analytic 0730
---+Analytic 0453
---+Analytic 1975
---+Analytic 0631
---+Analytic 0238
---+Analytic 0041
---+Analytic 0118
---+Analytic 1440
---+Analytic 1507
---+Analytic 0062
---+Analytic 1163
---+Analytic 1086
---+Analytic 1458
---+Analytic 1274
---+Analytic 0766
---+Analytic 0270
---+Analytic 0333
---+Analytic 1516
---+Analytic 0653
---+Analytic 1141
---+Analytic 1082
---+Analytic 0831
---+Analytic 0012
---+Analytic 0854
---+Analytic 1453
---+Analytic 0018
---+Analytic 1053
---+Analytic 1634
---+Analytic 0559
---+Analytic 1236
---+Analytic 0289
---+Analytic 0706
---+Analytic 0002
---+Analytic 1178
---+Analytic 1188
---+Analytic 0321
---+Analytic 0695
---+Analytic 0365
---+Analytic 1018
---+Analytic 0509
---+Analytic 1362
---+Analytic 0760
---+Analytic 1347
---+Analytic 0277
---+Analytic 0637
---+Analytic 1539
---+Analytic 0853
---+Analytic 1957
---+Analytic 1068
---+Analytic 1515
---+Analytic 0065
---+Analytic 0165
---+Analytic 2033
---+Analytic 0646
---+Analytic 0445
---+Analytic 1361
---+Analytic 0582
---+Analytic 0073
---+Analytic 1999
---+Analytic 0581
---+Analytic 1577
---+Analytic 0388
---+Analytic 0172
---+Analytic 1135
---+Analytic 0569
---+Analytic 0359
---+Analytic 0755
---+Analytic 1373
---+Analytic 2042
---+Analytic 0728
---+Analytic 0001
---+Analytic 0449
---+Analytic 1524
---+Analytic 1261
---+Analytic 1136
---+Analytic 0709
---+Analytic 0914
---+Analytic 0099
---+Analytic 0533
---+Analytic 0117
---+Analytic 1087
---+Analytic 1584
---+Analytic 0621
---+Analytic 0047
---+Analytic 1054
---+Analytic 0332
---+Analytic 0519
---+Analytic 0991
---+Analytic 0487
---+Analytic 0327
---+Analytic 0279
---+Analytic 1528
---+Analytic 0593
---+Analytic 0909
---+Analytic 1334
---+Analytic 0302
---+Analytic 0524
---+Analytic 1543
---+Analytic 0035
---+Analytic 0511
---+Analytic 0952
---+Analytic 0168
---+Analytic 0020
---+Analytic 1461
---+Analytic 0888
---+Analytic 1080
---+Analytic 0215
---+Analytic 0217
---+Analytic 0398
---+Analytic 0955
---+Analytic 2036
---+Analytic 0448
---+Analytic 1504
---+Analytic 0612
---+Analytic 0717
---+Analytic 1376
---+Analytic 0915
---+Analytic 0405
---+Analytic 1996
---+Analytic 0140
---+Analytic 1013
---+Analytic 1140
---+Analytic 1409
---+Analytic 0714
---+Analytic 1589
---+Analytic 1124
---+Analytic 0845
---+Analytic 1127
---+Analytic 0886
---+Analytic 1945
---+Analytic 1185
---+Analytic 1428
---+Analytic 0719
---+Analytic 0866
---+Analytic 1527
---+Analytic 1563
---+Analytic 0074
---+Active Directory Credential Request
---+WMI Creation
---+Group Modification
---+Image Modification
---+Pod Enumeration
---+Response Content
---+Volume Metadata
---+Response Metadata
---+Windows Registry Key Deletion
---+Instance Stop
---+Malware Content
---+Snapshot Deletion
---+Network Connection Creation
---+Process Access
---+Active Directory Object Creation
---+Certificate Registration
---+File Access
---+Kernel Module Load
---+Instance Enumeration
---+File Creation
---+Active DNS
---+Driver Load
---+Network Traffic Content
---+Logon Session Metadata
---+Volume Deletion
---+Process Creation
---+Drive Creation
---+Snapshot Creation
---+Cloud Storage Modification
---+Instance Modification
---+Instance Metadata
---+Cloud Storage Deletion
---+Drive Modification
---+Pod Creation
---+Service Creation
---+Cloud Storage Access
---+Cloud Storage Creation
---+Active Directory Object Modification
---+Active Directory Object Access
---+Web Credential Creation
---+Container Start
---+Process Termination
---+File Metadata
---+Service Modification
---+Pod Modification
---+Command Execution
---+Drive Access
---+Firewall Metadata
---+Service Metadata
---+Instance Deletion
---+Scheduled Job Metadata
---+Windows Registry Key Creation
---+File Modification
---+Host Status
---+Image Deletion
---+Snapshot Metadata
---+Cloud Service Enumeration
---+Group Metadata
---+Group Enumeration
---+Social Media
---+Active Directory Object Deletion
---+Container Enumeration
---+Malware Metadata
---+OS API Execution
---+Application Log Content
---+Logon Session Creation
---+Script Execution
---+Container Creation
---+Network Traffic Flow
---+User Account Authentication
---+Image Creation
---+Cloud Service Metadata
---+Image Metadata
---+Instance Creation
---+User Account Metadata
---+Named Pipe Metadata
---+Firmware Modification
---+Firewall Enumeration
---+Module Load
---+Pod Metadata
---+Firewall Disable
---+Passive DNS
---+User Account Modification
---+Firewall Rule Modification
---+Volume Modification
---+Process Modification
---+User Account Deletion
---+Windows Registry Key Modification
---+Volume Creation
---+User Account Creation
---+Container Metadata
---+Cloud Storage Metadata
---+Cloud Service Modification
---+File Deletion
---+Cloud Service Disable
---+Volume Enumeration
---+Windows Registry Key Access
---+Process Metadata
---+Snapshot Modification
---+Scheduled Job Creation
---+Network Share Access
---+Driver Metadata
---+Instance Start
---+Scheduled Job Modification
---+Cluster Metadata
---+Cloud Storage Enumeration
---+Web Credential Usage
---+Domain Registration
---+Snapshot Enumeration
---+Behavioral Detection of Network Share Connection Removal via CLI and SMB Disconnects
---+Detect Abuse of vSphere Installation Bundles (VIBs) for Persistent Access
---+Detection of Kernel/User-Level Rootkit Behavior Across Platforms
---+Detect Remote Email Collection via Abnormal Login and Programmatic Access
---+Detection of Malicious Control Panel Item Execution via control.exe or Rundll32
---+Detect Suspicious or Malicious Code Signing Abuse
---+Detection of Link Target
---+Detection of Botnet
---+Detect Archiving and Encryption of Collected Data (T1560)
---+Multi-Event Detection for SMB Admin Share Lateral Movement
---+Detection Strategy for T1546.016 - Event Triggered Execution via Installer Packages
---+Detection of Malware
---+Behavioral Detection of User Discovery via Local and Remote Enumeration
---+Detection Strategy for Plist File Modification (T1647)
---+Detection Strategy for Impair Defenses Indicator Blocking
---+Detection Strategy for Accessibility Feature Hijacking via Binary Replacement or Registry Modification
---+Detection of Msiexec Abuse for Local, Network, and DLL Execution
---+Detection Strategy for Dynamic API Resolution via Hash-Based Function Lookups
---+Detection Strategy for Hijack Execution Flow across OS platforms.
---+Detection Strategy for Hijack Execution Flow using Executable Installer File Permissions Weakness
---+Detection Strategy for Event Triggered Execution via Trap (T1546.005)
---+Behavioral Detection of Mailbox Data and Log Deletion for Anti-Forensics
---+Detection Strategy for Encrypted Channel across OS Platforms
---+Detection Strategy for NTFS File Attribute Abuse (ADS/EAs)
---+Detection of Establish Accounts
---+User-Initiated Malicious Library Installation via Package Manager (T1204.005)
---+Detection Strategy for System Binary Proxy Execution: Regsvr32
---+Detecting Steganographic Command and Control via File + Network Correlation
---+Behavior-chain detection for T1134.001 Access Token Manipulation: Token Impersonation/Theft on Windows
---+User Execution – Malicious Copy & Paste (browser/email → shell with obfuscated one-liner) – T1204.004
---+Detect Adversary-in-the-Middle via Network and Configuration Anomalies
---+Detection Strategy for Resource Forking on macOS
---+Detection of Botnet
---+Detection Strategy for SQL Stored Procedures Abuse via T1505.001
---+Detecting Malicious Browser Extensions Across Platforms
---+Detection of Registry Query for Environmental Discovery
---+Detect Compromise of Host Software Binaries
---+Detection Strategy for Hidden Windows
---+Multi-Platform Cloud Storage Exfiltration Behavior Chain
---+Detect Suspicious Access to Windows Credential Manager
---+Detection of Data Staging Prior to Exfiltration
---+Detection Strategy for Disable or Modify Cloud Firewall
---+Detection of Network Topology
---+Suspicious Addition to Local or Domain Groups
---+Detection Strategy for Exploitation for Credential Access
---+Credential Dumping from SAM via Registry Dump and Local File Access
---+Brute Force Authentication Failures with Multi-Platform Log Correlation
---+Detect LSA Authentication Package Persistence via Registry and LSASS DLL Load
---+Detection of Command and Control Over Application Layer Protocols
---+Detection Strategy for Lateral Tool Transfer across OS platforms
---+Detection of Digital Certificates
---+Detection Strategy for Modify Cloud Compute Infrastructure: Create Snapshot
---+Masquerading via Space After Filename - Behavioral Detection Strategy
---+Behavioral Detection of Publish/Subscribe Protocol Misuse for C2
---+Detection of Spearphishing Service
---+Detection Strategy for Log Enumeration
---+Detection of Social Media Accounts
---+Behavioral Detection of System Network Configuration Discovery
---+Detection Strategy for Exfiltration Over Web Service
---+Detection Strategy for ListPlanting Injection on Windows
---+Detection Strategy of Transmitted Data Manipulation
---+Credential Access via /etc/passwd and /etc/shadow Parsing
---+Behavioral Detection of Windows Command Shell Execution
---+Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps)
---+Behavioral detection for Supply Chain Compromise (package/update tamper → install → first-run)
---+Suspicious Database Access and Dump Activity Across Environments (T1213.006)
---+Cross-Platform Behavioral Detection of Python Execution
---+Detect Credentials Access from Password Stores
---+Detection Strategy for Endpoint DoS via Service Exhaustion Flood
---+Detection Strategy for Extra Window Memory (EWM) Injection on Windows
---+Detection Strategy for T1218.012 Verclsid Abuse
---+Detection Strategy for Disable or Modify Linux Audit System Log
---+Detection Strategy for Exclusive Control
---+Detection Strategy for Disk Structure Wipe via Boot/Partition Overwrite
---+Detection Strategy for Impersonation
---+Traffic Signaling (Port-knock / magic-packet → firewall or service activation) – T1205
---+Detection of Code Signing Certificates
---+Behavior-chain detection for T1132.001 Data Encoding: Standard Encoding (Base64/Hex/MIME) across Windows, Linux, macOS, ESXi
---+Detection of Cloud Accounts
---+Detection of File Transfer Protocol-Based C2 (FTP, FTPS, SMB, TFTP)
---+Detection Strategy for Junk Code Obfuscation with Suspicious Execution Patterns
---+Behavioral Detection of Log File Clearing on Linux and macOS
---+Detection of Remote Data Staging Prior to Exfiltration
---+Detection Strategy for Reflection Amplification DoS (T1498.002)
---+Detection Strategy for Temporary Elevated Cloud Access Abuse (T1548.005)
---+Detection Strategy for Network Address Translation Traversal
---+Local Account Enumeration Across Host Platforms
---+Detection Strategy for Cloud Infrastructure Discovery
---+T1136.001 Detection Strategy - Local Account Creation Across Platforms
---+Cross-Platform Detection of Data Transfer to Cloud Account
---+Detection Strategy for Debugger Evasion (T1622)
---+Detection Strategy for Application Shimming via sdbinst.exe and Registry Artifacts (Windows)
---+Email Collection via Local Email Access and Auto-Forwarding Behavior
---+Behavioral Detection of Internet Connection Discovery
---+Endpoint Resource Saturation and Crash Pattern Detection Across Platforms
---+Detect Mark-of-the-Web (MOTW) Bypass via Container and Disk Image Files
---+Detection Strategy for Dynamic Resolution using Domain Generation Algorithms.
---+Detection Strategy for Role Addition to Cloud Accounts
---+Container CLI and API Abuse via Docker/Kubernetes (T1059.013)
---+Detection of Bluetooth-Based Data Exfiltration
---+Detection Strategy for Hijack Execution Flow through Path Interception by Unquoted Path
---+Detection of Web Session Cookie Theft via File, Memory, and Network Artifacts
---+Detection of Remote Service Session Hijacking for RDP.
---+Detection Strategy for Process Argument Spoofing on Windows
---+Detection Strategy for T1505 - Server Software Component
---+Internal Proxy Behavior via Lateral Host-to-Host C2 Relay
---+Detection Strategy for Endpoint DoS via Application or System Exploitation
---+Detection Strategy for Ignore Process Interrupts
---+Detection of Phishing for Information
---+Multi-Platform Shutdown or Reboot Detection via Execution and Host Status Events
---+Behavioral Detection Strategy for Use Alternate Authentication Material (T1550)
---+Detection of Non-Application Layer Protocols for C2
---+Cross-host C2 via Removable Media Relay
---+Defacement via File and Web Content Modification Across Platforms
---+Detect LLMNR/NBT-NS Poisoning and SMB Relay on Windows
---+Detection Strategy for SNMP (MIB Dump) on Network Devices
---+macOS AuthorizationExecuteWithPrivileges Elevation Prompt Detection
---+Detection of Digital Certificates
---+Detect Network Logon Script Abuse via Multi-Event Correlation on Windows
---+Detection Strategy for Container and Resource Discovery
---+Detect abuse of Trusted Relationships (third-party and delegated admin access)
---+Detection Strategy for Weaken Encryption: Disable Crypto Hardware on Network Devices
---+Detection Strategy for T1547.009 – Shortcut Modification (Windows)
---+Detection of DNS
---+Detection of Adversarial Process Discovery Behavior
---+Behavioral Detection Strategy for Abuse of Sudo and Sudo Caching
---+Detection of Network Devices
---+Unix-like File Permission Manipulation Behavioral Chain Detection Strategy
---+Detection of Employee Names
---+Detection Strategy for T1505.004 - Malicious IIS Components
---+Detection Strategy for Encrypted Channel via Symmetric Cryptography across OS Platforms
---+Detection of Email Addresses
---+Recursive Enumeration of Files and Directories Across Privilege Contexts
---+Behavioral Detection of External Website Defacement across Platforms
---+Detection of Domain Trust Discovery via API, Script, and CLI Enumeration
---+Detecting Suspicious Access to CRM Data in SaaS Environments
---+Detection of Domains
---+Detect Kerberos Ticket Theft or Forgery (T1558)
---+Behavioral Detection of Native API Invocation via Unusual DLL Loads and Direct Syscalls
---+Detection of Local Data Collection Prior to Exfiltration
---+Detection of Unauthorized DCSync Operations via Replication API Abuse
---+Detection Strategy for Polymorphic Code Mutation and Execution
---+Detection Strategy for System Services across OS platforms.
---+Detection Strategy for Hijack Execution Flow through the AppDomainManager on Windows.
---+Detection of Business Relationships
---+Detection Strategy for Disk Content Wipe via Direct Access and Overwrite
---+Detection of Unauthorized Network Firewall Rule Modification
---+Detection of Defense Impairment
---+Detect Domain Controller Authentication Process Modification (Skeleton Key)
---+Detection of Search Open Websites/Domains
---+Detection of Systemd Service Creation or Modification on Linux
---+Detection of SEO Poisoning
---+Programmatic and Excessive Access to Confluence Documentation
---+Detection Strategy for AppCert DLLs Persistence via Registry Injection
---+Detection of Local Browser Artifact Access for Reconnaissance
---+Detection of Drive-by Target
---+Detection of Domain or Tenant Policy Modifications via AD and Identity Provider
---+Detection Strategy for Scheduled Transfer and Recurrent Exfiltration Patterns
---+IDE Tunneling Detection via Process, File, and Network Behaviors
---+Detect Logon Script Modifications and Execution
---+Detect Abuse of Dynamic Data Exchange (T1559.002)
---+Detection of Search Closed Sources
---+Detection Strategy for Hidden Files and Directories
---+Detection of Malware Relocation via Suspicious File Movement
---+Detection Strategy for Power Settings Abuse
---+Multi-hop Proxy Behavior via Relay Node Chaining, Onion Routing, and Network Tunneling
---+Behavioral Detection of Masquerading Across Platforms via Metadata and Execution Discrepancy
---+Detection Strategy for T1546.017 - Udev Rules (Linux)
---+Detection of Malvertising
---+Detection Strategy for Runtime Data Manipulation.
---+Detection of Serverless
---+Application Exhaustion Flood Detection Across Platforms
---+Detect malicious IDE extension install/usage and IDE tunneling
---+Detection of Firmware
---+Resource Hijacking Detection Strategy
---+Detection Strategy for Forged Web Credentials
---+Detection Strategy for /proc Memory Injection on Linux
---+Behavioral Detection of Asynchronous Procedure Call (APC) Injection via Remote Thread Queuing
---+Detection Strategy for Dynamic Resolution using Fast Flux DNS
---+Detection of Masqueraded Tasks or Services with Suspicious Naming and Execution
---+Behavioral Detection of Network History and Configuration Tampering
---+Clipboard Data Access with Anomalous Context
---+Behavioral Detection of Thread Execution Hijacking via Thread Suspension and Context Switching
---+Template Injection Detection - Windows
---+Detect Windows Firewall
---+Detect Social Engineering
---+Detection Strategy for Compile After Delivery - Source Code to Executable Transformation
---+Abuse of Information Repositories for Data Collection
---+Detection Strategy for Network Sniffing Across Platforms
---+Detect XSL Script Abuse via msxsl and wmic
---+Detect Remote Access via USB Hardware (TinyPilot, PiKVM)
---+Behavioral Detection of Visual Basic Execution (VBS/VBA/VBScript)
---+Behavioral Detection of Unix Shell Execution
---+Detection Strategy for Hijack Execution Flow using Path Interception by PATH Environment Variable.
---+Detection of Acquire Access
---+Detection of Exploits
---+Detection of Email Accounts
---+Detection of Digital Certificates
---+Detect Conditional Access Policy Modification in Identity and Cloud Platforms
---+Detection of Purchase Technical Data
---+Detection of Launch Agent Creation or Modification on macOS
---+Hardware Supply Chain Compromise Detection via Host Status & Boot Integrity Checks
---+Detecting Remote Script Proxy Execution via PubPrn.vbs
---+Detection of Obtain Capabilities
---+Detection Strategy for LC_LOAD_DYLIB Modification in Mach-O Binaries on macOS
---+Detection of Credentials
---+Domain Account Enumeration Across Platforms
---+Detection Strategy for Dynamic Resolution through DNS Calculation
---+Detection Strategy for Downgrade System Image on Network Devices
---+Detection of Search Victim-Owned Websites
---+Detection Strategy for ESXi Hypervisor CLI Abuse
---+Detect Persistence via Malicious Office Add-ins
---+Behavioral Detection of Remote SSH Logins Followed by Post-Login Execution
---+Detection Strategy for Modify System Image on Network Devices
---+Detection Strategy for Subvert Trust Controls using SIP and Trust Provider Hijacking.
---+Detect User Activity Based Sandbox Evasion via Input & Artifact Probing
---+Detection Strategy for Email Hiding Rules
---+Detect Network Provider DLL Registration and Credential Capture
---+Detection Strategy for T1136 - Create Account across platforms
---+Detection Strategy for Hidden Virtual Instance Execution
---+Detection of IP Addresses
---+Behavioral Detection of Cloud Group Enumeration via API and CLI Access
---+Detection of Acquire Infrastructure
---+Detection Strategy for T1550.002 - Pass the Hash (Windows)
---+Detecting Bulk or Anomalous Access to Private Code Repositories via SaaS Platforms
---+Detection of Vulnerability Scanning
---+Detection Strategy for T1528 - Steal Application Access Token
---+Detection of Determine Physical Locations
---+Detection of Stage Capabilities
---+Detect persistence via reopened application plist modification (macOS)
---+Detect Adversary Deobfuscation or Decoding of Files and Payloads
---+Detection of Identify Roles
---+Virtualization/Sandbox Evasion via System Checks across Windows, Linux, macOS
---+Detection of Malware
---+Detect Kerberos Ccache File Theft or Abuse (T1558.005)
---+Detection of Proxy Infrastructure Setup and Traffic Bridging
---+Detection of Remote Service Session Hijacking
---+Behavioral Detection Strategy for Exfiltration Over Symmetric Encrypted Non-C2 Protocol
---+Detection Strategy for Multi-Factor Authentication Request Generation (T1621)
---+Automated File and API Collection Detection Across Platforms
---+Detection Strategy for T1550.003 - Pass the Ticket (Windows)
---+Behavior-chain detection strategy for T1127.001 Trusted Developer Utilities Proxy Execution: MSBuild (Windows)
---+Detection of Social Media Accounts
---+Linux Python Startup Hook Persistence via .pth and Customize Files (T1546.018)
---+Detect Default File Association Hijack via Registry & Execution Correlation on Windows
---+Detect Access to Cloud Instance Metadata API (IaaS)
---+Detecting Code Injection via mavinject.exe (App-V Injector)
---+Detection Strategy for Build Image on Host
---+Detect Gatekeeper Bypass via Quarantine Flag and Trust Control Manipulation
---+Credential Stuffing Detection via Reused Breached Credentials Across Services
---+Detect Winlogon Helper DLL Abuse via Registry and Process Artifacts on Windows
---+Detect Multi-Stage Command and Control Channels
---+Detecting Downgrade Attacks
---+Detection Strategy for Exploitation for Privilege Escalation
---+Detect Access and Parsing of .bash_history Files for Credential Harvesting
---+Account Access Removal via Multi-Platform Audit Correlation
---+Behavioral Detection of PE Injection via Remote Memory Mapping
---+Detect Ingress Tool Transfers via Behavioral Chain
---+Detection Strategy for Addition of Email Delegate Permissions
---+Behavior-chain detection strategy for T1127.003 Trusted Developer Utilities Proxy Execution: JamPlus (Windows)
---+Multi-Platform File and Directory Permissions Modification Detection Strategy
---+Behavioral Detection of Permission Groups Discovery
---+Port-knock → rule/daemon change → first successful connect (T1205.001)
---+Boot or Logon Initialization Scripts Detection Strategy
---+Detect Access and Decryption of Group Policy Preference (GPP) Credentials in SYSVOL
---+Detection Strategy for Traffic Duplication via Mirroring in IaaS and Network Devices
---+Behavioral Detection of Domain Group Discovery
---+Detection of DNS Server
---+Detection Strategy for Login Hook Persistence on macOS
---+Detection Strategy for Indicator Removal from Tools - Post-AV Evasion Modification
---+Detection Strategy for Exfiltration to Text Storage Sites
---+Detection of Search Threat Vendor Data
---+Registry and LSASS Monitoring for Security Support Provider Abuse
---+Detect Hybrid Identity Authentication Process Modification
---+Cross-Platform Detection of Cron Job Abuse for Persistence and Execution
---+Detection of Server
---+Detection Strategy for SVG Smuggling with Script Execution and Delivery Behavior
---+Detect Credential Discovery via Windows Registry Enumeration
---+Detection Strategy for VBA Stomping
---+Cross-Platform Detection of JavaScript Execution Abuse
---+Detection Strategy for Email Spoofing
---+Detection Strategy for MFA Interception via Input Capture and Smart Card Proxying
---+Direct Network Flood Detection across IaaS, Linux, Windows, and macOS
---+Detection of Virtual Private Server
---+Detection Strategy for Event Triggered Execution: AppInit DLLs (Windows)
---+Detection Strategy for Web Service: Dead Drop Resolver
---+User Execution – multi-surface behavior chain (documents/links → helper/unpacker → LOLBIN/child → egress)
---+Detect Office Startup-Based Persistence via Macros, Forms, and Registry Hooks
---+Detection of Web Services
---+Behavioral Detection of Indicator Removal Across Platforms
---+Multi-event Detection Strategy for RDP-Based Remote Logins and Post-Access Activity
---+Password Policy Discovery – cross-platform behavior-chain analytics
---+Abuse of PowerShell for Arbitrary Execution
---+Detection Strategy for Command Obfuscation
---+Detection of Generate Content
---+Detect Subversion of Trust Controls via Certificate, Registry, and Attribute Manipulation
---+Detection Strategy for File Creation or Modification of Boot Files
---+System Discovery via Native and Remote Utilities
---+Detect Persistence via Outlook Custom Forms Triggered by Malicious Email
---+Behavioral Detection of Systemd Timer Abuse for Scheduled Execution
---+Detect browser session hijacking via privilege, handle access, and remote thread into browsers
---+Suspicious Use of Web Services for C2
---+Detection Strategy for System Services: Launchctl
---+Behavior-chain detection for T1134 Access Token Manipulation on Windows
---+Detecting Protocol or Service Impersonation via Anomalous TLS, HTTP Header, and Port Mismatch Correlation
---+Compromised software/update chain (installer/write → first-run/child → egress/signature anomaly)
---+Detect Forged Kerberos Silver Tickets (T1558.002)
---+Windows COM Hijacking Detection via Registry and DLL Load Correlation
---+Behavior-chain detection for T1134.002 Create Process with Token (Windows)
---+Detection of Credential Dumping from LSASS Memory via Access and Dump Sequence
---+Detection Strategy for Data from Network Shared Drive
---+Detection Strategy for Content Injection
---+Obfuscated Binary Unpacking Detection via Behavioral Patterns
---+Detection Strategy for Serverless Execution (T1648)
---+Detection of Group Policy Modifications via AD Object Changes and File Activity
---+Detection of Data Exfiltration via Removable Media
---+Detection Strategy for T1136.003 - Cloud Account Creation across IaaS, IdP, SaaS, Office
---+Detection of Develop Capabilities
---+Detection Strategy for Steal or Forge Authentication Certificates
---+Detection of Active Scanning
---+Detection of Selective Exclusion
---+Suspicious RoleBinding or ClusterRoleBinding Assignment in Kubernetes
---+Detection of System Network Connections Discovery Across Platforms
---+Detection Strategy for Hijack Execution Flow through Services File Permissions Weakness.
---+Detect Modification of macOS Startup Items
---+Detection Strategy for Phishing across platforms.
---+Detection Strategy for Hijack Execution Flow through the KernelCallbackTable on Windows.
---+Detection of Compromise Infrastructure
---+Detection Strategy for T1497 Virtualization/Sandbox Evasion
---+Detection of Malicious Code Execution via InstallUtil.exe
---+Behavioral Detection of WinRM-Based Remote Access
---+Detection of Vulnerabilities
---+Detection of Upload Tool
---+Detection of Persistence Artifact Removal Across Host Platforms
---+Behavioral Detection of T1498 – Network Denial of Service Across Platforms
---+Detect persistent or elevated container services via container runtime or cluster manipulation
---+Removable Media Execution Chain Detection via File and Process Activity
---+Detection Strategy for Hijack Execution Flow using the Windows COR_PROFILER.
---+Detection Strategy for Hidden File System Abuse
---+Behavioral Detection Strategy for Network Service Discovery Across Platforms
---+Remote Desktop Software Execution and Beaconing Detection
---+Detection Strategy for Process Doppelgänging on Windows
---+Behavioral Detection Strategy for WMI Execution Abuse on Windows
---+Detect Persistence via Malicious Outlook Rules
---+Detect Suspicious Access to Private Key Files and Export Attempts Across Platforms
---+Distributed Password Spraying via Authentication Failures Across Multiple Accounts
---+Detection Strategy for Defense Impairment via Prevent Command History Logging across OS platforms.
---+Behavioral Detection of Command and Scripting Interpreter Abuse
---+Detection Strategy for Virtual Machine Discovery
---+Detection Strategy for Escape to Host
---+Detection of Client Configurations
---+Cloud Account Enumeration via API, CLI, and Scripting Interfaces
---+Detection Strategy for System Services: Systemctl
---+Detect Modification of Network Device Authentication via Patched System Images
---+Detection of Script-Based Proxy Execution via Signed Microsoft Utilities
---+Detection of Credential Harvesting via Web Portal Modification
---+Credential Dumping via Sensitive Memory and Registry Access Correlation
---+Detection Strategy for Cloud Application Integration
---+Behavior-chain detection for T1132.002 Data Encoding: Non-Standard Encoding across Windows, Linux, macOS, ESXi
---+Local Storage Discovery via Drive Enumeration and Filesystem Probing
---+Detection Strategy for Safe Mode Boot Abuse
---+Detect Abuse of Container APIs for Credential Access
---+Detecting Mshta-based Proxy Execution via Suspicious HTA or Script Invocation
---+Detect Use of Stolen Web Session Cookies Across Platforms
---+Detection Strategy for Netsh Helper DLL Persistence via Registry and Child Process Monitoring (Windows)
---+Detection Strategy for Spearphishing Attachment across OS Platforms
---+Detection Strategy for Process Hollowing on Windows
---+Detection Strategy for Overwritten Process Arguments Masquerading
---+Detection Strategy for T1542.005 Pre-OS Boot: TFTP Boot
---+Detect Local Email Collection via Outlook Data File Access and Command Line Tooling
---+Detect Registry and Startup Folder Persistence (Windows)
---+Detect Suspicious Access to Browser Credential Stores
---+Detection of Gather Victim Network Information
---+Detection Strategy for Hijack Execution Flow using Path Interception by Search Order Hijacking
---+Behavioral Detection of Spoofed GUI Credential Prompts
---+Detection of Cached Domain Credential Dumping via Local Hash Cache Access
---+Detect Time-Based Evasion via Sleep, Timer Loops, and Delayed Execution
---+Detection Strategy for T1505.002 - Transport Agent Abuse (Windows/Linux)
---+Domain Fronting Behavior via Mismatched TLS SNI and HTTP Host Headers
---+Detection of Exfiltration Over Alternate Network Interfaces
---+Behavior-chain, platform-aware detection strategy for T1129 Shared Modules
---+Detection of WHOIS
---+Detection Strategy for Double File Extension Masquerading
---+Detecting Odbcconf Proxy Execution of Malicious DLLs
---+Detection of Wordlist Scanning
---+Detecting Abnormal SharePoint Data Mining by Privileged or Rare Users
---+Detection Strategy for Abuse Elevation Control Mechanism (T1548)
---+Detection of Software
---+Detection of Serverless
---+Detect Abuse of Component Object Model (T1559.001)
---+Behavioral Detection of Process Injection Across Platforms
---+Behavior-chain, platform-aware detection strategy for T1124 System Time Discovery
---+Detection Strategy for Dynamic Resolution across OS Platforms
---+Detection Strategy for Embedded Payloads
---+Behavior-chain detection for T1610 Deploy Container across Docker & Kubernetes control/node planes
---+Detect ARP Cache Poisoning Across Linux, Windows, and macOS
---+Multi-Platform Execution Guardrails Environmental Validation Detection Strategy
---+Detect WMI Event Subscription for Persistence via WmiPrvSE Process and MOF Compilation
---+Detection Strategy for Email Bombing
---+Detect Malicious Modification of Pluggable Authentication Modules (PAM)
---+Detecting .NET COM Registration Abuse via Regsvcs/Regasm
---+Detection Strategy for Obfuscated Files or Information: Binary Padding
---+Detection Strategy for Resource Hijacking: SMS Pumping via SaaS Application Logs
---+Detect Abuse of Windows Time Providers for Persistence
---+Detection Strategy for System Language Discovery
---+Detection Strategy for System Location Discovery
---+Detection of Trust Relationship Modifications in Domain or Tenant Policies
---+Detection Strategy for Remote System Enumeration Behavior
---+Detect DHCP Spoofing Across Linux, Windows, and macOS
---+Detection of Code Repositories
---+Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189)
---+Detection Strategy for TLS Callback Injection via PE Memory Modification and Hollowing
---+Detection of DNS Server
---+Detection of Abused or Compromised Cloud Accounts for Access and Persistence
---+Windows DACL Manipulation Behavioral Chain Detection Strategy
---+Detection of Compromise Accounts
---+Detection of Malicious Kubernetes CronJob Scheduling
---+Detection of Defense Impairment through Disabled or Modified Tools across OS Platforms.
---+Detection of Audio-Visual Content
---+Backup Software Discovery via CLI, Registry, and Process Inspection (T1518.002)
---+Detect Archiving via Library (T1560.002)
---+Detection Strategy for Hijack Execution Flow through Service Registry Premission Weakness.
---+Detection Strategy for T1218.011 Rundll32 Abuse
---+Detection Strategy for T1542.002 Pre-OS Boot: Component Firmware
---+Detect Unauthorized Access to Password Managers
---+Detection Strategy for Steganographic Abuse in File & Script Execution
---+Detection of Data Access and Collection from Removable Media
---+Environmental Keying Discovery-to-Decryption Behavioral Chain Detection Strategy
---+Detection of Valid Account Abuse Across Platforms
---+Detection Strategy for T1547.010 – Port Monitor DLL Persistence via spoolsv.exe (Windows)
---+Detection of Exfiltration Over Unencrypted Non-C2 Protocol
---+Detection Strategy for HTML Smuggling via JavaScript Blob + Dynamic File Drop
---+Detect Abuse of XPC Services (T1559.003)
---+Detection Strategy for Cloud Service Discovery
---+Detection Strategy for AutoHotKey & AutoIT Abuse
---+Boot or Logon Autostart Execution Detection Strategy
---+Detection of NTDS.dit Credential Dumping from Domain Controllers
---+Detect Unsecured Credentials Shared in Chat Messages
---+Detect Screen Capture via Commands and API Calls
---+T1136.002 Detection Strategy - Domain Account Creation Across Platforms
---+Firmware Modification via Flash Tool or Corrupted Firmware Upload
---+Web Shell Detection via Server Behavior and File Execution Chains
---+Detection Strategy for T1542 Pre-OS Boot
---+Detection Strategy for Exfiltration to Code Repository
---+Detection of Disabled or Modified System Firewalls across OS Platforms.
---+Internal Spearphishing via Trusted Accounts
---+Detection of Spoofed User-Agent
---+Detection of Install Digital Certificate
---+Behavioral Detection for Service Stop across Platforms
---+Detection Strategy for LNK Icon Smuggling
---+Detection Strategy for Fileless Storage via Registry, WMI, and Shared Memory
---+Detection Strategy for Modify Cloud Compute Infrastructure
---+Detection of AppleScript-Based Execution on macOS
---+Behavioral Detection Strategy for Use Alternate Authentication Material: Application Access Token (T1550.001)
---+Detection of Local Account Abuse for Initial Access and Persistence
---+Behavioral Detection for T1490 - Inhibit System Recovery
---+Detection of Gather Victim Host Information
---+Detect Access to Unsecured Credential Files Across Platforms
---+Detect Evil Twin Wi-Fi Access Points on Network Devices
---+Detect Abuse of Inter-Process Communication (T1559)
---+Password Guessing via Multi-Source Authentication Failure Correlation
---+Detect Forced SMB/WebDAV Authentication via lure files and outbound NTLM
---+Socket-filter trigger → on-host raw-socket activity → reverse connection (T1205.002)
---+Detection Strategy for VDSO Hijacking on Linux
---+Detection of Gather Victim Identity Information
---+Windows Detection Strategy for T1547.012 - Print Processor DLL Persistence
---+Detection Strategy for Masquerading via Legitimate Resource Name or Location
---+Detection Strategy for Forged SAML Tokens
---+Detection Strategy for Bind Mounts on Linux
---+Detect Modification of Authentication Process via Reversible Encryption
---+Behavioral Detection of Malicious File Deletion
---+User Execution – Malicious Link (click → suspicious egress → download/write → follow-on activity)
---+Detection Strategy for Hide Infrastructure
---+Detecting PowerShell Execution via SyncAppvPublishingServer.vbs Proxy Abuse
---+Abuse of Domain Accounts
---+Detect Active Setup Persistence via StubPath Execution
---+Behavioral Detection of Wi-Fi Discovery Activity
---+Detecting Junk Data in C2 Channels via Behavioral Analysis
---+Behavioral Detection of Unauthorized VNC Remote Control Sessions
---+Detection of Written Content
---+Suspicious Device Registration via Entra ID or MFA Platform
---+Setuid/Setgid Privilege Abuse Detection (Linux/macOS)
---+Detection of Mail Protocol-Based C2 Activity (SMTP, IMAP, POP3)
---+Detection of Domain Properties
---+Detection Strategy for Weaken Encryption: Reduce Key Space on Network Devices
---+Detection Strategy for Modify Cloud Compute Infrastructure: Create Cloud Instance
---+Detection Strategy for Hidden Artifacts Across Platforms
---+Detection Strategy for Hijack Execution Flow for DLLs
---+Detection Strategy for SSH Session Hijacking
---+Endpoint DoS via OS Exhaustion Flood Detection Strategy
---+Multi-Platform Behavioral Detection for Compute Hijacking
---+Detection Strategy for Boot or Logon Initialization Scripts: RC Scripts
---+Detection Strategy for Lua Scripting Abuse
---+Detection Strategy for Exfiltration Over C2 Channel
---+External Proxy Behavior via Outbound Relay to Intermediate Infrastructure
---+Detection Strategy for T1525 – Implant Internal Image
---+Detect Excessive or Unauthorized Bandwidth Usage for Botnet, Proxyjacking, or Scanning Purposes
---+Detection Strategy for ESXi Administration Command
---+Detection of Malicious Profile Installation via CMSTP.exe
---+Renamed Legitimate Utility Execution with Metadata Mismatch and Suspicious Path
---+Linux Detection Strategy for T1547.013 - XDG Autostart Entries
---+Behavioral Detection of DNS Tunneling and Application Layer Abuse
---+Detection Strategy for Ptrace-Based Process Injection on Linux
---+Detection of LSA Secrets Dumping via Registry and Memory Extraction
---+Detection of Exploits
---+Detection of Server
---+Detection Strategy for T1542.004 Pre-OS Boot: ROMMONkit
---+Right-to-Left Override Masquerading Detection via Filename and Execution Context
---+Detection Strategy for Hidden User Accounts
---+Detection Strategy for Cloud Storage Object Discovery
---+Detection of Data Destruction Across Platforms via Mass Overwrite and Deletion Patterns
---+Behavioral Detection of Event Triggered Execution Across Platforms
---+Detecting Unauthorized Collection from Messaging Applications in SaaS and Office Environments
---+Behavioral Detection Strategy for T1123 Audio Capture Across Windows, Linux, macOS
---+Detection of Suspicious Scheduled Task Creation and Execution on Windows
---+Detection of Windows Service Creation or Modification
---+Detection Strategy for Exfiltration to Cloud Storage
---+Detection of Code Signing Certificates
---+Internal Website and System Content Defacement via UI or Messaging Modifications
---+Behavioral Detection of Input Capture Across Platforms
---+Detection of Spearphishing Link
---+Detection Strategy for Patch System Image on Network Devices
---+Cross-Platform Detection of Scheduled Task/Job Abuse via `at` Utility
---+Behavioral Detection of CLI Abuse on Network Devices
---+Detection of Scanning IP Blocks
---+Detection Strategy for Poisoned Pipeline Execution via SaaS CI/CD Workflows
---+Detect Persistence via Office Test Registry DLL Injection
---+Detection of Tool
---+Detect Forged Kerberos Golden Tickets (T1558.001)
---+Detect Access to macOS Keychain for Credential Theft
---+Detection Strategy for Non-Standard Ports
---+Detection Strategy for Data Manipulation
---+Detection Strategy for Additional Cloud Credentials in IaaS/IdP/SaaS
---+Detection of Gather Victim Org Information
---+Detection of Tainted Content Written to Shared Storage
---+Detection of Proxy Execution via Trusted Signed Binaries Across Platforms
---+Detection of Spearphishing Voice
---+Detection Strategy for Modify Cloud Compute Infrastructure: Delete Cloud Instance
---+Detection of Search Engines
---+Detection Strategy for SSH Key Injection in Authorized Keys
---+Behavior-Based Registry Modification Detection on Windows
---+Detection of Virtual Private Server
---+Detection of Lifecycle Policy Modifications for Triggered Deletion in IaaS Cloud Storage
---+Detect Disabled Windows Event Log
---+Detection of Default Account Abuse Across Platforms
---+Detection of Multi-Platform File Encryption for Impact
---+Detection of Social Media
---+Detection of Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
---+Detect Access or Search for Unsecured Credentials Across Platforms
---+Detection of Mutex-Based Execution Guardrails Across Platforms
---+Detection of Application Window Enumeration via API or Scripting
---+Behavior-chain detection for T1134.005 Access Token Manipulation: SID-History Injection (Windows)
---+Behavioral Detection Strategy for Remote Service Logins and Post-Access Activity
---+Detection of Event Log Clearing on Windows via Behavioral Chain
---+Detect Screensaver-Based Persistence via Registry and Execution Chains
---+Detecting Electron Application Abuse for Proxy Execution
---+Detection Strategy for Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations
---+Detection of Network Trust Dependencies
---+Detection of Email Accounts
---+Detect Modification of Authentication Processes Across Platforms
---+Detection Strategy for IFEO Injection on Windows
---+Detection Strategy for T1548.002 – Bypass User Account Control (UAC)
---+Detection of Artificial Intelligence
---+Account Manipulation Behavior Chain Detection
---+Detection of Hardware
---+Encrypted or Encoded File Payload Detection Strategy
---+Detection Strategy for Data Encoding in C2 Channels
---+Detect AS-REP Roasting Attempts (T1558.004)
---+Detection of System Service Discovery Commands Across OS Platforms
---+Detection Strategy for T1505.005 – Terminal Services DLL Modification (Windows)
---+Detection of Credential Harvesting via API Hooking
---+Detection Strategy for Data Transfer Size Limits and Chunked Exfiltration
---+Behavior‑chain detection for T1134.003 Make and Impersonate Token (Windows)
---+Detection Strategy for Subvert Trust Controls via Install Root Certificate.
---+Detection Strategy for Disk Wipe via Direct Disk Access and Destructive Commands
---+Detection Strategy for Exploitation for Stealth
---+Detection Strategy for Hijack Execution Flow: Dynamic Linker Hijacking
---+Automated Exfiltration Detection Strategy
---+Detection of System Process Creation or Modification Across Platforms
---+Multi-Event Behavioral Detection for DCOM-Based Remote Code Execution
---+Detecting OS Credential Dumping via /proc Filesystem Access on Linux
---+Detection Strategy for Reflective Code Loading
---+Detection of Search Open Technical Databases
---+Detection Strategy for Launch Daemon Creation or Modification (macOS)
---+Detection Strategy for Exfiltration Over Webhook
---+Behavioral Detection of Command History Clearing
---+Detection of Domains
---+Detect Bidirectional Web Service C2 Channels via Process & Network Correlation
---+Detection Strategy for Spearphishing via a Service across OS Platforms
---+Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress)
---+Behavioral Detection of Local Group Enumeration Across OS Platforms
---+Detection Strategy for Weaken Encryption on Network Devices
---+Detect abuse of Windows BITS Jobs for download, execution and persistence
---+Detection of Threat Intel Vendors
---+Detection Strategy for Invisible Unicode
---+Cross-Platform Behavioral Detection of Scheduled Task/Job Abuse
---+Detection Strategy for Kernel Modules and Extensions Autostart Execution
---+Detection of Cloud Accounts
---+Detect Persistence via Office Template Macro Injection or Registry Hijack
---+Detect Obfuscated C2 via Network Traffic Analysis
---+Detection Strategy for Forged Web Cookies
---+User Execution – Malicious File via download/open → spawn chain (T1204.002)
---+Security Software Discovery Across Platforms
---+Detection of Cloud Service Dashboard Usage via GUI-Based Cloud Access
---+Detection of Query Public AI Services
---+Detection Strategy for Masquerading via File Type Modification
---+Enumeration of Global Address Lists via Email Account Discovery
---+Detection Strategy for Extended Attributes Abuse
---+Detect One-Way Web Service Command Channels
---+Behavioral Detection of Obfuscated Files or Information
---+Detection Strategy for Stored Data Manipulation across OS Platforms.
---+Detection Strategy for Stripped Payloads Across Platforms
---+Detection Strategy for Encrypted Channel via Asymmetric Cryptography across OS Platforms
---+Detect Persistence via Outlook Home Page Exploitation
---+Detection strategy for Group Policy Discovery on Windows
---+Detection of Spearphishing Attachment
---+Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets
---+Detection Strategy for Financial Theft
---+Detection Strategy for Cloud Service Hijacking via SaaS Abuse
---+Behavior-chain detection for T1135 Network Share Discovery across Windows, Linux, and macOS
---+Detection of DNS/Passive DNS
---+Behavioral Detection of Malicious Cloud API Scripting
---+Detect Archiving via Utility (T1560.001)
---+Detect unauthorized or suspicious Hardware Additions (USB/Thunderbolt/Network)
---+Detection Strategy for Impair Defenses Across Platforms
---+Detection Strategy for T1542.001 Pre-OS Boot: System Firmware
---+Detection of Local Data Staging Prior to Exfiltration
---+Behavior-chain detection for T1133 External Remote Services across Windows, Linux, macOS, Containers
---+Multi-Platform Detection Strategy for T1678 - Delay Execution
---+Detection Strategy for Container Administration Command Abuse
---+Behavioral Detection of DLL Injection via Windows API
---+Behavior-chain, platform-aware detection strategy for T1125 Video Capture
---+Detection of Adversary Abuse of Software Deployment Tools
---+Detection of Malicious or Unauthorized Software Extensions
---+Behavior-chain detection for T1134.004 Access Token Manipulation: Parent PID Spoofing (Windows)
---+Detection Strategy for Spearphishing Voice across OS platforms
---+Detection of Adversary Use of Unused or Unsupported Cloud Regions (IaaS)
---+Behavior-Chain Detection for Remote Access Tools (Tool-Agnostic)
---+Behavior-chain detection strategy for T1127.002 Trusted Developer Utilities Proxy Execution: ClickOnce (Windows)
---+Supply-chain tamper in dependencies/dev-tools (manager→write/install→first-run→egress)
---+Detection Strategy for Hijack Execution Flow: Dylib Hijacking
---+Detect MFA Modification or Disabling Across Platforms
---+Detection Strategy for Masquerading via Breaking Process Trees
---+Detection Strategy for Spearphishing Links
---+Behavioral Detection Strategy for Exfiltration Over Alternative Protocol
---+Detection of CDNs
---+Detect Archiving via Custom Method (T1560.003)
---+Post-Credential Dump Password Cracking Detection via Suspicious File Access and Hash Analysis Tools
---+Behavioral Detection of Fallback or Alternate C2 Channels
---+Detection of Direct Volume Access for File System Evasion
---+Exploitation of Remote Services – multi-platform lateral movement detection
---+User Execution – Malicious Image (containers & IaaS) – pull/run → start → anomalous behavior (T1204.003)
---+Detect Code Signing Policy Modification (Windows & macOS)
---+Detection Strategy for System Services Service Execution
---+Detection Strategy for Rogue Domain Controller (DCShadow) Registration and Replication Abuse
---+Detection Strategy for Disable or Modify Cloud Log
---+Detect Suspicious Access to securityd Memory for Credential Extraction
---+Detect Shell Configuration Modification for Persistence via Event-Triggered Execution
---+Detection Strategy for Event Triggered Execution via emond on macOS
---+Detection Strategy for Network Boundary Bridging
---+Multi-Platform Software Discovery Behavior Chain
---+Detection Strategy for Masquerading via Account Name Similarity
---+TCC Database Manipulation via Launchctl and Unprotected SIP
---+Detect Kerberoasting Attempts (T1558.003)
---+Peripheral Device Enumeration via System Utilities and API Calls
---+Detection Strategy for PowerShell Profile Persistence via profile.ps1 Modification
---+Detection of Web Services
---+Detection Strategy for Network Device Configuration Dump via Config Repositories
---+Indirect Command Execution – Windows utility abuse behavior chain
---+Detection Strategy for T1547.015 – Login Items on macOS
---+Detection Strategy for Compressed Payload Creation and Execution
---+Detection of Direct VM Console Access via Cloud-Native Methods
---+Detecting MMC (.msc) Proxy Execution and Malicious COM Activation
---+Behavior-chain, platform-aware detection strategy for T1127 Trusted Developer Utilities Proxy Execution (Windows)
---+Detection Strategy for Input Injection
---+Detection of Identify Business Tempo
---+Detection Strategy for Modify Cloud Compute Infrastructure: Revert Cloud Instance
---+Email Forwarding Rule Abuse Detection Across Platforms
---+Detect Unauthorized Access to Cloud Secrets Management Stores
---+Detection of USB-Based Data Exfiltration
---+Behavioral Detection of Remote Cloud Logins via Valid Accounts
---+Detect Malicious Password Filter DLL Registration
---+Detection Strategy for File/Path Exclusions
---+Detection Strategy for Wi-Fi Networks
---+Cross-Platform Behavioral Detection of File Timestomping via Metadata Tampering
---+Detection of Scan Databases
---+Detection of Upload Malware
---+Detection of Suspicious Compiled HTML File Execution via hh.exe
---+Detection of Network Security Appliances
---+Detect unauthorized LSASS driver persistence via LSA plugin abuse (Windows)
---+Invalid Code Signature Execution Detection via Metadata and Behavioral Context
---+Detection Strategy for Cloud Administration Command
---+Detection Strategy for Modify Cloud Resource Hierarchy
---+Enumeration of User or Account Information Across Platforms
---+Behavioral Detection of Keylogging Activity Across Platforms
---+Detection for Spoofing Tool UI across OS Platforms
---+Detection Strategy for Device Driver Discovery
---+Detection Strategy for Data from Configuration Repository on Network Devices
---+Detection Strategy for Protocol Tunneling accross OS platforms.
---+Enterprise ATT&CK
------+Reconnaissance
---------+Gather Victim Host Information
------------+Hardware
------------+Client Configurations
------------+Firmware
------------+Software
---------+Query Public AI Services
---------+Search Victim-Owned Websites
---------+Gather Victim Identity Information
------------+Email Addresses
------------+Employee Names
------------+Credentials
---------+Search Open Technical Databases
------------+Digital Certificates
------------+WHOIS
------------+DNS/Passive DNS
------------+CDNs
------------+Scan Databases
---------+Search Threat Vendor Data
---------+Active Scanning
------------+Vulnerability Scanning
------------+Wordlist Scanning
------------+Scanning IP Blocks
---------+Gather Victim Org Information
------------+Identify Business Tempo
------------+Business Relationships
------------+Identify Roles
------------+Determine Physical Locations
---------+Gather Victim Network Information
------------+IP Addresses
------------+DNS
------------+Network Topology
------------+Network Trust Dependencies
------------+Network Security Appliances
------------+Domain Properties
---------+Search Open Websites/Domains
------------+Search Engines
------------+Code Repositories
------------+Social Media
---------+Search Closed Sources
------------+Purchase Technical Data
------------+Threat Intel Vendors
---------+Phishing for Information
------------+Spearphishing Link
------------+Spearphishing Voice
------------+Spearphishing Attachment
------------+Spearphishing Service
------+Resource Development
---------+Acquire Infrastructure
------------+Serverless
------------+Malvertising
------------+DNS Server
------------+Botnet
------------+Domains
------------+Server
------------+Virtual Private Server
------------+Web Services
---------+Compromise Infrastructure
------------+Network Devices
------------+Virtual Private Server
------------+Botnet
------------+Web Services
------------+DNS Server
------------+Serverless
------------+Server
------------+Domains
---------+Compromise Accounts
------------+Social Media Accounts
------------+Cloud Accounts
------------+Email Accounts
---------+Stage Capabilities
------------+Drive-by Target
------------+Upload Malware
------------+Upload Tool
------------+Link Target
------------+Install Digital Certificate
------------+SEO Poisoning
---------+Generate Content
------------+Written Content
------------+Audio-Visual Content
---------+Establish Accounts
------------+Email Accounts
------------+Cloud Accounts
------------+Social Media Accounts
---------+Obtain Capabilities
------------+Artificial Intelligence
------------+Digital Certificates
------------+Vulnerabilities
------------+Malware
------------+Tool
------------+Code Signing Certificates
------------+Exploits
---------+Acquire Access
---------+Develop Capabilities
------------+Digital Certificates
------------+Malware
------------+Code Signing Certificates
------------+Exploits
------+Initial Access
---------+External Remote Services
---------+Replication Through Removable Media
---------+Supply Chain Compromise
------------+Compromise Software Dependencies and Development Tools
------------+Compromise Hardware Supply Chain
------------+Compromise Software Supply Chain
---------+Exploit Public-Facing Application
---------+Content Injection
---------+Trusted Relationship
---------+Phishing
------------+Spearphishing Link
------------+Spearphishing Attachment
------------+Spearphishing Voice
------------+Spearphishing via Service
---------+Valid Accounts
------------+Default Accounts
------------+Domain Accounts
------------+Cloud Accounts
------------+Local Accounts
---------+Hardware Additions
---------+Drive-by Compromise
---------+Wi-Fi Networks
------+Execution
---------+Windows Management Instrumentation
---------+Shared Modules
---------+ESXi Administration Command
---------+Scheduled Task/Job
------------+Scheduled Task
------------+Container Orchestration Job
------------+Cron
------------+Launchd
------------+Systemd Timers
------------+At
---------+Native API
---------+Source
---------+Deploy Container
---------+Input Injection
---------+Command and Scripting Interpreter
------------+JavaScript
------------+AppleScript
------------+AutoHotKey & AutoIT
------------+Cloud API
------------+Network Device CLI
------------+PowerShell
------------+Unix Shell
------------+Lua
------------+Container CLI/API
------------+Python
------------+Windows Command Shell
------------+Hypervisor CLI
------------+Visual Basic
---------+Poisoned Pipeline Execution
---------+Component Object Model and Distributed COM
---------+Container Administration Command
---------+Scripting
---------+User Execution
------------+Malicious File
------------+Malicious Library
------------+Malicious Image
------------+Malicious Copy and Paste
------------+Malicious Link
---------+Software Deployment Tools
---------+Graphical User Interface
---------+Inter-Process Communication
------------+Dynamic Data Exchange
------------+Component Object Model
------------+XPC Services
---------+Hijack Execution Flow
------------+Path Interception by PATH Environment Variable
------------+Services Registry Permissions Weakness
------------+DLL
------------+AppDomainManager
------------+Path Interception by Search Order Hijacking
------------+Dynamic Linker Hijacking
------------+Executable Installer File Permissions Weakness
------------+Services File Permissions Weakness
------------+KernelCallbackTable
------------+Path Interception by Unquoted Path
------------+Dylib Hijacking
------------+COR_PROFILER
---------+Exploitation for Client Execution
---------+BITS Jobs
---------+System Services
------------+Systemctl
------------+Launchctl
------------+Service Execution
---------+Cloud Administration Command
---------+Serverless Execution
---------+Trusted Developer Utilities Proxy Execution
------------+JamPlus
------------+MSBuild
------------+ClickOnce
------+Persistence
---------+Boot or Logon Initialization Scripts
------------+Login Hook
------------+Startup Items
------------+Network Logon Script
------------+RC Scripts
------------+Logon Script (Windows)
---------+Create or Modify System Process
------------+Windows Service
------------+Launch Daemon
------------+Container Service
------------+Launch Agent
------------+Systemd Service
---------+Boot or Logon Autostart Execution
------------+Active Setup
------------+Print Processors
------------+Port Monitors
------------+Shortcut Modification
------------+Security Support Provider
------------+Time Providers
------------+Winlogon Helper DLL
------------+Login Items
------------+Registry Run Keys / Startup Folder
------------+Kernel Modules and Extensions
------------+Authentication Package
------------+XDG Autostart Entries
------------+Re-opened Applications
------------+LSASS Driver
---------+Office Application Startup
------------+Add-ins
------------+Outlook Rules
------------+Office Template Macros
------------+Outlook Forms
------------+Outlook Home Page
------------+Office Test
---------+Software Extensions
------------+Browser Extensions
------------+IDE Extensions
---------+Traffic Signaling
------------+Socket Filters
------------+Port Knocking
---------+Hypervisor
---------+Implant Internal Image
---------+Modify Registry
---------+Redundant Access
---------+Pre-OS Boot
------------+System Firmware
------------+Bootkit
------------+TFTP Boot
------------+Component Firmware
------------+ROMMONkit
---------+Compromise Host Software Binary
---------+Account Manipulation
------------+Additional Cloud Roles
------------+Additional Container Cluster Roles
------------+Additional Local or Domain Groups
------------+SSH Authorized Keys
------------+Device Registration
------------+Additional Cloud Credentials
------------+Additional Email Delegate Permissions
---------+Event Triggered Execution
------------+PowerShell Profile
------------+LC_LOAD_DYLIB Addition
------------+Application Shimming
------------+Trap
------------+Image File Execution Options Injection
------------+Accessibility Features
------------+AppCert DLLs
------------+Windows Management Instrumentation Event Subscription
------------+Change Default File Association
------------+Emond
------------+Unix Shell Configuration Modification
------------+Component Object Model Hijacking
------------+Python Startup Hooks
------------+AppInit DLLs
------------+Screensaver
------------+Installer Packages
------------+Udev Rules
------------+Netsh Helper DLL
---------+Cloud Application Integration
---------+Path Interception
---------+Server Software Component
------------+Transport Agent
------------+Terminal Services DLL
------------+Web Shell
------------+IIS Components
------------+vSphere Installation Bundles
------------+SQL Stored Procedures
---------+Exclusive Control
---------+Create Account
------------+Local Account
------------+Domain Account
------------+Cloud Account
---------+Power Settings
---------+Modify Authentication Process
------------+Pluggable Authentication Modules
------------+Password Filter DLL
------------+Hybrid Identity
------------+Network Provider DLL
------------+Multi-Factor Authentication
------------+Conditional Access Policies
------------+Domain Controller Authentication
------------+Reversible Encryption
------------+Network Device Authentication
------+Privilege Escalation
---------+Process Injection
------------+Extra Window Memory Injection
------------+Thread Execution Hijacking
------------+Process Doppelgänging
------------+Asynchronous Procedure Call
------------+Portable Executable Injection
------------+VDSO Hijacking
------------+Process Hollowing
------------+Proc Memory
------------+Thread Local Storage
------------+Ptrace System Calls
------------+ListPlanting
------------+Dynamic-link Library Injection
---------+Escape to Host
---------+Abuse Elevation Control Mechanism
------------+Bypass User Account Control
------------+Sudo and Sudo Caching
------------+Setuid and Setgid
------------+Temporary Elevated Cloud Access
------------+Elevated Execution with Prompt
------------+TCC Manipulation
---------+Exploitation for Privilege Escalation
---------+Access Token Manipulation
------------+Create Process with Token
------------+Token Impersonation/Theft
------------+Make and Impersonate Token
------------+Parent PID Spoofing
------------+SID-History Injection
---------+Domain or Tenant Policy Modification
------------+Trust Modification
------------+Group Policy Modification
------+Stealth
---------+Direct Volume Access
---------+Rootkit
---------+Hide Artifacts
------------+File/Path Exclusions
------------+Email Hiding Rules
------------+Ignore Process Interrupts
------------+Bind Mounts
------------+Extended Attributes
------------+Hidden Users
------------+Resource Forking
------------+Run Virtual Instance
------------+VBA Stomping
------------+Hidden Window
------------+Hidden File System
------------+Hidden Files and Directories
------------+NTFS File Attributes
------------+Process Argument Spoofing
---------+Indirect Command Execution
---------+Deobfuscate/Decode Files or Information
---------+Social Engineering
------------+Impersonation
------------+Email Spoofing
---------+Masquerading
------------+Double File Extension
------------+Match Legitimate Resource Name or Location
------------+Masquerade File Type
------------+Break Process Trees
------------+Overwrite Process Arguments
------------+Right-to-Left Override
------------+Masquerade Task or Service
------------+Browser Fingerprint
------------+Invalid Code Signature
------------+Rename Legitimate Utilities
------------+Masquerade Account Name
------------+Space after Filename
---------+System Binary Proxy Execution
------------+Rundll32
------------+Mavinject
------------+InstallUtil
------------+Msiexec
------------+CMSTP
------------+Control Panel
------------+Electron Applications
------------+Odbcconf
------------+Verclsid
------------+Mshta
------------+Compiled HTML File
------------+Regsvr32
------------+Regsvcs/Regasm
------------+MMC
---------+Reflective Code Loading
---------+Unused/Unsupported Cloud Regions
---------+Indicator Removal
------------+Clear Network Connection History and Configurations
------------+Clear Command History
------------+Clear Mailbox Data
------------+Timestomp
------------+Network Share Connection Removal
------------+Relocate Malware
------------+Clear Persistence
------------+File Deletion
---------+Build Image on Host
---------+Virtualization/Sandbox Evasion
------------+System Checks
------------+Time Based Checks
------------+User Activity Based Checks
---------+Execution Guardrails
------------+Mutual Exclusion
------------+Environmental Keying
---------+Selective Exclusion
---------+LC_MAIN Hijacking
---------+Delay Execution
---------+Obfuscated Files or Information
------------+Fileless Storage
------------+Embedded Payloads
------------+Encrypted/Encoded File
------------+Stripped Payloads
------------+Binary Padding
------------+Junk Code Insertion
------------+SVG Smuggling
------------+LNK Icon Smuggling
------------+Indicator Removal from Tools
------------+Polymorphic Code
------------+Steganography
------------+Compile After Delivery
------------+HTML Smuggling
------------+Command Obfuscation
------------+Software Packing
------------+Invisible Unicode
------------+Dynamic API Resolution
------------+Compression
---------+Template Injection
---------+Debugger Evasion
---------+XSL Script Processing
---------+System Script Proxy Execution
------------+PubPrn
------------+SyncAppvPublishingServer
---------+Exploitation for Stealth
------+Defense Impairment
---------+Exploitation for Defense Impairment
---------+Modify Cloud Resource Hierarchy
---------+Modify Cloud Compute Infrastructure
------------+Revert Cloud Instance
------------+Delete Cloud Instance
------------+Modify Cloud Compute Configurations
------------+Create Cloud Instance
------------+Create Snapshot
---------+Weaken Encryption
------------+Reduce Key Space
------------+Disable Crypto Hardware
---------+Downgrade Attack
---------+Rogue Domain Controller
---------+File and Directory Permissions Modification
------------+Linux and Mac Permissions
------------+Windows Permissions
---------+Plist File Modification
---------+Modify System Image
------------+Patch System Image
------------+Downgrade System Image
---------+Network Boundary Bridging
------------+Network Address Translation Traversal
---------+Prevent Command History Logging
---------+Subvert Trust Controls
------------+Gatekeeper Bypass
------------+Code Signing
------------+SIP and Trust Provider Hijacking
------------+Code Signing Policy Modification
------------+Mark-of-the-Web Bypass
------------+Install Root Certificate
---------+Disable or Modify Tools
------------+Modify or Spoof Tool UI
------------+Disable or Modify Windows Event Log
------------+Disable or Modify Linux Audit System Log
------------+Disable or Modify Cloud Log
------------+Clear Linux or Mac System Logs
------------+Clear Windows Event Logs
---------+Safe Mode Boot
---------+Disable or Modify System Firewall
------------+Windows Host Firewall
------------+Network Device Firewall
------------+Cloud Firewall
------+Credential Access
---------+Adversary-in-the-Middle
------------+Evil Twin
------------+DHCP Spoofing
------------+Name Resolution Poisoning and SMB Relay
------------+ARP Cache Poisoning
---------+OS Credential Dumping
------------+Security Account Manager
------------+LSA Secrets
------------+Proc Filesystem
------------+LSASS Memory
------------+Cached Domain Credentials
------------+/etc/passwd and /etc/shadow
------------+NTDS
------------+DCSync
---------+Steal Web Session Cookie
---------+Network Sniffing
---------+Steal or Forge Kerberos Tickets
------------+Ccache Files
------------+AS-REP Roasting
------------+Golden Ticket
------------+Silver Ticket
------------+Kerberoasting
---------+Credentials from Password Stores
------------+Securityd Memory
------------+Keychain
------------+Password Managers
------------+Credentials from Web Browsers
------------+Cloud Secrets Management Stores
------------+Windows Credential Manager
---------+Unsecured Credentials
------------+Cloud Instance Metadata API
------------+Credentials in Registry
------------+Private Keys
------------+Shell History
------------+Credentials In Files
------------+Group Policy Preferences
------------+Chat Messages
------------+Container API
---------+Steal or Forge Authentication Certificates
---------+Steal Application Access Token
---------+Forge Web Credentials
------------+SAML Tokens
------------+Web Cookies
---------+Multi-Factor Authentication Request Generation
---------+Exploitation for Credential Access
---------+Brute Force
------------+Password Guessing
------------+Password Cracking
------------+Password Spraying
------------+Credential Stuffing
---------+Forced Authentication
---------+Input Capture
------------+Keylogging
------------+Web Portal Capture
------------+GUI Input Capture
------------+Credential API Hooking
---------+Multi-Factor Authentication Interception
------+Discovery
---------+System Owner/User Discovery
---------+Container and Resource Discovery
---------+Permission Groups Discovery
------------+Cloud Groups
------------+Domain Groups
------------+Local Groups
---------+Group Policy Discovery
---------+Device Driver Discovery
---------+System Service Discovery
---------+Network Share Discovery
---------+Peripheral Device Discovery
---------+System Information Discovery
---------+Application Window Discovery
---------+Cloud Infrastructure Discovery
---------+Browser Information Discovery
---------+Virtual Machine Discovery
---------+System Network Configuration Discovery
------------+Internet Connection Discovery
------------+Wi-Fi Discovery
---------+Account Discovery
------------+Domain Account
------------+Local Account
------------+Email Account
------------+Cloud Account
---------+Domain Trust Discovery
---------+File and Directory Discovery
---------+System Network Connections Discovery
---------+Cloud Storage Object Discovery
---------+Log Enumeration
---------+Process Discovery
---------+Password Policy Discovery
---------+Query Registry
---------+System Location Discovery
------------+System Language Discovery
---------+Cloud Service Discovery
---------+Remote System Discovery
---------+Network Service Discovery
---------+Software Discovery
------------+Backup Software Discovery
------------+Security Software Discovery
---------+Cloud Service Dashboard
---------+Local Storage Discovery
---------+System Time Discovery
------+Lateral Movement
---------+Taint Shared Content
---------+Use Alternate Authentication Material
------------+Pass the Ticket
------------+Web Session Cookie
------------+Pass the Hash
------------+Application Access Token
---------+Remote Services
------------+VNC
------------+SSH
------------+Direct Cloud VM Connections
------------+SMB/Windows Admin Shares
------------+Windows Remote Management
------------+Distributed Component Object Model
------------+Cloud Services
------------+Remote Desktop Protocol
---------+Remote Service Session Hijacking
------------+SSH Hijacking
------------+RDP Hijacking
---------+Shared Webroot
---------+Exploitation of Remote Services
---------+Internal Spearphishing
---------+Lateral Tool Transfer
------+Collection
---------+Screen Capture
---------+Data from Configuration Repository
------------+Network Device Configuration Dump
------------+SNMP (MIB Dump)
---------+Audio Capture
---------+Email Collection
------------+Local Email Collection
------------+Email Forwarding Rule
------------+Remote Email Collection
---------+Data from Removable Media
---------+Automated Collection
---------+Clipboard Data
---------+Data from Cloud Storage
---------+Data from Local System
---------+Archive Collected Data
------------+Archive via Utility
------------+Archive via Custom Method
------------+Archive via Library
---------+Browser Session Hijacking
---------+Video Capture
---------+Data Staged
------------+Local Data Staging
------------+Remote Data Staging
---------+Data from Network Shared Drive
---------+Data from Information Repositories
------------+Sharepoint
------------+Databases
------------+Confluence
------------+Customer Relationship Management Software
------------+Code Repositories
------------+Messaging Applications
------+Command and Control
---------+Application Layer Protocol
------------+DNS
------------+Publish/Subscribe Protocols
------------+Mail Protocols
------------+File Transfer Protocols
------------+Web Protocols
---------+Remote Access Tools
------------+IDE Tunneling
------------+Remote Access Hardware
------------+Remote Desktop Software
---------+Protocol Tunneling
---------+Communication Through Removable Media
---------+Proxy
------------+External Proxy
------------+Multi-hop Proxy
------------+Domain Fronting
------------+Internal Proxy
---------+Dynamic Resolution
------------+Domain Generation Algorithms
------------+Fast Flux DNS
------------+DNS Calculation
---------+Web Service
------------+One-Way Communication
------------+Bidirectional Communication
------------+Dead Drop Resolver
---------+Multi-Stage Channels
---------+Multiband Communication
---------+Data Obfuscation
------------+Protocol or Service Impersonation
------------+Steganography
------------+Junk Data
---------+Non-Standard Port
---------+Encrypted Channel
------------+Symmetric Cryptography
------------+Asymmetric Cryptography
---------+Non-Application Layer Protocol
---------+Data Encoding
------------+Standard Encoding
------------+Non-Standard Encoding
---------+Ingress Tool Transfer
---------+Hide Infrastructure
---------+Fallback Channels
---------+Commonly Used Port
------+Exfiltration
---------+Exfiltration Over Web Service
------------+Exfiltration Over Webhook
------------+Exfiltration to Code Repository
------------+Exfiltration to Text Storage Sites
------------+Exfiltration to Cloud Storage
---------+Scheduled Transfer
---------+Exfiltration Over Other Network Medium
------------+Exfiltration Over Bluetooth
---------+Automated Exfiltration
------------+Traffic Duplication
---------+Exfiltration Over C2 Channel
---------+Exfiltration Over Alternative Protocol
------------+Exfiltration Over Symmetric Encrypted Non-C2 Protocol
------------+Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
------------+Exfiltration Over Unencrypted Non-C2 Protocol
---------+Data Transfer Size Limits
---------+Transfer Data to Cloud Account
---------+Exfiltration Over Physical Medium
------------+Exfiltration over USB
------+Impact
---------+Disk Wipe
------------+Disk Structure Wipe
------------+Disk Content Wipe
---------+Service Stop
---------+Defacement
------------+External Defacement
------------+Internal Defacement
---------+Financial Theft
---------+Data Manipulation
------------+Stored Data Manipulation
------------+Runtime Data Manipulation
------------+Transmitted Data Manipulation
---------+Account Access Removal
---------+Data Encrypted for Impact
---------+Email Bombing
---------+Endpoint Denial of Service
------------+OS Exhaustion Flood
------------+Application Exhaustion Flood
------------+Application or System Exploitation
------------+Service Exhaustion Flood
---------+Resource Hijacking
------------+SMS Pumping
------------+Bandwidth Hijacking
------------+Cloud Service Hijacking
------------+Compute Hijacking
---------+Data Destruction
------------+Lifecycle-Triggered Deletion
---------+Network Denial of Service
------------+Direct Network Flood
------------+Reflection Amplification
---------+Firmware Corruption
---------+Inhibit System Recovery
---------+System Shutdown/Reboot
|
Enterprise ATT&CK
ATT&CK for Enterprise provides a knowledge base of real-world adversary behavior targeting traditional enterprise networks. ATT&CK for Enterprise covers the following platforms: Windows, macOS, Linux, PRE, Office 365, Google Workspace, IaaS, Network, and Containers.
1. Overview
| Summary |
Standard |
|
Password Filter DLL Mitigation
|
Ensure only valid password filters are registered. Filter DLLs must be present in Windows installation directory (C:\Windows\System32\ by default) of a domain controller and/or local computer with a corresponding entry in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages. (Citation: Microsoft Install Password Filter n.d)
|
|
Space after Filename Mitigation
|
Prevent files from having a trailing space after the extension.
|
|
HISTCONTROL Mitigation
|
Prevent users from changing the HISTCONTROL environment variable (Citation: Securing bash history). Also, make sure that the HISTCONTROL environment variable is set to “ignoredup” instead of “ignoreboth” or “ignorespace”.
|
|
Credentials in Files Mitigation
|
Establish an organizational policy that prohibits password storage in files. Ensure that developers and system administrators are aware of the risk associated with having plaintext passwords in software configuration files that may be left on endpoint systems or servers. Preemptively search for files containing passwords and remove when found. Restrict file shares to specific directories with access only to necessary users. Remove vulnerable Group Policy Preferences. (Citation: Microsoft MS14-025)
|
|
Exploitation for Credential Access Mitigation
|
Update software regularly by employing patch management for internal enterprise endpoints and servers. Develop a robust cyber threat intelligence capability to determine what types and levels of threat may use software exploits and 0-days against a particular organization. Make it difficult for adversaries to advance their operation through exploitation of undiscovered or unpatched vulnerabilities by using sandboxing, if available. Other types of virtualization and application microsegmentation may also mitigate the impact of some types of exploitation. The risks of additional exploits and weaknesses in implementation may still exist. (Citation: Ars Technica Pwn2Own 2017 VM Escape)
Security applications that look for behavior used during exploitation such as Windows Defender Exploit Guard (WDEG) and the Enhanced Mitigation Experience Toolkit (EMET) can be used to mitigate some exploitation behavior. (Citation: TechNet Moving Beyond EMET) Control flow integrity checking is another way to potentially identify and stop a software exploit from occurring. (Citation: Wikipedia Control Flow Integrity) Many of these protections depend on the architecture and target application binary for compatibility and may not work for software targeted for defense evasion.
|
|
Query Registry Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to acquire information within the Registry, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Login Item Mitigation
|
Restrict users from being able to create their own login items. Additionally, holding the shift key during login prevents apps from opening automatically (Citation: Re-Open windows on Mac).
|
|
Setuid and Setgid Mitigation
|
Applications with known vulnerabilities or known shell escapes should not have the setuid or setgid bits set to reduce potential damage if an application is compromised. Additionally, the number of programs with setuid or setgid bits set should be minimized across a system.
|
|
Compiled HTML File Mitigation
|
Consider blocking download/transfer and execution of potentially uncommon file types known to be used in adversary campaigns, such as CHM files. (Citation: PaloAlto Preventing Opportunistic Attacks Apr 2016) Also consider using application whitelisting to prevent execution of hh.exe if it is not required for a given system or network to prevent potential misuse by adversaries.
|
|
Data Destruction Mitigation
|
Consider implementing IT disaster recovery plans that contain procedures for taking regular data backups that can be used to restore organizational data.(Citation: Ready.gov IT DRP) Ensure backups are stored off system and is protected from common methods adversaries may use to gain access and destroy the backups to prevent recovery.
Identify potentially malicious software and audit and/or block it by using whitelisting(Citation: Beechey 2010) tools, like AppLocker,(Citation: Windows Commands JPCERT)(Citation: NSA MS AppLocker) or Software Restriction Policies(Citation: Corio 2008) where appropriate.(Citation: TechNet Applocker vs SRP)
|
|
Windows Management Instrumentation Event Subscription Mitigation
|
Disabling WMI services may cause system instability and should be evaluated to assess the impact to a network. By default, only administrators are allowed to connect remotely using WMI; restrict other users that are allowed to connect, or disallow all users from connecting remotely to WMI. Prevent credential overlap across systems of administrator and privileged accounts. (Citation: FireEye WMI 2015)
|
|
File System Permissions Weakness Mitigation
|
Use auditing tools capable of detecting file system permissions abuse opportunities on systems within an enterprise and correct them. Limit privileges of user accounts and groups so that only authorized administrators can interact with service changes and service binary target path locations. Toolkits like the PowerSploit framework contain PowerUp modules that can be used to explore systems for service file system permissions weaknesses. (Citation: Powersploit)
Identify and block potentially malicious software that may be executed through abuse of file, directory, and service permissions by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) that are capable of auditing and/or blocking unknown programs. Deny execution from user directories such as file download directories and temp directories where able. (Citation: Seclists Kanthak 7zip Installer)
Turn off UAC's privilege elevation for standard users [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]to automatically deny elevation requests, add: "ConsentPromptBehaviorUser"=dword:00000000 (Citation: Seclists Kanthak 7zip Installer). Consider enabling installer detection for all users by adding: "EnableInstallerDetection"=dword:00000001. This will prompt for a password for installation and also log the attempt. To disable installer detection, instead add: "EnableInstallerDetection"=dword:00000000. This may prevent potential elevation of privileges through exploitation during the process of UAC detecting the installer, but will allow the installation process to continue without being logged.
|
|
AppInit DLLs Mitigation
|
Upgrade to Windows 8 or later and enable secure boot.
Identify and block potentially malicious software that may be executed through AppInit DLLs by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) that are capable of auditing and/or blocking unknown DLLs.
|
|
Launch Agent Mitigation
|
Restrict user's abilities to create Launch Agents with group policy.
|
|
Network Intrusion Prevention
|
Use intrusion detection signatures to block traffic at network boundaries.
|
|
Regsvr32 Mitigation
|
Microsoft's Enhanced Mitigation Experience Toolkit (EMET) Attack Surface Reduction (ASR) feature can be used to block regsvr32.exe from being used to bypass whitelisting. (Citation: Secure Host Baseline EMET)
|
|
Hidden Users Mitigation
|
If the computer is domain joined, then group policy can help restrict the ability to create or hide users. Similarly, preventing the modification of the /Library/Preferences/com.apple.loginwindow Hide500Users value will force all users to be visible.
|
|
Data from Information Repositories Mitigation
|
To mitigate adversary access to information repositories for collection:
* Develop and publish policies that define acceptable information to be stored
* Appropriate implementation of access control mechanisms that include both authentication and appropriate authorization
* Enforce the principle of least-privilege
* Periodic privilege review of accounts
* Mitigate access to [Valid Accounts](https://attack.mitre.org/techniques/T1078) that may be used to access repositories
|
|
Exploitation of Remote Services Mitigation
|
Segment networks and systems appropriately to reduce access to critical systems and services to controlled methods. Minimize available services to only those that are necessary. Regularly scan the internal network for available services to identify new and potentially vulnerable services. Minimize permissions and access for service accounts to limit impact of exploitation.
Update software regularly by employing patch management for internal enterprise endpoints and servers. Develop a robust cyber threat intelligence capability to determine what types and levels of threat may use software exploits and 0-days against a particular organization. Make it difficult for adversaries to advance their operation through exploitation of undiscovered or unpatched vulnerabilities by using sandboxing, if available. Other types of virtualization and application microsegmentation may also mitigate the impact of some types of exploitation. The risks of additional exploits and weaknesses in implementation may still exist. (Citation: Ars Technica Pwn2Own 2017 VM Escape)
Security applications that look for behavior used during exploitation such as Windows Defender Exploit Guard (WDEG) and the Enhanced Mitigation Experience Toolkit (EMET) can be used to mitigate some exploitation behavior. (Citation: TechNet Moving Beyond EMET) Control flow integrity checking is another way to potentially identify and stop a software exploit from occurring. (Citation: Wikipedia Control Flow Integrity) Many of these protections depend on the architecture and target application binary for compatibility and may not work for all software or services targeted.
|
|
Vulnerability Scanning
|
Vulnerability scanning involves the automated or manual assessment of systems, applications, and networks to identify misconfigurations, unpatched software, or other security weaknesses. The process helps prioritize remediation efforts by classifying vulnerabilities based on risk and impact, reducing the likelihood of exploitation by adversaries. This mitigation can be implemented through the following measures:
Proactive Identification of Vulnerabilities
- Implementation: Use tools like Nessus or OpenVAS to scan endpoints, servers, and applications for missing patches and configuration issues. Schedule regular scans to ensure timely identification of vulnerabilities introduced by new deployments or updates.
- Use Case: A scan identifies unpatched software, such as outdated Apache servers, which could be exploited via CVE-XXXX-XXXX. The server is promptly patched, mitigating the risk.
Cloud Environment Scanning
- Implementation: Use cloud-specific vulnerability management tools like AWS Inspector, Azure Security Center, or GCP Security Command Center to identify issues like open S3 buckets or overly permissive IAM roles.
- Use Case: The scan detects a misconfigured S3 bucket with public read access, which is remediated to prevent potential data leakage.
Network Device Scanning
- Implementation: Use tools to scan network devices for vulnerabilities, such as weak SNMP strings or outdated firmware. Correlate scan results with vendor advisories to prioritize updates.
- Use Case: Scanning detects a router running outdated firmware vulnerable to CVE-XXXX-YYYY. The firmware is updated to a secure version.
Web Application Scanning
- Implementation: Use dynamic application security testing (DAST) tools such as OWASP ZAP or Burp Suite to scan for common vulnerabilities like SQL injection or cross-site scripting (XSS). Perform regular scans post-deployment to identify newly introduced vulnerabilities.
- Use Case: A scan identifies a cross-site scripting vulnerability in a form input field, which is promptly remediated by developers.
Prioritizing Vulnerabilities
- Implementation: Use vulnerability scoring frameworks like CVSS to assess severity.
Integrate vulnerability scanning tools with ticketing systems to assign remediation tasks based on criticality.
- Use Case: A critical vulnerability with a CVSS score of 9.8 affecting remote access servers is prioritized and patched first.
*Tools for Implementation*
Open Source Tools:
- OpenVAS: Comprehensive network and system vulnerability scanning.
- OWASP ZAP: Dynamic scanning of web applications for vulnerabilities.
- Nmap with NSE Scripts: Network scanning with scripts to detect vulnerabilities.
|
|
Domain Trust Discovery Mitigation
|
Map the trusts within existing domains/forests and keep trust relationships to a minimum. Employ network segmentation for sensitive domains.(Citation: Harmj0y Domain Trusts)
|
|
Third-party Software Mitigation
|
Evaluate the security of third-party software that could be used in the enterprise environment. Ensure that access to management systems for third-party systems is limited, monitored, and secure. Have a strict approval policy for use of third-party systems.
Grant access to Third-party systems only to a limited number of authorized administrators. Ensure proper system and access isolation for critical network systems through use of firewalls, account privilege separation, group policy, and multi-factor authentication. Verify that account credentials that may be used to access third-party systems are unique and not used throughout the enterprise network. Ensure that any accounts used by third-party providers to access these systems are traceable to the third-party and are not used throughout the network or used by other third-party providers in the same environment. Ensure third-party systems are regularly patched by users or the provider to prevent potential remote access through [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068).
Ensure there are regular reviews of accounts provisioned to these systems to verify continued business need, and ensure there is governance to trace de-provisioning of access that is no longer required.
Where the third-party system is used for deployment services, ensure that it can be configured to deploy only signed binaries, then ensure that the trusted signing certificates are not co-located with the third-party system and are instead located on a system that cannot be accessed remotely or to which remote access is tightly controlled.
|
|
Binary Padding Mitigation
|
Identify potentially malicious software that may be executed from a padded or otherwise obfuscated binary, and audit and/or block it by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Audio Capture Mitigation
|
Mitigating this technique specifically may be difficult as it requires fine-grained API control. Efforts should be focused on preventing unwanted or unknown code from executing on a system.
Identify and block potentially malicious software that may be used to record audio by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
System Owner/User Discovery Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to acquire information about system users, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Peripheral Device Discovery Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to acquire information about peripheral devices, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Clipboard Data Mitigation
|
Instead of blocking software based on clipboard capture behavior, identify potentially malicious software that may contain this functionality, and audit and/or block it by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Gatekeeper Bypass Mitigation
|
Other tools should be used to supplement Gatekeeper's functionality. Additionally, system settings can prevent applications from running that haven't been downloaded through the Apple Store which can help mitigate some of these issues.
|
|
Scheduled Transfer Mitigation
|
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary command and control infrastructure and malware can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific obfuscation technique used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool command and control signatures over time or construct protocols in such a way to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Browser Bookmark Discovery Mitigation
|
File system activity is a common part of an operating system, so it is unlikely that mitigation would be appropriate for this technique. For example, mitigating accesses to browser bookmark files will likely have unintended side effects such as preventing legitimate software from operating properly. Efforts should be focused on preventing adversary tools from running earlier in the chain of activity and on identification of subsequent malicious behavior. It may still be beneficial to identify and block unnecessary system utilities or potentially malicious software by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Port Monitors Mitigation
|
Identify and block potentially malicious software that may persist in this manner by using whitelisting (Citation: Beechey 2010) tools capable of monitoring DLL loads by processes running under SYSTEM permissions.
|
|
Limit Access to Resource Over Network
|
Restrict access to network resources, such as file shares, remote systems, and services, to only those users, accounts, or systems with a legitimate business requirement. This can include employing technologies like network concentrators, RDP gateways, and zero-trust network access (ZTNA) models, alongside hardening services and protocols. This mitigation can be implemented through the following measures:
Audit and Restrict Access:
- Regularly audit permissions for file shares, network services, and remote access tools.
- Remove unnecessary access and enforce least privilege principles for users and services.
- Use Active Directory and IAM tools to restrict access based on roles and attributes.
Deploy Secure Remote Access Solutions:
- Use RDP gateways, VPN concentrators, and ZTNA solutions to aggregate and secure remote access connections.
- Configure access controls to restrict connections based on time, device, and user identity.
- Enforce MFA for all remote access mechanisms.
Disable Unnecessary Services:
- Identify running services using tools like netstat (Windows/Linux) or Nmap.
- Disable unused services, such as Telnet, FTP, and legacy SMB, to reduce the attack surface.
- Use firewall rules to block traffic on unused ports and protocols.
Network Segmentation and Isolation:
- Use VLANs, firewalls, or micro-segmentation to isolate critical network resources from general access.
- Restrict communication between subnets to prevent lateral movement.
Monitor and Log Access:
- Monitor access attempts to file shares, RDP, and remote network resources using SIEM tools.
- Enable auditing and logging for successful and failed attempts to access restricted resources.
*Tools for Implementation*
File Share Management:
- Microsoft Active Directory Group Policies
- Samba (Linux/Unix file share management)
- AccessEnum (Windows access auditing tool)
Secure Remote Access:
- Microsoft Remote Desktop Gateway
- Apache Guacamole (open-source RDP/VNC gateway)
- Zero Trust solutions: Tailscale, Cloudflare Zero Trust
Service and Protocol Hardening:
- Nmap or Nessus for network service discovery
- Windows Group Policy Editor for disabling SMBv1, Telnet, and legacy protocols
- iptables or firewalld (Linux) for blocking unnecessary traffic
Network Segmentation:
- pfSense for open-source network isolation
|
|
AppleScript Mitigation
|
Require that all AppleScript be signed by a trusted developer ID before being executed - this will prevent random AppleScript code from executing (Citation: applescript signing). This subjects AppleScript code to the same scrutiny as other .app files passing through Gatekeeper.
|
|
Indirect Command Execution Mitigation
|
Identify or block potentially malicious software that may contain abusive functionality by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP). These mechanisms can also be used to disable and/or limit user access to Windows utilities and file types/locations used to invoke malicious execution.(Citation: SpectorOPs SettingContent-ms Jun 2018)
|
|
Network Share Discovery Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to acquire network share information, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Remote Data Storage
|
Remote Data Storage focuses on moving critical data, such as security logs and sensitive files, to secure, off-host locations to minimize unauthorized access, tampering, or destruction by adversaries. By leveraging remote storage solutions, organizations enhance the protection of forensic evidence, sensitive information, and monitoring data. This mitigation can be implemented through the following measures:
Centralized Log Management:
- Configure endpoints to forward security logs to a centralized log collector or SIEM.
- Use tools like Splunk Graylog, or Security Onion to aggregate and store logs.
- Example command (Linux): `sudo auditd | tee /var/log/audit/audit.log | nc 514`
Remote File Storage Solutions:
- Utilize cloud storage solutions like AWS S3, Google Cloud Storage, or Azure Blob Storage for sensitive data.
- Ensure proper encryption at rest and access control policies (IAM roles, ACLs).
Intrusion Detection Log Forwarding:
- Forward logs from IDS/IPS systems (e.g., Zeek/Suricata) to a remote security information system.
- Example for Suricata log forwarding:
`outputs:
- type: syslog
protocol: tls
address: `
Immutable Backup Configurations:
- Enable immutable storage settings for backups to prevent adversaries from modifying or deleting data.
- Example: AWS S3 Object Lock.
Data Encryption:
- Ensure encryption for sensitive data using AES-256 at rest and TLS 1.2+ for data in transit.
Tools: OpenSSL, BitLocker, LUKS for Linux.
|
|
Filter Network Traffic
|
Employ network appliances and endpoint software to filter ingress, egress, and lateral network traffic. This includes protocol-based filtering, enforcing firewall rules, and blocking or restricting traffic based on predefined conditions to limit adversary movement and data exfiltration. This mitigation can be implemented through the following measures:
Ingress Traffic Filtering:
- Use Case: Configure network firewalls to allow traffic only from authorized IP addresses to public-facing servers.
- Implementation: Limit SSH (port 22) and RDP (port 3389) traffic to specific IP ranges.
Egress Traffic Filtering:
- Use Case: Use firewalls or endpoint security software to block unauthorized outbound traffic to prevent data exfiltration and command-and-control (C2) communications.
- Implementation: Block outbound traffic to known malicious IPs or regions where communication is unexpected.
Protocol-Based Filtering:
- Use Case: Restrict the use of specific protocols that are commonly abused by adversaries, such as SMB, RPC, or Telnet, based on business needs.
- Implementation: Disable SMBv1 on endpoints to prevent exploits like EternalBlue.
Network Segmentation:
- Use Case: Create network segments for critical systems and restrict communication between segments unless explicitly authorized.
- Implementation: Implement VLANs to isolate IoT devices or guest networks from core business systems.
Application Layer Filtering:
- Use Case: Use proxy servers or Web Application Firewalls (WAFs) to inspect and block malicious HTTP/S traffic.
- Implementation: Configure a WAF to block SQL injection attempts or other web application exploitation techniques.
|
|
Restrict Web-Based Content
|
Restricting web-based content involves enforcing policies and technologies that limit access to potentially malicious websites, unsafe downloads, and unauthorized browser behaviors. This can include URL filtering, download restrictions, script blocking, and extension control to protect against exploitation, phishing, and malware delivery. This mitigation can be implemented through the following measures:
Deploy Web Proxy Filtering:
- Use solutions to filter web traffic based on categories, reputation, and content types.
- Enforce policies that block unsafe websites or file types at the gateway level.
Enable DNS-Based Filtering:
- Implement tools to restrict access to domains associated with malware or phishing campaigns.
- Use public DNS filtering services to enhance protection.
Enforce Content Security Policies (CSP):
- Configure CSP headers on internal and external web applications to restrict script execution, iframe embedding, and cross-origin requests.
Control Browser Features:
- Disable unapproved browser features like automatic downloads, developer tools, or unsafe scripting.
- Enforce policies through tools like Group Policy Management to control browser settings.
Monitor and Alert on Web-Based Threats:
- Use SIEM tools to collect and analyze web proxy logs for signs of anomalous or malicious activity.
- Configure alerts for access attempts to blocked domains or repeated file download failures.
|
|
Install Root Certificate Mitigation
|
HTTP Public Key Pinning (HPKP) is one method to mitigate potential man-in-the-middle situations where and adversary uses a mis-issued or fraudulent certificate to intercept encrypted communications by enforcing use of an expected certificate. (Citation: Wikipedia HPKP)
Windows Group Policy can be used to manage root certificates and the Flags value of HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots can be set to 1 to prevent non-administrator users from making further root installations into their own HKCU certificate store. (Citation: SpectorOps Code Signing Dec 2017)
|
|
Limit Software Installation
|
Prevent users or groups from installing unauthorized or unapproved software to reduce the risk of introducing malicious or vulnerable applications. This can be achieved through allowlists, software restriction policies, endpoint management tools, and least privilege access principles. This mitigation can be implemented through the following measures:
Application Whitelisting
- Implement Microsoft AppLocker or Windows Defender Application Control (WDAC) to create and enforce allowlists for approved software.
- Whitelist applications based on file hash, path, or digital signatures.
Restrict User Permissions
- Remove local administrator rights for all non-IT users.
- Use Role-Based Access Control (RBAC) to restrict installation permissions to privileged accounts only.
Software Restriction Policies (SRP)
- Use GPO to configure SRP to deny execution of binaries from directories such as `%AppData%`, `%Temp%`, and external drives.
- Restrict specific file types (`.exe`, `.bat`, `.msi`, `.js`, `.vbs`) to trusted directories only.
Endpoint Management Solutions
- Deploy tools like Microsoft Intune, SCCM, or Jamf for centralized software management.
- Maintain a list of approved software, versions, and updates across the enterprise.
Monitor Software Installation Events
- Enable logging of software installation events and monitor Windows Event ID 4688 and Event ID 11707 for software installs.
- Use SIEM or EDR tools to alert on attempts to install unapproved software.
Implement Software Inventory Management
- Use tools like OSQuery or Wazuh to scan for unauthorized software on endpoints and servers.
- Conduct regular audits to detect and remove unapproved software.
*Tools for Implementation*
Application Whitelisting:
- Microsoft AppLocker
- Windows Defender Application Control (WDAC)
Endpoint Management:
- Microsoft Intune
- SCCM (System Center Configuration Manager)
- Jamf Pro (macOS)
- Puppet or Ansible for automation
Software Restriction Policies:
- Group Policy Object (GPO)
- Microsoft Software Restriction Policies (SRP)
Monitoring and Logging:
- Splunk
- OSQuery
- Wazuh (open-source SIEM and XDR)
- EDRs
Inventory Management and Auditing:
- OSQuery
- Wazuh
|
|
Sudo Mitigation
|
The sudoers file should be strictly edited such that passwords are always required and that users can’t spawn risky processes as users with higher privilege. By requiring a password, even if an adversary can get terminal access, they must know the password to run anything in the sudoers file.
|
|
Multilayer Encryption Mitigation
|
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Use of encryption protocols may make typical network-based C2 detection more difficult due to a reduced ability to signature the traffic. Prior knowledge of adversary C2 infrastructure may be useful for domain and IP address blocking, but will likely not be an effective long-term solution because adversaries can change infrastructure often. (Citation: University of Birmingham C2)
|
|
Transmitted Data Manipulation Mitigation
|
Identify critical business and system processes that may be targeted by adversaries and work to secure communications related to those processes against tampering. Encrypt all important data flows to reduce the impact of tailored modifications on data in transit.
|
|
Automated Exfiltration Mitigation
|
Identify unnecessary system utilities, scripts, or potentially malicious software that may be used to transfer data outside of a network, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Application Window Discovery Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to acquire information, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Application Developer Guidance
|
Application Developer Guidance focuses on providing developers with the knowledge, tools, and best practices needed to write secure code, reduce vulnerabilities, and implement secure design principles. By integrating security throughout the software development lifecycle (SDLC), this mitigation aims to prevent the introduction of exploitable weaknesses in applications, systems, and APIs. This mitigation can be implemented through the following measures:
Preventing SQL Injection (Secure Coding Practice):
- Implementation: Train developers to use parameterized queries or prepared statements instead of directly embedding user input into SQL queries.
- Use Case: A web application accepts user input to search a database. By sanitizing and validating user inputs, developers can prevent attackers from injecting malicious SQL commands.
Cross-Site Scripting (XSS) Mitigation:
- Implementation: Require developers to implement output encoding for all user-generated content displayed on a web page.
- Use Case: An e-commerce site allows users to leave product reviews. Properly encoding and escaping user inputs prevents malicious scripts from being executed in other users’ browsers.
Secure API Design:
- Implementation: Train developers to authenticate all API endpoints and avoid exposing sensitive information in API responses.
- Use Case: A mobile banking application uses APIs for account management. By enforcing token-based authentication for every API call, developers reduce the risk of unauthorized access.
Static Code Analysis in the Build Pipeline:
- Implementation: Incorporate tools into CI/CD pipelines to automatically scan for vulnerabilities during the build process.
- Use Case: A fintech company integrates static analysis tools to detect hardcoded credentials in their source code before deployment.
Threat Modeling in the Design Phase:
- Implementation: Use frameworks like STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) to assess threats during application design.
- Use Case: Before launching a customer portal, a SaaS company identifies potential abuse cases, such as session hijacking, and designs mitigations like secure session management.
**Tools for Implementation**:
- Static Code Analysis Tools: Use tools that can scan for known vulnerabilities in source code.
- Dynamic Application Security Testing (DAST): Use tools like Burp Suite or OWASP ZAP to simulate runtime attacks and identify vulnerabilities.
- Secure Frameworks: Recommend secure-by-default frameworks (e.g., Django for Python, Spring Security for Java) that enforce security best practices.
|
|
System Firmware Mitigation
|
Prevent adversary access to privileged accounts or access necessary to perform this technique. Check the integrity of the existing BIOS or EFI to determine if it is vulnerable to modification. Patch the BIOS and EFI as necessary. Use Trusted Platform Module technology. (Citation: TCG Trusted Platform Module)
|
|
Data Compressed Mitigation
|
Identify unnecessary system utilities, third-party tools, or potentially malicious software that may be used to compress files, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
If network intrusion prevention or data loss prevention tools are set to block specific file types from leaving the network over unencrypted channels, then an adversary may move to an encrypted channel.
|
|
Limit Hardware Installation
|
Prevent unauthorized users or groups from installing or using hardware, such as external drives, peripheral devices, or unapproved internal hardware components, by enforcing hardware usage policies and technical controls. This includes disabling USB ports, restricting driver installation, and implementing endpoint security tools to monitor and block unapproved devices. This mitigation can be implemented through the following measures:
Disable USB Ports and Hardware Installation Policies:
- Use Group Policy Objects (GPO) to disable USB mass storage devices:
- Navigate to Computer Configuration > Administrative Templates > System > Removable Storage Access.
- Deny write and read access to USB devices.
- Whitelist approved devices using unique serial numbers via Windows Device Installation Policies.
Deploy Endpoint Protection and Device Control Solutions:
- Use tools like Microsoft Defender for Endpoint, Symantec Endpoint Protection, or Tanium to monitor and block unauthorized hardware.
- Implement device control policies to allow specific hardware types (e.g., keyboards, mice) and block others.
Harden BIOS/UEFI and System Firmware:
- Set strong passwords for BIOS/UEFI access.
- Enable Secure Boot to prevent rogue hardware components from loading unauthorized firmware.
Restrict Peripheral Devices and Drivers:
- Use Windows Device Manager Policies to block installation of unapproved drivers.
- Monitor hardware installation attempts through endpoint monitoring tools.
Disable Bluetooth and Wireless Hardware:
- Use GPO or MDM tools to disable Bluetooth and Wi-Fi interfaces across systems.
- Restrict hardware pairing to approved devices only.
Logging and Monitoring:
- Enable logging for hardware installation events in Windows Event Logs (Event ID 20001 for Device Setup Manager).
- Use SIEM solutions (e.g., Splunk, Elastic Stack) to detect unauthorized hardware installation activities.
*Tools for Implementation*
USB and Device Control:
- Microsoft Group Policy Objects (GPO)
- Microsoft Defender for Endpoint
- Symantec Endpoint Protection
- McAfee Device Control
Endpoint Monitoring:
- EDRs
- OSSEC (open-source host-based IDS)
Hardware Whitelisting:
- BitLocker for external drives (Windows)
- Windows Device Installation Policies
- Device Control
BIOS/UEFI Security:
- Secure Boot (Windows/Linux)
Firmware management tools like Dell Command Update or HP Sure Start
|
|
User Training
|
User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures:
Create Comprehensive Training Programs:
- Design training modules tailored to the organization's risk profile, covering topics such as phishing, password management, and incident reporting.
- Provide role-specific training for high-risk employees, such as helpdesk staff or executives.
Use Simulated Exercises:
- Conduct phishing simulations to measure user susceptibility and provide targeted follow-up training.
- Run social engineering drills to evaluate employee responses and reinforce protocols.
Leverage Gamification and Engagement:
- Introduce interactive learning methods such as quizzes, gamified challenges, and rewards for successful detection and reporting of threats.
Incorporate Security Policies into Onboarding:
- Include cybersecurity training as part of the onboarding process for new employees.
- Provide easy-to-understand materials outlining acceptable use policies and reporting procedures.
Regular Refresher Courses:
- Update training materials to include emerging threats and techniques used by adversaries.
- Ensure all employees complete periodic refresher courses to stay informed.
Emphasize Real-World Scenarios:
- Use case studies of recent attacks to demonstrate the consequences of successful phishing or social engineering.
- Discuss how specific employee actions can prevent or mitigate such attacks.
|
|
Data Encrypted Mitigation
|
Identify unnecessary system utilities, third-party tools, or potentially malicious software that may be used to encrypt files, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
File and Directory Discovery Mitigation
|
File system activity is a common part of an operating system, so it is unlikely that mitigation would be appropriate for this technique. It may still be beneficial to identify and block unnecessary system utilities or potentially malicious software by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
User Account Control
|
User Account Control (UAC) is a security feature in Microsoft Windows that prevents unauthorized changes to the operating system. UAC prompts users to confirm or provide administrator credentials when an action requires elevated privileges. Proper configuration of UAC reduces the risk of privilege escalation attacks. This mitigation can be implemented through the following measures:
Enable UAC Globally:
- Ensure UAC is enabled through Group Policy by setting `User Account Control: Run all administrators in Admin Approval Mode` to `Enabled`.
Require Credential Prompt:
- Use Group Policy to configure UAC to prompt for administrative credentials instead of just confirmation (`User Account Control: Behavior of the elevation prompt`).
Restrict Built-in Administrator Account:
Set `Admin Approval Mode` for the built-in Administrator account to `Enabled` in Group Policy.
Secure the UAC Prompt:
- Configure UAC prompts to display on the secure desktop (`User Account Control: Switch to the secure desktop when prompting for elevation`).
Prevent UAC Bypass:
- Block untrusted applications from triggering UAC prompts by configuring `User Account Control: Only elevate executables that are signed and validated`.
- Use EDR tools to detect and block known UAC bypass techniques.
Monitor UAC-Related Events:
- Use Windows Event Viewer to monitor for event ID 4688 (process creation) and look for suspicious processes attempting to invoke UAC elevation.
*Tools for Implementation*
Built-in Windows Tools:
- Group Policy Editor: Configure UAC settings centrally for enterprise environments.
- Registry Editor: Modify UAC-related settings directly, such as `EnableLUA` and `ConsentPromptBehaviorAdmin`.
Endpoint Security Solutions:
- Microsoft Defender for Endpoint: Detects and blocks UAC bypass techniques.
- Sysmon: Logs process creations and monitors UAC elevation attempts for suspicious activity.
Third-Party Security Tools:
- Process Monitor (Sysinternals): Tracks real-time processes interacting with UAC.
- EventSentry: Monitors Windows Event Logs for UAC-related alerts.
|
|
Hypervisor Mitigation
|
Prevent adversary access to privileged accounts necessary to install a hypervisor.
|
|
Plist Modification Mitigation
|
Prevent plist files from being modified by users by making them read-only.
|
|
Operating System Configuration
|
Operating System Configuration involves adjusting system settings and hardening the default configurations of an operating system (OS) to mitigate adversary exploitation and prevent abuse of system functionality. Proper OS configurations address security vulnerabilities, limit attack surfaces, and ensure robust defense against a wide range of techniques. This mitigation can be implemented through the following measures:
Disable Unused Features:
- Turn off SMBv1, LLMNR, and NetBIOS where not needed.
- Disable remote registry and unnecessary services.
Enforce OS-level Protections:
- Enable Data Execution Prevention (DEP), Address Space Layout Randomization (ASLR), and Control Flow Guard (CFG) on Windows.
- Use AppArmor or SELinux on Linux for mandatory access controls.
Secure Access Settings:
- Enable User Account Control (UAC) for Windows.
- Restrict root/sudo access on Linux/macOS and enforce strong permissions using sudoers files.
File System Hardening:
- Implement least-privilege access for critical files and system directories.
- Audit permissions regularly using tools like icacls (Windows) or getfacl/chmod (Linux/macOS).
Secure Remote Access:
- Restrict RDP, SSH, and VNC to authorized IPs using firewall rules.
- Enable NLA for RDP and enforce strong password/lockout policies.
Harden Boot Configurations:
- Enable Secure Boot and enforce UEFI/BIOS password protection.
- Use BitLocker or LUKS to encrypt boot drives.
Regular Audits:
- Periodically audit OS configurations using tools like CIS Benchmarks or SCAP tools.
*Tools for Implementation*
Windows:
- Microsoft Group Policy Objects (GPO): Centrally enforce OS security settings.
- Windows Defender Exploit Guard: Built-in OS protection against exploits.
- CIS-CAT Pro: Audit Windows security configurations based on CIS Benchmarks.
Linux/macOS:
- AppArmor/SELinux: Enforce mandatory access controls.
- Lynis: Perform comprehensive security audits.
- SCAP Security Guide: Automate configuration hardening using Security Content Automation Protocol.
Cross-Platform:
- Ansible or Chef/Puppet: Automate configuration hardening at scale.
- OpenSCAP: Perform compliance and configuration checks.
|
|
Windows Admin Shares Mitigation
|
Do not reuse local administrator account passwords across systems. Ensure password complexity and uniqueness such that the passwords cannot be cracked or guessed. Deny remote use of local admin credentials to log into systems. Do not allow domain user accounts to be in the local Administrators group multiple systems.
Identify unnecessary system utilities or potentially malicious software that may be used to leverage SMB and the Windows admin shares, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Winlogon Helper DLL Mitigation
|
Limit the privileges of user accounts so that only authorized administrators can perform Winlogon helper changes.
Identify and block potentially malicious software that may be executed through the Winlogon helper process by using whitelisting (Citation: Beechey 2010) tools like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) that are capable of auditing and/or blocking unknown DLLs.
|
|
Runtime Data Manipulation Mitigation
|
Identify critical business and system processes that may be targeted by adversaries and work to secure those systems against tampering. Prevent critical business and system processes from being replaced, overwritten, or reconfigured to load potentially malicious code. Identify potentially malicious software and audit and/or block it by using whitelisting(Citation: Beechey 2010) tools, like AppLocker,(Citation: Windows Commands JPCERT)(Citation: NSA MS AppLocker) or Software Restriction Policies(Citation: Corio 2008) where appropriate.(Citation: TechNet Applocker vs SRP)
|
|
Image File Execution Options Injection Mitigation
|
This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of operating system design features. For example, mitigating all IFEO will likely have unintended side effects, such as preventing legitimate software (i.e., security products) from operating properly. (Citation: Microsoft IFEOorMalware July 2015) Efforts should be focused on preventing adversary tools from running earlier in the chain of activity and on identifying subsequent malicious behavior.
Identify and block potentially malicious software that may be executed through IFEO by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) that are capable of auditing and/or blocking unknown executables.
|
|
Process Doppelgänging Mitigation
|
This type of attack technique cannot be easily mitigated with preventive controls or patched since it is based on the abuse of operating system design features. For example, mitigating specific API calls will likely have unintended side effects, such as preventing legitimate process-loading mechanisms from operating properly. Efforts should be focused on preventing adversary tools from running earlier in the chain of activity and on identifying subsequent malicious behavior.
Although Process Doppelgänging may be used to evade certain types of defenses, it is still good practice to identify potentially malicious software that may be used to perform adversarial actions and audit and/or block it by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
File Deletion Mitigation
|
Identify unnecessary system utilities, third-party tools, or potentially malicious software that may be used to delete files, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Exploitation for Defense Evasion Mitigation
|
Update software regularly by employing patch management for internal enterprise endpoints and servers. Develop a robust cyber threat intelligence capability to determine what types and levels of threat may use software exploits and 0-days against a particular organization. Make it difficult for adversaries to advance their operation through exploitation of undiscovered or unpatched vulnerabilities by using sandboxing, if available. Other types of virtualization and application microsegmentation may also mitigate the impact of some types of exploitation. The risks of additional exploits and weaknesses in implementation may still exist. (Citation: Ars Technica Pwn2Own 2017 VM Escape)
Security applications that look for behavior used during exploitation such as Windows Defender Exploit Guard (WDEG) and the Enhanced Mitigation Experience Toolkit (EMET) can be used to mitigate some exploitation behavior. (Citation: TechNet Moving Beyond EMET) Control flow integrity checking is another way to potentially identify and stop a software exploit from occurring. (Citation: Wikipedia Control Flow Integrity) Many of these protections depend on the architecture and target application binary for compatibility and may not work for software targeted for defense evasion.
|
|
Email Collection Mitigation
|
Use of encryption provides an added layer of security to sensitive information sent over email. Encryption using public key cryptography requires the adversary to obtain the private certificate along with an encryption key to decrypt messages.
Use of two-factor authentication for public-facing webmail servers is also a recommended best practice to minimize the usefulness of user names and passwords to adversaries.
Identify unnecessary system utilities or potentially malicious software that may be used to collect email data files or access the corporate email server, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Disabling Security Tools Mitigation
|
Ensure proper process, registry, and file permissions are in place to prevent adversaries from disabling or interfering with security services.
|
|
Data from Removable Media Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to collect data from removable media, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Standard Non-Application Layer Protocol Mitigation
|
Properly configure firewalls and proxies to limit outgoing traffic to only necessary ports and through proper network gateway systems. Also ensure hosts are only provisioned to communicate over authorized interfaces.
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific obfuscation technique used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool C2 signatures over time or construct protocols in such a way as to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Control Panel Items Mitigation
|
This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of operating system design features. For example, mitigating specific Windows API calls and/or execution of particular file extensions will likely have unintended side effects, such as preventing legitimate software (i.e., drivers and configuration tools) from operating properly. Efforts should be focused on preventing adversary tools from running earlier in the chain of activity and on identification of subsequent malicious behavior.
Restrict storage and execution of Control Panel items to protected directories, such as C:\Windows, rather than user directories.
Index known safe Control Panel items and block potentially malicious software using whitelisting (Citation: Beechey 2010) tools like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) that are capable of auditing and/or blocking unknown executable files.
Consider fully enabling User Account Control (UAC) to impede system-wide changes from illegitimate administrators. (Citation: Microsoft UAC)
|
|
Pass the Ticket Mitigation
|
Monitor domains for unusual credential logons. Limit credential overlap across systems to prevent the damage of credential compromise. Ensure that local administrator accounts have complex, unique passwords. Do not allow a user to be a local administrator for multiple systems. Limit domain admin account permissions to domain controllers and limited servers. Delegate other admin functions to separate accounts. (Citation: ADSecurity AD Kerberos Attacks)
For containing the impact of a previously generated golden ticket, reset the built-in KRBTGT account password twice, which will invalidate any existing golden tickets that have been created with the KRBTGT hash and other Kerberos tickets derived from it. (Citation: CERT-EU Golden Ticket Protection)
Attempt to identify and block unknown or malicious software that could be used to obtain Kerberos tickets and use them to authenticate by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Domain Generation Algorithms Mitigation
|
This technique may be difficult to mitigate since the domains can be registered just before they are used, and disposed shortly after. Malware researchers can reverse-engineer malware variants that use DGAs and determine future domains that the malware will attempt to contact, but this is a time and resource intensive effort.(Citation: Cybereason Dissecting DGAs)(Citation: Cisco Umbrella DGA Brute Force) Malware is also increasingly incorporating seed values that can be unique for each instance, which would then need to be determined to extract future generated domains. In some cases, the seed that a particular sample uses can be extracted from DNS traffic.(Citation: Akamai DGA Mitigation) Even so, there can be thousands of possible domains generated per day; this makes it impractical for defenders to preemptively register all possible C2 domains due to the cost. In some cases a local DNS sinkhole may be used to help prevent DGA-based command and control at a reduced cost.
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific protocol used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool C2 signatures over time or construct protocols in such a way as to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Clear Command History Mitigation
|
Preventing users from deleting or writing to certain files can stop adversaries from maliciously altering their ~/.bash_history files. Additionally, making these environment variables readonly can make sure that the history is preserved (Citation: Securing bash history).
|
|
Windows Remote Management Mitigation
|
Disable the WinRM service. If the service is necessary, lock down critical enclaves with separate WinRM infrastructure, accounts, and permissions. Follow WinRM best practices on configuration of authentication methods and use of host firewalls to restrict WinRM access to allow communication only to/from specific devices. (Citation: NSA Spotting)
|
|
Data Backup
|
Data Backup involves taking and securely storing backups of data from end-user systems and critical servers. It ensures that data remains available in the event of system compromise, ransomware attacks, or other disruptions. Backup processes should include hardening backup systems, implementing secure storage solutions, and keeping backups isolated from the corporate network to prevent compromise during active incidents. This mitigation can be implemented through the following measures:
Regular Backup Scheduling:
- Use Case: Ensure timely and consistent backups of critical data.
- Implementation: Schedule daily incremental backups and weekly full backups for all critical servers and systems.
Immutable Backups:
- Use Case: Protect backups from modification or deletion, even by attackers.
- Implementation: Use write-once-read-many (WORM) storage for backups, preventing ransomware from encrypting or deleting backup files.
Backup Encryption:
- Use Case: Protect data integrity and confidentiality during transit and storage.
- Implementation: Encrypt backups using strong encryption protocols (e.g., AES-256) before storing them in local, cloud, or remote locations.
Offsite Backup Storage:
- Use Case: Ensure data availability during physical disasters or onsite breaches.
- Implementation: Use cloud-based solutions like AWS S3, Azure Backup, or physical offsite storage to maintain a copy of critical data.
Backup Testing:
- Use Case: Validate backup integrity and ensure recoverability.
- Implementation: Regularly test data restoration processes to ensure that backups are not corrupted and can be recovered quickly.
|
|
Launch Daemon Mitigation
|
Limit privileges of user accounts and remediate Privilege Escalation vectors so only authorized administrators can create new Launch Daemons.
|
|
Service Stop Mitigation
|
Ensure proper process, registry, and file permissions are in place to inhibit adversaries from disabling or interfering with critical services. Limit privileges of user accounts and groups so that only authorized administrators can interact with service changes and service configurations. Harden systems used to serve critical network, business, and communications functions. Operate intrusion detection, analysis, and response systems on a separate network from the production environment to lessen the chances that an adversary can see and interfere with critical response functions.
|
|
SSH Hijacking Mitigation
|
Ensure SSH key pairs have strong passwords and refrain from using key-store technologies such as ssh-agent unless they are properly protected. Ensure that all private keys are stored securely in locations where only the legitimate owner has access to with strong passwords and are rotated frequently. Ensure proper file permissions are set and harden system to prevent root privilege escalation opportunities. Do not allow remote access via SSH as root or other privileged accounts. Ensure that agent forwarding is disabled on systems that do not explicitly require this feature to prevent misuse. (Citation: Symantec SSH and ssh-agent)
|
|
Data Encrypted for Impact Mitigation
|
Consider implementing IT disaster recovery plans that contain procedures for regularly taking and testing data backups that can be used to restore organizational data.(Citation: Ready.gov IT DRP)
In some cases, the means to decrypt files affected by a ransomware campaign is released to the public. Research trusted sources for public releases of decryptor tools/keys to reverse the effects of ransomware.
Identify potentially malicious software and audit and/or block it by using whitelisting(Citation: Beechey 2010) tools, like AppLocker,(Citation: Windows Commands JPCERT)(Citation: NSA MS AppLocker) or Software Restriction Policies(Citation: Corio 2008) where appropriate.(Citation: TechNet Applocker vs SRP)
|
|
Data Staged Mitigation
|
Identify system utilities, remote access or third-party tools, users or potentially malicious software that may be used to store compressed or encrypted data in a publicly writeable directory, central location, or commonly used staging directories (e.g. recycle bin) that is indicative of non-standard behavior, and audit and/or block them by using file integrity monitoring tools where appropriate. Consider applying data size limits or blocking file writes of common compression and encryption utilities such as 7zip, RAR, ZIP, or zlib on frequently used staging directories or central locations and monitor attempted violations of those restrictions.
|
|
Shared Webroot Mitigation
|
Networks that allow for open development and testing of Web content and allow users to set up their own Web servers on the enterprise network may be particularly vulnerable if the systems and Web servers are not properly secured to limit privileged account use, unauthenticated network share access, and network/system isolation.
Ensure proper permissions on directories that are accessible through a Web server. Disallow remote access to the webroot or other directories used to serve Web content. Disable execution on directories within the webroot. Ensure that permissions of the Web server process are only what is required by not using built-in accounts; instead, create specific accounts to limit unnecessary access or permissions overlap across multiple systems. (Citation: acunetix Server Secuirty) (Citation: NIST Server Security July 2008)
|
|
Kernel Modules and Extensions Mitigation
|
Common tools for detecting Linux rootkits include: rkhunter (Citation: SourceForge rkhunter), chrootkit (Citation: Chkrootkit Main), although rootkits may be designed to evade certain detection tools.
LKMs and Kernel extensions require root level permissions to be installed. Limit access to the root account and prevent users from loading kernel modules and extensions through proper privilege separation and limiting Privilege Escalation opportunities.
Application whitelisting and software restriction tools, such as SELinux, can also aide in restricting kernel module loading. (Citation: Kernel.org Restrict Kernel Module)
|
|
Credentials in Registry Mitigation
|
Do not store credentials within the Registry. Proactively search for credentials within Registry keys and attempt to remediate the risk. If necessary software must store credentials, then ensure those accounts have limited permissions so they cannot be abused if obtained by an adversary.
|
|
Masquerading Mitigation
|
When creating security rules, avoid exclusions based on file name or file path. Require signed binaries. Use file system access controls to protect folders such as C:\Windows\System32. Use tools that restrict program execution via whitelisting by attributes other than file name.
Identify potentially malicious software that may look like a legitimate program based on name and location, and audit and/or block it by using whitelisting (Citation: Beechey 2010) tools like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Web Service Mitigation
|
Firewalls and Web proxies can be used to enforce external network communication policy. It may be difficult for an organization to block particular services because so many of them are commonly used during the course of business.
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific protocol or encoded commands used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool C2 signatures over time or construct protocols in such a way as to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Resource Hijacking Mitigation
|
Identify potentially malicious software and audit and/or block it by using whitelisting(Citation: Beechey 2010) tools, like AppLocker,(Citation: Windows Commands JPCERT)(Citation: NSA MS AppLocker) or Software Restriction Policies(Citation: Corio 2008) where appropriate.(Citation: TechNet Applocker vs SRP)
|
|
Network Sniffing Mitigation
|
Ensure that all wireless traffic is encrypted appropriately. Use Kerberos, SSL, and multifactor authentication wherever possible. Monitor switches and network for span port usage, ARP/DNS poisoning, and router reconfiguration.
Identify and block potentially malicious software that may be used to sniff or analyze network traffic by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Execution Prevention
|
Prevent the execution of unauthorized or malicious code on systems by implementing application control, script blocking, and other execution prevention mechanisms. This ensures that only trusted and authorized code is executed, reducing the risk of malware and unauthorized actions. This mitigation can be implemented through the following measures:
Application Control:
- Use Case: Use tools like AppLocker or Windows Defender Application Control (WDAC) to create whitelists of authorized applications and block unauthorized ones. On Linux, use tools like SELinux or AppArmor to define mandatory access control policies for application execution.
- Implementation: Allow only digitally signed or pre-approved applications to execute on servers and endpoints. (e.g., `New-AppLockerPolicy -PolicyType Enforced -FilePath "C:\Policies\AppLocker.xml"`)
Script Blocking:
- Use Case: Use script control mechanisms to block unauthorized execution of scripts, such as PowerShell or JavaScript. Web Browsers: Use browser extensions or settings to block JavaScript execution from untrusted sources.
- Implementation: Configure PowerShell to enforce Constrained Language Mode for non-administrator users. (e.g., `Set-ExecutionPolicy AllSigned`)
Executable Blocking:
- Use Case: Prevent execution of binaries from suspicious locations, such as `%TEMP%` or `%APPDATA%` directories.
- Implementation: Block execution of `.exe`, `.bat`, or `.ps1` files from user-writable directories.
Dynamic Analysis Prevention:
- Use Case: Use behavior-based execution prevention tools to identify and block malicious activity in real time.
- Implemenation: Employ EDR solutions that analyze runtime behavior and block suspicious code execution.
|
|
Password Policy Discovery Mitigation
|
Mitigating discovery of password policies is not advised since the information is required to be known by systems and users of a network. Ensure password policies are such that they mitigate brute force attacks yet will not give an adversary an information advantage because the policies are too light. Active Directory is a common way to set and enforce password policies throughout an enterprise network. (Citation: Microsoft Password Complexity)
|
|
Credential Access Protection
|
Credential Access Protection focuses on implementing measures to prevent adversaries from obtaining credentials, such as passwords, hashes, tokens, or keys, that could be used for unauthorized access. This involves restricting access to credential storage mechanisms, hardening configurations to block credential dumping methods, and using monitoring tools to detect suspicious credential-related activity. This mitigation can be implemented through the following measures:
Restrict Access to Credential Storage:
- Use Case: Prevent adversaries from accessing the SAM (Security Account Manager) database on Windows systems.
- Implementation: Enforce least privilege principles and restrict administrative access to credential stores such as `C:\Windows\System32\config\SAM`.
Use Credential Guard:
- Use Case: Isolate LSASS (Local Security Authority Subsystem Service) memory to prevent credential dumping.
- Implementation: Enable Windows Defender Credential Guard on enterprise endpoints to isolate secrets and protect them from unauthorized access.
Monitor for Credential Dumping Tools:
- Use Case: Detect and block known tools like Mimikatz or Windows Credential Editor.
- Implementation: Flag suspicious process behavior related to credential dumping.
Disable Cached Credentials:
- Use Case: Prevent adversaries from exploiting cached credentials on endpoints.
- Implementation: Configure group policy to reduce or eliminate the use of cached credentials (e.g., set Interactive logon: Number of previous logons to cache to 0).
Enable Secure Boot and Memory Protections:
- Use Case: Prevent memory-based attacks used to extract credentials.
- Implementation: Configure Secure Boot and enforce hardware-based security features like DEP (Data Execution Prevention) and ASLR (Address Space Layout Randomization).
|
|
Brute Force Mitigation
|
Set account lockout policies after a certain number of failed login attempts to prevent passwords from being guessed.
Too strict a policy can create a denial of service condition and render environments un-usable, with all accounts being locked-out permanently. Use multifactor authentication. Follow best practices for mitigating access to [Valid Accounts](https://attack.mitre.org/techniques/T1078)
Refer to NIST guidelines when creating passwords.(Citation: NIST 800-63-3)
Where possible, also enable multi factor authentication on external facing services.
|
|
Indicator Removal from Tools Mitigation
|
Mitigation is difficult in instances like this because the adversary may have access to the system through another channel and can learn what techniques or tools are blocked by resident defenses. Exercising best practices with configuration and security as well as ensuring that proper process is followed during investigation of potential compromise is essential to detecting a larger intrusion through discrete alerts.
Identify and block potentially malicious software that may be used by an adversary by using whitelisting (Citation: Beechey 2010) tools like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
.bash_profile and .bashrc Mitigation
|
Making these files immutable and only changeable by certain administrators will limit the ability for adversaries to easily create user level persistence.
|
|
Signed Script Proxy Execution Mitigation
|
Certain signed scripts that can be used to execute other programs may not be necessary within a given environment. Use application whitelisting configured to block execution of these scripts if they are not required for a given system or network to prevent potential misuse by adversaries.
|
|
Multi-Stage Channels Mitigation
|
Command and control infrastructure used in a multi-stage channel may be blocked if known ahead of time. If unique signatures are present in the C2 traffic, they could also be used as the basis of identifying and blocking the channel. (Citation: University of Birmingham C2)
|
|
Fallback Channels Mitigation
|
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific protocol used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool C2 signatures over time or construct protocols in such a way as to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Screen Capture Mitigation
|
Blocking software based on screen capture functionality may be difficult, and there may be legitimate software that performs those actions. Instead, identify potentially malicious software that may have functionality to acquire screen captures, and audit and/or block it by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Source Mitigation
|
Due to potential legitimate uses of source commands, it's may be difficult to mitigate use of this technique.
|
|
Remote Desktop Protocol Mitigation
|
Disable the RDP service if it is unnecessary, remove unnecessary accounts and groups from Remote Desktop Users groups, and enable firewall rules to block RDP traffic between network security zones. Audit the Remote Desktop Users group membership regularly. Remove the local Administrators group from the list of groups allowed to log in through RDP. Limit remote user permissions if remote access is necessary. Use remote desktop gateways and multifactor authentication for remote logins. (Citation: Berkley Secure) Do not leave RDP accessible from the internet. Change GPOs to define shorter timeouts sessions and maximum amount of time any single session can be active. Change GPOs to specify the maximum amount of time that a disconnected session stays active on the RD session host server. (Citation: Windows RDP Sessions)
|
|
LLMNR/NBT-NS Poisoning Mitigation
|
Disable LLMNR and NetBIOS in local computer security settings or by group policy if they are not needed within an environment. (Citation: ADSecurity Windows Secure Baseline)
Use host-based security software to block LLMNR/NetBIOS traffic. Enabling SMB Signing can stop NTLMv2 relay attacks.(Citation: byt3bl33d3r NTLM Relaying)(Citation: Secure Ideas SMB Relay)(Citation: Microsoft SMB Packet Signing)
|
|
User Execution Mitigation
|
Use user training as a way to bring awareness to common phishing and spearphishing techniques and how to raise suspicion for potentially malicious events. Application whitelisting may be able to prevent the running of executables masquerading as other files.
If a link is being visited by a user, block unknown or unused files in transit by default that should not be downloaded or by policy from suspicious sites as a best practice to prevent some vectors, such as .scr, .exe, .lnk, .pif, .cpl, etc. Some download scanning devices can open and analyze compressed and encrypted formats, such as zip and RAR that may be used to conceal malicious files in [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027).
If a link is being visited by a user, network intrusion prevention systems and systems designed to scan and remove malicious downloads can be used to block activity. Solutions can be signature and behavior based, but adversaries may construct files in a way to avoid these systems.
|
|
Hardware Additions Mitigation
|
Establish network access control policies, such as using device certificates and the 802.1x standard. (Citation: Wikipedia 802.1x) Restrict use of DHCP to registered devices to prevent unregistered devices from communicating with trusted systems.
Block unknown devices and accessories by endpoint security configuration and monitoring agent.
|
|
Keychain Mitigation
|
The password for the user's login keychain can be changed from the user's login password. This increases the complexity for an adversary because they need to know an additional password.
|
|
Scripting Mitigation
|
Turn off unused features or restrict access to scripting engines such as VBScript or scriptable administration frameworks such as PowerShell.
Configure Office security settings enable Protected View, to execute within a sandbox environment, and to block macros through Group Policy. (Citation: Microsoft Block Office Macros) Other types of virtualization and application microsegmentation may also mitigate the impact of compromise. The risks of additional exploits and weaknesses in implementation may still exist. (Citation: Ars Technica Pwn2Own 2017 VM Escape)
|
|
Code Signing
|
Code Signing is a security process that ensures the authenticity and integrity of software by digitally signing executables, scripts, and other code artifacts. It prevents untrusted or malicious code from executing by verifying the digital signatures against trusted sources. Code signing protects against tampering, impersonation, and distribution of unauthorized or malicious software, forming a critical defense against supply chain and software exploitation attacks. This mitigation can be implemented through the following measures:
Enforce Signed Code Execution:
- Implementation: Configure operating systems (e.g., Windows with AppLocker or Linux with Secure Boot) to allow only signed code to execute.
- Use Case: Prevent the execution of malicious PowerShell scripts by requiring all scripts to be signed with a trusted certificate.
Vendor-Signed Driver Enforcement:
- Implementation: Enable kernel-mode code signing to ensure that only drivers signed by trusted vendors can be loaded.
- Use Case: A malicious driver attempting to modify system memory fails to load because it lacks a valid signature.
Certificate Revocation Management:
- Implementation: Use Online Certificate Status Protocol (OCSP) or Certificate Revocation Lists (CRLs) to block certificates associated with compromised or deprecated code.
- Use Case: A compromised certificate used to sign a malicious update is revoked, preventing further execution of the software.
Third-Party Software Verification:
- Implementation: Require software from external vendors to be signed with valid certificates before deployment.
- Use Case: An organization only deploys signed and verified third-party software to prevent supply chain attacks.
Script Integrity in CI/CD Pipelines:
- Implementation: Integrate code signing into CI/CD pipelines to sign and verify code artifacts before production release.
- Use Case: A software company ensures that all production builds are signed, preventing tampered builds from reaching customers.
**Key Components of Code Signing**
- Digital Signature Verification: Verifies the authenticity of code by ensuring it was signed by a trusted entity.
- Certificate Management: Uses Public Key Infrastructure (PKI) to manage signing certificates and revocation lists.
- Enforced Policy for Unsigned Code: Prevents the execution of unsigned or untrusted binaries and scripts.
- Hash Integrity Check: Confirms that code has not been altered since signing by comparing cryptographic hashes.
|
|
Timestomp Mitigation
|
Mitigation of timestomping specifically is likely difficult. Efforts should be focused on preventing potentially malicious software from running. Identify and block potentially malicious software that may contain functionality to perform timestomping by using whitelisting (Citation: Beechey 2010) tools like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Account Discovery Mitigation
|
Prevent administrator accounts from being enumerated when an application is elevating through UAC since it can lead to the disclosure of account names. The Registry key is located HKLM\ SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\CredUI\EnumerateAdministrators. It can be disabled through GPO: Computer Configuration > [Policies] > Administrative Templates > Windows Components > Credential User Interface: E numerate administrator accounts on elevation. (Citation: UCF STIG Elevation Account Enumeration)
Identify unnecessary system utilities or potentially malicious software that may be used to acquire information about system and domain accounts, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Defacement Mitigation
|
Implementing best practices for websites such as defending against [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190) (Citation: OWASP Top 10 2017). Consider implementing IT disaster recovery plans that contain procedures for taking regular data backups that can be used to restore organizational data. (Ready.gov IT DRP) Ensure backups are stored off system and is protected from common methods adversaries may use to gain access and destroy the backups to prevent recovery.
|
|
Environment Variable Permissions
|
Restrict the modification of environment variables to authorized users and processes by enforcing strict permissions and policies. This ensures the integrity of environment variables, preventing adversaries from abusing or altering them for malicious purposes. This mitigation can be implemented through the following measures:
Restrict Write Access:
- Use Case: Set file system-level permissions to restrict access to environment variable configuration files (e.g., `.bashrc`, `.bash_profile`, `.zshrc`, `systemd` service files).
- Implementation: Configure `/etc/environment` or `/etc/profile` on Linux systems to only allow root or administrators to modify the file.
Secure Access Controls:
- Use Case: Limit access to environment variable settings in application deployment tools or CI/CD pipelines to authorized personnel.
- Implementation: Use role-based access control (RBAC) in tools like Jenkins or GitLab to ensure only specific users can modify environment variables.
Restrict Process Scope:
- Use Case: Configure policies to ensure environment variables are only accessible to the processes they are explicitly intended for.
- Implementation: Use containerized environments like Docker to isolate environment variables to specific containers and ensure they are not inherited by other processes.
Audit Environment Variable Changes:
- Use Case: Enable logging for changes to critical environment variables.
- Implementation: Use `auditd` on Linux to monitor changes to files like `/etc/environment` or application-specific environment files.
|
|
Re-opened Applications Mitigation
|
Holding the Shift key while logging in prevents apps from opening automatically (Citation: Re-Open windows on Mac). This feature can be disabled entirely with the following terminal command: defaults write -g ApplePersistence -bool no.
|
|
Netsh Helper DLL Mitigation
|
Identify and block potentially malicious software that may persist in this manner by using whitelisting (Citation: Beechey 2010) tools capable of monitoring DLL loads by Windows utilities like AppLocker. (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker)
|
|
Domain Fronting Mitigation
|
If it is possible to inspect HTTPS traffic, the captures can be analyzed for connections that appear to be Domain Fronting.
In order to use domain fronting, attackers will likely need to deploy additional tools to compromised systems. (Citation: FireEye APT29 Domain Fronting With TOR March 2017) (Citation: Mandiant No Easy Breach) It may be possible to detect or prevent the installation of these tools with Host-based solutions.
|
|
Data Loss Prevention
|
Data Loss Prevention (DLP) involves implementing strategies and technologies to identify, categorize, monitor, and control the movement of sensitive data within an organization. This includes protecting data formats indicative of Personally Identifiable Information (PII), intellectual property, or financial data from unauthorized access, transmission, or exfiltration. DLP solutions integrate with network, endpoint, and cloud platforms to enforce security policies and prevent accidental or malicious data leaks. (Citation: PurpleSec Data Loss Prevention) This mitigation can be implemented through the following measures:
Sensitive Data Categorization:
- Use Case: Identify and classify data based on sensitivity (e.g., PII, financial data, trade secrets).
- Implementation: Use DLP solutions to scan and tag files containing sensitive information using predefined patterns, such as Social Security Numbers or credit card details.
Exfiltration Restrictions:
- Use Case: Prevent unauthorized transmission of sensitive data.
- Implementation: Enforce policies to block unapproved email attachments, unauthorized USB usage, or unencrypted data uploads to cloud storage.
Data-in-Transit Monitoring:
- Use Case: Detect and prevent the transmission of sensitive data over unapproved channels.
- Implementation: Deploy network-based DLP tools to inspect outbound traffic for sensitive content (e.g., financial records or PII) and block unapproved transmissions.
Endpoint Data Protection:
- Use Case: Monitor and control sensitive data usage on endpoints.
- Implementation: Use endpoint-based DLP agents to block copy-paste actions of sensitive data and unauthorized printing or file sharing.
Cloud Data Security:
- Use Case: Protect data stored in cloud platforms.
- Implementation: Integrate DLP with cloud storage platforms like Google Drive, OneDrive, or AWS to monitor and restrict sensitive data sharing or downloads.
|
|
Network Denial of Service Mitigation
|
When flood volumes exceed the capacity of the network connection being targeted, it is typically necessary to intercept the incoming traffic upstream to filter out the attack traffic from the legitimate traffic. Such defenses can be provided by the hosting Internet Service Provider (ISP) or by a 3rd party such as a Content Delivery Network (CDN) or providers specializing in DoS mitigations.(Citation: CERT-EU DDoS March 2017)
Depending on flood volume, on-premises filtering may be possible by blocking source addresses sourcing the attack, blocking ports that are being targeted, or blocking protocols being used for transport.(Citation: CERT-EU DDoS March 2017)
As immediate response may require rapid engagement of 3rd parties, analyze the risk associated to critical resources being affected by Network DoS attacks and create a disaster recovery plan/business continuity plan to respond to incidents.(Citation: CERT-EU DDoS March 2017)
|
|
Exploit Public-Facing Application Mitigation
|
Application isolation and least privilege help lesson the impact of an exploit. Application isolation will limit what other processes and system features the exploited target can access, and least privilege for service accounts will limit what permissions the exploited process gets on the rest of the system. Web Application Firewalls may be used to limit exposure of applications.
Segment externally facing servers and services from the rest of the network with a DMZ or on separate hosting infrastructure.
Use secure coding best practices when designing custom software that is meant for deployment to externally facing systems. Avoid issues documented by OWASP, CWE, and other software weakness identification efforts.
Regularly scan externally facing systems for vulnerabilities and establish procedures to rapidly patch systems when critical vulnerabilities are discovered through scanning and through public disclosure.
|
|
Component Firmware Mitigation
|
Prevent adversary access to privileged accounts or access necessary to perform this technique.
Consider removing and replacing system components suspected of being compromised.
|
|
System Network Configuration Discovery Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to acquire information about a system's network configuration, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Indicator Removal on Host Mitigation
|
Automatically forward events to a log server or data repository to prevent conditions in which the adversary can locate and manipulate data on the local system. When possible, minimize time delay on event reporting to avoid prolonged storage on the local system. Protect generated event files that are stored locally with proper permissions and authentication and limit opportunities for adversaries to increase privileges by preventing Privilege Escalation opportunities. Obfuscate/encrypt event files locally and in transit to avoid giving feedback to an adversary.
|
|
LC_MAIN Hijacking Mitigation
|
Enforce valid digital signatures for signed code on all applications and only trust applications with signatures from trusted parties.
|
|
Forced Authentication Mitigation
|
Block SMB traffic from exiting an enterprise network with egress filtering or by blocking TCP ports 139, 445 and UDP port 137. Filter or block WebDAV protocol traffic from exiting the network. If access to external resources over SMB and WebDAV is necessary, then traffic should be tightly limited with whitelisting. (Citation: US-CERT SMB Security) (Citation: US-CERT APT Energy Oct 2017)
For internal traffic, monitor the workstation-to-workstation unusual (vs. baseline) SMB traffic. For many networks there should not be any, but it depends on how systems on the network are configured and where resources are located.
Use strong passwords to increase the difficulty of credential hashes from being cracked if they are obtained.
|
|
Firmware Corruption Mitigation
|
Prevent adversary access to privileged accounts or access necessary to perform this technique. Check the integrity of the existing BIOS and device firmware to determine if it is vulnerable to modification. Patch the BIOS and other firmware as necessary to prevent successful use of known vulnerabilities.
|
|
Privileged Process Integrity
|
Privileged Process Integrity focuses on defending highly privileged processes (e.g., system services, antivirus, or authentication processes) from tampering, injection, or compromise by adversaries. These processes often interact with critical components, making them prime targets for techniques like code injection, privilege escalation, and process manipulation. This mitigation can be implemented through the following measures:
Protected Process Mechanisms:
- Enable RunAsPPL on Windows systems to protect LSASS and other critical processes.
- Use registry modifications to enforce protected process settings: `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL`
Anti-Injection and Memory Protection:
- Enable Control Flow Guard (CFG), DEP, and ASLR to protect against process memory tampering.
- Deploy endpoint protection tools that actively block process injection attempts.
Code Signing Validation:
- Implement policies for Windows Defender Application Control (WDAC) or AppLocker to enforce execution of signed binaries.
- Ensure critical processes are signed with valid certificates.
Access Controls:
- Use DACLs and MIC to limit which users and processes can interact with privileged processes.
- Disable unnecessary debugging capabilities for high-privileged processes.
Kernel-Level Protections:
- Ensure Kernel Patch Protection (PatchGuard) is enabled on Windows systems.
- Leverage SELinux or AppArmor on Linux to enforce kernel-level security policies.
*Tools for Implementation*
Protected Process Light (PPL):
- RunAsPPL (Windows)
- Windows Defender Credential Guard
Code Integrity and Signing:
- Windows Defender Application Control (WDAC)
- AppLocker
- SELinux/AppArmor (Linux)
Memory Protection:
- Control Flow Guard (CFG), Data Execution Prevention (DEP), ASLR
Process Isolation/Sandboxing:
- Firejail (Linux Sandbox)
- Windows Sandbox
- QEMU/KVM-based isolation
Kernel Protection:
- PatchGuard (Windows Kernel Patch Protection)
- SELinux (Mandatory Access Control for Linux)
- AppArmor
|
|
Multi-hop Proxy Mitigation
|
Traffic to known anonymity networks and C2 infrastructure can be blocked through the use of network black and white lists. It should be noted that this kind of blocking may be circumvented by other techniques like [Domain Fronting](https://attack.mitre.org/techniques/T1172).
|
|
XSL Script Processing Mitigation
|
[Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) and/or msxsl.exe may or may not be used within a given environment. Disabling WMI may cause system instability and should be evaluated to assess the impact to a network. If msxsl.exe is unnecessary, then block its execution to prevent abuse by adversaries.
|
|
LC_LOAD_DYLIB Addition Mitigation
|
Enforce that all binaries be signed by the correct Apple Developer IDs, and whitelist applications via known hashes. Binaries can also be baselined for what dynamic libraries they require, and if an app requires a new dynamic library that wasn’t included as part of an update, it should be investigated.
|
|
Do Not Mitigate
|
The Do Not Mitigate category highlights scenarios where attempting to mitigate a specific technique may inadvertently increase the organization's security risk or operational instability. This could happen due to the complexity of the system, the integration of critical processes, or the potential for introducing new vulnerabilities. Instead of direct mitigation, these situations may call for alternative strategies such as detection, monitoring, or response. The Do Not Mitigate category underscores the importance of assessing the trade-offs between mitigation efforts and overall system integrity. This mitigation can be implemented through the following measures:
Complex Systems Where Mitigation is Risky:
- Interpretation: In certain systems, direct mitigation could introduce new risks, especially if the system is highly interconnected or complex, such as in legacy industrial control systems (ICS). Patching or modifying these systems could result in unplanned downtime, disruptions, or even safety risks.
- Use Case: In a power grid control system, attempting to patch or disable certain services related to device communications might disrupt critical operations, leading to unintended service outages.
Risk of Reducing Security Coverage:
- Interpretation: In some cases, mitigating a technique might reduce the visibility or effectiveness of other security controls, limiting an organization’s ability to detect broader attacks.
- Use Case: Disabling script execution on a web server to mitigate potential PowerShell-based attacks could interfere with legitimate administrative operations that rely on scripting, while attackers may still find alternate ways to execute code.
Introduction of New Vulnerabilities:
- Interpretation: In highly sensitive or tightly controlled environments, implementing certain mitigations might create vulnerabilities in other parts of the system. For instance, disabling default security mechanisms in an attempt to resolve compatibility issues may open the system to exploitation.
- Use Case: Disabling certificate validation to resolve internal communication issues in a secure environment could lead to man-in-the-middle attacks, creating a greater vulnerability than the original problem.
Negative Impact on Performance and Availability:
- Interpretation: Mitigations that involve removing or restricting system functionalities can have unintended consequences for system performance and availability. Some mitigations, while effective at blocking certain attacks, may introduce performance bottlenecks or compromise essential operations.
- Use Case: Implementing high levels of encryption to mitigate data theft might result in significant performance degradation in systems handling large volumes of real-time transactions.
|
|
Pre-compromise
|
Pre-compromise mitigations involve proactive measures and defenses implemented to prevent adversaries from successfully identifying and exploiting weaknesses during the Reconnaissance and Resource Development phases of an attack. These activities focus on reducing an organization's attack surface, identify adversarial preparation efforts, and increase the difficulty for attackers to conduct successful operations. This mitigation can be implemented through the following measures:
Limit Information Exposure:
- Regularly audit and sanitize publicly available data, including job posts, websites, and social media.
- Use tools like OSINT monitoring platforms (e.g., SpiderFoot, Recon-ng) to identify leaked information.
Protect Domain and DNS Infrastructure:
- Enable DNSSEC and use WHOIS privacy protection.
- Monitor for domain hijacking or lookalike domains using services like RiskIQ or DomainTools.
External Monitoring:
- Use tools like Shodan, Censys to monitor your external attack surface.
- Deploy external vulnerability scanners to proactively address weaknesses.
Threat Intelligence:
- Leverage platforms like MISP, Recorded Future, or Anomali to track adversarial infrastructure, tools, and activity.
Content and Email Protections:
- Use email security solutions like Proofpoint, Microsoft Defender for Office 365, or Mimecast.
- Enforce SPF/DKIM/DMARC policies to protect against email spoofing.
Training and Awareness:
- Educate employees on identifying phishing attempts, securing their social media, and avoiding information leaks.
|
|
Trusted Relationship Mitigation
|
Network segmentation can be used to isolate infrastructure components that do not require broad network access. Properly manage accounts and permissions used by parties in trusted relationships to minimize potential abuse by the party and if the party is compromised by an adversary. Vet the security policies and procedures of organizations that are contracted for work that require privileged access to network resources.
|
|
DLL Side-Loading Mitigation
|
Update software regularly. Install software in write-protected locations. Use the program sxstrace.exe that is included with Windows along with manual inspection to check manifest files for side-loading vulnerabilities in software.
|
|
Drive-by Compromise Mitigation
|
Drive-by compromise relies on there being a vulnerable piece of software on the client end systems. Use modern browsers with security features turned on. Ensure all browsers and plugins kept updated can help prevent the exploit phase of this technique.
For malicious code served up through ads, adblockers can help prevent that code from executing in the first place. Script blocking extensions can help prevent the execution of JavaScript that may commonly be used during the exploitation process.
Browser sandboxes can be used to mitigate some of the impact of exploitation, but sandbox escapes may still exist. (Citation: Windows Blogs Microsoft Edge Sandbox) (Citation: Ars Technica Pwn2Own 2017 VM Escape)
Other types of virtualization and application microsegmentation may also mitigate the impact of client-side exploitation. The risks of additional exploits and weaknesses in implementation may still exist. (Citation: Ars Technica Pwn2Own 2017 VM Escape)
Security applications that look for behavior used during exploitation such as Windows Defender Exploit Guard (WDEG) and the Enhanced Mitigation Experience Toolkit (EMET) can be used to mitigate some exploitation behavior. (Citation: TechNet Moving Beyond EMET) Control flow integrity checking is another way to potentially identify and stop a software exploit from occurring. (Citation: Wikipedia Control Flow Integrity) Many of these protections depend on the architecture and target application binary for compatibility.
|
|
LSASS Driver Mitigation
|
On Windows 8.1 and Server 2012 R2, enable LSA Protection by setting the Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL to dword:00000001. (Citation: Microsoft LSA Protection Mar 2014) LSA Protection ensures that LSA plug-ins and drivers are only loaded if they are digitally signed with a Microsoft signature and adhere to the Microsoft Security Development Lifecycle (SDL) process guidance.
On Windows 10 and Server 2016, enable Windows Defender Credential Guard (Citation: Microsoft Enable Cred Guard April 2017) to run lsass.exe in an isolated virtualized environment without any device drivers. (Citation: Microsoft Credential Guard April 2017)
Ensure safe DLL search mode is enabled HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode to mitigate risk that lsass.exe loads a malicious code library. (Citation: Microsoft DLL Security)
|
|
Hooking Mitigation
|
This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of operating system design features. For example, mitigating all hooking will likely have unintended side effects, such as preventing legitimate software (i.e., security products) from operating properly. Efforts should be focused on preventing adversary tools from running earlier in the chain of activity and on identifying subsequent malicious behavior.
|
|
SSL/TLS Inspection
|
SSL/TLS inspection involves decrypting encrypted network traffic to examine its content for signs of malicious activity. This capability is crucial for detecting threats that use encryption to evade detection, such as phishing, malware, or data exfiltration. After inspection, the traffic is re-encrypted and forwarded to its destination. This mitigation can be implemented through the following measures:
Deploy SSL/TLS Inspection Appliances:
- Implement SSL/TLS inspection solutions to decrypt and inspect encrypted traffic.
- Ensure appliances are placed at critical network choke points for maximum coverage.
Configure Decryption Policies:
- Define rules to decrypt traffic for specific applications, ports, or domains.
- Avoid decrypting sensitive or privacy-related traffic, such as financial or healthcare websites, to comply with regulations.
Integrate Threat Intelligence:
- Use threat intelligence feeds to correlate inspected traffic with known indicators of compromise (IOCs).
Integrate with Security Tools:
- Combine SSL/TLS inspection with SIEM and NDR tools to analyze decrypted traffic and generate alerts for suspicious activity.
- Example Tools: Splunk, Darktrace
Implement Certificate Management:
- Use trusted internal or third-party certificates for traffic re-encryption after inspection.
- Regularly update certificate authorities (CAs) to ensure secure re-encryption.
Monitor and Tune:
- Continuously monitor SSL/TLS inspection logs for anomalies and fine-tune policies to reduce false positives.
|
|
Commonly Used Port Mitigation
|
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific protocol used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool C2 signatures over time or construct protocols in such a way as to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Process Hollowing Mitigation
|
This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of operating system design features. For example, mitigating specific API calls will likely have unintended side effects, such as preventing legitimate software (i.e., security products) from operating properly. Efforts should be focused on preventing adversary tools from running earlier in the chain of activity and on identifying subsequent malicious behavior.
Although process hollowing may be used to evade certain types of defenses, it is still good practice to identify potentially malicious software that may be used to perform adversarial actions and audit and/or block it by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Boot Integrity
|
Boot Integrity ensures that a system starts securely by verifying the integrity of its boot process, operating system, and associated components. This mitigation focuses on leveraging secure boot mechanisms, hardware-rooted trust, and runtime integrity checks to prevent tampering during the boot sequence. It is designed to thwart adversaries attempting to modify system firmware, bootloaders, or critical OS components. This mitigation can be implemented through the following measures:
Implementation of Secure Boot:
- Implementation: Enable UEFI Secure Boot on all systems and configure it to allow only signed bootloaders and operating systems.
- Use Case: An adversary attempts to replace the system’s bootloader with a malicious version to gain persistence. Secure Boot prevents the untrusted bootloader from executing, halting the attack.
Utilization of TPMs:
- Implementation: Configure systems to use TPM-based attestation for boot integrity, ensuring that any modification to the firmware, bootloader, or OS is detected.
- Use Case: A compromised firmware component alters the boot sequence. The TPM detects the change and triggers an alert, allowing the organization to respond before further damage.
Enable Bootloader Passwords:
- Implementation: Protect BIOS/UEFI settings with a strong password and limit physical access to devices.
- Use Case: An attacker with physical access attempts to disable Secure Boot or modify the boot sequence. The password prevents unauthorized changes.
Runtime Integrity Monitoring:
- Implementation: Deploy solutions to verify the integrity of critical files and processes after boot.
- Use Case: A malware infection modifies kernel modules post-boot. Runtime integrity monitoring detects the modification and prevents the malicious module from loading.
|
|
Data from Local System Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to collect data from the local system, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Trap Mitigation
|
Due to potential legitimate uses of trap commands, it's may be difficult to mitigate use of this technique.
|
|
Out-of-Band Communications Channel
|
Establish secure out-of-band communication channels to ensure the continuity of critical communications during security incidents, data integrity attacks, or in-network communication failures. Out-of-band communication refers to using an alternative, separate communication path that is not dependent on the potentially compromised primary network infrastructure. This method can include secure messaging apps, encrypted phone lines, satellite communications, or dedicated emergency communication systems. Leveraging these alternative channels reduces the risk of adversaries intercepting, disrupting, or tampering with sensitive communications and helps coordinate an effective incident response.(Citation: TrustedSec OOB Communications)(Citation: NIST Special Publication 800-53 Revision 5)
|
|
Dynamic Data Exchange Mitigation
|
Registry keys specific to Microsoft Office feature control security can be set to disable automatic DDE/OLE execution. (Citation: Microsoft DDE Advisory Nov 2017) (Citation: BleepingComputer DDE Disabled in Word Dec 2017) (Citation: GitHub Disable DDEAUTO Oct 2017) Microsoft also created, and enabled by default, Registry keys to completely disable DDE execution in Word and Excel. (Citation: Microsoft ADV170021 Dec 2017)
Ensure Protected View is enabled (Citation: Microsoft Protected View) and consider disabling embedded files in Office programs, such as OneNote, not enrolled in Protected View. (Citation: Enigma Reviving DDE Jan 2018) (Citation: GitHub Disable DDEAUTO Oct 2017)
On Windows 10, enable Attack Surface Reduction (ASR) rules to prevent DDE attacks and spawning of child processes from Office programs. (Citation: Microsoft ASR Nov 2017) (Citation: Enigma Reviving DDE Jan 2018)
|
|
Endpoint Denial of Service Mitigation
|
Leverage services provided by Content Delivery Networks (CDN) or providers specializing in DoS mitigations to filter traffic upstream from services.(Citation: CERT-EU DDoS March 2017) Filter boundary traffic by blocking source addresses sourcing the attack, blocking ports that are being targeted, or blocking protocols being used for transport. To defend against SYN floods, enable SYN Cookies.
|
|
System Time Discovery Mitigation
|
Benign software uses legitimate processes to gather system time. Efforts should be focused on preventing unwanted or unknown code from executing on a system. Some common tools, such as net.exe, may be blocked by policy to prevent common ways of acquiring remote system time.
Identify unnecessary system utilities or potentially malicious software that may be used to acquire system time information, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Code Signing Mitigation
|
Process whitelisting and trusted publishers to verify authenticity of software can help prevent signed malicious or untrusted code from executing on a system. (Citation: NSA MS AppLocker) (Citation: TechNet Trusted Publishers) (Citation: Securelist Digital Certificates)
|
|
Systemd Service Mitigation
|
The creation and modification of systemd service unit files is generally reserved for administrators such as the Linux root user and other users with superuser privileges. Limit user access to system utilities such as systemctl to only users who have a legitimate need. Restrict read/write access to systemd unit files to only select privileged users who have a legitimate need to manage system services. Additionally, the installation of software commonly adds and changes systemd service unit files. Restrict software installation to trusted repositories only and be cautious of orphaned software packages. Utilize malicious code protection and application whitelisting to mitigate the ability of malware to create or modify systemd services.
|
|
Hidden Files and Directories Mitigation
|
Mitigation of this technique may be difficult and unadvised due to the the legitimate use of hidden files and directories.
|
|
Network Segmentation
|
Network segmentation involves dividing a network into smaller, isolated segments to control and limit the flow of traffic between devices, systems, and applications. By segmenting networks, organizations can reduce the attack surface, restrict lateral movement by adversaries, and protect critical assets from compromise.
Effective network segmentation leverages a combination of physical boundaries, logical separation through VLANs, and access control policies enforced by network appliances like firewalls, routers, and cloud-based configurations. This mitigation can be implemented through the following measures:
Segment Critical Systems:
- Identify and group systems based on their function, sensitivity, and risk. Examples include payment systems, HR databases, production systems, and internet-facing servers.
- Use VLANs, firewalls, or routers to enforce logical separation.
Implement DMZ for Public-Facing Services:
- Host web servers, DNS servers, and email servers in a DMZ to limit their access to internal systems.
- Apply strict firewall rules to filter traffic between the DMZ and internal networks.
Use Cloud-Based Segmentation:
- In cloud environments, use VPCs, subnets, and security groups to isolate applications and enforce traffic rules.
- Apply AWS Transit Gateway or Azure VNet peering for controlled connectivity between cloud segments.
Apply Microsegmentation for Workloads:
- Use software-defined networking (SDN) tools to implement workload-level segmentation and prevent lateral movement.
Restrict Traffic with ACLs and Firewalls:
- Apply Access Control Lists (ACLs) to network devices to enforce "deny by default" policies.
- Use firewalls to restrict both north-south (external-internal) and east-west (internal-internal) traffic.
Monitor and Audit Segmented Networks:
- Regularly review firewall rules, ACLs, and segmentation policies.
- Monitor network flows for anomalies to ensure segmentation is effective.
Test Segmentation Effectiveness:
- Perform periodic penetration tests to verify that unauthorized access is blocked between network segments.
|
|
Threat Intelligence Program
|
A Threat Intelligence Program enables organizations to proactively identify, analyze, and act on cyber threats by leveraging internal and external data sources. The program supports decision-making processes, prioritizes defenses, and improves incident response by delivering actionable intelligence tailored to the organization's risk profile and operational environment. This mitigation can be implemented through the following measures:
Establish a Threat Intelligence Team:
- Form a dedicated team or assign responsibility to existing security personnel to collect, analyze, and act on threat intelligence.
Define Intelligence Requirements:
- Identify the organization’s critical assets and focus intelligence gathering efforts on threats targeting these assets.
Leverage Internal and External Data Sources:
- Collect intelligence from internal sources such as logs, incidents, and alerts.
Subscribe to external threat intelligence feeds, participate in ISACs, and monitor open-source intelligence (OSINT).
Implement Tools for Automation:
- Use threat intelligence platforms (TIPs) to automate the collection, enrichment, and dissemination of threat data.
- Integrate threat intelligence with SIEMs to correlate IOCs with internal events.
Analyze and Act on Intelligence:
- Use frameworks like MITRE ATT&CK to map intelligence to adversary TTPs.
- Prioritize defensive measures, such as patching vulnerabilities or deploying IOCs, based on analyzed threats.
Share and Collaborate:
- Share intelligence with industry peers through ISACs or threat-sharing platforms to enhance collective defense.
Evaluate and Update the Program:
- Regularly assess the effectiveness of the threat intelligence program.
- Update intelligence priorities and capabilities as new threats emerge.
*Tools for Implementation*
Threat Intelligence Platforms (TIPs):
- OpenCTI: An open-source platform for structuring and sharing threat intelligence.
- MISP: A threat intelligence sharing platform for sharing structured threat data.
Threat Intelligence Feeds:
- Open Threat Exchange (OTX): Provides free access to a large repository of threat intelligence.
- CIRCL OSINT Feed: A free source for IOCs and threat information.
Automation and Enrichment Tools:
- TheHive: An open-source incident response platform with threat intelligence integration.
- Yeti: A platform for managing and structuring knowledge about threats.
Analysis Frameworks:
- MITRE ATT&CK Navigator: A tool for mapping threat intelligence to adversary behaviors.
- Cuckoo Sandbox: Analyzes malware to extract behavioral indicators.
Community and Collaboration Tools:
- ISAC Memberships: Join industry-specific ISACs for intelligence sharing.
- Slack/Discord Channels: Participate in threat intelligence communities for real-time collaboration.
|
|
Input Prompt Mitigation
|
This technique exploits users' tendencies to always supply credentials when prompted, which makes it very difficult to mitigate. Use user training as a way to bring awareness and raise suspicion for potentially malicious events (ex: Office documents prompting for credentials).
|
|
Registry Run Keys / Startup Folder Mitigation
|
Identify and block potentially malicious software that may be executed through run key or startup folder persistence using whitelisting (Citation: Beechey 2010) tools like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Automated Collection Mitigation
|
Encryption and off-system storage of sensitive information may be one way to mitigate collection of files, but may not stop an adversary from acquiring the information if an intrusion persists over a long period of time and the adversary is able to discover and access the data through other means. A keylogger installed on a system may be able to intercept passwords through [Input Capture](https://attack.mitre.org/techniques/T1056) and be used to decrypt protected documents that an adversary may have collected. Strong passwords should be used to prevent offline cracking of encrypted documents through [Brute Force](https://attack.mitre.org/techniques/T1110) techniques.
Identify unnecessary system utilities, third-party tools, or potentially malicious software that may be used to collect files and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Rundll32 Mitigation
|
Microsoft's Enhanced Mitigation Experience Toolkit (EMET) Attack Surface Reduction (ASR) feature can be used to block methods of using rundll32.exe to bypass whitelisting. (Citation: Secure Host Baseline EMET)
|
|
Spearphishing Attachment Mitigation
|
Network intrusion prevention systems and systems designed to scan and remove malicious email attachments can be used to block activity. Solutions can be signature and behavior based, but adversaries may construct attachments in a way to avoid these systems.
Block unknown or unused attachments by default that should not be transmitted over email as a best practice to prevent some vectors, such as .scr, .exe, .pif, .cpl, etc. Some email scanning devices can open and analyze compressed and encrypted formats, such as zip and rar that may be used to conceal malicious attachments in [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027).
Because this technique involves user interaction on the endpoint, it's difficult to fully mitigate. However, there are potential mitigations. Users can be trained to identify social engineering techniques and spearphishing emails. To prevent the attachments from executing, application whitelisting can be used. Anti-virus can also automatically quarantine suspicious files.
|
|
File System Logical Offsets Mitigation
|
Identify potentially malicious software that may be used to access logical drives in this manner, and audit and/or block it by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Password Policies
|
Set and enforce secure password policies for accounts to reduce the likelihood of unauthorized access. Strong password policies include enforcing password complexity, requiring regular password changes, and preventing password reuse. This mitigation can be implemented through the following measures:
Windows Systems:
- Use Group Policy Management Console (GPMC) to configure:
- Minimum password length (e.g., 12+ characters).
- Password complexity requirements.
- Password history (e.g., disallow last 24 passwords).
- Account lockout duration and thresholds.
Linux Systems:
- Configure Pluggable Authentication Modules (PAM):
- Use `pam_pwquality` to enforce complexity and length requirements.
- Implement `pam_tally2` or `pam_faillock` for account lockouts.
- Use `pwunconv` to disable password reuse.
Password Managers:
- Enforce usage of enterprise password managers (e.g., Bitwarden, 1Password, LastPass) to generate and store strong passwords.
Password Blacklisting:
- Use tools like Have I Been Pwned password checks or NIST-based blacklist solutions to prevent users from setting compromised passwords.
Regular Auditing:
- Periodically audit password policies and account configurations to ensure compliance using tools like LAPS (Local Admin Password Solution) and vulnerability scanners.
*Tools for Implementation*
Windows:
- Group Policy Management Console (GPMC): Enforce password policies.
- Microsoft Local Administrator Password Solution (LAPS): Enforce random, unique admin passwords.
Linux/macOS:
- PAM Modules (pam_pwquality, pam_tally2, pam_faillock): Enforce password rules.
- Lynis: Audit password policies and system configurations.
Cross-Platform:
- Password Managers (Bitwarden, 1Password, KeePass): Manage and enforce strong passwords.
- Have I Been Pwned API: Prevent the use of breached passwords.
- NIST SP 800-63B compliant tools: Enforce password guidelines and blacklisting.
|
|
Behavior Prevention on Endpoint
|
Behavior Prevention on Endpoint refers to the use of technologies and strategies to detect and block potentially malicious activities by analyzing the behavior of processes, files, API calls, and other endpoint events. Rather than relying solely on known signatures, this approach leverages heuristics, machine learning, and real-time monitoring to identify anomalous patterns indicative of an attack. This mitigation can be implemented through the following measures:
Suspicious Process Behavior:
- Implementation: Use Endpoint Detection and Response (EDR) tools to monitor and block processes exhibiting unusual behavior, such as privilege escalation attempts.
- Use Case: An attacker uses a known vulnerability to spawn a privileged process from a user-level application. The endpoint tool detects the abnormal parent-child process relationship and blocks the action.
Unauthorized File Access:
- Implementation: Leverage Data Loss Prevention (DLP) or endpoint tools to block processes attempting to access sensitive files without proper authorization.
- Use Case: A process tries to read or modify a sensitive file located in a restricted directory, such as /etc/shadow on Linux or the SAM registry hive on Windows. The endpoint tool identifies this anomalous behavior and prevents it.
Abnormal API Calls:
- Implementation: Implement runtime analysis tools to monitor API calls and block those associated with malicious activities.
- Use Case: A process dynamically injects itself into another process to hijack its execution. The endpoint detects the abnormal use of APIs like `OpenProcess` and `WriteProcessMemory` and terminates the offending process.
Exploit Prevention:
- Implementation: Use behavioral exploit prevention tools to detect and block exploits attempting to gain unauthorized access.
- Use Case: A buffer overflow exploit is launched against a vulnerable application. The endpoint detects the anomalous memory write operation and halts the process.
|
|
Distributed Component Object Model Mitigation
|
Modify Registry settings (directly or using Dcomcnfg.exe) in HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AppID_GUID} associated with the process-wide security of individual COM applications. (Citation: Microsoft Process Wide Com Keys)
Modify Registry settings (directly or using Dcomcnfg.exe) in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole associated with system-wide security defaults for all COM applications that do no set their own process-wide security. (Citation: Microsoft System Wide Com Keys) (Citation: Microsoft COM ACL)
Consider disabling DCOM through Dcomcnfg.exe. (Citation: Microsoft Disable DCOM)
Enable Windows firewall, which prevents DCOM instantiation by default.
Ensure all COM alerts and Protected View are enabled. (Citation: Microsoft Protected View)
|
|
CMSTP Mitigation
|
CMSTP.exe may not be necessary within a given environment (unless using it for VPN connection installation). Consider using application whitelisting configured to block execution of CMSTP.exe if it is not required for a given system or network to prevent potential misuse by adversaries. (Citation: MSitPros CMSTP Aug 2017)
|
|
Exfiltration Over Command and Control Channel Mitigation
|
Mitigations for command and control apply. Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific obfuscation technique used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool command and control signatures over time or construct protocols in such a way to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Exploitation for Privilege Escalation Mitigation
|
Update software regularly by employing patch management for internal enterprise endpoints and servers. Develop a robust cyber threat intelligence capability to determine what types and levels of threat may use software exploits and 0-days against a particular organization. Make it difficult for adversaries to advance their operation through exploitation of undiscovered or unpatched vulnerabilities by using sandboxing, if available. Other types of virtualization and application microsegmentation may also mitigate the impact of some types of client-side exploitation. The risks of additional exploits and weaknesses in implementation may still exist. (Citation: Ars Technica Pwn2Own 2017 VM Escape)
Security applications that look for behavior used during exploitation such as Windows Defender Exploit Guard (WDEG) and the Enhanced Mitigation Experience Toolkit (EMET) can be used to mitigate some exploitation behavior. (Citation: TechNet Moving Beyond EMET) Control flow integrity checking is another way to potentially identify and stop a software exploit from occurring. (Citation: Wikipedia Control Flow Integrity) Many of these protections depend on the architecture and target application binary for compatibility and may not work for software components targeted for privilege escalation.
|
|
Service Registry Permissions Weakness Mitigation
|
Ensure proper permissions are set for Registry hives to prevent users from modifying keys for system components that may lead to privilege escalation.
Identify and block potentially malicious software that may be executed through service abuse by using whitelisting (Citation: Beechey 2010) tools like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) that are capable of auditing and/or blocking unknown programs.
|
|
User Account Management
|
User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:
Enforcing the Principle of Least Privilege
- Implementation: Assign users only the minimum permissions required to perform their job functions. Regularly audit accounts to ensure no excess permissions are granted.
- Use Case: Reduces the risk of privilege escalation by ensuring accounts cannot perform unauthorized actions.
Implementing Strong Password Policies
- Implementation: Enforce password complexity requirements (e.g., length, character types). Require password expiration every 90 days and disallow password reuse.
- Use Case: Prevents adversaries from gaining unauthorized access through password guessing or brute force attacks.
Managing Dormant and Orphaned Accounts
- Implementation: Implement automated workflows to disable accounts after a set period of inactivity (e.g., 30 days). Remove orphaned accounts (e.g., accounts without an assigned owner) during regular account audits.
- Use Case: Eliminates dormant accounts that could be exploited by attackers.
Account Lockout Policies
- Implementation: Configure account lockout thresholds (e.g., lock accounts after five failed login attempts). Set lockout durations to a minimum of 15 minutes.
- Use Case: Mitigates automated attack techniques that rely on repeated login attempts.
Multi-Factor Authentication (MFA) for High-Risk Accounts
- Implementation: Require MFA for all administrative accounts and high-risk users. Use MFA mechanisms like hardware tokens, authenticator apps, or biometrics.
- Use Case: Prevents unauthorized access, even if credentials are stolen.
Restricting Interactive Logins
- Implementation: Restrict interactive logins for privileged accounts to specific secure systems or management consoles. Use group policies to enforce logon restrictions.
- Use Case: Protects sensitive accounts from misuse or exploitation.
*Tools for Implementation*
Built-in Tools:
- Microsoft Active Directory (AD): Centralized account management and RBAC enforcement.
- Group Policy Object (GPO): Enforce password policies, logon restrictions, and account lockout policies.
Identity and Access Management (IAM) Tools:
- Okta: Centralized user provisioning, MFA, and SSO integration.
- Microsoft Azure Active Directory: Provides advanced account lifecycle management, role-based access, and conditional access policies.
Privileged Account Management (PAM):
- CyberArk, BeyondTrust, Thycotic: Manage and monitor privileged account usage, enforce session recording, and JIT access.
|
|
Authentication Package Mitigation
|
Windows 8.1, Windows Server 2012 R2, and later versions, may make LSA run as a Protected Process Light (PPL) by setting the Registry key HKLM\SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL, which requires all DLLs loaded by LSA to be signed by Microsoft. (Citation: Graeber 2014) (Citation: Microsoft Configure LSA)
|
|
Startup Items Mitigation
|
Since StartupItems are deprecated, preventing all users from writing to the /Library/StartupItems directory would prevent any startup items from getting registered. Similarly, appropriate permissions should be applied such that only specific users can edit the startup items so that they can’t be leveraged for privilege escalation.
|
|
Network Share Connection Removal Mitigation
|
Follow best practices for mitigation of activity related to establishing [Windows Admin Shares](https://attack.mitre.org/techniques/T1077).
Identify unnecessary system utilities or potentially malicious software that may be used to leverage network shares, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Man in the Browser Mitigation
|
Since browser pivoting requires a high integrity process to launch from, restricting user permissions and addressing Privilege Escalation and [Bypass User Account Control](https://attack.mitre.org/techniques/T1088) opportunities can limit the exposure to this technique.
Close all browser sessions regularly and when they are no longer needed.
|
|
AppCert DLLs Mitigation
|
Identify and block potentially malicious software that may be executed through AppCert DLLs by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) that are capable of auditing and/or blocking unknown DLLs.
|
|
Rootkit Mitigation
|
Identify potentially malicious software that may contain rootkit functionality, and audit and/or block it by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Bootkit Mitigation
|
Ensure proper permissions are in place to help prevent adversary access to privileged accounts necessary to perform this action. Use Trusted Platform Module technology and a secure or trusted boot process to prevent system integrity from being compromised. (Citation: TCG Trusted Platform Module) (Citation: TechNet Secure Boot Process)
|
|
DLL Search Order Hijacking Mitigation
|
Disallow loading of remote DLLs. (Citation: Microsoft DLL Preloading) This is included by default in Windows Server 2012+ and is available by patch for XP+ and Server 2003+. (Citation: Microsoft DLL Search) Path Algorithm
Enable Safe DLL Search Mode to force search for system DLLs in directories with greater restrictions (e.g. %SYSTEMROOT%)to be used before local directory DLLs (e.g. a user's home directory). The Safe DLL Search Mode can be enabled via Group Policy at Computer Configuration > [Policies] > Administrative Templates > MSS (Legacy): MSS: (SafeDllSearchMode) Enable Safe DLL search mode. The associated Windows Registry key for this is located at HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SafeDLLSearchMode (Citation: Microsoft DLL Search)
Use auditing tools capable of detecting DLL search order hijacking opportunities on systems within an enterprise and correct them. Toolkits like the PowerSploit framework contain PowerUp modules that can be used to explore systems for DLL hijacking weaknesses. (Citation: Powersploit)
Identify and block potentially malicious software that may be executed through search order hijacking by using whitelisting (Citation: Beechey 2010) tools like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) that are capable of auditing and/or blocking unknown DLLs.
|
|
Supply Chain Compromise Mitigation
|
Apply supply chain risk management (SCRM) practices and procedures (Citation: MITRE SE Guide 2014), such as supply chain analysis and appropriate risk management, throughout the life-cycle of a system.
Leverage established software development lifecycle (SDLC) practices (Citation: NIST Supply Chain 2012):
* Uniquely Identify Supply Chain Elements, Processes, and Actors
* Limit Access and Exposure within the Supply Chain
* Establish and Maintain the Provenance of Elements, Processes, Tools, and Data
* Share Information within Strict Limits
* Perform SCRM Awareness and Training
* Use Defensive Design for Systems, Elements, and Processes
* Perform Continuous Integrator Review
* Strengthen Delivery Mechanisms
* Assure Sustainment Activities and Processes
* Manage Disposal and Final Disposition Activities throughout the System or Element Life Cycle
A patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation. Continuous monitoring of vulnerability sources and the use of automatic and manual code review tools should also be implemented as well. (Citation: OWASP Top 10 2017)
|
|
Restrict File and Directory Permissions
|
Restricting file and directory permissions involves setting access controls at the file system level to limit which users, groups, or processes can read, write, or execute files. By configuring permissions appropriately, organizations can reduce the attack surface for adversaries seeking to access sensitive data, plant malicious code, or tamper with system files.
Enforce Least Privilege Permissions:
- Remove unnecessary write permissions on sensitive files and directories.
- Use file ownership and groups to control access for specific roles.
Example (Windows): Right-click the shared folder → Properties → Security tab → Adjust permissions for NTFS ACLs.
Harden File Shares:
- Disable anonymous access to shared folders.
- Enforce NTFS permissions for shared folders on Windows.
Example: Set permissions to restrict write access to critical files, such as system executables (e.g., `/bin` or `/sbin` on Linux). Use tools like `chown` and `chmod` to assign file ownership and limit access.
On Linux, apply:
`chmod 750 /etc/sensitive.conf`
`chown root:admin /etc/sensitive.conf`
File Integrity Monitoring (FIM):
- Use tools like Tripwire, Wazuh, or OSSEC to monitor changes to critical file permissions.
Audit File System Access:
- Enable auditing to track permission changes or unauthorized access attempts.
- Use auditd (Linux) or Event Viewer (Windows) to log activities.
Restrict Startup Directories:
- Configure permissions to prevent unauthorized writes to directories like `C:\ProgramData\Microsoft\Windows\Start Menu`.
Example: Restrict write access to critical directories like `/etc/`, `/usr/local/`, and Windows directories such as `C:\Windows\System32`.
- On Windows, use icacls to modify permissions: `icacls "C:\Windows\System32" /inheritance:r /grant:r SYSTEM:(OI)(CI)F`
- On Linux, monitor permissions using tools like `lsattr` or `auditd`.
|
|
Create Account Mitigation
|
Use and enforce multifactor authentication. Follow guidelines to prevent or limit adversary access to [Valid Accounts](https://attack.mitre.org/techniques/T1078) that may be used to create privileged accounts within an environment.
Adversaries that create local accounts on systems may have limited access within a network if access levels are properly locked down. These accounts may only be needed for persistence on individual systems and their usefulness depends on the utility of the system they reside on.
Protect domain controllers by ensuring proper security configuration for critical servers. Configure access controls and firewalls to limit access to these systems. Do not allow domain administrator accounts to be used for day-to-day operations that may expose them to potential adversaries on unprivileged systems.
|
|
Remote System Discovery Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to acquire information on remotely available systems, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Logon Scripts Mitigation
|
Restrict write access to logon scripts to specific administrators. Prevent access to administrator accounts by mitigating Credential Access techniques and limiting account access and permissions of [Valid Accounts](https://attack.mitre.org/techniques/T1078).
Identify and block potentially malicious software that may be executed through logon script modification by using whitelisting (Citation: Beechey 2010) tools like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) that are capable of auditing and/or blocking unknown programs.
|
|
Privileged Account Management
|
Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:
Account Permissions and Roles:
- Implement RBAC and least privilege principles to allocate permissions securely.
- Use tools like Active Directory Group Policies to enforce access restrictions.
Credential Security:
- Deploy password vaulting tools like CyberArk, HashiCorp Vault, or KeePass for secure storage and rotation of credentials.
- Enforce password policies for complexity, uniqueness, and expiration using tools like Microsoft Group Policy Objects (GPO).
Multi-Factor Authentication (MFA):
- Enforce MFA for all privileged accounts using Duo Security, Okta, or Microsoft Azure AD MFA.
Privileged Access Management (PAM):
- Use PAM solutions like CyberArk, BeyondTrust, or Thycotic to manage, monitor, and audit privileged access.
Auditing and Monitoring:
- Integrate activity monitoring into your SIEM (e.g., Splunk or QRadar) to detect and alert on anomalous privileged account usage.
Just-In-Time Access:
- Deploy JIT solutions like Azure Privileged Identity Management (PIM) or configure ephemeral roles in AWS and GCP to grant time-limited elevated permissions.
*Tools for Implementation*
Privileged Access Management (PAM):
- CyberArk, BeyondTrust, Thycotic, HashiCorp Vault.
Credential Management:
- Microsoft LAPS (Local Admin Password Solution), Password Safe, HashiCorp Vault, KeePass.
Multi-Factor Authentication:
- Duo Security, Okta, Microsoft Azure MFA, Google Authenticator.
Linux Privilege Management:
- sudo configuration, SELinux, AppArmor.
Just-In-Time Access:
- Azure Privileged Identity Management (PIM), AWS IAM Roles with session constraints, GCP Identity-Aware Proxy.
|
|
Screensaver Mitigation
|
Block .scr files from being executed from non-standard locations. Set Group Policy to force users to have a dedicated screensaver where local changes should not override the settings to prevent changes. Use Group Policy to disable screensavers if they are unnecessary. (Citation: TechNet Screensaver GP)
|
|
Security Support Provider Mitigation
|
Windows 8.1, Windows Server 2012 R2, and later versions may make LSA run as a Protected Process Light (PPL) by setting the Registry key HKLM\SYSTEM\CurrentControlSet\Control\Lsa\RunAsPPL, which requires all SSP DLLs to be signed by Microsoft. (Citation: Graeber 2014) (Citation: Microsoft Configure LSA)
|
|
Uncommonly Used Port Mitigation
|
Properly configure firewalls and proxies to limit outgoing traffic to only necessary ports.
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific protocol used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool C2 signatures over time or construct protocols in such a way as to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Shortcut Modification Mitigation
|
Limit permissions for who can create symbolic links in Windows to appropriate groups such as Administrators and necessary groups for virtualization. This can be done through GPO: Computer Configuration > [Policies] > Windows Settings > Security Settings > Local Policies > User Rights Assignment: Create symbolic links. (Citation: UCF STIG Symbolic Links)
Identify and block unknown, potentially malicious software that may be executed through shortcut modification by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Time Providers Mitigation
|
Identify and block potentially malicious software that may be executed as a time provider by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) that are capable of auditing and/or blocking unknown DLLs.
Consider using Group Policy to configure and block subsequent modifications to W32Time parameters. (Citation: Microsoft W32Time May 2017)
|
|
Restrict Registry Permissions
|
Restricting registry permissions involves configuring access control settings for sensitive registry keys and hives to ensure that only authorized users or processes can make modifications. By limiting access, organizations can prevent unauthorized changes that adversaries might use for persistence, privilege escalation, or defense evasion. This mitigation can be implemented through the following measures:
Review and Adjust Permissions on Critical Keys
- Regularly review permissions on keys such as `Run`, `RunOnce`, and `Services` to ensure only authorized users have write access.
- Use tools like `icacls` or `PowerShell` to automate permission adjustments.
Enable Registry Auditing
- Enable auditing on sensitive keys to log access attempts.
- Use Event Viewer or SIEM solutions to analyze logs and detect suspicious activity.
- Example Audit Policy: `auditpol /set /subcategory:"Registry" /success:enable /failure:enable`
Protect Credential-Related Hives
- Limit access to hives like `SAM`,`SECURITY`, and `SYSTEM` to prevent credential dumping or other unauthorized access.
- Use LSA Protection to add an additional security layer for credential storage.
Restrict Registry Editor Usage
- Use Group Policy to restrict access to regedit.exe for non-administrative users.
- Block execution of registry editing tools on endpoints where they are unnecessary.
Deploy Baseline Configuration Tools
- Use tools like Microsoft Security Compliance Toolkit or CIS Benchmarks to apply and maintain secure registry configurations.
*Tools for Implementation*
Registry Permission Tools:
- Registry Editor (regedit): Built-in tool to manage registry permissions.
- PowerShell: Automate permissions and manage keys. `Set-ItemProperty -Path "HKLM:\Software\Microsoft\Windows\CurrentVersion\Run" -Name "KeyName" -Value "Value"`
- icacls: Command-line tool to modify ACLs.
Monitoring Tools:
- Sysmon: Monitor and log registry events.
- Event Viewer: View registry access logs.
Policy Management Tools:
- Group Policy Management Console (GPMC): Enforce registry permissions via GPOs.
- Microsoft Endpoint Manager: Deploy configuration baselines for registry permissions.
|
|
Kerberoasting Mitigation
|
Ensure strong password length (ideally 25+ characters) and complexity for service accounts and that these passwords periodically expire. (Citation: AdSecurity Cracking Kerberos Dec 2015) Also consider using Group Managed Service Accounts or another third party product such as password vaulting. (Citation: AdSecurity Cracking Kerberos Dec 2015)
Limit service accounts to minimal required privileges, including membership in privileged groups such as Domain Administrators. (Citation: AdSecurity Cracking Kerberos Dec 2015)
Enable AES Kerberos encryption (or another stronger encryption algorithm), rather than RC4, where possible. (Citation: AdSecurity Cracking Kerberos Dec 2015)
|
|
Custom Cryptographic Protocol Mitigation
|
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Since the custom protocol used may not adhere to typical protocol standards, there may be opportunities to signature the traffic on a network level for detection. Signatures are often for unique indicators within protocols and may be based on the specific protocol used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool C2 signatures over time or construct protocols in such a way as to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Antivirus/Antimalware
|
Antivirus/Antimalware solutions utilize signatures, heuristics, and behavioral analysis to detect, block, and remediate malicious software, including viruses, trojans, ransomware, and spyware. These solutions continuously monitor endpoints and systems for known malicious patterns and suspicious behaviors that indicate compromise. Antivirus/Antimalware software should be deployed across all devices, with automated updates to ensure protection against the latest threats. This mitigation can be implemented through the following measures:
Signature-Based Detection:
- Implementation: Use predefined signatures to identify known malware based on unique patterns such as file hashes, byte sequences, or command-line arguments. This method is effective against known threats.
- Use Case: When malware like "Emotet" is detected, its signature (such as a specific file hash) matches a known database of malicious software, triggering an alert and allowing immediate quarantine of the infected file.
Heuristic-Based Detection:
- Implementation: Deploy heuristic algorithms that analyze behavior and characteristics of files and processes to identify potential malware, even if it doesn’t match a known signature.
- Use Case: If a program attempts to modify multiple critical system files or initiate suspicious network communications, heuristic analysis may flag it as potentially malicious, even if no specific malware signature is available.
Behavioral Detection (Behavior Prevention):
- Implementation: Use behavioral analysis to detect patterns of abnormal activities, such as unusual system calls, unauthorized file encryption, or attempts to escalate privileges.
- Use Case: Behavioral analysis can detect ransomware attacks early by identifying behavior like mass file encryption, even before a specific ransomware signature has been identified.
Real-Time Scanning:
- Implementation: Enable real-time scanning to automatically inspect files and network traffic for signs of malware as they are accessed, downloaded, or executed.
- Use Case: When a user downloads an email attachment, the antivirus solution scans the file in real-time, checking it against both signatures and heuristics to detect any malicious content before it can be opened.
Cloud-Assisted Threat Intelligence:
- Implementation: Use cloud-based threat intelligence to ensure the antivirus solution can access the latest malware definitions and real-time threat feeds from a global database of emerging threats.
- Use Case: Cloud-assisted antivirus solutions quickly identify newly discovered malware by cross-referencing against global threat databases, providing real-time protection against zero-day attacks.
**Tools for Implementation**:
- Endpoint Security Platforms: Use solutions such as EDR for comprehensive antivirus/antimalware protection across all systems.
- Centralized Management: Implement centralized antivirus management consoles that provide visibility into threat activity, enable policy enforcement, and automate updates.
- Behavioral Analysis Tools: Leverage solutions with advanced behavioral analysis capabilities to detect malicious activity patterns that don’t rely on known signatures.
|
|
Standard Cryptographic Protocol Mitigation
|
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Use of encryption protocols may make typical network-based C2 detection more difficult due to a reduced ability to signature the traffic. Prior knowledge of adversary C2 infrastructure may be useful for domain and IP address blocking, but will likely not be an effective long-term solution because adversaries can change infrastructure often. (Citation: University of Birmingham C2)
|
|
Regsvcs/Regasm Mitigation
|
Regsvcs and Regasm may not be necessary within a given environment. Block execution of Regsvcs.exe and Regasm.exe if they are not required for a given system or network to prevent potential misuse by adversaries.
|
|
Exfiltration Over Other Network Medium Mitigation
|
Ensure host-based sensors maintain visibility into usage of all network adapters and prevent the creation of new ones where possible. (Citation: Microsoft GPO Bluetooth FEB 2009) (Citation: TechRepublic Wireless GPO FEB 2009)
|
|
Graphical User Interface Mitigation
|
Prevent adversaries from gaining access to credentials through Credential Access that can be used to log into remote desktop sessions on systems.
Identify unnecessary system utilities, third-party tools, or potentially malicious software that may be used to log into remote interactive sessions, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) and Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
NTFS File Attributes Mitigation
|
It may be difficult or inadvisable to block access to EA and ADSs. (Citation: Microsoft ADS Mar 2014) (Citation: Symantec ADS May 2009) Efforts should be focused on preventing potentially malicious software from running. Identify and block potentially malicious software that may contain functionality to hide information in EA and ADSs by using whitelisting (Citation: Beechey 2010) tools like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
Consider adjusting read and write permissions for NTFS EA, though this should be tested to ensure routine OS operations are not impeded. (Citation: InsiderThreat NTFS EA Oct 2017)
|
|
Bash History Mitigation
|
There are multiple methods of preventing a user's command history from being flushed to their .bash_history file, including use of the following commands:
set +o history and set -o history to start logging again;
unset HISTFILE being added to a user's .bash_rc file; and
ln -s /dev/null ~/.bash_history to write commands to /dev/nullinstead.
|
|
Spearphishing Link Mitigation
|
Because this technique involves user interaction on the endpoint, it's difficult to fully mitigate. However, there are potential mitigations. Users can be trained to identify social engineering techniques and spearphishing emails with malicious links. Determine if certain websites that can be used for spearphishing are necessary for business operations and consider blocking access if activity cannot be monitored well or if it poses a significant risk. Other mitigations can take place as [User Execution](https://attack.mitre.org/techniques/T1204) occurs.
|
|
Compile After Delivery Mitigation
|
This type of technique cannot be easily mitigated with preventive controls or patched since it is based on the abuse of operating system design features. For example, blocking all file compilation may have unintended side effects, such as preventing legitimate OS frameworks and code development mechanisms from operating properly. Consider removing compilers if not needed, otherwise efforts should be focused on preventing adversary tools from running earlier in the chain of activity and on identifying subsequent malicious behavior.
Identify unnecessary system utilities or potentially malicious software that may be used to decrypt, deobfuscate, decode, and compile files or information, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Credential Dumping Mitigation
|
### Windows
Monitor/harden access to LSASS and SAM table with tools that allow process whitelisting. Limit credential overlap across systems to prevent lateral movement opportunities using [Valid Accounts](https://attack.mitre.org/techniques/T1078) if passwords and hashes are obtained. Ensure that local administrator accounts have complex, unique passwords across all systems on the network. Do not put user or admin domain accounts in the local administrator groups across systems unless they are tightly controlled, as this is often equivalent to having a local administrator account with the same password on all systems. Follow best practices for design and administration of an enterprise network to limit privileged account use across administrative tiers. (Citation: Microsoft Securing Privileged Access)
On Windows 8.1 and Windows Server 2012 R2, enable Protected Process Light for LSA. (Citation: Microsoft LSA)
Identify and block potentially malicious software that may be used to dump credentials by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
With Windows 10, Microsoft implemented new protections called Credential Guard to protect the LSA secrets that can be used to obtain credentials through forms of credential dumping. It is not configured by default and has hardware and firmware system requirements. (Citation: TechNet Credential Guard) It also does not protect against all forms of credential dumping. (Citation: GitHub SHB Credential Guard)
Manage the access control list for “Replicating Directory Changes” and other permissions associated with domain controller replication. (Citation: AdSecurity DCSync Sept 2015) (Citation: Microsoft Replication ACL)
Consider disabling or restricting NTLM traffic. (Citation: Microsoft Disable NTLM Nov 2012)
### Linux
Scraping the passwords from memory requires root privileges. Follow best practices in restricting access to escalated privileges to avoid hostile programs from accessing such sensitive regions of memory.
|
|
Remote Access Tools Mitigation
|
Properly configure firewalls, application firewalls, and proxies to limit outgoing traffic to sites and services used by remote access tools.
Network intrusion detection and prevention systems that use network signatures may be able to prevent traffic to these services as well.
Use application whitelisting to mitigate use of and installation of unapproved software.
|
|
Multi-factor Authentication
|
Multi-Factor Authentication (MFA) enhances security by requiring users to provide at least two forms of verification to prove their identity before granting access. These factors typically include:
- *Something you know*: Passwords, PINs.
- *Something you have*: Physical tokens, smartphone authenticator apps.
- *Something you are*: Biometric data such as fingerprints, facial recognition, or retinal scans.
Implementing MFA across all critical systems and services ensures robust protection against account takeover and unauthorized access. This mitigation can be implemented through the following measures:
Identity and Access Management (IAM):
- Use IAM solutions like Azure Active Directory, Okta, or AWS IAM to enforce MFA policies for all user logins, especially for privileged roles.
- Enable conditional access policies to enforce MFA for risky sign-ins (e.g., unfamiliar devices, geolocations).
- Enable Conditional Access policies to only allow logins from trusted devices, such as those enrolled in Intune or joined via Hybrid/Entra.
Authentication Tools and Methods:
- Use authenticator applications such as Google Authenticator, Microsoft Authenticator, or Authy for time-based one-time passwords (TOTP).
- Deploy hardware-based tokens like YubiKey, RSA SecurID, or smart cards for additional security.
- Enforce biometric authentication for compatible devices and applications.
Secure Legacy Systems:
- Integrate MFA solutions with older systems using third-party tools like Duo Security or Thales SafeNet.
- Enable RADIUS/NPS servers to facilitate MFA for VPNs, RDP, and other network logins.
Monitoring and Alerting:
- Use SIEM tools to monitor failed MFA attempts, login anomalies, or brute-force attempts against MFA systems.
- Implement alerts for suspicious MFA activities, such as repeated failed codes or new device registrations.
Training and Policy Enforcement:
- Educate employees on the importance of MFA and secure authenticator usage.
- Enforce policies that require MFA on all critical systems, especially for remote access, privileged accounts, and cloud applications.
|
|
Browser Extensions Mitigation
|
Only install browser extensions from trusted sources that can be verified. Ensure extensions that are installed are the intended ones as many malicious extensions will masquerade as legitimate ones.
Browser extensions for some browsers can be controlled through Group Policy. Set a browser extension white or black list as appropriate for your security policy. (Citation: Technospot Chrome Extensions GP)
Change settings to prevent the browser from installing extensions without sufficient permissions.
Close out all browser sessions when finished using them.
|
|
Software Configuration
|
Software configuration refers to making security-focused adjustments to the settings of applications, middleware, databases, or other software to mitigate potential threats. These changes help reduce the attack surface, enforce best practices, and protect sensitive data. This mitigation can be implemented through the following measures:
Conduct a Security Review of Application Settings:
- Review the software documentation to identify recommended security configurations.
- Compare default settings against organizational policies and compliance requirements.
Implement Access Controls and Permissions:
- Restrict access to sensitive features or data within the software.
- Enforce least privilege principles for all roles and accounts interacting with the software.
Enable Logging and Monitoring:
- Configure detailed logging for key application events such as authentication failures, configuration changes, or unusual activity.
- Integrate logs with a centralized monitoring solution, such as a SIEM.
Update and Patch Software Regularly:
- Ensure the software is kept up-to-date with the latest security patches to address known vulnerabilities.
- Use automated patch management tools to streamline the update process.
Disable Unnecessary Features or Services:
- Turn off unused functionality or components that could introduce vulnerabilities, such as debugging interfaces or deprecated APIs.
Test Configuration Changes:
- Perform configuration changes in a staging environment before applying them in production.
- Conduct regular audits to ensure that settings remain aligned with security policies.
*Tools for Implementation*
Configuration Management Tools:
- Ansible: Automates configuration changes across multiple applications and environments.
- Chef: Ensures consistent application settings through code-based configuration management.
- Puppet: Automates software configurations and audits changes for compliance.
Security Benchmarking Tools:
- CIS-CAT: Provides benchmarks and audits for secure software configurations.
- Aqua Security Trivy: Scans containerized applications for configuration issues.
Vulnerability Management Solutions:
- Nessus: Identifies misconfigurations and suggests corrective actions.
Logging and Monitoring Tools:
- Splunk: Aggregates and analyzes application logs to detect suspicious activity.
|
|
DCShadow Mitigation
|
This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of AD design features. For example, mitigating specific AD API calls will likely have unintended side effects, such as preventing DC replication from operating properly. Efforts should be focused on preventing adversary tools from running earlier in the chain of activity and on identification of subsequent malicious behavior.
|
|
New Service Mitigation
|
Limit privileges of user accounts and remediate Privilege Escalation vectors so only authorized administrators can create new services.
Identify and block unnecessary system utilities or potentially malicious software that may be used to create services by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Communication Through Removable Media Mitigation
|
Disable Autorun if it is unnecessary. (Citation: Microsoft Disable Autorun) Disallow or restrict removable media at an organizational policy level if they are not required for business operations. (Citation: TechNet Removable Media Control)
|
|
SID-History Injection Mitigation
|
Clean up SID-History attributes after legitimate account migration is complete.
Consider applying SID Filtering to interforest trusts, such as forest trusts and external trusts, to exclude SID-History from requests to access domain resources. SID Filtering ensures that any authentication requests over a trust only contain SIDs of security principals from the trusted domain (i.e. preventing the trusted domain from claiming a user has membership in groups outside of the domain).
SID Filtering of forest trusts is enabled by default, but may have been disabled in some cases to allow a child domain to transitively access forest trusts. SID Filtering of external trusts is automatically enabled on all created external trusts using Server 2003 or later domain controllers. (Citation: Microsoft Trust Considerations Nov 2014) (Citation: Microsoft SID Filtering Quarantining Jan 2009) However note that SID Filtering is not automatically applied to legacy trusts or may have been deliberately disabled to allow inter-domain access to resources.
SID Filtering can be applied by: (Citation: Microsoft Netdom Trust Sept 2012)
* Disabling SIDHistory on forest trusts using the netdom tool (netdom trust /domain: /EnableSIDHistory:no on the domain controller).
* Applying SID Filter Quarantining to external trusts using the netdom tool (netdom trust /domain: /quarantine:yes on the domain controller)
Applying SID Filtering to domain trusts within a single forest is not recommended as it is an unsupported configuration and can cause breaking changes. (Citation: Microsoft Netdom Trust Sept 2012) (Citation: AdSecurity Kerberos GT Aug 2015) If a domain within a forest is untrustworthy then it should not be a member of the forest. In this situation it is necessary to first split the trusted and untrusted domains into separate forests where SID Filtering can be applied to an interforest trust.
|
|
Application Isolation and Sandboxing
|
Application Isolation and Sandboxing refers to the technique of restricting the execution of code to a controlled and isolated environment (e.g., a virtual environment, container, or sandbox). This method prevents potentially malicious code from affecting the rest of the system or network by limiting access to sensitive resources and critical operations. The goal is to contain threats and minimize their impact. This mitigation can be implemented through the following measures:
Browser Sandboxing:
- Use Case: Implement browser sandboxing to isolate untrusted web content and prevent malicious web pages or scripts from accessing sensitive system resources or initiating unauthorized downloads.
- Implementation: Use browsers with built-in sandboxing features (e.g., Google Chrome, Microsoft Edge) or deploy enhanced browser security frameworks that limit the execution scope of active content. Consider controls that monitor or restrict script-based file generation and downloads commonly abused in evasion techniques like HTML smuggling.
Application Virtualization:
- Use Case: Deploy critical or high-risk applications in a virtualized environment to ensure any compromise does not affect the host system.
- Implementation: Use application virtualization platforms to run applications in isolated environments.
Email Attachment Sandboxing:
- Use Case: Route email attachments to a sandbox environment to detect and block malware before delivering emails to end-users.
- Implementation: Integrate security solutions with sandbox capabilities to analyze email attachments.
Endpoint Sandboxing:
- Use Case: Run all downloaded files and applications in a restricted environment to monitor their behavior for malicious activity.
- Implementation: Use endpoint protection tools for sandboxing at the endpoint level.
|
|
Data Transfer Size Limits Mitigation
|
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary command and control infrastructure and malware can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific obfuscation technique used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool command and control signatures over time or construct protocols in such a way to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Inhibit System Recovery Mitigation
|
Consider technical controls to prevent the disabling of services or deletion of files involved in system recovery.
Consider implementing IT disaster recovery plans that contain procedures for taking regular data backups that can be used to restore organizational data.(Citation: Ready.gov IT DRP) Ensure backups are stored off system and is protected from common methods adversaries may use to gain access and destroy the backups to prevent recovery.
Identify potentially malicious software and audit and/or block it by using whitelisting(Citation: Beechey 2010) tools, like AppLocker,(Citation: Windows Commands JPCERT)(Citation: NSA MS AppLocker) or Software Restriction Policies(Citation: Corio 2008) where appropriate.(Citation: TechNet Applocker vs SRP)
|
|
Web Shell Mitigation
|
Ensure that externally facing Web servers are patched regularly to prevent adversary access through [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068) to gain remote code access or through file inclusion weaknesses that may allow adversaries to upload files or scripts that are automatically served as Web pages.
Audit account and group permissions to ensure that accounts used to manage servers do not overlap with accounts and permissions of users in the internal network that could be acquired through Credential Access and used to log into the Web server and plant a Web shell or pivot from the Web server into the internal network. (Citation: US-CERT Alert TA15-314A Web Shells)
|
|
Pass the Hash Mitigation
|
Monitor systems and domain logs for unusual credential logon activity. Prevent access to [Valid Accounts](https://attack.mitre.org/techniques/T1078). Apply patch KB2871997 to Windows 7 and higher systems to limit the default access of accounts in the local administrator group.
Enable pass the hash mitigations to apply UAC restrictions to local accounts on network logon. The associated Registry key is located HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy Through GPO: Computer Configuration > [Policies] > Administrative Templates > SCM: Pass the Hash Mitigations: Apply UAC restrictions to local accounts on network logons. (Citation: GitHub IAD Secure Host Baseline UAC Filtering)
Limit credential overlap across systems to prevent the damage of credential compromise and reduce the adversary's ability to perform Lateral Movement between systems. Ensure that built-in and created local administrator accounts have complex, unique passwords. Do not allow a domain user to be in the local administrator group on multiple systems.
|
|
Security Software Discovery Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to acquire information about local security software, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Bypass User Account Control Mitigation
|
Remove users from the local administrator group on systems. Although UAC bypass techniques exist, it is still prudent to use the highest enforcement level for UAC when possible and mitigate bypass opportunities that exist with techniques such as [DLL Search Order Hijacking](https://attack.mitre.org/techniques/T1038).
Check for common UAC bypass weaknesses on Windows systems to be aware of the risk posture and address issues where appropriate. (Citation: Github UACMe)
|
|
Accessibility Features Mitigation
|
To use this technique remotely, an adversary must use it in conjunction with RDP. Ensure that Network Level Authentication is enabled to force the remote desktop session to authenticate before the session is created and the login screen displayed. It is enabled by default on Windows Vista and later. (Citation: TechNet RDP NLA)
If possible, use a Remote Desktop Gateway to manage connections and security configuration of RDP within a network. (Citation: TechNet RDP Gateway)
Identify and block potentially malicious software that may be executed by an adversary with this technique by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
System Network Connections Discovery Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to acquire information about network connections, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Rc.common Mitigation
|
Limit privileges of user accounts so only authorized users can edit the rc.common file.
|
|
Local Job Scheduling Mitigation
|
Limit privileges of user accounts and remediate Privilege Escalation vectors so only authorized users can create scheduled jobs. Identify and block unnecessary system utilities or potentially malicious software that may be used to schedule jobs using whitelisting tools.
|
|
Environmental Keying Mitigation
|
This technique likely should not be mitigated with preventative controls because it may protect unintended targets from being compromised. If targeted, efforts should be focused on preventing adversary tools from running earlier in the chain of activity and on identifying subsequent malicious behavior if compromised.
|
|
Access Token Manipulation Mitigation
|
Access tokens are an integral part of the security system within Windows and cannot be turned off. However, an attacker must already have administrator level access on the local system to make full use of this technique; be sure to restrict users and accounts to the least privileges they require to do their job.
Any user can also spoof access tokens if they have legitimate credentials. Follow mitigation guidelines for preventing adversary use of [Valid Accounts](https://attack.mitre.org/techniques/T1078). Limit permissions so that users and user groups cannot create tokens. This setting should be defined for the local system account only. GPO: Computer Configuration > [Policies] > Windows Settings > Security Settings > Local Policies > User Rights Assignment: Create a token object. (Citation: Microsoft Create Token) Also define who can create a process level token to only the local and network service through GPO: Computer Configuration > [Policies] > Windows Settings > Security Settings > Local Policies > User Rights Assignment: Replace a process level token. (Citation: Microsoft Replace Process Token)
Also limit opportunities for adversaries to increase privileges by limiting Privilege Escalation opportunities.
|
|
System Information Discovery Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to acquire information about the operating system and underlying hardware, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Template Injection Mitigation
|
Consider disabling Microsoft Office macros/active content to prevent the execution of malicious payloads in documents (Citation: Microsoft Disable Macros), though this setting may not mitigate the [Forced Authentication](https://attack.mitre.org/techniques/T1187) use for this technique.
Because this technique involves user interaction on the endpoint, it's difficult to fully mitigate. However, there are potential mitigations including training users to identify social engineering techniques and spearphishing emails. Network/Host intrusion prevention systems, antivirus, and detonation chambers can be employed to prevent documents from fetching and/or executing malicious payloads. (Citation: Anomali Template Injection MAR 2018)
|
|
Spearphishing via Service Mitigation
|
Determine if certain social media sites, personal webmail services, or other service that can be used for spearphishing is necessary for business operations and consider blocking access if activity cannot be monitored well or if it poses a significant risk.
Because this technique involves use of legitimate services and user interaction on the endpoint, it's difficult to fully mitigate. However, there are potential mitigations. Users can be trained to identify social engineering techniques and spearphishing emails with malicious links. To prevent the downloads from executing, application whitelisting can be used. Anti-virus can also automatically quarantine suspicious files.
|
|
Application Deployment Software Mitigation
|
Grant access to application deployment systems only to a limited number of authorized administrators. Ensure proper system and access isolation for critical network systems through use of firewalls, account privilege separation, group policy, and multifactor authentication. Verify that account credentials that may be used to access deployment systems are unique and not used throughout the enterprise network. Patch deployment systems regularly to prevent potential remote access through [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068).
If the application deployment system can be configured to deploy only signed binaries, then ensure that the trusted signing certificates are not co-located with the application deployment system and are instead located on a system that cannot be accessed remotely or to which remote access is tightly controlled.
|
|
Software Packing Mitigation
|
Ensure updated virus definitions. Create custom signatures for observed malware. Employ heuristic-based malware detection.
Identify and prevent execution of potentially malicious software that may have been packed by using whitelisting (Citation: Beechey 2010) tools like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
BITS Jobs Mitigation
|
This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of operating system design features. For example, disabling all BITS functionality will likely have unintended side effects, such as preventing legitimate software patching and updating. Efforts should be focused on preventing adversary tools from running earlier in the chain of activity and on identification of subsequent malicious behavior. (Citation: Mondok Windows PiggyBack BITS May 2007)
Modify network and/or host firewall rules, as well as other network controls, to only allow legitimate BITS traffic.
Consider limiting access to the BITS interface to specific users or groups. (Citation: Symantec BITS May 2007)
Consider reducing the default BITS job lifetime in Group Policy or by editing the JobInactivityTimeout and MaxDownloadTime Registry values in HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\BITS. (Citation: Microsoft BITS)
|
|
Extra Window Memory Injection Mitigation
|
This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of operating system design features. For example, mitigating specific API calls will likely have unintended side effects, such as preventing legitimate software (i.e., security products) from operating properly. Efforts should be focused on preventing adversary tools from running earlier in the chain of activity and on identifying subsequent malicious behavior.
Although EWM injection may be used to evade certain types of defenses, it is still good practice to identify potentially malicious software that may be used to perform adversarial actions and audit and/or block it by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Audit
|
Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.
Auditing is applicable to all systems used within an organization, from the front door of a building to accessing a file on a fileserver. It is considered more critical for regulated industries such as, healthcare, finance and government where compliance requirements demand stringent tracking of user and system activates.This mitigation can be implemented through the following measures:
System Audit:
- Use Case: Regularly assess system configurations to ensure compliance with organizational security policies.
- Implementation: Use tools to scan for deviations from established benchmarks.
Permission Audits:
- Use Case: Review file and folder permissions to minimize the risk of unauthorized access or privilege escalation.
- Implementation: Run access reviews to identify users or groups with excessive permissions.
Software Audits:
- Use Case: Identify outdated, unsupported, or insecure software that could serve as an attack vector.
- Implementation: Use inventory and vulnerability scanning tools to detect outdated versions and recommend secure alternatives.
Configuration Audits:
- Use Case: Evaluate system and network configurations to ensure secure settings (e.g., disabled SMBv1, enabled MFA).
- Implementation: Implement automated configuration scanning tools like SCAP (Security Content Automation Protocol) to identify non-compliant systems.
Network Audits:
- Use Case: Examine network traffic, firewall rules, and endpoint communications to identify unauthorized or insecure connections.
- Implementation: Utilize tools such as Wireshark, or Zeek to monitor and log suspicious network behavior.
|
|
Remote File Copy Mitigation
|
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware or unusual data transfer over known tools and protocols like FTP can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific obfuscation technique used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool C2 signatures over time or construct protocols in such a way as to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Application Shimming Mitigation
|
There currently aren't a lot of ways to mitigate application shimming. Disabling the Shim Engine isn't recommended because Windows depends on shimming for interoperability and software may become unstable or not work. Microsoft released an optional patch update - KB3045645 - that will remove the "auto-elevate" flag within the sdbinst.exe. This will prevent use of application shimming to bypass UAC.
Changing UAC settings to "Always Notify" will give the user more visibility when UAC elevation is requested, however, this option will not be popular among users due to the constant UAC interruptions.
|
|
Execution through Module Load Mitigation
|
Directly mitigating module loads and API calls related to module loads will likely have unintended side effects, such as preventing legitimate software from operating properly. Efforts should be focused on preventing adversary tools from running earlier in the chain of activity and on identifying and correlated subsequent behavior to determine if it is the result of malicious activity.
|
|
Deobfuscate/Decode Files or Information Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to deobfuscate or decode files or information, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
PowerShell Mitigation
|
It may be possible to remove PowerShell from systems when not needed, but a review should be performed to assess the impact to an environment, since it could be in use for many legitimate purposes and administrative functions. When PowerShell is necessary, restrict PowerShell execution policy to administrators and to only execute signed scripts. Be aware that there are methods of bypassing the PowerShell execution policy, depending on environment configuration. (Citation: Netspi PowerShell Execution Policy Bypass) Disable/restrict the WinRM Service to help prevent uses of PowerShell for remote execution.
|
|
Data Obfuscation Mitigation
|
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific obfuscation technique used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool C2 signatures over time or construct protocols in such a way as to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Network Service Scanning Mitigation
|
Use network intrusion detection/prevention systems to detect and prevent remote service scans. Ensure that unnecessary ports and services are closed and proper network segmentation is followed to protect critical servers and devices.
Identify unnecessary system utilities or potentially malicious software that may be used to acquire information about services running on remote systems, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Exploit Protection
|
Deploy capabilities that detect, block, and mitigate conditions indicative of software exploits. These capabilities aim to prevent exploitation by addressing vulnerabilities, monitoring anomalous behaviors, and applying exploit-mitigation techniques to harden systems and software.
Operating System Exploit Protections:
- Use Case: Enable built-in exploit protection features provided by modern operating systems, such as Microsoft's Exploit Protection, which includes techniques like Data Execution Prevention (DEP), Address Space Layout Randomization (ASLR), and Control Flow Guard (CFG).
- Implementation: Enforce DEP for all programs and enable ASLR to randomize memory addresses used by system and application processes. Windows: Configure Exploit Protection through the Windows Security app or deploy settings via Group Policy.
`ExploitProtectionExportSettings.exe -path "exploit_settings.xml"`
Linux: Use Kernel-level hardening features like SELinux, AppArmor, or GRSEC to enforce memory protections and prevent exploits.
Third-Party Endpoint Security:
- Use Case: Use endpoint protection tools with built-in exploit protection, such as enhanced memory protection, behavior monitoring, and real-time exploit detection.
- Implementation: Deploy tools to detect and block exploitation attempts targeting unpatched software.
Virtual Patching:
- Use Case: Use tools to implement virtual patches that mitigate vulnerabilities in applications or operating systems until official patches are applied.
- Implementation: Use Intrusion Prevention System (IPS) to block exploitation attempts on known vulnerabilities in outdated applications.
Hardening Application Configurations:
- Use Case: Disable risky application features that can be exploited, such as macros in Microsoft Office or JScript in Internet Explorer.
- Implementation: Configure Microsoft Office Group Policies to disable execution of macros in downloaded files.
|
|
Mshta Mitigation
|
Mshta.exe may not be necessary within a given environment since its functionality is tied to older versions of Internet Explorer that have reached end of life. Use application whitelisting configured to block execution of mshta.exe if it is not required for a given system or network to prevent potential misuse by adversaries.
|
|
Valid Accounts Mitigation
|
Take measures to detect or prevent techniques such as [OS Credential Dumping](https://attack.mitre.org/techniques/T1003) or installation of keyloggers to acquire credentials through [Input Capture](https://attack.mitre.org/techniques/T1056). Limit credential overlap across systems to prevent access if account credentials are obtained. Ensure that local administrator accounts have complex, unique passwords across all systems on the network. Do not put user or admin domain accounts in the local administrator groups across systems unless they are tightly controlled and use of accounts is segmented, as this is often equivalent to having a local administrator account with the same password on all systems.
Follow best practices for design and administration of an enterprise network to limit privileged account use across administrative tiers. (Citation: Microsoft Securing Privileged Access)
Audit domain and local accounts as well as their permission levels routinely to look for situations that could allow an adversary to gain wide access by obtaining credentials of a privileged account. (Citation: TechNet Credential Theft) (Citation: TechNet Least Privilege) These audits should also include if default accounts have been enabled, or if new local accounts are created that have not be authorized.
Applications and appliances that utilize default username and password should be changed immediately after the installation, and before deployment to a production environment. (Citation: US-CERT Alert TA13-175A Risks of Default Passwords on the Internet) When possible, applications that use SSH keys should be updated periodically and properly secured.
|
|
External Remote Services Mitigation
|
Limit access to remote services through centrally managed concentrators such as VPNs and other managed remote access systems. Deny direct remote access to internal systems through the use of network proxies, gateways, and firewalls. Disable or block remotely available services such as [Windows Remote Management](https://attack.mitre.org/techniques/T1028). Use strong two-factor or multi-factor authentication for remote service accounts to mitigate an adversary's ability to leverage stolen credentials, but be aware of [Multi-Factor Authentication Interception](https://attack.mitre.org/techniques/T1111) techniques for some two-factor authentication implementations.
|
|
Service Execution Mitigation
|
Ensure that permissions disallow services that run at a higher permissions level from being created or interacted with by a user with a lower permission level. Also ensure that high permission level service binaries cannot be replaced or modified by users with a lower permission level.
Identify unnecessary system utilities or potentially malicious software that may be used to interact with Windows services, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Change Default File Association Mitigation
|
Direct mitigation of this technique is not recommended since it is a legitimate function that can be performed by users for software preferences. Follow Microsoft's best practices for file associations. (Citation: MSDN File Associations)
Identify and block potentially malicious software that may be executed by this technique using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
System Service Discovery Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to acquire information about services, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Data from Network Shared Drive Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to collect data from a network share, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Video Capture Mitigation
|
Mitigating this technique specifically may be difficult as it requires fine-grained API control. Efforts should be focused on preventing unwanted or unknown code from executing on a system.
Identify and block potentially malicious software that may be used to capture video and images by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Multiband Communication Mitigation
|
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific protocol used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool C2 signatures over time or construct protocols in such a way as to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Sudo Caching Mitigation
|
Setting the timestamp_timeout to 0 will require the user to input their password every time sudo is executed. Similarly, ensuring that the tty_tickets setting is enabled will prevent this leakage across tty sessions.
|
|
Dylib Hijacking Mitigation
|
Prevent users from being able to write files to the search paths for applications, both in the folders where applications are run from and the standard dylib folders. If users can't write to these directories, then they can't intercept the search path.
|
|
Permission Groups Discovery Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to acquire information about groups and permissions, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Path Interception Mitigation
|
Eliminate path interception weaknesses in program configuration files, scripts, the PATH environment variable, services, and in shortcuts by surrounding PATH variables with quotation marks when functions allow for them (Citation: Microsoft CreateProcess). Be aware of the search order Windows uses for executing or loading binaries and use fully qualified paths wherever appropriate (Citation: MSDN DLL Security). Clean up old Windows Registry keys when software is uninstalled to avoid keys with no associated legitimate binaries.
Periodically search for and correct or report path interception weaknesses on systems that may have been introduced using custom or available tools that report software using insecure path configurations (Citation: Kanthak Sentinel).
Require that all executables be placed in write-protected directories. Ensure that proper permissions and directory access control are set to deny users the ability to write files to the top-level directory C: and system directories, such as C:\Windows\, to reduce places where malicious files could be placed for execution.
Identify and block potentially malicious software that may be executed through the path interception by using whitelisting (Citation: Beechey 2010) tools, like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies, (Citation: Corio 2008) that are capable of auditing and/or blocking unknown executables.
|
|
Launchctl Mitigation
|
Prevent users from installing their own launch agents or launch daemons and instead require them to be pushed out by group policy.
|
|
Active Directory Configuration
|
Implement robust Active Directory (AD) configurations using group policies to secure user accounts, control access, and minimize the attack surface. AD configurations enable centralized control over account settings, logon policies, and permissions, reducing the risk of unauthorized access and lateral movement within the network. This mitigation can be implemented through the following measures:
Account Configuration:
- Implementation: Use domain accounts instead of local accounts to leverage AD’s centralized management, including group policies, auditing, and access control.
- Use Case: For IT staff managing shared resources, provision domain accounts that allow IT teams to log in centrally, reducing the risk of unmanaged, rogue local accounts on individual machines.
Interactive Logon Restrictions:
- Implementation: Configure group policies to restrict interactive logons (e.g., direct physical or RDP logons) for service accounts or privileged accounts that do not require such access.
- Use Case: Prevent service accounts, such as SQL Server accounts, from having interactive logon privileges. This reduces the risk of these accounts being leveraged for lateral movement if compromised.
Remote Desktop Settings:
- Implementation: Limit Remote Desktop Protocol (RDP) access to specific, authorized accounts. Use group policies to enforce this, allowing only necessary users to establish RDP sessions.
- Use Case: On sensitive servers (e.g., domain controllers or financial databases), restrict RDP access to administrative accounts only, while all other users are denied access.
Dedicated Administrative Accounts:
- Implementation: Create domain-wide administrative accounts that are restricted from interactive logons, designed solely for high-level tasks (e.g., software installation, patching).
- Use Case: Create separate administrative accounts for different purposes, such as one set of accounts for installations and another for managing repository access. This limits exposure and helps reduce attack vectors.
Authentication Silos:
- Implementation: Configure Authentication Silos in AD, using group policies to create access zones with restrictions based on membership, such as the Protected Users security group. This restricts access to critical accounts and minimizes exposure to potential threats.
- Use Case: Place high-risk or high-value accounts, such as executive or administrative accounts, in an Authentication Silo with extra controls, limiting their exposure to only necessary systems. This reduces the risk of credential misuse or abuse if these accounts are compromised.
**Tools for Implementation**:
- Active Directory Group Policies: Use Group Policy Management Console (GPMC) to configure, deploy, and enforce policies across AD environments.
- PowerShell: Automate account configuration, logon restrictions, and policy application using PowerShell scripts.
- AD Administrative Center: Manage Authentication Silos and configure high-level policies for critical user groups within AD.
|
|
Exfiltration Over Physical Medium Mitigation
|
Disable Autorun if it is unnecessary. (Citation: Microsoft Disable Autorun) Disallow or restrict removable media at an organizational policy level if they are not required for business operations. (Citation: TechNet Removable Media Control)
|
|
Update Software
|
Software updates ensure systems are protected against known vulnerabilities by applying patches and upgrades provided by vendors. Regular updates reduce the attack surface and prevent adversaries from exploiting known security gaps. This includes patching operating systems, applications, drivers, and firmware. This mitigation can be implemented through the following measures:
Regular Operating System Updates
- Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance windows.
- Use Case: Prevents exploitation of OS vulnerabilities such as privilege escalation or remote code execution.
Application Patching
- Implementation: Monitor Apache's update release notes for security patches addressing vulnerabilities. Schedule updates for off-peak hours to avoid downtime while maintaining security compliance.
- Use Case: Prevents exploitation of web application vulnerabilities, such as those leading to unauthorized access or data breaches.
Firmware Updates
- Implementation: Regularly check the vendor’s website for firmware updates addressing vulnerabilities. Plan for update deployment during scheduled maintenance to minimize business disruption.
- Use Case: Protects against vulnerabilities that adversaries could exploit to gain access to network devices or inject malicious traffic.
Emergency Patch Deployment
- Implementation: Use the emergency patch deployment feature of the organization's patch management tool to apply updates to all affected Exchange servers within 24 hours.
- Use Case: Reduces the risk of exploitation by rapidly addressing critical vulnerabilities.
Centralized Patch Management
- Implementation: Implement a centralized patch management system, such as SCCM or ManageEngine, to automate and track patch deployment across all environments. Generate regular compliance reports to ensure all systems are updated.
- Use Case: Streamlines patching processes and ensures no critical systems are missed.
*Tools for Implementation*
Patch Management Tools:
- WSUS: Manage and deploy Microsoft updates across the organization.
- ManageEngine Patch Manager Plus: Automate patch deployment for OS and third-party apps.
- Ansible: Automate updates across multiple platforms, including Linux and Windows.
Vulnerability Scanning Tools:
- OpenVAS: Open-source vulnerability scanning to identify missing patches.
|
|
Restrict Library Loading
|
Restricting library loading involves implementing security controls to ensure that only trusted and verified libraries (DLLs, shared objects, etc.) are loaded into processes. Adversaries often abuse Dynamic-Link Library (DLL) Injection, DLL Search Order Hijacking, or LD_PRELOAD mechanisms to execute malicious code by forcing the operating system to load untrusted libraries. This mitigation can be implemented through the following measures:
Enforce Safe Library Loading Practices:
- Enable `SafeDLLSearchMode` on Windows.
- Restrict `LD_PRELOAD` and `LD_LIBRARY_PATH` usage on Linux systems.
Code Signing Enforcement:
- Require digital signatures for all libraries loaded into processes.
- Use tools like Signtool, and WDAC to enforce signed DLL execution.
Environment Hardening:
- Secure library paths and directories to prevent adversaries from placing rogue libraries.
- Monitor user-writable directories and system configurations for unauthorized changes.
Audit and Monitor Library Loading:
- Enable `Sysmon` on Windows to monitor for suspicious library loads.
- Use `auditd` on Linux to monitor shared library paths and configuration file changes.
Use Application Control Solutions:
- Implement AppLocker, WDAC, or SELinux to allow only trusted libraries.
*Tools for Implementation*
Windows-Specific Tools:
- AppLocker: Application whitelisting for DLLs.
- Windows Defender Application Control (WDAC): Restrict unauthorized library execution.
- Signtool: Verify and enforce code signing.
- Sysmon: Monitor DLL load events (Event ID 7).
Linux-Specific Tools:
- auditd: Monitor changes to library paths and critical files.
- SELinux/AppArmor: Define policies to restrict library loading.
- ldconfig and chattr: Secure LD configuration files and prevent unauthorized modifications.
Cross-Platform Solutions:
- Wazuh or OSSEC: File integrity monitoring for library changes.
- Tripwire: Detect and alert on unauthorized library modifications.
|
|
Two-Factor Authentication Interception Mitigation
|
Remove smart cards when not in use. Protect devices and services used to transmit and receive out-of-band codes.
Identify and block potentially malicious software that may be used to intercept 2FA credentials on a system by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Stored Data Manipulation Mitigation
|
Identify critical business and system processes that may be targeted by adversaries and work to secure the data related to those processes against tampering. Ensure least privilege principles are applied to important information resources to reduce exposure to data manipulation risk. Consider encrypting important information to reduce an adversaries ability to perform tailor data modifications. Where applicable, examine using file monitoring software to check integrity on important files and directories as well as take corrective actions when unauthorized changes are detected.
Consider implementing IT disaster recovery plans that contain procedures for taking regular data backups that can be used to restore organizational data.(Citation: Ready.gov IT DRP) Ensure backups are stored off system and is protected from common methods adversaries may use to gain access and manipulate backups.
|
|
Disable or Remove Feature or Program
|
Disable or remove unnecessary and potentially vulnerable software, features, or services to reduce the attack surface and prevent abuse by adversaries. This involves identifying software or features that are no longer needed or that could be exploited and ensuring they are either removed or properly disabled. This mitigation can be implemented through the following measures:
Remove Legacy Software:
- Use Case: Disable or remove older versions of software that no longer receive updates or security patches (e.g., legacy Java, Adobe Flash).
- Implementation: A company removes Flash Player from all employee systems after it has reached its end-of-life date.
Disable Unused Features:
- Use Case: Turn off unnecessary operating system features like SMBv1, Telnet, or RDP if they are not required.
- Implementation: Disable SMBv1 in a Windows environment to mitigate vulnerabilities like EternalBlue.
Control Applications Installed by Users:
- Use Case: Prevent users from installing unauthorized software via group policies or other management tools.
- Implementation: Block user installations of unauthorized file-sharing applications (e.g., BitTorrent clients) in an enterprise environment.
Remove Unnecessary Services:
- Use Case: Identify and disable unnecessary default services running on endpoints, servers, or network devices.
- Implementation: Disable unused administrative shares (e.g., C$, ADMIN$) on workstations.
Restrict Add-ons and Plugins:
- Use Case: Remove or disable browser plugins and add-ons that are not needed for business purposes.
- Implementation: Disable Java and ActiveX plugins in web browsers to prevent drive-by attacks.
|
|
InstallUtil Mitigation
|
InstallUtil may not be necessary within a given environment. Use application whitelisting configured to block execution of InstallUtil.exe if it is not required for a given system or network to prevent potential misuse by adversaries.
|
|
Indicator Blocking Mitigation
|
Ensure event tracers/forwarders (Citation: Microsoft ETW May 2018), firewall policies, and other associated mechanisms are secured with appropriate permissions and access controls. Consider automatically relaunching forwarding mechanisms at recurring intervals (ex: temporal, on-logon, etc.) as well as applying appropriate change management to firewall rules and other related system configurations.
|
|
Modify Registry Mitigation
|
Misconfiguration of permissions in the Registry may lead to opportunities for an adversary to execute code, like through [Service Registry Permissions Weakness](https://attack.mitre.org/techniques/T1058). Ensure proper permissions are set for Registry hives to prevent users from modifying keys for system components that may lead to privilege escalation.
Identify and block unnecessary system utilities or potentially malicious software that may be used to modify the Registry by using whitelisting (Citation: Beechey 2010) tools like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
SIP and Trust Provider Hijacking Mitigation
|
Ensure proper permissions are set for Registry hives to prevent users from modifying keys related to SIP and trust provider components. Also ensure that these values contain their full path to prevent [DLL Search Order Hijacking](https://attack.mitre.org/techniques/T1038). (Citation: SpectorOps Subverting Trust Sept 2017)
Consider removing unnecessary and/or stale SIPs. (Citation: SpectorOps Subverting Trust Sept 2017)
Restrict storage and execution of SIP DLLs to protected directories, such as C:\Windows, rather than user directories.
Enable whitelisting solutions such as AppLocker and/or Device Guard to block the loading of malicious SIP DLLs. Components may still be able to be hijacked to suitable functions already present on disk if malicious modifications to Registry keys are not prevented.
|
|
Replication Through Removable Media Mitigation
|
Disable Autorun if it is unnecessary. (Citation: Microsoft Disable Autorun) Disallow or restrict removable media at an organizational policy level if it is not required for business operations. (Citation: TechNet Removable Media Control)
Identify potentially malicious software that may be used to infect removable media or may result from tainted removable media, and audit and/or block it by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Taint Shared Content Mitigation
|
Protect shared folders by minimizing users who have write access. Use utilities that detect or mitigate common features used in exploitation, such as the Microsoft Enhanced Mitigation Experience Toolkit (EMET).
Reduce potential lateral movement risk by using web-based document management and collaboration services that do not use network file and directory sharing.
Identify potentially malicious software that may be used to taint content or may result from it and audit and/or block the unknown programs by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Private Keys Mitigation
|
Use strong passphrases for private keys to make cracking difficult. When possible, store keys on separate cryptographic hardware instead of on the local system. Ensure only authorized keys are allowed access to critical resources and audit access lists regularly. Ensure permissions are properly set on folders containing sensitive private keys to prevent unintended access. Use separate infrastructure for managing critical systems to prevent overlap of credentials and permissions on systems that could be used as vectors for lateral movement. Follow other best practices for mitigating access through use of [Valid Accounts](https://attack.mitre.org/techniques/T1078).
|
|
Scheduled Task Mitigation
|
Limit privileges of user accounts and remediate Privilege Escalation vectors so only authorized administrators can create scheduled tasks on remote systems. Toolkits like the PowerSploit framework contain PowerUp modules that can be used to explore systems for permission weaknesses in scheduled tasks that could be used to escalate privileges. (Citation: Powersploit)
Configure settings for scheduled tasks to force tasks to run under the context of the authenticated account instead of allowing them to run as SYSTEM. The associated Registry key is located at HKLM\SYSTEM\CurrentControlSet\Control\Lsa\SubmitControl. The setting can be configured through GPO: Computer Configuration > [Policies] > Windows Settings > Security Settings > Local Policies > Security Options: Domain Controller: Allow server operators to schedule tasks, set to disabled. (Citation: TechNet Server Operator Scheduled Task)
Configure the Increase Scheduling Priority option to only allow the Administrators group the rights to schedule a priority process. This can be can be configured through GPO: Computer Configuration > [Policies] > Windows Settings > Security Settings > Local Policies > User Rights Assignment: Increase scheduling priority. (Citation: TechNet Scheduling Priority)
Identify and block unnecessary system utilities or potentially malicious software that may be used to schedule tasks using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Exploitation for Client Execution Mitigation
|
Browser sandboxes can be used to mitigate some of the impact of exploitation, but sandbox escapes may still exist. (Citation: Windows Blogs Microsoft Edge Sandbox) (Citation: Ars Technica Pwn2Own 2017 VM Escape)
Other types of virtualization and application microsegmentation may also mitigate the impact of client-side exploitation. The risks of additional exploits and weaknesses in implementation may still exist. (Citation: Ars Technica Pwn2Own 2017 VM Escape)
Security applications that look for behavior used during exploitation such as Windows Defender Exploit Guard (WDEG) and the Enhanced Mitigation Experience Toolkit (EMET) can be used to mitigate some exploitation behavior. (Citation: TechNet Moving Beyond EMET) Control flow integrity checking is another way to potentially identify and stop a software exploit from occurring. (Citation: Wikipedia Control Flow Integrity) Many of these protections depend on the architecture and target application binary for compatibility.
|
|
Custom Command and Control Protocol Mitigation
|
Properly configure firewalls and proxies to limit outgoing traffic to only necessary ports and through proper network gateway systems. Also ensure hosts are only provisioned to communicate over authorized interfaces.
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific protocol used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool C2 signatures over time or construct protocols in such a way as to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Process Discovery Mitigation
|
Identify unnecessary system utilities or potentially malicious software that may be used to acquire information about processes, and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Port Knocking Mitigation
|
Mitigation of some variants of this technique could be achieved through the use of stateful firewalls, depending upon how it is implemented.
|
|
Redundant Access Mitigation
|
Identify and block potentially malicious software that may be used as a remote access tool, and audit and/or block it by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and will be different across various malware families and versions. Adversaries will likely change tool signatures over time or construct protocols in such a way as to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Account Use Policies
|
Account Use Policies help mitigate unauthorized access by configuring and enforcing rules that govern how and when accounts can be used. These policies include enforcing account lockout mechanisms, restricting login times, and setting inactivity timeouts. Proper configuration of these policies reduces the risk of brute-force attacks, credential theft, and unauthorized access by limiting the opportunities for malicious actors to exploit accounts. This mitigation can be implemented through the following measures:
Account Lockout Policies:
- Implementation: Configure account lockout settings so that after a defined number of failed login attempts (e.g., 3-5 attempts), the account is locked for a specific time period (e.g., 15 minutes) or requires an administrator to unlock it.
- Use Case: This prevents brute-force attacks by limiting how many incorrect password attempts can be made before the account is temporarily disabled, reducing the likelihood of an attacker successfully guessing a password.
Login Time Restrictions:
- Implementation: Set up login time policies to restrict when users or groups can log into systems. For example, only allowing login during standard business hours (e.g., 8 AM to 6 PM) for non-administrative accounts.
- Use Case: This prevents unauthorized access outside of approved working hours, where login attempts might be more suspicious or harder to monitor. For example, if an account that is only supposed to be active during the day logs in at 2 AM, it should raise an alert or be blocked.
Inactivity Timeout and Session Termination:
- Implementation: Enforce session timeouts after a period of inactivity (e.g., 10-15 minutes) and require users to re-authenticate if they wish to resume the session.
- Use Case: This policy prevents attackers from hijacking active sessions left unattended. For example, if an employee walks away from their computer without locking it, an attacker with physical access to the system would be unable to exploit the session.
Password Aging Policies:
- Implementation: Enforce password aging rules, requiring users to change their passwords after a defined period (e.g., 90 days) and ensure passwords are not reused by maintaining a password history.
- Use Case: This limits the risk of compromised passwords being used indefinitely. Regular password changes make it more difficult for attackers to reuse stolen credentials.
Account Expiration and Deactivation:
- Implementation: Configure user accounts, especially for temporary or contract workers, to automatically expire after a set date or event. Accounts that remain unused for a specific period should be deactivated automatically.
- Use Case: This prevents dormant accounts from becoming an attack vector. For example, an attacker can exploit unused accounts if they are not properly monitored or deactivated.
**Tools for Implementation**:
- Group Policy Objects (GPOs) in Windows: To enforce account lockout thresholds, login time restrictions, session timeouts, and password policies.
- Identity and Access Management (IAM) solutions: For centralized management of user accounts, session policies, and automated deactivation of accounts.
- Security Information and Event Management (SIEM) platforms: To monitor and alert on unusual login activity, such as failed logins or out-of-hours access attempts.
- Multi-Factor Authentication (MFA) Tools: To further enforce secure login attempts, preventing brute-force or credential stuffing attacks.
|
|
Hidden Window Mitigation
|
Whitelist programs that are allowed to have this plist tag. All other programs should be considered suspicious.
|
|
Data Encoding Mitigation
|
Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific obfuscation technique used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool C2 signatures over time or construct protocols in such a way as to avoid detection by common defensive tools. (Citation: University of Birmingham C2)
|
|
Modify Existing Service Mitigation
|
Use auditing tools capable of detecting privilege and service abuse opportunities on systems within an enterprise and correct them. Limit privileges of user accounts and groups so that only authorized administrators can interact with service changes and service configurations. Toolkits like the PowerSploit framework contain the PowerUp modules that can be used to explore systems for Privilege Escalation weaknesses. (Citation: Powersploit)
Identify and block potentially malicious software that may be executed through service abuse by using whitelisting (Citation: Beechey 2010) tools like AppLocker (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) that are capable of auditing and/or blocking unknown programs.
|
|
Encrypt Sensitive Information
|
Protect sensitive information at rest, in transit, and during processing by using strong encryption algorithms. Encryption ensures the confidentiality and integrity of data, preventing unauthorized access or tampering. This mitigation can be implemented through the following measures:
Encrypt Data at Rest:
- Use Case: Use full-disk encryption or file-level encryption to secure sensitive data stored on devices.
- Implementation: Implement BitLocker for Windows systems or FileVault for macOS devices to encrypt hard drives.
Encrypt Data in Transit:
- Use Case: Use secure communication protocols (e.g., TLS, HTTPS) to encrypt sensitive data as it travels over networks.
- Implementation: Enable HTTPS for all web applications and configure mail servers to enforce STARTTLS for email encryption.
Encrypt Backups:
- Use Case: Ensure that backup data is encrypted both during storage and transfer to prevent unauthorized access.
- Implementation: Encrypt cloud backups using AES-256 before uploading them to Amazon S3 or Google Cloud.
Encrypt Application Secrets:
- Use Case: Store sensitive credentials, API keys, and configuration files in encrypted vaults.
- Implementation: Use HashiCorp Vault or AWS Secrets Manager to manage and encrypt secrets.
Database Encryption:
- Use Case: Enable Transparent Data Encryption (TDE) or column-level encryption in database management systems.
- Implementation: Use MySQL’s built-in encryption features to encrypt sensitive database fields such as social security numbers.
|
|
Component Object Model Hijacking Mitigation
|
Direct mitigation of this technique may not be recommended for a particular environment since COM objects are a legitimate part of the operating system and installed software. Blocking COM object changes may have unforeseen side effects to legitimate functionality.
Instead, identify and block potentially malicious software that may execute, or be executed by, this technique using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
|
|
Analytic 0110
|
Monitor /var/log/audit/audit.log and DNS resolver logs for repeated failed lookups or connections to high-entropy domain names. Correlate suspicious DNS queries with process lineage (e.g., Python, bash, or unusual system daemons).
|
|
Analytic 0613
|
Detection of Linux container escape attempts via syscalls (`unshare`, `keyctl`, `mount`) or process execution outside container namespaces. Defenders may correlate unusual system calls from containerized processes with subsequent process creation on the host or modification of host resources.
|
|
Analytic 0769
|
The adversary invokes built-in scripting or decoding tools like base64, plutil, or AppleScript-based utilities to decode files embedded in staging artifacts. Decoding often occurs post-download or as part of post-exploitation payload deployment via zsh, python, or osascript.
|
|
Analytic 0068
|
Detection of packed Mach-O binaries unpacking into memory and transferring control to dynamically modified code segments.
|
|
Analytic 0887
|
Execution of commands that stop or kill processes associated with logging or security daemons (auditd, syslog, falco). Detect modifications to iptables or disabling SELinux/AppArmor enforcement. Correlate sudo/root context with abrupt service halts.
|
|
Analytic 0061
|
Adversary disables or stops critical services (e.g., Exchange, SQL, AV, endpoint monitoring) using native utilities or API calls, often preceding destructive actions (T1485, T1486). Behavioral chain: Elevated execution context + stop-service or sc.exe or ChangeServiceConfigW + terminated or disabled service + possible follow-up file manipulation.
|
|
Analytic 1421
|
Detects use of vulnerable kernel extensions or entitlements abused via setuid or AppleScript injection chains.
|
|
Analytic 0295
|
Sudden valid logins from accounts that previously had credentials dumped but had not authenticated successfully in the past; correlated with timeline of suspected hash cracking
|
|
Analytic 0534
|
Suspicious sign-ins to Graph API or sensitive resources using non-browser scripting agents (e.g., Python, PowerShell), often for programmatic access to mailbox or OneDrive content.
|
|
Analytic 0010
|
User modification of the $PATH environment variable in shell configuration files or direct runtime PATH changes, followed by execution of binaries from user-controlled directories. Defender observes file edits to ~/.bashrc, ~/.profile, or /etc/paths.d and process execution resolving to unexpected binary locations.
|
|
Analytic 0491
|
Flood of incoming TLS or HTTP(S) connections to macOS-hosted services (e.g., MAMP, Apache), causing high CPU usage and system unresponsiveness.
|
|
Analytic 1104
|
Adversary uses 'esxcli software vib list' to enumerate installed VIBs, drivers, and modules.
|
|
Analytic 1112
|
Detects suspicious access to macOS Keychain files and APIs. Observes processes invoking the 'security' utility or accessing Keychain databases directly, correlates these with abnormal parent process lineage or unexpected user context. Monitors attempts to dump, unlock, or read credential storage beyond normal application workflows.
|
|
Analytic 1532
|
Use of hcitool, bluetoothctl, or rfcomm to initialize Bluetooth connection paired with recent file reads by the same user or session.
|
|
Analytic 0417
|
Adversary gains access to cloud-hosted services such as AWS SES, SNS, or OpenAI API, enables or modifies usage policies, and initiates resource-intensive actions (e.g., mass email/SMS or LLM queries), often from unauthorized regions or under anomalous identity conditions.
|
|
Analytic 0726
|
Detects staged data aggregated in /Users/Shared, /private/tmp with compression tools like ditto or zip, initiated via Terminal or AppleScript.
|
|
Analytic 0469
|
Detects PowerShell `Clear-History` invocation or deletion of `ConsoleHost_history.txt` to erase past PowerShell session history.
|
|
Analytic 0053
|
A process loads a shared object (.so) via dlopen/LD_PRELOAD/open from non-standard or temporary locations (e.g., /tmp, /dev/shm), especially shortly after that .so is written or fetched, or linked via manipulated environment variables (LD_PRELOAD/LD_LIBRARY_PATH).
|
|
Analytic 0860
|
Access to local credential/config files (e.g., ~/.aws/credentials) followed by metadata API calls or cloud role assumptions.
|
|
Analytic 0876
|
Correlates interface mode changes to promiscuous with execution of sniffing tools like tcpdump, tshark, or custom pcap libraries. Detects abnormal NIC configurations and unauthorized sniffing from non-root sessions.
|
|
Analytic 0595
|
Adversary modifies or replaces the Terminal Services DLL (`termsrv.dll`) or changes the associated `ServiceDll` Registry value to load an arbitrary or patched DLL that enables persistent and enhanced RDP access. This may include binary replacement, registry tampering, and unexpected module loads by the `svchost.exe -k termsvcs` process.
|
|
Analytic 0656
|
Phishing attachments executed on Linux systems are detected by linking email logs to file creation in mail directories and subsequent suspicious process execution. Look for unexpected binaries or scripts spawned from user mail directories and anomalous outbound network activity.
|
|
Analytic 1063
|
Execution of unsigned kernel extensions (KEXTs), tampering with LaunchDaemons, or userspace hooks into system libraries.
|
|
Analytic 1079
|
Detects adversary creation of cloud or IdP accounts whose names resemble existing privileged or service accounts. May indicate preparation for privilege escalation or defense evasion.
|
|
Analytic 1503
|
Detects anomalous authentication activity such as sign-ins from impossible geolocations or legacy protocols from high-privileged accounts.
|
|
Analytic 0036
|
Opening of Office files where VBA source code appears benign or missing, but p-code remains active. Defender perspective: process execution of Office apps with macro execution lacking visible source components.
|
|
Analytic 0856
|
Correlated file access to insecure credential files (e.g., *.env, *.xml, *.ps1) followed by suspicious process execution or authentication using retrieved credentials. Detected through Sysmon logs and Windows Security Event logs.
|
|
Analytic 0736
|
Abuse of launchctl to execute or manage Launch Agents and Daemons. Defender perspective: correlation of suspicious plist file creation or modification in LaunchAgents/LaunchDaemons directories with subsequent execution of the launchctl command. Abnormal executable paths (e.g., /tmp, /Shared) or launchctl activity followed by network connections are highly suspicious.
|
|
Analytic 0296
|
Offline cracking inferred by subsequent successful CLI or web-based authentications into routers or switches from previously dumped accounts
|
|
Analytic 1531
|
Detection of non-interactive or suspicious processes accessing Bluetooth interfaces and transmitting outbound traffic following file access or staging activity.
|
|
Analytic 1115
|
Observation of LaunchAgents or LaunchDaemons establishing periodic external connections indicative of automated data transfer.
|
|
Analytic 0530
|
Compromised service account tokens mounted inside containers and reused for external API calls or lateral movement across services.
|
|
Analytic 1365
|
Monitor email and document management systems for fraudulent invoices, impersonation of vendors, or BEC-style payment redirections. Detect abnormal editing of invoice templates, or emails containing known fraud language combined with attachment delivery.
|
|
Analytic 0008
|
macOS clients joined to AD via LDAP may script account provisioning via `dsconfigad`, `dscl`, or LDAP scripts. Detection occurs when such tools run on a domain-joined system, followed by authentication attempts by a previously unseen account.
|
|
Analytic 1488
|
Detects anomalous SaaS application integration activity across environments such as Slack, Salesforce, or other enterprise SaaS services. Focus is on unauthorized app additions, unusual permission grants, and persistence through service principal tokens.
|
|
Analytic 1473
|
Detects anomalous CI/CD workflow execution originating from forked repositories, with pull request (PR) metadata or commit messages containing suspicious patterns (e.g., encoded payloads), coupled with the use of insecure pipeline triggers like `pull_request_target` or excessive API usage of CI/CD secrets. Correlation with unusual artifact generation or secret exfiltration via encoded or external network destination URLs confirms suspicious behavior.
|
|
Analytic 0867
|
Detects use of `dseditgroup` or `dscl` to add users to privileged macOS groups (e.g., admin).
|
|
Analytic 1061
|
Unauthorized or anomalous loading of kernel-mode drivers or DLLs, concealed services, or abnormal modification of boot components indicative of rootkit activity.
|
|
Analytic 0679
|
Database enumeration and export activity (e.g., `SELECT * FROM`, `SHOW DATABASES`) issued via ephemeral VMs, admin APIs, or cloud shell from non-monitoring accounts. Defender correlates audit logs (CloudTrail, GCP Admin, AzureDiagnostics), storage write ops, and cross-region transfers by identities not tied to DB operations.
|
|
Analytic 0809
|
Detects successful login to cloud identity portals (e.g., Okta, Azure AD, Google Identity) from atypical geolocations, devices, or user agents immediately followed by dashboard/portal navigation to sensitive pages such as user or app configuration.
|
|
Analytic 0771
|
Detection of new IAM roles or policies attached to a user/service in AWS/GCP/Azure outside normal patterns or hours, often following account compromise.
|
|
Analytic 1209
|
Detection focuses on identifying abuse of LD_PRELOAD and related linker variables. Defender perspective: monitor unexpected setting or modification of LD_PRELOAD in shell initialization scripts or environment exports, file creation of suspicious shared libraries, and correlation of these modifications with anomalous process execution. Key signals include execve events with LD_PRELOAD defined, newly created .so files in user directories, and processes hooking libc functions exhibiting abnormal behavior.
|
|
Analytic 0478
|
Script or binary performs a rapid sequence of system discovery checks (e.g., CPU count, RAM size, registry keys, running processes) indicative of VM detection
|
|
Analytic 1251
|
Detects suspicious changes to macOS authorization and PAM plugin files. Correlates file modifications under /etc/pam.d/ or /Library/Security/SecurityAgentPlugins with unexpected authentication attempts or anomalous account usage.
|
|
Analytic 0447
|
Insertion of USB-based hardware proxies (e.g., PiKVM) which register under predictable names (e.g., tinypilot) or mount under known paths (e.g., /opt/tinypilot-privileged).
|
|
Analytic 1007
|
Connections to exposed container services (e.g., Docker API, Kubernetes API server) from unauthorized external IPs → abnormal container creation/start → lateral activity within cluster nodes.
|
|
Analytic 0075
|
Detects unexpected or high-volume HTTP/S/WebSocket communication from suspicious processes (e.g., PowerShell, rundll32) using uncommon user agents or mimicking browser traffic to unusual domains or IPs.
|
|
Analytic 0032
|
Previously unseen applications generating outbound connections with atypical data flow characteristics, such as excessive data with no return response.
|
|
Analytic 0121
|
Detection of system calls or commands accessing system locale (e.g., 'defaults read -g AppleLocale', 'systemsetup -gettimezone'). Correlate with unusual parent processes or execution contexts.
|
|
Analytic 1339
|
Sign-in failures across enterprise SSO applications or SaaS platforms from same IP address using the same password against multiple user identities
|
|
Analytic 0437
|
Processes such as curl, wget, or custom scripts initiating POST requests to webhook endpoints with encoded or bulk data. Defender perspective: abnormal chaining of file compression or access followed by outbound data to webhook URLs.
|
|
Analytic 1987
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0699
|
Execution of `pip.exe`, `npm.cmd`, or MSI installers within user context, followed by script interpreter startup (e.g., python.exe) or PowerShell with unusual child processes or file writes in `%APPDATA%`, `%TEMP%`, or `%LOCALAPPDATA%`. Defender correlates command-line install tools with Sysmon and Event Logs to trace downstream behavior.
|
|
Analytic 1187
|
Detection focuses on correlating snapshot creation events with subsequent instance creation and mounting activities. From a defender perspective, suspicious sequences include snapshot creation by unexpected or newly created IAM users, snapshots created from sensitive volumes without preceding change-control activity, or snapshots immediately followed by mounting to unauthorized instances. Cross-referencing with user behavior, IP geolocation, and automation context helps distinguish benign backup operations from adversary-driven snapshot exploitation.
|
|
Analytic 1291
|
Detects rogue DHCP activity by monitoring syslog for dhclient messages assigning unauthorized DNS/gateway values. Packet capture or IDS can detect multiple competing DHCP OFFERs from non-authorized servers.
|
|
Analytic 0917
|
Detection of suspicious use of ioctl/sysfs calls to access device firmware, unexpected flashing tools execution, and anomalous firmware checksums logged by SMART or kernel audit mechanisms.
|
|
Analytic 0797
|
Cause→effect chain: (1) A client app (browser, Office, PDF/Flash/reader) experiences a crash/abnormal exit or loads from an unusual location, then (2) drops or modifies a file in user-writable paths, and/or (3) spawns an unexpected child (e.g., powershell/cmd/mshta/rundll32/wscript/installer), and (4) establishes outbound C2-like connections shortly after. Correlate application logs, file writes, process lineage, and network egress within a short window.
|
|
Analytic 0224
|
Adversary exploits exposed OpenSLP on ESXi or vCenter public endpoints. Chain: inbound request pattern to mgmt service → hostd/vpxd error/crash/restart → unexpected process behavior or datastore access → outbound callback.
|
|
Analytic 0834
|
Sequential behavioral chain of privilege escalation through permission modification: (1) Process creation of permission-modifying utilities (icacls, takeown, attrib, cacls), (2) Correlation with unusual user context or timing, (3) DACL modification events targeting sensitive files/directories, (4) Subsequent file access or modification attempts indicating successful privilege bypass
|
|
Analytic 1427
|
Programmatic access to user content via stolen access tokens in platforms like Slack, GitHub, Google Workspace — especially from new IPs, apps, or excessive resource access.
|
|
Analytic 1976
|
Consider use of services that may aid in the tracking of certificates in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of certificate information to uncover other adversary infrastructure.(Citation: Splunk Kovar Certificates 2017)
Detection efforts may be focused on related behaviors, such as [Web Protocols](https://attack.mitre.org/techniques/T1071/001) , [Asymmetric Cryptography](https://attack.mitre.org/techniques/T1573/002) , and/or [Install Root Certificate](https://attack.mitre.org/techniques/T1553/004) .
|
|
Analytic 1619
|
Account discovery via VBA macros, COM objects, or embedded scripting.
|
|
Analytic 1247
|
Detection monitors extended attribute manipulation (xattr) to strip quarantine or trust metadata, anomalous installation of root certificates in /etc/ssl or /usr/local/share/ca-certificates, and unauthorized modification of system trust stores. Correlates with unexpected process execution involving package managers or custom certificate utilities.
|
|
Analytic 1132
|
Unauthorized mirroring sessions initiated on routers/switches (e.g., via `monitor session`, `mirror port`) coupled with outbound traffic from mirrored interface to unexpected destinations.
|
|
Analytic 0817
|
Detects tenant-wide authentication or conditional access changes that weaken hybrid identity enforcement, including disabling AD FS or bypassing hybrid MFA policies.
|
|
Analytic 0145
|
Identifies custom or previously unseen userland processes initiating high-volume HTTP connections with low response volume.
|
|
Analytic 0308
|
Observation of chmod commands setting setuid/setgid bits, paired with launch of binaries under elevated execution context (e.g., root-owned binaries launched by unprivileged users).
|
|
Analytic 0211
|
Detects abuse of Mono/.NET Core environments to execute VB-like scripts, often in environments with Office emulation or WINE. Focus is on rare invocations of scripting hosts like mono.exe or .NET shells, often seen in spam filtering or forensic labs with Office support.
|
|
Analytic 1037
|
Detects tampered Mac hardware/firmware by analyzing unified logs, EndpointSecurity events, and Apple Mobile File Integrity (AMFI) checks. Behavioral chain: (1) Boot process reports firmware signature mismatch; (2) Secure Boot policy altered; (3) new EFI drivers or hardware devices appear in inventory; (4) system extension loads from unapproved developer IDs post-boot.
|
|
Analytic 1023
|
Outbound encrypted traffic initiated from hypervisor shell or via VM backdoor mechanisms to relays in VPS infrastructure, especially if traversing multiple nodes before reaching Internet destination. Packet captures or firewall logs show non-VM communication paths.
|
|
Analytic 1448
|
A remote host sends a short sequence of failed connection attempts (RST/ICMP unreachable) to a set of closed ports. Within a brief window the endpoint (a) adds/enables a firewall rule or (b) a sniffer-backed process begins listening or opens a new socket, after which a successful connection occurs. Also detects Wake-on-LAN magic packets seen on local segment.
|
|
Analytic 1090
|
Access to organizational directories via Google Workspace Directory API, Slack SCIM, or Okta SCIM by apps or identities outside normal roles.
|
|
Analytic 0997
|
Detection of execution of legacy scripting runtimes (e.g., older versions of Python, Bash, or PowerShell Core) lacking auditing. Monitoring for changes to EFI or system boot files indicative of downgrade-based persistence or bypass of integrity features.
|
|
Analytic 1143
|
Cloud-hosted VM or container generates spoofed UDP requests to third-party services on known amplifier ports, with high outbound-to-inbound traffic ratios in VPC Flow Logs
|
|
Analytic 0775
|
Detection of writes to /boot or EFI directories outside of expected package manager updates. Monitoring kernel log and auditd events for attempts to overwrite bootloader binaries (e.g., grub, shim). Unexpected execution of efibootmgr or dd writing to /dev/sdX devices followed by boot parameter changes.
|
|
Analytic 0928
|
Shell scripts or binaries implement custom mapping tables (tr/sed/awk/golang/rust/python encode loops), or emit long high-entropy tokens that fail Base64/Hex validation → correlated with egress showing asymmetric flow, protocol-mismatch payloads, or DNS/HTTP bodies containing low-diversity-but-long custom alphabets.
|
|
Analytic 1965
|
Consider analyzing self-signed code signing certificates for features that may be associated with the adversary and/or their developers, such as the thumbprint, algorithm used, validity period, and common name. Malware repositories can also be used to identify additional samples associated with the adversary and identify patterns an adversary has used in crafting self-signed code signing certificates.
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related follow-on behavior, such as [Code Signing](https://attack.mitre.org/techniques/T1553/002) or [Install Root Certificate](https://attack.mitre.org/techniques/T1553/004).
|
|
Analytic 1244
|
Detect user-initiated kextload commands or modifications to /Library/Extensions. Correlate with changes to KextPolicy database or unauthorized developer signing identities. Alert on attempts to disable SIP or load legacy extensions from unsigned sources.
|
|
Analytic 1253
|
A process (often after stealing/creating a token) calls CreateProcessWithTokenW/CreateProcessAsUserW or uses runas to spawn a **new** process whose security context (SID/LogonId/IntegrityLevel) differs from its parent. Chain: (1) suspicious command/API → (2) privileged handle or token duplication/open → (3) new child process running as another user / higher integrity → (4) optional follow‑on privileged/lateral actions.
|
|
Analytic 1089
|
Bulk enumeration of cloud user email identities through `Get-Recipient`, `Get-Mailbox`, `Get-User`, or Graph API directory listings by abnormal accounts or suspicious sessions.
|
|
Analytic 0256
|
Adversary uses `dscl`, `who`, or environment variables like `$USER` to identify accounts or sessions via Terminal or malicious LaunchAgents.
|
|
Analytic 1628
|
Detects timestamp changes using `touch`, `SetFile`, or direct metadata tampering (e.g., xattr manipulation) from Terminal, scripts, or low-level APIs.
|
|
Analytic 2030
|
A process with no prior history or outside of known whitelisted tools initiates file or registry modifications to configure exclusion rules for antivirus, backup, or file-handling systems. Or a file system enumeration for specific file names andcritical extensions like .dll, .exe, .sys, or specific directories such as 'Program Files' or security tool paths or system component discovery for the exclusion of the files or components.
|
|
Analytic 0142
|
Correlate command executions involving 'sudo' with elevated effective user ID (euid=0), especially when tty_tickets is disabled or timestamp_timeout is actively abused.
|
|
Analytic 0192
|
Phishing attempts targeting IdPs often manifest as anomalous login attempts from suspicious email invitations or fake SSO prompts. Detection correlates login flows, MFA bypass attempts, and anomalous geographic patterns following phishing email delivery.
|
|
Analytic 0184
|
Adversary installs or modifies IIS components (ISAPI filters, extensions, or modules) using DLL files registered via configuration changes or administrative tools like AppCmd.exe. These components intercept or manipulate HTTP requests/responses for persistence or C2.
|
|
Analytic 0046
|
Detects adversary attempts to monopolize control of compromised systems by issuing service stop commands, unloading vulnerable modules, or forcefully killing competing processes. Defenders should monitor audit logs and syslog for administrative utilities (systemctl, service, kill) being invoked outside of normal change management.
|
|
Analytic 1211
|
Modification or replacement of service executables due to weak file or directory permissions. Defender observes file writes to service binary paths, unexpected modifications of executables associated with registered services, and subsequent service execution of attacker-supplied binaries under elevated permissions.
|
|
Analytic 0732
|
Anomalous or bulk download activity from private or restricted repositories by non-developer or privileged accounts, often preceded by unusual login behavior (e.g., unfamiliar geo, OAuth token use, elevated API rate).
|
|
Analytic 1074
|
Adversaries accessing datastore or configuration files via `vim-cmd`, `esxcli`, or SCP to extract logs, VMs, or host configurations.
|
|
Analytic 0459
|
Chain: (1) IdP policy/read operations by a principal (e.g., Microsoft Entra/Graph requests to read password or authentication policies); (2) adjacent risky changes (role assignment, app consent) by same principal. Use IdP audit logs.
|
|
Analytic 1165
|
Repeated invocation of high-resource application endpoints or GUI components causing CPU and memory spikes, logged as elevated request volumes, prolonged handle locks, or frequent crash recoveries.
|
|
Analytic 0496
|
Detects exploitation of vulnerabilities in cloud identity providers (IdPs) such as Azure AD or Okta for credential access. Defender perspective includes anomalous token creation or renewal, authentication bypass events, and API abuse to mint unauthorized tokens. Correlation highlights exploitation attempts tied to absent or inconsistent audit logs.
|
|
Analytic 0892
|
Changes to security configurations such as disabling MFA requirements, reducing session token lifetimes, or turning off risk-based policies. Correlate admin logins with sudden policy downgrades.
|
|
Analytic 0134
|
Detects deletion or overwriting of logs/configs that store SSH or proxy activity, such as /var/log/auth.log or custom .bash_history clearing tied to SSH sessions or firewall rule changes.
|
|
Analytic 0871
|
Multi-event correlation of Registry creation under Active Setup with anomalous execution of processes at user logon. Behavioral patterns include creation/modification of HKLM Active Setup keys with non-standard StubPath values, followed by process execution from uncommon paths, unsigned binaries, or unusual parent-child lineage post-user login.
|
|
Analytic 0147
|
Sequence of internal email sent from a recently compromised user account (preceded by abnormal logon or device activity), with attachments or links leading to execution or credential harvesting. Defender observes: internal mail delivery to peers with high entropy attachments, followed by click events, process initiation, or credential prompts.
|
|
Analytic 0244
|
Detects non-system processes accessing /dev/input/* or issuing ptrace/evdev syscalls used for reading keystroke buffers directly.
|
|
Analytic 1204
|
Detects suspicious inbound mail traffic where SPF/DKIM/DMARC authentication fails or where sender and return-path domains mismatch, observable in Apple Mail unified logs or MDM-controlled logging pipelines.
|
|
Analytic 1357
|
Detects anomalous use of COM, DDE, or named pipes for execution. Correlates creation or access of IPC mechanisms (e.g., named pipes, COM objects) with unusual parent-child process relationships or code injection patterns (e.g., Office spawning cmd.exe via DDE).
|
|
Analytic 1566
|
Suspicious access to Microsoft Teams chat messages via eDiscovery, Graph API, or export methods after rare or compromised sign-in. Often associated with excessive file access, sensitive content review, or anomaly from expected user behavior.
|
|
Analytic 0925
|
ESXi shell or guest VM tools initiate external connections via scripted traffic forwarding to Internet-based proxies. Detected by firewall or shell audit logs showing outbound connection spikes from hypervisor or guest VM to remote proxy nodes.
|
|
Analytic 1995
|
Monitor for logged domain name system (DNS) registry data that may hijack domains and/or subdomains that can be used during targeting. In some cases, abnormal subdomain IP addresses (such as those originating in a different country from the root domain) may indicate a malicious subdomain.(Citation: Palo Alto Unit 42 Domain Shadowing 2022) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
Consider monitoring for anomalous changes to domain registrant information and/or domain resolution information that may indicate the compromise of a domain. Efforts may need to be tailored to specific domains of interest as benign registration and resolution changes are a common occurrence on the internet.
Monitor for queried domain name system (DNS) registry data that may hijack domains and/or subdomains that can be used during targeting. In some cases, abnormal subdomain IP addresses (such as those originating in a different country from the root domain) may indicate a malicious subdomain.(Citation: Palo Alto Unit 42 Domain Shadowing 2022) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
|
|
Analytic 0872
|
Detection of browser-based or email client-driven file creation (often from temp directories) following navigation to or execution of HTML files containing JavaScript Blob APIs or base64 Data URLs, with follow-on execution of the dropped payload. Leveraging Sysmon EventID 15 to inspect Zone.Identifier ADS for HostUrl/ReferrerUrl indicators (e.g., HostUrl=about:internet). Optional: absence of a large HTTP download record for the same URL/client in proxy logs (suggests local assembly)
|
|
Analytic 0969
|
High-volume packet generation by local processes (e.g., PowerShell, cmd, curl.exe) or network service processes resulting in excessive outbound traffic over short time window, correlated with abnormal resource usage or degraded host responsiveness.
|
|
Analytic 0197
|
Detects remote writes or snapshots mounted from other systems into a central ESXi VMFS path or NFS store used for remote staging of files before exfiltration.
|
|
Analytic 0665
|
Adversary defaces internal VM-hosted portals or web UIs by modifying static content on datastore-mounted paths.
|
|
Analytic 0239
|
Detection of encoded payloads being decoded and executed in-memory using scripting tools or third-party decoders.
|
|
Analytic 1229
|
Suspicious process spawning (e.g., `rundll32`, `svchost`, `powershell`, or `netsh`) followed by network connection creation to internal hosts or uncommon external endpoints on high or non-standard ports.
|
|
Analytic 0034
|
Discrepancies between VBA source code and p-code inside Office documents. Defender perspective: anomalies in file metadata streams, execution of Office processes loading macros without source code consistency, and script execution with no corresponding source metadata.
|
|
Analytic 0266
|
Use of native tools or scripting (e.g., `usermod`, `passwd`, `groupmod`) to escalate permissions or persist access on existing users, correlated with login or process events.
|
|
Analytic 0467
|
Detects adversary behavior clearing command history via `history -c`, deletion or modification of ~/.bash_history, or manipulation of the HISTFILE environment variable post-login.
|
|
Analytic 1156
|
Unusual web-based access or API scraping of password managers, single sign-on sessions, or credential sync services via browser automation or anomalous API tokens.
|
|
Analytic 1434
|
Executable or script generating large outbound network traffic targeting remote hosts or known amplification ports
|
|
Analytic 1567
|
Detects suspicious USB HID device enumeration and keystroke injection patterns, such as rapid sequences of input with no user context, scripts executed through simulated keystrokes, or rogue devices presenting themselves as keyboards.
|
|
Analytic 0023
|
Developer tools (Homebrew, pip, npm/yarn, Xcode builds) install or update dependencies; new Mach-O or scripts appear under /usr/local, /opt/homebrew, ~/Library/Application Support, project dirs (node_modules/.bin, venv/bin). First run spawns sh/zsh/osascript/curl and new outbound flows; Gatekeeper/AMFI may flag unsigned components.
|
|
Analytic 1460
|
Detects use of macOS-native archiving or encryption tools (zip, ditto, hdiutil) for staging collected data. Identifies unexpected invocation of archive utilities by Office apps, browsers, or background daemons. Correlates file creation of .zip/.dmg containers with process lineage anomalies.
|
|
Analytic 0868
|
Detection of inconsistencies between reported sensor health and actual process/service state. For example, Windows Defender tray icon/UI showing healthy status while corresponding Defender services (WinDefend, MsMpEng) are stopped or disabled. Correlates process creation events with missing or terminated security processes and spoofed health events.
|
|
Analytic 0312
|
Detection of changes or execution of shell initialization scripts like .bashrc, .profile, or /etc/profile for persistence.
|
|
Analytic 0791
|
A remote DCOM invocation by a privileged account using RPC (port 135), followed by abnormal process instantiation or module loading on the remote system indicative of code execution.
|
|
Analytic 1499
|
VMware services (hostd, vpxa) unexpectedly negotiating asymmetric crypto sessions to external endpoints outside vCenter or update servers. Defender sees encrypted handshakes in logs inconsistent with baseline ESXi communication patterns.
|
|
Analytic 1093
|
Detects anomalous ARP cache changes and unsolicited ARP broadcasts using unified logs and packet capture. Behavioral detection includes multiple IP addresses mapped to the same MAC address and repeated gratuitous ARP traffic.
|
|
Analytic 1179
|
Identify processes issuing repeated DNS queries to random-looking domains with abnormal entropy or word concatenations. Correlate resolver logs with high NXDOMAIN rates and auditd socket connections.
|
|
Analytic 0027
|
Monitors cloud function creation triggered by specific audit log events (e.g., IAM changes, object creation), followed by anomalous behavior from new service accounts.
|
|
Analytic 0805
|
Detects creation or modification of crontab entries by non-root users or from abnormal parent processes, followed by the execution of uncommon binaries at scheduled intervals.
|
|
Analytic 2006
|
Once adversaries have provisioned software on a compromised server (ex: for use as a command and control server), internet scans may reveal servers that adversaries have compromised. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021)
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
|
|
Analytic 0209
|
Detects execution of VB-based scripts or macros (VBS/VBA/VBScript) through cscript.exe/wscript.exe, Office-based process chains, or HTA usage. Focuses on chained behavior: Office or HTML container spawns script host > script host spawns PowerShell, network connections, or process injection.
|
|
Analytic 1207
|
Abuse of mavinject.exe to inject DLLs or import descriptors into another running process. Chain: (1) mavinject.exe starts with /INJECTRUNNING or /HMODULE → (2) mavinject obtains high-access handles to a target process (VM_WRITE/CREATE_THREAD) → (3) target process loads attacker DLL (module load) → (4) optional follow-on child activity or network egress from the target process.
|
|
Analytic 1176
|
Monitor pmset command executions altering sleep/hibernate/standby parameters. Unexpected modifications to /Library/Preferences/SystemConfiguration/com.apple.PowerManagement.plist or similar files should be correlated with process activity.
|
|
Analytic 1960
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1621
|
Detects enabling of reversible password encryption in Active Directory or Group Policy, suspicious PowerShell commands modifying AD user properties, and unusual account configuration changes correlated with policy modifications. Multi-event correlation links Group Policy edits, PowerShell command execution, and user account property changes to identify tampering with authentication encryption settings.
|
|
Analytic 0884
|
Abnormal invocation of diskutil or asr with destructive flags (eraseDisk, zeroDisk), or low-level IOKit calls that overwrite raw disk content. Detect correlation between elevated process execution and disk erase operations.
|
|
Analytic 0103
|
Adversary registers new devices to compromised user accounts to bypass MFA or conditional access policies via Azure Entra ID, Okta, or Duo self-enrollment portals.
|
|
Analytic 0396
|
Process creation involving suspicious delays (e.g., Sleep, ping -n loops, WaitForSingleObject), followed by sensitive system access or lateral movement behaviors.
|
|
Analytic 0466
|
Detects adversary behavior where the command-line arguments of a running process are overwritten in memory to spoof the process name, typically replacing it with a benign or misleading string. The detection correlates unexpected null byte sequences, discrepancies between `/proc//cmdline` and process ancestry, and suspicious memory writes shortly after process start.
|
|
Analytic 0904
|
Detects use of netstat, ss, lsof, or custom shell scripts to list current network connections. Often paired with privilege escalation or staging.
|
|
Analytic 0081
|
User-initiated processes generating sustained outbound traffic over common or non-standard ports, often outside business hours, potentially linked to scanning or proxyjacking. Includes curl, wget, masscan, or proxy clients.
|
|
Analytic 0602
|
High-frequency file write operations using uncommon extensions, followed by ransom note creation, registry tampering, or shadow copy deletion. Often uses CLI tools like vssadmin, wbadmin, cipher, or PowerShell.
|
|
Analytic 0549
|
Detects MFA bypass attempts by modifying tenant-wide authentication policies or excluding high-value accounts from MFA enforcement.
|
|
Analytic 1119
|
Detection of cron-based or script-based recurring transfers where the same script, user, or destination reappears at predictable intervals.
|
|
Analytic 0130
|
Detection focuses on processes that attempt to locate, access, or exfiltrate local Outlook data files (.pst/.ost) using file system access, native Windows utilities (e.g., PowerShell, WMI), or remote access tools with file browsing capabilities. The behavior chain includes directory enumeration, file access, optional compression or staging, and network transfer.
|
|
Analytic 1125
|
Detects unusual outbound DNS traffic from ESXi hosts, often from shell scripts, custom daemons, or malicious VIBs interacting with external DNS infrastructure outside the management plane.
|
|
Analytic 1134
|
Correlates LNK file execution with embedded resource extraction or suspicious network activity following initial launch, often leading to payload delivery via disguised icons.
|
|
Analytic 0975
|
Correlate registry modifications (e.g., UAC bypass registry keys), unusual parent-child process relationships (e.g., control.exe spawning cmd.exe), and unsigned elevated process executions with non-standard tokens or elevation flags.
|
|
Analytic 0410
|
Detection of firewall ACL or rule base changes through CLI (e.g., no access-list, permit any any). Monitor configuration commits from unusual users or sessions.
|
|
Analytic 0982
|
Use of tools like xwd or import to generate screenshots, especially under non-GUI parent processes.
|
|
Analytic 1193
|
Processes accessing raw logical drives (e.g., \.\C:) to bypass file system protections or directly manipulate data structures.
|
|
Analytic 0203
|
Web session tokens reused in native Office apps (e.g., Outlook, Teams) without associated token refresh or login behavior on the endpoint.
|
|
Analytic 0372
|
Adversary-created named mutex using system APIs (e.g., CreateMutexW) followed by conditional process termination or alternate code path indicating malware avoiding reinfection.
|
|
Analytic 1020
|
Suspicious processes (e.g., Tor clients, relays, unknown binaries) launch with sustained encrypted outbound traffic to known anonymity infrastructure (e.g., Tor, I2P), and may relay to additional internal systems via reverse proxying, ICMP tunneling, or socket forwarding.
|
|
Analytic 0178
|
Behavioral chain: (1) a user-facing app (browser/Office/email client) launches a URL or handles a link, then (2) the same process lineage makes an outbound connection to an untrusted domain/IP, (3) a file is downloaded or unpacked to a user-writable location shortly after the click. Optional enrichment: subsequent child execution by LOLBINs.
|
|
Analytic 1085
|
A process outside of interactive shell context reads ~/.bash_history directly (e.g., using cat, less, grep), often shortly after privilege escalation or user switch (su/sudo). This may be followed by credential scanning in memory or file writes to new locations.
|
|
Analytic 0841
|
Execution of files originating from removable media after drive mount, with correlation to file write activity, autorun usage, or lateral spread via staged tools.
|
|
Analytic 0458
|
Chain: (1) cloud API calls that fetch tenant/organization password policy (e.g., AWS `GetAccountPasswordPolicy`, GCP/OCI equivalents or IAM settings reads); (2) within a short window, the same principal creates users, rotates creds, or changes auth settings. Use cloud audit logs.
|
|
Analytic 0794
|
Monitor Mail.app activity or unified logs for anomalous SMTP usage, including mismatches between display name and authenticated AppleID or Exchange credentials. Detect use of third-party mail utilities that attempt to send on behalf of corporate identities.
|
|
Analytic 0959
|
Access token reuse to connect to SharePoint or Outlook APIs without interactive user context.
|
|
Analytic 0004
|
Detects osascript, curl, or custom binaries interacting with XMPP/MQTT brokers in unapproved destinations with encrypted payloads or frequent POST-like requests to broker URIs.
|
|
Analytic 1420
|
Detects escalation via vulnerable setuid binaries or kernel modules, often chained with unusual access to /proc/kallsyms or /dev/kmem.
|
|
Analytic 0934
|
Shell utilities or scripts deleting `/etc/systemd/system/rescue.target`, `/etc/fstab` backups, or `/boot/efi` partitions; chattr used to block snapshot auto-recovery
|
|
Analytic 1525
|
Login attempt failures over SNMP, Telnet, or SSH interface, often reflected in logs or syslog events
|
|
Analytic 0705
|
Monitor for use of native utilities such as wevtutil.exe or PowerShell cmdlets (Get-WinEvent, Get-EventLog) to enumerate or export logs. Unusual access to security or system event channels, especially by non-administrative users or processes, should be correlated with subsequent file export or network transfer activity.
|
|
Analytic 0837
|
ESXi hypervisor permission modification behavioral chain: (1) SSH access to ESXi host, (2) chmod/chown execution on VMFS datastore files or system configuration, (3) Modification of VM configuration files (.vmx) or virtual disk permissions, (4) Hostd service log correlation, (5) vCenter permission change events if centrally managed
|
|
Analytic 1094
|
Detects a multi-event behavior chain involving UAC bypass attempts via known auto-elevated binaries (e.g., eventvwr.exe, sdclt.exe), unauthorized Registry changes to UAC-related keys, and anomalous process execution with elevated privileges but lacking standard parent-child lineage. Suspicious patterns include invocation of auto-elevated COM objects or manipulation of isolatedCommand Registry entries without consent prompts.
|
|
Analytic 0164
|
Detect manipulation of system or application files in `/Library`, `/System`, or user data directories using FSEvents and Unified Logs. Identify anomalous process execution modifying plist files, structured data, or logs outside expected update cycles.
|
|
Analytic 0284
|
Monitors for TCC-bypassing or unauthorized access to input services like IOHIDSystem or Quartz Event Services used in keylogging or screen monitoring.
|
|
Analytic 1522
|
Repeated failed SSH login attempts followed by a possible success from the same remote host
|
|
Analytic 1216
|
Detects the relocation of malicious executables via copy/move actions across suspicious folders (e.g., from Downloads to System32), followed by deletion of the original source or renaming to blend into legitimate binaries.
|
|
Analytic 1017
|
Execution of ping, traceroute, or network utility tools to external destinations; may include `scutil` or system_profiler.
|
|
Analytic 0676
|
Unusual database command-line access (e.g., `psql`, `mysql`, `mongo`) from non-admin users, occurring outside typical automation windows or without known service context. Often followed by data dumps to .sql/.csv files or outbound data transfers. Defender sees CLI tools launched interactively or by unusual parent processes, file writes to dump-like filenames, and external connections shortly after.
|
|
Analytic 0195
|
Detects inbound SCP, rsync, or NFS mounts from remote systems followed by aggregation of files into known staging paths like /mnt/staging or /var/tmp.
|
|
Analytic 1006
|
Unexpected inbound or outbound VNC/SSH/Screen Sharing connections from external sources → repeated failed logins followed by success → remote interactive sessions or abnormal file transfers.
|
|
Analytic 0367
|
Detects unusual outbound file transfer behavior using protocols like FTP, SMB, SMTP, or DNS, involving non-standard processes, off-hour activity, or uncommonly high volume.
|
|
Analytic 0765
|
Correlates creation/modification of systemd service files or /etc/init.d scripts with outlier process behavior during boot
|
|
Analytic 1435
|
Flooding tools like hping3 or nping sending large volumes of packets across multiple ports or IPs
|
|
Analytic 1455
|
Execution of `esxcli system hostname get`, `esxcli system version get`, or `esxcli hardware` commands through SSH or local shell.
|
|
Analytic 0045
|
Detects unusual command executions and service modifications that indicate self-patching or disabling of vulnerable services post-compromise. Defenders should monitor for service stop commands, suspicious process termination, and execution of binaries or scripts aligned with known patching or service management tools outside of expected admin contexts.
|
|
Analytic 1170
|
Detects usage of FTP, SCP, or TFTP by non-interactive shells or automation scripts transferring large data volumes to untrusted IPs.
|
|
Analytic 0568
|
A non-standard process (or script-hosted process) loads camera/video-capture libraries (e.g., avicap32.dll, mf.dll, ksproxy.ax), opens the Camera Frame Server/device, writes video/image artifacts (e.g., .mp4/.avi/.yuv) to unusual locations, and optionally initiates outbound transfer shortly after.
|
|
Analytic 0219
|
Adversary sends crafted HTTP/S (or other service) input to an Internet-facing app (IIS/ASP.NET, API, device portal). Chain: (1) abnormal request patterns to public endpoint → (2) elevated 4xx/5xx or unusual methods/paths → (3) server process (w3wp.exe/other service) spawns shell/LOLbins or loads non-standard modules → (4) optional outbound callback from the host/container.
|
|
Analytic 0394
|
Detects removal of adversary artifacts via `rm`, `unlink`, or secure tools, with focus on shell sessions, temp files, and modified LaunchAgents or system directories.
|
|
Analytic 2026
|
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)).
|
|
Analytic 1031
|
Detects adversarial abuse of WMI to execute local or remote commands via WMIC, PowerShell, or COM API through a multi-event chain: process creation, command execution, and corresponding network connection if remote.
|
|
Analytic 1514
|
Abnormal API calls from user accounts invoking file upload endpoints outside normal baselines (M365, Google Drive, Box). Defender perspective: monitor unified audit logs for elevated frequency of Upload, Create, or Copy operations from compromised accounts.
|
|
Analytic 0329
|
Detects exploitation targeting ESXi/vCenter by correlating attempts to reach known exploitable endpoints (OpenSLP 427, CIM 5989, Hostd/Vpxa HTTPS 443, ESXi SOAP) with vmkernel/hostd crashes, unexpected hostd/vpxa restarts, or new reverse/outbound connections from ESXi host/vCenter to internal assets.
|
|
Analytic 1437
|
Malicious VBA macros embedded in base templates like Normal.dotm or Personal.xlsb are automatically loaded and executed at startup. Template path may be hijacked to load a remote or attacker-controlled template via GlobalDotName registry setting.
|
|
Analytic 0855
|
Defender observes configuration changes on firewall/network appliance involving rule creation, modification, or deletion from abnormal management IPs or non-console channels (e.g., remote CLI, API). These are often correlated with a spike in previously blocked outbound traffic, unexpected allow-all rules, or bulk rule deletions. Behavior often follows unauthorized login, privilege escalation, or API abuse.
|
|
Analytic 0223
|
Adversary targets cloud-hosted public endpoints. Chain: (1) ALB/ELB/Cloud LB logs show exploit-like inputs or error spikes → (2) workload spawns shell or reaches metadata API → (3) egress to new external hosts.
|
|
Analytic 0782
|
Monitors for compression tool usage (e.g., 7zip, WinRAR, MakeCab) that follows or precedes file modification, suspicious file types (e.g., .exe, .dll) being compressed, or dropped from self-extracting archives followed by immediate execution.
|
|
Analytic 0963
|
User pastes a multi-line or one-liner into a terminal (bash/zsh) that downloads/decodes and executes content. Chain: terminal exec of curl/wget/bash/sh with pipe to interpreter or base64-decode → transient file under /tmp|~/.cache → immediate outbound egress.
|
|
Analytic 1641
|
Detection of suspicious access to password manager processes (KeePass, 1Password, LastPass, Bitwarden) through abnormal process injection, memory reads, or command-line usage of vault-related DLLs. Correlates process creation with OS API calls and file access to vault databases (.kdbx, .opvault, .ldb).
|
|
Analytic 1417
|
Detects adversary behavior accessing Windows cached domain credential files using tools like Mimikatz, reg.exe, or PowerShell, often combined with registry exports or LSASS memory scraping.
|
|
Analytic 0731
|
Analyze ESXi syslogs for management agents or VMs making outbound connections to dynamically calculated ports derived from DNS responses. Cross-check with VM traffic baselines to identify anomalies.
|
|
Analytic 0833
|
Detects invocation of macOS-native archiving utilities (zip, ditto, hdiutil) or openssl used for encryption. Correlates execution with archive or encrypted file creation (.zip, .dmg, .tar.gz) in user or temporary directories. Identifies anomalous use of archiving commands by Office applications or daemons.
|
|
Analytic 1595
|
Monitor for suspicious usage of driver enumeration utilities (driverquery.exe) or API calls such as EnumDeviceDrivers(). Registry queries against HKLM\SYSTEM\CurrentControlSet\Services and HardwareProfiles that are abnormal may also indicate attempts to discover installed drivers and services. Correlate command execution, process creation, and registry access to build a behavioral chain of driver discovery.
|
|
Analytic 0652
|
Unusual use of steganographic or media processing binaries (e.g., `steghide`, `ffmpeg`, `imagemagick`) followed by outbound communication to external IPs with high data output and media MIME types.
|
|
Analytic 1940
|
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the potential use of exploits for vulnerabilities (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)).
|
|
Analytic 1356
|
Defenders should monitor for anomalous or unauthorized changes to cloud compute configurations that alter quotas, tenant-wide policies, subscription associations, or allowed deployment regions. From a defender’s perspective, suspicious behavior chains include a sudden increase in compute quota requests followed by new instance or resource creation, policy modifications that weaken security restrictions, or enabling previously unused/unsupported cloud regions. Correlation across identity, configuration, and subsequent provisioning logs is critical to distinguish legitimate administrative activity from adversarial abuse.
|
|
Analytic 0342
|
Detects removable drive insertion followed by unusual file access, compression, or staging activity by unauthorized users or unexpected processes.
|
|
Analytic 1129
|
Discovery of SaaS services connected to productivity platforms (e.g., Microsoft 365, Google Workspace). Defender perspective includes unexpected enumeration of enabled services, API integrations, or OAuth applications tied to user accounts.
|
|
Analytic 0236
|
Monitor for creation of WMI EventFilter, EventConsumer, and FilterToConsumerBinding objects through WMI or MOF file execution. Detect command-line execution of `mofcomp.exe`, usage of `Register-WmiEvent` via PowerShell, and anomalous child processes of `WmiPrvSE.exe` that indicate triggered execution. Look for lateral anomalies in process lineage and WMI logging channels.
|
|
Analytic 0107
|
Detects abnormal access to Safari credential stores (Keychain-backed) or Chrome/Firefox login databases. Observes processes executing `security dump-keychain` or directly reading credential files in `~/Library/Application Support`. Correlates file access with suspicious process ancestry or unsigned binaries.
|
|
Analytic 0688
|
Detection of unauthorized keylogger behavior through access to `/dev/input`, loading kernel modules (e.g., via insmod), or polling user input devices from non-user shells
|
|
Analytic 1468
|
An SMB-based remote file share access followed by lateral movement actions such as remote service creation, task scheduling, or suspicious process execution on the target host using ADMIN$ or C$ shares.
|
|
Analytic 1215
|
Detects custom archiving by monitoring execution of Swift/Objective-C apps or scripts producing high-entropy files with non-standard headers. Correlates unified logs of abnormal NSFileHandle/NSData operations, memory use of XOR/bitwise operations, and file creation events.
|
|
Analytic 1158
|
Access to container image layers or mounted secrets (e.g., Docker secrets) by processes not tied to entrypoint or orchestration context.
|
|
Analytic 0537
|
Abnormal use of `lsblk`, `fdisk -l`, `lshw -class disk`, or `parted` by non-admin users or within non-interactive shells suggests suspicious disk enumeration activity.
|
|
Analytic 0377
|
Detection of JetBrains or VSCode tunnel profile creation followed by unusual persistent SSH or IDE-based tunnel communications to devtunnel APIs.
|
|
Analytic 2063
|
Detection identifies execution of scripts or files that appear visually benign (low printable character ratio) but result in runtime decoding, dynamic evaluation, and subsequent process or network activity. Correlation links script execution with abnormal Unicode density and follow-on behavior such as child process creation or outbound connections.
|
|
Analytic 1623
|
Adversary compromises a Linux-based web server and modifies hosted web files by exploiting upload vulnerabilities, remote code execution, or replacing index.html via SSH/webshell.
|
|
Analytic 1969
|
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during [Phishing](https://attack.mitre.org/techniques/T1566), [Endpoint Denial of Service](https://attack.mitre.org/techniques/T1499), or [Network Denial of Service](https://attack.mitre.org/techniques/T1498).
|
|
Analytic 1269
|
Use of leaked credential pairs against Outlook Web Access (OWA), Microsoft 365, or Exchange from a single client IP with multiple failures
|
|
Analytic 0348
|
ESXi shell (BusyBox) or VMware utilities (openssl, python if present) used to Base64/hex encode data from datastore or config files → followed by abnormal egress from the host (NSX/flow logs) with asymmetric bytes_out or HTTPS posts to non-management endpoints.
|
|
Analytic 0057
|
Creation of run-only AppleScripts or Mach-O binaries lacking symbol table and string references, especially when dropped by user space scripting engines or staging apps.
|
|
Analytic 1640
|
SSH login via hostd or `/var/log/auth.log`, followed by CLI access to host shell or file manipulation in restricted areas.
|
|
Analytic 1036
|
Monitors for hardware or firmware tampering by correlating system boot logs, hardware inventory changes, and secure boot/firmware verification failures. Behavioral chain: (1) UEFI/BIOS version drift; (2) secure boot disabled or signature verification errors; (3) unexpected modules or hardware devices enumerated at boot; (4) new device firmware images loaded from non-approved sources.
|
|
Analytic 1066
|
Monitors use of archive or encryption tools (zip, openssl) tied to user-scripted activity or binaries writing encoded payloads under /Users or /Volumes.
|
|
Analytic 1629
|
Detects abuse of busybox commands (e.g., `touch`) or log timestamp tampering during backdoor persistence or evasion.
|
|
Analytic 1611
|
Detects credential dumping attempts targeting the NTDS.dit database by monitoring shadow copy creation, suspicious file access to %SystemRoot%\NTDS\ntds.dit, and the use of tooling like ntdsutil.exe or volume management APIs.
|
|
Analytic 1554
|
ESXi hypervisor environmental validation behavioral chain: (1) Virtual machine inventory and configuration enumeration through vim-cmd and esxcli commands, (2) Host hardware and network configuration discovery for hypervisor environment validation, (3) Datastore and storage configuration reconnaissance, (4) vCenter connectivity and cluster membership validation, (5) Selective malware deployment based on virtualization infrastructure characteristics and target VM validation
|
|
Analytic 0716
|
Initiation of remote desktop sessions via AnyDesk, TeamViewer, or Chrome Remote Desktop accompanied by unexpected user logins or system modifications
|
|
Analytic 1526
|
Password guessing attempts against web-based apps (e.g., Dropbox, Google Workspace) reflected in API or sign-in logs
|
|
Analytic 1360
|
Defenders may observe attempts to disable dedicated crypto hardware on network devices, often visible through anomalous CLI commands, unexpected firmware or configuration updates, and degraded encryption performance. Suspicious indicators include commands that alter hardware acceleration settings (e.g., disabling AES-NI or crypto engines), modification of system image files, or logs showing fallback from hardware to software encryption. Network traffic analysis may also reveal a sudden downgrade in throughput or cipher negotiation behavior consistent with the absence of hardware acceleration.
|
|
Analytic 1064
|
Correlates script execution or suspicious parent processes with creation or modification of encoded, compressed, or encrypted file formats (e.g., .zip, .7z, .enc) and abnormal command-line syntax or PowerShell obfuscation.
|
|
Analytic 0150
|
Internal spearphishing via SaaS applications (e.g., Slack, Teams, Gmail): message sent from compromised user with attachment or URL, followed by click and credential access behavior.
|
|
Analytic 0596
|
Adversary uses a process to establish outbound connections that transmit uniform packet sizes at a consistent interval, avoiding threshold-based network alerts.
|
|
Analytic 0101
|
Non-interactive system processes making encrypted HTTPS connections to well-known web services followed by high outbound traffic volume or scripted upload patterns.
|
|
Analytic 0079
|
Detects Web protocol misuse such as encoded HTTP headers, WebSocket upgrade requests with abnormal payloads, or TLS handshake anomalies suggesting embedded C2 channels.
|
|
Analytic 1281
|
File access to NetworkManager connection configs and attempts to read PSK credentials from `/etc/NetworkManager/system-connections/*`.
|
|
Analytic 1008
|
Detect abnormally high volume of inbound email messages or repetitive attachments being delivered to a single mailbox within a short time window. Defenders should look for anomalous spikes in message counts and repetitive attachment file creation events correlated with targeted users.
|
|
Analytic 1555
|
Detection of environment variable tampering (HISTFILE, HISTCONTROL, HISTFILESIZE) and absence of expected bash history writes. Correlation of unset or zeroed history variables with active shell sessions is indicative of adversarial evasion.
|
|
Analytic 0521
|
Detects deletion or overwriting of bash history, syslog, audit logs, and .ssh metadata following privilege elevation or suspicious process spawning.
|
|
Analytic 1305
|
Windows-specific environmental keying behavioral chain: (1) Rapid system information discovery through multiple techniques (WMI queries, registry enumeration, network share discovery, hostname/domain checks), (2) Target validation through specific environmental artifact collection (AD domain membership, network topology, installed software versions), (3) Cryptographic operation correlation indicating payload decryption based on collected environmental values, (4) Subsequent malicious code execution following successful environmental validation, (5) Temporal clustering of discovery activities suggesting automated environmental assessment
|
|
Analytic 1971
|
If infrastructure or patterns in malware, tooling, certificates, or malicious web content have been previously identified, internet scanning may uncover when an adversary has staged their capabilities.
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as initial access and post-compromise behaviors.
|
|
Analytic 0409
|
Detection of firewall changes using esxcli network firewall set or vSphere API modifications. Sudden disabling of firewall rules across management interfaces is a strong adversarial signal.
|
|
Analytic 1396
|
Detection of obfuscated commands via shell, osascript, or AppleScript interpreters using unusual tokens, encoding, variable substitution, or runtime string reconstruction.
|
|
Analytic 0386
|
Abnormal invocation of diskutil, asr, or low-level APIs (IOKit) to erase/partition drives. Correlate process execution with unified log entries showing destructive disk operations.
|
|
Analytic 0605
|
Ransomware encrypts .vmdk, .vmx, .log, or VM config files in VMFS datastores. May rename to .locked or delete/overwrite with encrypted versions. Often correlates with shell commands run through `dcui`, SSH, or vSphere.
|
|
Analytic 0378
|
Detects unauthorized access to Windows Credential Manager through anomalous process execution (vaultcmd.exe, rundll32.exe keymgr.dll), suspicious API calls (CredEnumerateA), or direct file access to Credential Locker files. Correlates process creation with subsequent file reads of .vcrd/.vpol files under user Credential Locker directories.
|
|
Analytic 1326
|
Execution of service management commands like `systemctl list-units`, `service --status-all`, or direct reading of `/etc/init.d`.
|
|
Analytic 0291
|
Detects unauthorized changes to IAM authentication configurations such as disabling MFA, creating backdoor access keys, or altering trust policies. Correlates identity policy updates with unusual login behavior.
|
|
Analytic 1478
|
Detects unauthorized Wi-Fi associations and SSID scanning activity using unified logs and airport command telemetry. Anomalies include rapid SSID switching, connections to unapproved SSIDs, or repeated authentication failures.
|
|
Analytic 0980
|
Unusual use of screen capture APIs (e.g., CopyFromScreen) or command-line tools to write image files to disk.
|
|
Analytic 1416
|
Detects unexpected encrypted outbound connections from management components or guest VMs using TLS, particularly after data volume spikes or script-based orchestration from within guest environments.
|
|
Analytic 0958
|
Container process uses mounted cloud credentials or token cache to authenticate without known orchestration.
|
|
Analytic 0941
|
Detects the use of message-based injection by monitoring for sequences involving FindWindow (EnumWindows or EnumChildWindows), VirtualAllocEx or related API calls, combined with suspicious PostMessage/SendMessage (e.g., LVM_SETITEMPOSITION) use to SysListView32 controls, followed by LVM_SORTITEMS invocation instead of WriteProcessMemory.
|
|
Analytic 1183
|
Access to shell history or GUI input state (xdotool, xinput) for presence validation prior to payload execution.
|
|
Analytic 1565
|
Atypical access to Slack or Teams conversations via APIs, automation tokens, or bulk message export functionality, particularly after an account takeover or rare sign-in pattern. Often includes mass retrieval of chat history, download of message content, or scraping of workspace/channel metadata.
|
|
Analytic 0698
|
User-initiated installation of Python (pip), NodeJS (npm), or other language libraries, followed by unexpected network connections, credential access, or startup file modifications. Defender sees `pip install` or `npm install` commands run by a non-root user, followed shortly by new `.py`, `.sh`, or `.js` files in hidden directories, or interpreter-based execution during boot/login.
|
|
Analytic 0795
|
Monitor SaaS mail platforms (Google Workspace, M365, Okta-integrated apps) for SendAs/SendOnBehalfOf operations where the delegated permissions are unusual or newly granted. Detect impersonation attempts where adversaries configure rules to auto-forward or auto-reply with impersonated content.
|
|
Analytic 0263
|
Adversary uses a tool like Ruler or MFCMapi to create a malicious Outlook rule that triggers execution upon receipt of a crafted email. On email delivery, Outlook executes the rule, resulting in code execution (e.g., launching mshta.exe or PowerShell). Outlook spawns a non-standard child process, often unsanctioned, without user interaction.
|
|
Analytic 1333
|
Use unified logs to identify processes issuing repeated DNS queries where the resolved IP addresses change frequently within very short TTL values. Correlate with outbound network traffic to validate C2-like patterns.
|
|
Analytic 1592
|
Modification of Thunderbird message filters file or execution of CLI tools (e.g., formail/procmail) that alter .forward behavior.
|
|
Analytic 0842
|
A remote source rapidly touches a short sequence of closed ports (SYN→RST/S0) on a Windows host. Within a short window the host changes firewall state (WFP rule added/modified or service starts listening) and then the same source completes the first successful handshake to the newly opened port.
|
|
Analytic 0500
|
Correlated evidence where Safari/Chrome/WebKit-based processes issue network requests for uncommon or obfuscated JS resources followed by spawning of script interpreters, launchd or ad-hoc binaries, unusual child processes, or dynamic library loads into browser processes. Defender sees: proxy/HTTP logs with suspicious resource content + unifiedlogs/ASL showing browser/plugin crashes or extension loads + process events indicating child process creation and file writes to /var/folders or /tmp shortly after the fetch.
|
|
Analytic 1948
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1025
|
Detection of domain group enumeration through command-line utilities such as 'net group /domain' or PowerShell cmdlets, followed by suspicious access to API calls or LSASS memory.
|
|
Analytic 0557
|
Monitor sensitive data files such as plist-based storage, mail archives, or Office files for unexpected modifications. Detect anomalous processes modifying stored data outside expected update cycles using FSEvents and Unified Logs.
|
|
Analytic 1106
|
Token creation or access delegation where a user impersonates a higher-privileged service account or performs domain-wide delegation actions, such as GCP's serviceAccountTokenCreator or Workspace impersonation.
|
|
Analytic 2007
|
Consider analyzing code signing certificates for features that may be associated with the adversary and/or their developers, such as the thumbprint, algorithm used, validity period, common name, and certificate authority. Malware repositories can also be used to identify additional samples associated with the adversary and identify patterns an adversary has used in procuring code signing certificates.
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related follow-on behavior, such as [Code Signing](https://attack.mitre.org/techniques/T1553/002) or [Install Root Certificate](https://attack.mitre.org/techniques/T1553/004).
|
|
Analytic 1268
|
Credential stuffing attempts against Kubernetes API or containerized login shells using stolen or leaked user credentials
|
|
Analytic 0968
|
Execution of hh.exe to open a .chm file followed by suspicious child processes or script engine invocation (VBScript, JScript, mshta, powershell). Behavior includes loading a CHM file from untrusted locations, or immediately spawning commands indicative of payload execution.
|
|
Analytic 1027
|
Enumeration of domain groups using dscacheutil or dscl commands, often following initial login or domain trust queries.
|
|
Analytic 1944
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1021
|
Tools such as `tor`, `nglite`, `proxychains`, `chisel`, or custom daemons repeatedly initiate outbound sessions to multiple nodes before final destination. This behavior is abnormal for Linux services outside of VPN, monitoring, or CDN relay contexts.
|
|
Analytic 0838
|
Detect anomalous chains of memory allocation and execution inside the same process (e.g., VirtualAlloc → memcpy → VirtualProtect → CreateThread). Unlike process injection, reflective code loading does not perform cross-process memory writes — the suspicious activity occurs entirely within the process’s own PID context.
|
|
Analytic 0609
|
Unusual modifications to service binary paths, registry keys, or DLL load paths resulting in alternate execution flow. Defender observes registry key modifications, suspicious file writes into system directories, and processes loading libraries from abnormal paths.
|
|
Analytic 1614
|
Detection of account enumeration through directory service queries or system utilities accessing account metadata stores, followed by structured enumeration output.
|
|
Analytic 0517
|
Monitor scp, rsync, curl, sftp, or ftp processes initiating transfers to internal systems combined with file creation events in unusual directories. Correlate transfer activity with subsequent execution of those binaries.
|
|
Analytic 1963
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1265
|
Same source IP performing multiple authentication attempts using known breached username/password combinations across different identities in Azure AD, Okta, or Duo
|
|
Analytic 0796
|
Monitor Office Suite applications (Outlook, Word mail merge, Excel macros) for abnormal automated message sending, especially when macros or scripts trigger email delivery. Detect patterns of impersonation language (urgent, payment, executive request) combined with anomalous execution of Office macros.
|
|
Analytic 0432
|
Process/script execution of systemsetup -gettimezone, date, ioreg, or API usage (timeIntervalSinceNow, gettimeofday) followed by time-based scheduling (launchd plist modification) or sleep-based execution.
|
|
Analytic 0879
|
Detects execution of capture commands via CLI (`monitor capture`, `debug packet`, etc.) or unauthorized CLI access followed by logging configuration changes on Cisco/Juniper/Arista gear.
|
|
Analytic 2062
|
Much of this takes place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1051
|
Detection of anomalous or unauthorized mailbox delegation activity (e.g., Add-MailboxPermission, Default/Anonymous mailbox permissions, Gmail delegation setup).
|
|
Analytic 0322
|
Phishing attempts via iCloud Mail, Gmail, or social media apps accessed on macOS systems. Defender view includes Mail.app or Safari downloads of files followed by osascript, Terminal, or abnormal child process execution.
|
|
Analytic 0735
|
Detects Node.js or JavaScript interpreter execution from web shells, cron jobs, or local users. Correlates execution with reverse shell behavior, file modifications, or abnormal outbound connections.
|
|
Analytic 1418
|
Detects access to SSSD or Quest VAS cached credential databases using tdbdump or other file access patterns, requiring sudo/root access.
|
|
Analytic 1224
|
Detects execution patterns where a child process is detached from its original parent, often showing up under 'launchd' (PID 1) with no parent lineage. These breakages in the process tree are indicative of evasive techniques using `daemon()`, `fork()` or background execution flags.
|
|
Analytic 1138
|
Detects interactive or service logins from local accounts outside expected operational context or at anomalous times.
|
|
Analytic 0822
|
Detects hijacking of an existing thread (OpenThread) through a behavioral chain involving thread suspension (SuspendThread), memory modification (VirtualAllocEx + WriteProcessMemory), context manipulation (SetThreadContext), and thread resumption—all within another live process's address space (ResumeThread).
|
|
Analytic 1154
|
Reading of sensitive files like .bash_history, /etc/shadow, or private key directories by unauthorized users or unusual processes.
|
|
Analytic 0227
|
Execution of trusted system binaries (e.g., `split`, `tee`, `bash`, `env`) used in uncommon sequences or chained behaviors to execute malicious payloads or perform actions inconsistent with normal system or script behavior.
|
|
Analytic 0486
|
Forged cookies on macOS may show up as abnormal access to Safari/Chrome cookie databases in ~/Library/Cookies, combined with unexpected logon sessions authenticated by those cookies. Unified Logs may show cookie injection events or abnormal access patterns to Keychain when linked to browser authentication flows.
|
|
Analytic 0100
|
Suspicious processes initiating encrypted HTTPS connections to common web service domains, followed by abnormal data upload behavior or automated posting behavior indicative of C2 bidirectional traffic.
|
|
Analytic 0727
|
Detects local staging behavior via snapshot creation or files written into VMFS partitions by scripts or unauthorized shell access.
|
|
Analytic 0672
|
Monitor for file access to certificate directories, commands invoking OpenSSL or PKCS#12 utilities to export or modify certificates, and processes accessing sensitive key storage paths.
|
|
Analytic 1249
|
Defenders may observe suspicious SNMP MIB enumeration through abnormal queries for large sets of OIDs, repeated SNMP GETBULK/GETNEXT requests, or queries originating from non-administrative IP addresses. Anomalous use of community strings, authentication failures, or enumeration activity outside maintenance windows may also indicate attempts to dump MIB contents. Correlation across syslog, NetFlow, and SNMP audit data can reveal chains of behavior such as repeated authentication failures followed by successful large-scale OID retrieval.
|
|
Analytic 1497
|
Processes (e.g., bash, python, custom binaries) dynamically linking libcrypto/libssl for RSA key exchange, then creating external connections with abnormal certificate validation or handshake anomalies. Defender observes syscall traces and outbound asymmetric key exchanges from non-SSL-native processes.
|
|
Analytic 1058
|
Detects use of network scanning utilities or scripts performing rapid connections to multiple services or hosts using auditd and netflow/pcap telemetry.
|
|
Analytic 1407
|
Detects suspicious SVG file creation or download events followed by script engine execution (e.g., wscript.exe, mshta.exe, rundll32.exe), network callbacks, or browser-based credential collection.
|
|
Analytic 0196
|
Detects rsync or scp inbound from other hosts that then aggregate content into /Users/Shared or /private/tmp, often involving compressed files or scripts.
|
|
Analytic 0988
|
Identifies suspicious outbound traffic volume mismatches from processes that typically do not generate network activity, particularly over C2 protocols like HTTPS, DNS, or custom TCP/UDP ports, following file or data access.
|
|
Analytic 1048
|
Correlated use of sleep/delay mechanisms (e.g., kernel32!Sleep, NTDLL APIs) in short-lived processes, combined with parent processes invoking suspicious scripts (e.g., wscript, powershell) with minimal user interaction.
|
|
Analytic 1059
|
Detects Bonjour-based mDNS enumeration or use of system tools (e.g., dns-sd, nmap) to find active services via multicast probing or targeted scans.
|
|
Analytic 0650
|
Unsigned processes accessing system memory or launching known credential scraping tools (e.g., osascript, dylib injections) to access the Keychain or sensitive memory regions.
|
|
Analytic 0531
|
Automated execution of native utilities and scripts to discover, enumerate, and exfiltrate files and clipboard content. Focus is on detecting repeated file access, scripting engine use, and use of command-line utilities commonly leveraged by collection scripts.
|
|
Analytic 1245
|
Defenders can identify PowerShell profile-based persistence by correlating file creation or modification in known profile locations with subsequent PowerShell process launches that do not use the `-NoProfile` flag. Profile scripts loading unusual modules or launching external programs, particularly under elevated contexts, are suspicious and may represent adversary persistence or privilege escalation.
|
|
Analytic 0351
|
Insertion of public keys into authorized_keys using bash/zsh or editor tools, correlated with suspicious process ancestry.
|
|
Analytic 0763
|
Unusual TLS tunnels through ports not normally encrypted (e.g., TLS on port 8080, 53). Defender sees NetFlow/IPFIX or packet inspection indicating high-entropy traffic volumes and asymmetric client/server exchange ratios.
|
|
Analytic 2032
|
Observation of scripted network requests (e.g., using osascript, curl, or python) that include mismatched or spoofed browser User-Agent strings compared to the typical macOS Safari or Chrome baseline, especially when triggered by non-interactive launch agents, login hooks, or background daemons.
|
|
Analytic 0190
|
Detection of phishing through anomalous Mail app activity, such as attachments saved to disk and immediately executed, or Safari/Preview launching URLs and files linked from email messages. Correlate UnifiedLogs events with subsequent process execution.
|
|
Analytic 1465
|
Unusual or suspicious processes loading critical native API DLLs (e.g., ntdll.dll, kernel32.dll) followed by direct syscall behavior, memory manipulation, or hollowing.
|
|
Analytic 2004
|
Consider analyzing malware for features that may be associated with the adversary and/or their developers, such as compiler used, debugging artifacts, or code similarities. Malware repositories can also be used to identify additional samples associated with the adversary and identify development patterns over time.
Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle.
|
|
Analytic 0889
|
Modification of container runtime security profiles (AppArmor, seccomp) or removal of monitoring agents within containers. Detect unauthorized mounting/unmounting of host /proc or /sys to disable logging or auditing.
|
|
Analytic 1556
|
Detection of bash/zsh history suppression via HISTFILE/HISTCONTROL manipulation and absence of ~/.bash_history updates. Observing environment variable changes tied to terminal processes is a strong indicator.
|
|
Analytic 1422
|
Detects container breakout behavior via exploitation (e.g., DirtyPipe, CVE-2022-0847), followed by host OS interaction or escalated capability assignment.
|
|
Analytic 0070
|
Detects abnormal interaction with memory-based Kerberos ccache (API:{uuid}) or file-based overrides. Focus on processes attempting to enumerate or extract Kerberos tickets outside of built-in utilities. Detects use of open-source tools (e.g., Bifrost, modified Mimikatz ports) that interact with the Kerberos framework APIs.
|
|
Analytic 1084
|
Detects Unix shell usage on network appliances (e.g., routers, firewalls, embedded Linux) through rare console commands, CLI interfaces, or script injection via exposed APIs or SSH.
|
|
Analytic 0913
|
Detects the presence of executables with high NOP padding, unusually large binary size for their function, and follow-on execution or memory injection from such files, especially when originating from temp or user-space paths.
|
|
Analytic 1030
|
A non-privileged or abnormal process attempts to open a handle with full access (0x1F0FFF) to lsass.exe and subsequently invokes memory dump, file creation, or registry modification indicative of credential scraping. This behavior chain reflects staged credential theft activity.
|
|
Analytic 1337
|
Authentication failures across different accounts using a repeated or similar password via SSH or PAM stack within a short window
|
|
Analytic 2044
|
Detects esxcli commands disabling syslog, firewall, lockdown mode, or stopping hostd/vpxa; correlates command execution with reduced forwarding activity.
|
|
Analytic 0397
|
Script-based execution of sleep loops or time delay commands (e.g., sleep, ping delay, while-loops) followed by file creation or network connections.
|
|
Analytic 0632
|
Detects binaries disguised as media or document types through extension-only masquerading or by modifying the file signature. Observes execution of files whose extension is not typically executable (.jpg, .txt), yet have valid Mach-O headers or execute via Terminal or launch services.
|
|
Analytic 1200
|
Monitors Keychain database access and suspicious invocations of security and osascript utilities. Correlates process execution with attempts to dump or unlock Keychain data.
|
|
Analytic 0304
|
Processes use built-in encoding utilities (e.g., `base64`, `xxd`, or `plutil`) to encode file contents followed by HTTP/HTTPS transfer via curl or custom applications.
|
|
Analytic 0451
|
Detect repeated failed login events followed by MFA challenges triggered in rapid succession, especially if originating from service accounts or anomalous IP addresses.
|
|
Analytic 1385
|
Hidden file creation using leading '.' or file attribute changes with chattr (immutable/hidden flags). Defender view: detect execution of chattr, lsattr anomalies, and unusual hidden files appearing in system directories.
|
|
Analytic 0337
|
Invocation of esxcli 'system account remove' from vCLI, SSH, or vSphere API with anomalous user access or outside maintenance windows.
|
|
Analytic 0473
|
Adversary installs or modifies email content filters or transport scripts (e.g., Postfix milter, Sendmail milter, Exim filters) using shell access or configuration manipulation.
|
|
Analytic 1201
|
Detects attempts to access or enumerate cloud password/secrets storage services such as AWS Secrets Manager, Azure Key Vault, or GCP Secret Manager. Monitors API calls for abnormal enumeration or bulk retrieval of secrets.
|
|
Analytic 0540
|
Detection of known tools or malware flagged by antivirus, followed by a near-term drop of a similar binary with modified signature and resumed activity (execution, C2, or persistence).
|
|
Analytic 1308
|
Detects rundll32.exe invoked with atypical arguments (.dll, .cpl, javascript:, mshtml). DLLs not normally loaded by rundll32 are mapped into memory. Control_RunDLL or RunHTMLApplication invoked. Suspicious DLLs or scripts accessed from disk or network. Rundll32 reaches out to external domains (e.g., fetching .sct or .hta).
|
|
Analytic 0571
|
Detection correlates anomalous Docker or Kubernetes API requests with access to logs, secrets, or service accounts. Observes unauthorized use of `docker logs`, `kubectl get secrets`, or direct API calls to Kubernetes API server endpoints. Identifies behavioral patterns where adversaries escalate from basic pod/container interaction to privileged API calls exposing sensitive credential material.
|
|
Analytic 1146
|
Unusual access or copying of files from mounted network drives (e.g., NFS, CIFS/SMB) by user shells or scripts followed by large data transfer.
|
|
Analytic 0999
|
macOS permission and attribute manipulation behavioral chain: (1) Process execution of permission utilities (chmod, chown, chgrp) or macOS-specific tools (chflags) with suspicious parameters, (2) System Integrity Protection (SIP) bypass attempts through permission modifications, (3) File flags manipulation (uchg, schg, hidden) for evasion or persistence, (4) Extended attribute (xattr) modifications affecting security metadata, (5) Unified log correlation with file system events and subsequent access patterns, (6) Gatekeeper and code signing bypass through permission/attribute manipulation
|
|
Analytic 0493
|
Detects adversary exploitation of authentication mechanisms or credential validation processes. Defender perspective includes forged Kerberos tickets (e.g., MS14-068), abnormal LSASS memory access, replayed authentication attempts, and unexpected crashes of authentication services. Multi-event correlation ties exploitation attempts to abnormal process creation, service instability, and suspicious authentication events.
|
|
Analytic 0514
|
CLI tools (smbclient -L, smbmap, rpcclient, nmblookup) or custom scripts enumerate SMB shares on many internal hosts → corresponding SMB connections (445/139) captured by Zeek/Netflow within a short window.
|
|
Analytic 0512
|
SQL stored procedures that invoke OS-level commands via `xp_cmdshell` equivalent or via UDF (User-Defined Functions) mechanisms.
|
|
Analytic 0433
|
Interactive or remote shell/API invocation of esxcli system clock get or querying time parameters via hostd/vpxa shortly followed by time/ntp configuration checks or scheduled task creation, executed by non-standard accounts or outside maintenance windows.
|
|
Analytic 0626
|
Detects cloud-native software deployment or management (e.g., SSM Run Command, Intune) initiating script execution on endpoints outside expected org IDs, admin groups, or maintenance windows.
|
|
Analytic 0163
|
Detect unauthorized manipulation of log files, database entries, or system configuration files through auditd and syslog. Correlate shell commands that alter HISTFILE or data-related processes with abnormal file access patterns.
|
|
Analytic 1449
|
Closed-port knock sequence from a remote IP followed by on-host firewall change (iptables/nftables) or daemon starts listening (socket open) and a successful TCP/UDP connect. Optional detection of libpcap/raw-socket sniffers spawning to watch for secret values.
|
|
Analytic 2005
|
Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
Consider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently created/modified accounts making numerous connection requests to accounts affiliated with your organization.
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: [Phishing](https://attack.mitre.org/techniques/T1566)).
|
|
Analytic 1107
|
Detection of ApplicationImpersonation role assignment or delegated mailbox access to service principals or rarely used users, especially outside of normal hours or geographic norms.
|
|
Analytic 0522
|
Detects clearing of unified logs, deletion of plist files tied to persistence, and manipulation of Terminal history after initial execution.
|
|
Analytic 0758
|
Detects unauthorized modification of network device authentication by correlating OS image file changes, checksum mismatches, or memory verification failures with anomalous authentication events. Focus is on behaviors where patched images introduce hardcoded passwords or bypass native authentication.
|
|
Analytic 0851
|
User or remote input triggers application crash or segmentation fault (e.g., SIGSEGV) with service recovery attempts, observed via audit logs and systemd journaling.
|
|
Analytic 1533
|
Observation of `blueutil`/`networksetup` commands or low-level APIs toggling Bluetooth or initiating transfers, especially if paired with recent large file read activity by non-GUI processes.
|
|
Analytic 0939
|
Detection of maintainer scripts (e.g., postinst, preinst) being modified or executed during dpkg or rpm operations. Watch for script content that spawns additional processes or writes outside package scope.
|
|
Analytic 1537
|
Detects suspicious use of ESXi native CLI tools like esxcli and vim-cmd by unauthorized users or outside expected maintenance windows. Focus is on actions such as stopping VMs, reconfiguring network/firewall settings, and enabling SSH or logging.
|
|
Analytic 1312
|
Correlates unusual auto-forwarding rule creation via Exchange Web Services or Outlook rules engine, presence of X-MS-Exchange-Organization-AutoForwarded headers, and logon session anomalies from abnormal IPs.
|
|
Analytic 0083
|
Containerized apps or sidecar containers generating excessive outbound traffic or being leveraged for proxy networks. Includes sudden increases in network interface stats, especially in dormant or low-util apps.
|
|
Analytic 1287
|
Login activity from default admin credentials (e.g., 'admin', 'cisco') on routers, firewalls, and switches.
|
|
Analytic 0484
|
Forged web cookies on Windows endpoints can be detected by monitoring unusual modifications of browser cookie stores (e.g., Chrome SQLite DB, Edge cache) by processes outside of browsers, followed by authentication events to SaaS or IaaS services. Defenders may observe processes writing directly to cookie storage paths or injecting tokens into browser sessions.
|
|
Analytic 0545
|
Detects API calls to cloud secrets/MFA configurations where MFA enforcement policies are disabled or bypassed.
|
|
Analytic 0873
|
Detection of browser-based downloads from HTML sources that trigger file creation in temp or user directories followed by execution of new files within short timeframes and suspicious parent-child lineage.
|
|
Analytic 1552
|
Linux environmental validation behavioral chain: (1) Intensive system enumeration through command execution (uname, hostname, ifconfig, lsblk, mount), (2) File system reconnaissance targeting specific paths, network configurations, and installed packages, (3) Process and user enumeration to validate target environment characteristics, (4) Conditional script execution or binary activation based on environmental criteria, (5) Network connectivity validation and external IP address resolution for geolocation verification
|
|
Analytic 0584
|
Excessive resource exhaustion or service crash induced by processes launched by users or scripts that rapidly consume CPU/memory or attempt malformed service interactions.
|
|
Analytic 0877
|
Detects enabling of interface sniffing via packet capture tools or AppleScript triggering `tcpdump`. Leverages Unified Logs and process lineage to identify suspicious use of `pfctl`, `tcpdump`, or `libpcap` libraries.
|
|
Analytic 1351
|
A process explicitly forges its parent using EXTENDED_STARTUPINFO + PROC_THREAD_ATTRIBUTE_PARENT_PROCESS (UpdateProcThreadAttribute → CreateProcess[A/W]/CreateProcessAsUserW) or other Native API paths, resulting in **mismatched/implausible lineage** across ETW EventHeader ProcessId, Security 4688 Creator Process ID/Name, and sysmon ParentProcessGuid. Often paired with privilege escalation when the chosen parent runs as SYSTEM.
|
|
Analytic 0042
|
Detects files collected into user temp or shared directories followed by compression with ditto, zip, or custom scripts.
|
|
Analytic 0501
|
Post-compromise identity & session anomalies that follow a drive-by compromise: token reuse from new/unfamiliar IPs, anomalous sign-in patterns for previously inactive users, unexpected consent/grant events, or provisioning changes. Defender sees an endpoint/browser compromise (network + endpoint signals) followed by unusual IdP events: new refresh token issuance, consent/consent-grant events, odd MFA bypass patterns, or unusual OAuth client registrations.
|
|
Analytic 0112
|
Monitor esxcli and syslog records for DNS resolver changes or repeated queries to unusual external domains by management agents. Detect unauthorized changes to VM or host network settings that redirect DNS lookups.
|
|
Analytic 0356
|
Adversary drops renamed binaries in uncommon directories (e.g., /tmp, /dev/shm) or uses special characters in names (e.g., trailing space, Unicode RLO). Execution or cronjob registration follows shortly after file drop.
|
|
Analytic 1114
|
Background scripts (e.g., via cron) or daemons transmitting data repeatedly to remote IPs or URLs.
|
|
Analytic 1009
|
Monitor mail server logs (e.g., Postfix, Sendmail) for excessive connections or inbound message counts targeting a single recipient. Correlate with repetitive attachment storage in /var/mail or /var/spool/mail directories.
|
|
Analytic 0314
|
Detection of modification to ESXi rc.local.d or rc scripts that are used to execute on boot.
|
|
Analytic 1174
|
Monitor command execution of powercfg.exe with arguments modifying sleep, hibernate, or display timeouts. Abnormal or repeated modifications to power settings outside administrative baselines may indicate persistence attempts. Correlate process creation with registry and system configuration changes to build behavioral chains.
|
|
Analytic 0664
|
Adversary modifies internal or external site content through manipulated application bundles, hosted content, or web server configs.
|
|
Analytic 0819
|
User opens a file delivered by email, web, chat, or share. The handler application (Word/PDF reader/archiver) creates a file in user-controlled paths (Downloads, Temp, Desktop) and then spawns a new or unusual child process (e.g., powershell.exe, wscript.exe, cmd.exe, regsvr32.exe, rundll32.exe, msiexec.exe). Optional precursors include FileStreamCreated (URL/UNC) and Office → system32 batch writes.
|
|
Analytic 0202
|
Session cookie reuse on unmanaged browsers, devices, or client types deviating from user baseline (e.g., switching from Chrome to curl).
|
|
Analytic 0499
|
Correlated evidence of browser or webview fetches to uncommon domains or mutated JS resources (proxy/NGFW logs + Zeek/HTTP logs) followed by unexpected interpreters or script engines executing (python, ruby, sh) spawned from browser processes or user sessions, rapid on-disk staging in /tmp, and outbound connections that deviate from baseline. Defender sees: uncommon resource fetch → short-lived child process executions from user browser context → file writes in temp directories → anomalous outbound C2-like connections.
|
|
Analytic 1214
|
Detects custom archive routines by correlating script execution (Python, Perl, Bash) with creation of high-entropy files in temporary or user directories. Flags processes performing unusual bitwise operations or writing files without standard compression headers.
|
|
Analytic 0015
|
From a defender’s perspective, suspicious bridging is observed when network devices begin allowing traffic that contradicts existing segmentation or access policies. Observable behaviors include sudden modifications to ACLs or firewall rules, unusual cross-boundary traffic flows (e.g., east-west communications across separated VLANs), or simultaneous ingress/egress anomalies. Multi-event correlation is key: configuration changes on a router/firewall followed by unexpected traffic patterns, especially from unusual sources, is a strong indicator of compromise.
|
|
Analytic 0330
|
Ties inbound access to exposed services (ARD/VNC 5900, SSH 22, ScreenSharing, web services) with process crashes in unified logs and abnormal child processes spawned under those services (e.g., bash, curl) to indicate exploitation.
|
|
Analytic 0407
|
Detection of iptables, nftables, or firewalld rule modifications. Correlation of sudden drops in active firewall rules with suspicious processes suggests adversarial evasion.
|
|
Analytic 0013
|
Execution of renamed or relocated native macOS utilities with uncommon names or non-default paths (e.g., renamed `osascript`, `bash`, or `curl`).
|
|
Analytic 2061
|
Much of this takes place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0259
|
Detects creation or modification of cron jobs via crontab, /etc/cron.* directories, or systemd timer units with execution by unusual users or non-standard intervals.
|
|
Analytic 1399
|
Detects process injection by correlating memory manipulation API calls (e.g., VirtualAllocEx, WriteProcessMemory), suspicious thread creation (e.g., CreateRemoteThread), and unusual DLL loads within another process's context.
|
|
Analytic 0544
|
Detects conditional access policy changes, exclusion of accounts from MFA enforcement, or registration of new MFA factors by non-admin or anomalous users.
|
|
Analytic 1604
|
Adversary uses built-in OS tools or API calls to create local or domain accounts for persistence or lateral movement. Tools such as 'net user', PowerShell, or MMC snap-ins may be used. Detection focuses on Event ID 4720 paired with process lineage and user context.
|
|
Analytic 1026
|
Behavioral detection of domain group enumeration via ldapsearch or custom scripts leveraging LDAP over the network.
|
|
Analytic 0814
|
Detects injection or tampering of DLLs in hybrid identity agents (e.g., AzureADConnectAuthenticationAgentService), registry or configuration changes tied to PTA/AD FS, and anomalous LSASS or AD FS module loads correlated with authentication anomalies.
|
|
Analytic 0827
|
Processes attempting raw disk access to overwrite sensitive structures such as the MBR or partition table using \\.\PhysicalDrive notation. Detection relies on correlating process creation, privilege escalation, and raw sector writes in Sysmon and Security logs.
|
|
Analytic 0686
|
Correlate MFA push fatigue or unusual consent grant attempts with call activity where adversaries may have socially engineered the user over voice.
|
|
Analytic 0750
|
Logon via RDP or WMI by a user account followed by uncommon command execution, file manipulation, or lateral network connections.
|
|
Analytic 0518
|
Detect anomalous use of scp, rsync, curl, or third-party sync apps transferring executables into user directories. Correlate new file creation with immediate execution events.
|
|
Analytic 0770
|
Detection of rogue Domain Controller registration and Active Directory replication abuse by correlating: (1) creation/modification of nTDSDSA and server objects in the Configuration partition, (2) unexpected usage of Directory Replication Service SPNs (GC/ or E3514235-4B06-11D1-AB04-00C04FC2DCD2), (3) replication RPC calls (DrsAddEntry, DrsReplicaAdd, GetNCChanges) originating from non-DC hosts, and (4) Kerberos authentication by non-DC machines using DRS-related SPNs. These events in combination, especially from hosts outside the Domain Controllers OU, may indicate DCShadow or rogue DC activity.
|
|
Analytic 0710
|
Suspicious reuse of SSH agent sockets across multiple users or processes, anomalous access to ~/.ssh/ or /tmp/ssh-* sockets, and abnormal patterns of lateral movement via SSH without new authentication events. Defender view: detect when one process accesses another user's SSH agent or when an existing SSH connection is used to pivot unexpectedly.
|
|
Analytic 1272
|
Unusual mounting of loopback or pseudo file systems not aligned with legitimate administrative activity. Defender view: monitoring auditd and syslog for mount commands involving suspicious mount points, reserved blocks, or device mappings indicative of hidden partitions.
|
|
Analytic 0149
|
Abnormal Apple Mail use, including internal email relays followed by file execution or script events (e.g., attachments launched via Preview, terminal triggered from Mail.app)
|
|
Analytic 0039
|
Scripting or CLI tool access to ~/Library/Application Support/Google/Chrome or ~/Library/Safari bookmarks, cookies, or history databases. Detection relies on unexpected processes accessing or reading from these locations.
|
|
Analytic 0498
|
Correlated evidence of anomalous browser/network behavior (suspicious external resource fetches and script injection patterns) followed by atypical child processes, ephemeral execution contexts, memory modification or process injection, and unexpected file drops. Defender sees network requests to previously unseen/suspicious domains or resources + browser process spawning unusual children or loading unsigned modules + file writes or registry changes shortly after those requests.
|
|
Analytic 1517
|
User or script-based access to ~/.ssh or other directories containing private keys followed by unusual shell activity or network connections.
|
|
Analytic 1485
|
launchd or user-invoked processes (ssh, socat) encapsulating traffic via SSH tunnels, VPN-style tooling, or DNS-over-HTTPS clients. Defender sees outbound TLS traffic with embedded DNS or RDP payloads.
|
|
Analytic 0082
|
Suspicious long-lived or high-throughput connections by non-Apple signed apps or processes not commonly associated with network uploads. Detect background processes using open sockets for data egress.
|
|
Analytic 1246
|
Detection correlates abnormal installation or modification of root or code-signing certificates, creation/modification of suspicious registry keys for trust providers, and unusual module loads from non-standard locations. Identifies unsigned or improperly signed executables bypassing trust prompts, combined with persistence artifacts.
|
|
Analytic 1166
|
Automated scripts or repeated CLI/API requests that trigger application backends to consume high CPU or memory (e.g., Apache/PHP, MySQL, mail servers), resulting in syslog errors and excessive process spawning.
|
|
Analytic 0090
|
Binaries or applications executed with tampered or unverifiable code signatures. Often tied to Gatekeeper bypasses, App Translocation, or use of unsigned launch daemons by untrusted users.
|
|
Analytic 2059
|
Much of this takes place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0141
|
Suspicious file creation or modification in directories ignored by XProtect or AV exclusions (e.g., ~/Library, temporary cache directories). Defender perspective: monitor file events in ignored paths with correlation to execution or persistence activity.
|
|
Analytic 0069
|
Detects unauthorized access, copying, or modification of Kerberos ccache files (krb5cc_%UID% or krb5.ccache) in /tmp or custom paths defined by KRB5CCNAME. Correlates file access with suspicious processes (e.g., credential dumping tools) and subsequent anomalous Kerberos authentication requests from non-standard processes.
|
|
Analytic 1162
|
Abuse of SaaS platforms such as Confluence, GitHub, SharePoint Online, or Slack to access excessive internal documentation or export source code/data. Includes use of tokens or browser automation from unapproved IPs.
|
|
Analytic 0956
|
Token replay or impersonation in federated logins without interactive browser session or MFA prompts.
|
|
Analytic 0294
|
Unsigned or scripting-based processes invoking password cracking binaries or accessing hashed credential artifacts post-login
|
|
Analytic 1338
|
Multiple failed login attempts across different users using common password patterns (e.g., 'Welcome2023')
|
|
Analytic 1570
|
Defenders may observe adversary attempts to downgrade system images by monitoring for anomalous file transfers of OS image files (via TFTP, FTP, SCP), configuration changes pointing boot system variables to older image files, unexpected OS version strings after reboot, and checksum mismatches against approved baseline images. Suspicious chains include transfer of an older image, alteration of boot configuration, and reboot/reload of the device. Adversaries may also tamper with CLI output to disguise downgrade attempts, requiring independent validation of OS version and integrity.
|
|
Analytic 0439
|
VMware services or management daemons generating HTTP POST requests to webhook endpoints, chained with unusual datastore or log access. Defender perspective: exfiltration from VM logs or disk images over webhook URLs.
|
|
Analytic 1501
|
Detects adversary abuse of Transactional NTFS (TxF) and undocumented process loading mechanisms (e.g., NtCreateProcessEx) to create a hollowed process from an uncommitted, maliciously tainted file image in memory, later executed via NtCreateThreadEx.
|
|
Analytic 0371
|
Detects outbound traffic from hostd/vpxa or guest VM interfaces using unauthorized protocols such as FTP, HTTP POST bursts, or long-lived DNS tunnels.
|
|
Analytic 0078
|
Detects HTTP or HTTPS communication initiated by shell-based scripts or management daemons, especially those reaching public IPs over ports 80/443 using embedded curl or wget.
|
|
Analytic 0966
|
Detection of pbpaste/pbcopy clipboard access by processes without terminal sessions or linked to launch agents, potentially staged for collection.
|
|
Analytic 1203
|
Detects spoofed emails by analyzing mail server logs (e.g., Postfix, Sendmail) for mismatched header fields, failed SPF/DKIM checks, and anomalies in SMTP proxy logs. Defender observes discrepancies between sending domain, return-path domain, and message metadata.
|
|
Analytic 1580
|
Detects snapshot sharing, backup exports, or data object transfers from victim-owned cloud accounts to other cloud identities within the same provider (e.g., AWS, Azure) using snapshot sharing, S3 bucket policy updates, or SAS URI generation.
|
|
Analytic 0408
|
Detection of PF firewall rule modifications via pfctl, socketfilterfw, or defaults write to com.apple.alf. Adversaries often disable firewall profiles entirely or whitelist malicious processes.
|
|
Analytic 0049
|
Adversary runs discovery commands such as `ps aux`, `systemctl status`, or `cat /etc/init.d/` to enumerate security software or services. Often occurs alongside privilege escalation or bash script execution.
|
|
Analytic 1352
|
Detection of adversary attempts to enumerate containers, pods, nodes, and related resources within containerized environments. Defenders may observe anomalous API calls to Docker or Kubernetes (e.g., 'docker ps', 'kubectl get pods', 'kubectl get nodes'), unusual account activity against the Kubernetes dashboard, or unexpected queries against container metadata endpoints. These events should be correlated with user context and network activity to reveal resource discovery attempts.
|
|
Analytic 1002
|
Use of gsettings or direct Display Manager modifications to hide users from greeter login screen. Defender view: anomalous command execution modifying org.gnome.login-screen or other greeter configurations.
|
|
Analytic 1217
|
Detects binary movement or copying between untrusted and trusted paths (e.g., /tmp/ → /usr/bin/ or /etc/init.d/) that may indicate persistence attempts or cleanup of origin traces.
|
|
Analytic 1319
|
Modification of COR_PROFILER-related environment variables or Registry keys (COR_ENABLE_PROFILING, COR_PROFILER, COR_PROFILER_PATH), combined with anomalous .NET process creation or unmanaged DLL loads. Defender observes registry modifications, suspicious process creation with altered environment variables, and profiler DLLs loaded unexpectedly into .NET CLR processes.
|
|
Analytic 0477
|
Firmware image uploaded via TFTP/SCP or web interface followed by reboot or unexpected loss of connectivity.
|
|
Analytic 0844
|
A source performs a closed-port sequence; the endpoint enables a PF/socketfilterfw rule or a background process binds a port; then a successful connection completes from the same source.
|
|
Analytic 0623
|
Detects SCCM, Intune, or remote push execution spawning scripts or binaries from SYSTEM context or unusual consoles (e.g., cmtrace.exe launching PowerShell or cmd.exe).
|
|
Analytic 0547
|
Detects modifications to authorization plugins responsible for MFA enforcement and correlates with suspicious login sessions missing MFA prompts.
|
|
Analytic 1494
|
Detects adversary behavior where a process enumerates and modifies another process's memory using /proc/[pid]/maps and /proc/[pid]/mem files. This includes identifying gadgets via memory mappings and overwriting process memory via low-level file modification or dd usage.
|
|
Analytic 1610
|
Abuse of JamPlus.exe to launch malicious payloads via crafted .jam files, resulting in abnormal process creation, command execution, or artifact generation outside of standard development workflows.
|
|
Analytic 1317
|
Cause→effect chain in CI/dev desktops: (1) user triggers container run/pull after opening a doc/link/script, (2) newly created image/container uses unexpected external registry or entrypoint, (3) container starts and immediately egresses to suspicious destinations.
|
|
Analytic 0170
|
Detects modification of registry keys used for default file handlers, followed by anomalous process execution from user-initiated file opens. This includes tracking changes under HKCU and HKCR for file extension mappings, and correlating them with new or suspicious handler paths launching unusual child processes (e.g., PowerShell, cmd, wscript).
|
|
Analytic 0620
|
Processes accessing ALSA/PulseAudio devices or executing audio capture binaries like 'arecord', followed by file creation or suspicious child process spawning.
|
|
Analytic 0938
|
Correlation of package install event with execution of postinstall scripts containing unknown binaries or abnormal CLI usage. Look for `/usr/sbin/installer` execution followed by child processes originating from postinstall script.
|
|
Analytic 0059
|
Detects modification of shell startup/logout scripts such as ~/.bashrc, ~/.bash_profile, or /etc/profile, followed by anomalous process execution or network connections upon interactive or remote shell login.
|
|
Analytic 0132
|
Monitors programmatic access to user mailboxes in cloud-based email systems (e.g., O365, Exchange Online) using APIs or tokens. Focuses on OAuth misuse, suspicious MailItemsAccessed patterns, scripted keyword searches, and connections from untrusted agents or locations.
|
|
Analytic 1429
|
Detects use of shell interpreters (e.g., bash, sh, python, perl) initiated by users or processes not normally executing them, especially when chaining suspicious utilities like netcat, curl, or ssh.
|
|
Analytic 0604
|
Userland or kernel-level ransomware encrypting user files (Documents, Desktop) using `srm`, `gpg`, or compiled payloads. Often correlated with ransom note creation in multiple directories.
|
|
Analytic 0313
|
Monitoring for modification and execution of login hook scripts or LaunchAgents/LaunchDaemons used for persistence.
|
|
Analytic 1937
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1442
|
Detects AppleScript or Objective-C usage to generate fake authentication windows (e.g., using display dialog or NSAlert) from user-launched or persistence-related processes.
|
|
Analytic 1364
|
Monitor SaaS financial systems (e.g., QuickBooks, Workday, SAP S/4HANA cloud) for unauthorized access, rule changes, or mass export of financial data. Detect anomalous transfers initiated via SaaS APIs or new MFA-disabled logins targeting finance apps.
|
|
Analytic 0216
|
Detection of anomalous RDP or remote service session activity where a logon session is hijacked rather than newly created. Indicators include mismatched user credentials vs. active session tokens, service session takeovers without corresponding successful logon events, or RDP shadowing activity without user consent.
|
|
Analytic 2060
|
Much of this takes place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0067
|
Correlates ELF file execution with high-entropy writable memory segments and self-modifying code patterns.
|
|
Analytic 0418
|
Forged SAML tokens can be observed as authentication attempts with valid signatures but missing expected preceding Kerberos or authentication events. Defenders may correlate SAML assertions with absent Event IDs 4769, 1200, or 1202, or tokens issued with abnormal lifetimes, issuers, or claims compared to baseline.
|
|
Analytic 1103
|
Adversary uses cloud-native APIs or CLI (e.g., AWS Systems Manager, Azure Resource Graph) to list installed software on cloud workloads.
|
|
Analytic 1381
|
Detects compilation activity using csc.exe, ilasm.exe, or msbuild.exe initiated by user-space processes outside typical development environments, followed by execution or network activity from newly written binaries.
|
|
Analytic 0824
|
Detects unauthorized edits to /etc/hosts, /etc/resolv.conf, or suspicious ARP broadcasts. Correlates file modifications with subsequent unexpected network sessions or service creation.
|
|
Analytic 1952
|
Internet scanners may be used to look for patterns associated with malicious content designed to collect client configuration information from visitors.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: ATT ScanBox)
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1088
|
Use of AWS CLI (`aws iam list-users`, `list-roles`), Azure CLI (`az ad user list`), or GCP CLI (`gcloud iam service-accounts list`) from endpoints or cloud shells where such activity is unexpected.
|
|
Analytic 0429
|
Detection of suspicious write operations to block devices, modifications of bootloader files (GRUB, initrd, vmlinuz), and unexpected changes within the EFI System Partition. Monitors privileged execution of utilities like dd, grub-install, or efibootmgr that modify boot sectors or loader entries.
|
|
Analytic 0362
|
Modification of plist files to set apple.awt.UIElement or similar flags hiding app icons and windows, and dscl/command-line activity that suppresses visibility. Defender view: correlation of plist modifications with unexpected hidden user applications.
|
|
Analytic 0399
|
Detects unauthorized or anomalous use of command-line interfaces (CLI) on network devices. Focuses on remote access sessions (e.g., SSH/Telnet), privilege escalation within CLI sessions, execution of high-risk commands (e.g., config replace, terminal monitor, no logging), and configuration changes outside of approved windows.
|
|
Analytic 1157
|
Unauthorized API or console calls to retrieve or reset password credentials, download key material, or modify SSO settings.
|
|
Analytic 0228
|
Use of system binaries such as `osascript`, `bash`, or `curl` to download or execute unsigned code or files in conjunction with application proxying.
|
|
Analytic 1500
|
Encrypted sessions detected with asymmetric key exchange anomalies on non-standard ports or with invalid/malformed certs. Defender correlates NetFlow/IPFIX with IDS/IPS detecting RSA exchanges outside expected TLS flows.
|
|
Analytic 1186
|
Registry key modifications under IFEO paths (e.g., Debugger value set under Image File Execution Options), especially for security-related or accessibility binaries, followed by anomalous process execution with debugger flags or SYSTEM-level access at login. Detectable by correlating registry modifications, process creation, and parent-child anomalies with unusual command-line usage or access tokens.
|
|
Analytic 1378
|
Outbound fallback traffic from low-profile or background launch agents using unusual protocols or destinations after primary channel inactivity.
|
|
Analytic 1065
|
Detects use of gzip, base64, tar, or openssl in scripts or commands that encode/encrypt files after file staging or system enumeration.
|
|
Analytic 0030
|
Processes generating large outbound connections with disproportionate send/receive ratios, often to uncommon ports or hosts, potentially inserting meaningless data into protocol payloads.
|
|
Analytic 0678
|
Execution of Java-based or CLI database tools (e.g., DBeaver, Beekeeper, mysql, psql) from user profiles not tied to dev/admin roles, especially when followed by file writes and cloud sync activity. Defender correlates GUI tool launches, file write events in ~/Downloads or ~/Documents, and outbound API calls to known cloud services.
|
|
Analytic 0171
|
Disabling or modifying the Linux Audit system through process termination (auditd killed), service management (systemctl stop auditd), or tampering with rule/configuration files (/etc/audit/audit.rules, audit.conf). Defender view: suspicious execution of auditctl/systemctl commands, file modifications to audit rules, or sudden absence of audit logs correlated with privileged execution.
|
|
Analytic 0807
|
Detects direct modification of crontab entries in /var/spool/cron/crontabs/root or /etc/rc.local.d/local.sh followed by execution of scripts linked to lateral movement or malware persistence.
|
|
Analytic 0003
|
Detects CLI tools (e.g., mosquitto_pub, nc, python scripts) interacting with pub/sub brokers using unusual topic names, high-frequency publication rates, or obfuscated payloads to non-standard hosts.
|
|
Analytic 1992
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0542
|
Detection of XProtect or AV quarantining a known tool, followed by modification (file size, hash, string) and subsequent re-execution by the same or related user.
|
|
Analytic 0733
|
Detects JavaScript execution through WSH (wscript.exe, cscript.exe) or HTA (mshta.exe), particularly when spawned from Office macros, web browsers, or abnormal user paths. Correlates script execution with outbound network activity or system modification.
|
|
Analytic 1300
|
Detects modification of shared network folders via .app bundles or scripting files with hidden extensions (e.g., double extensions like docx.app).
|
|
Analytic 0494
|
Detects exploitation of authentication daemons or PAM modules. Defender perspective includes failed or anomalous PAM authentications, abnormal segfaults in authentication services, and exploitation attempts followed by successful unauthorized logins. Correlation identifies memory corruption, replay attempts, and privilege escalation tied to credential services.
|
|
Analytic 1359
|
Detects anomalous use of Mach ports, Apple Events, or XPC services for inter-process execution or code injection. Focuses on unexpected processes attempting to send privileged Apple Events (e.g., automation scripts injecting into security-sensitive apps).
|
|
Analytic 1213
|
Detects suspicious custom compression/encryption routines through anomalous script or binary execution that produces high-entropy files without standard archiving utilities. Correlates script execution, memory API usage (bitwise ops, CryptoAPI calls), and creation of archive-like files with uncommon headers.
|
|
Analytic 0395
|
Detects manual or scripted removal of logs, artifacts, or malware droppings via `rm` or PowerCLI in ESXi shell. Focus on deletions from /tmp/, /var/core/, or /scratch.
|
|
Analytic 0180
|
Behavioral chain: (1) Safari/Chrome/Firefox/Office handles a URL; unified logs show open/click or LSQuarantine assignment, (2) outbound connection to untrusted domain, (3) a new file appears in ~/Downloads or /private/var/folders/* with quarantine flag.
|
|
Analytic 1151
|
Inspect network telemetry for adversary attempts to blend malicious traffic with legitimate flows using VPNs, proxies, or geolocation spoofing. Defensive teams may observe anomalous tunnels, encrypted sessions to suspicious domains, or geo-mismatched IP activity.
|
|
Analytic 1404
|
Detects unauthorized access to browser cookie paths (e.g., `~/Library/Application Support/Google/Chrome/Default/Cookies`) or `task_for_pid`/`vm_read` calls to Safari/Chrome memory space.
|
|
Analytic 1457
|
Execution of `show version`, `show hardware`, or `show system` commands through CLI via SSH or console.
|
|
Analytic 1121
|
Detects high-frequency or anomalous DNS queries initiated by non-browser, non-system processes (e.g., PowerShell, rundll32, python.exe) used to establish command and control via DNS tunneling.
|
|
Analytic 0757
|
Detects anomalous process access to LSASS on domain controllers, suspicious module loads of authentication DLLs, and registry or file modifications indicative of Skeleton Key–style patching. Correlates LSASS access attempts with subsequent abnormal logon activity patterns.
|
|
Analytic 0972
|
VM or cloud instance generating anomalously high network egress targeting same destination IP or service, especially using stateless protocols.
|
|
Analytic 2012
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0124
|
Installation of malicious .mobileconfig profiles or browser extension plist entries followed by abnormal browser child process activity.
|
|
Analytic 0128
|
Execution of commands to enumerate virtualization-related files or processes (e.g., '/sys/class/dmi/id/product_name', dmesg, lscpu, lspci), or querying hypervisor interfaces prior to malware execution.
|
|
Analytic 0315
|
Detection of changes to device startup-config files that include boot scripts or scheduled execution routines.
|
|
Analytic 0567
|
Traffic originating from ESXi hosts or management interfaces displays SNI-to-Host mismatch behavior, particularly anomalous given typical infrastructure communication patterns.
|
|
Analytic 1959
|
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)).
|
|
Analytic 0556
|
Detect suspicious file creation, modification, or deletion in stored data directories (e.g., `/var/lib/mysql/`, `/var/log/`, mail spools). Identify shell commands interacting directly with structured data files instead of legitimate database utilities.
|
|
Analytic 0900
|
Adversaries use cloud API, CLI, or console to create IAM users or roles. Initial CreateUser is followed by policy/role attachment. Detection monitors temporal chains involving IAM:CreateUser, AttachUserPolicy, and credential generation, especially from automation or foreign IP ranges.
|
|
Analytic 1042
|
Execution of file or directory discovery commands (e.g., 'ls', 'find') from terminal or script-based tooling, especially outside normal user workflows.
|
|
Analytic 1123
|
Detects scripting environments (AppleScript, osascript, curl) or non-native tools performing DNS queries with encoded subdomains, often used for data exfiltration or beaconing.
|
|
Analytic 0208
|
Configuration of internal NAT or proxy rules that redirect traffic between client segments internally (e.g., site-to-site port forwarding). Often used to relay internal beaconing or move traffic laterally through trust zones.
|
|
Analytic 0708
|
Monitor for cloud API calls that export or collect guest or system logs. Abnormal use of Azure VM Agent’s CollectGuestLogs.exe or AWS CloudWatch GetLogEvents across multiple instances should be correlated with lateral movement or data staging.
|
|
Analytic 1052
|
Execution of PowerShell commands that modify mailbox permissions using Exchange cmdlets (e.g., Add-MailboxPermission), often tied to BEC or post-compromise persistence.
|
|
Analytic 0381
|
Detects email-sending behavior via Terminal, AppleScript, or Automator that interfaces with SMTP or IMAP, typically using curl or mail-related APIs in unsanctioned contexts.
|
|
Analytic 0776
|
Abnormal modification of EFI firmware binaries in /System/Library/CoreServices/ or NVRAM parameters not associated with OS updates. Unified logs capturing calls to bless or nvram commands executed from untrusted parent processes. Sudden unsigned kext loads after EFI variable tampering.
|
|
Analytic 1991
|
Once adversaries leverage compromised network devices as infrastructure (ex: for command and control), it may be possible to look for unique characteristics associated with adversary software, if known.(Citation: ThreatConnect Infrastructure Dec 2020) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle.
|
|
Analytic 1410
|
Adversary mounts a USB device and begins enumerating, copying, or compressing files using scripting engines, cmd, or remote access tools.
|
|
Analytic 0526
|
Use of AWS STS or GCP IAM APIs to request temporary tokens or federation sessions inconsistent with normal account activity, including from unexpected principals or regions.
|
|
Analytic 1195
|
Unauthorized modification of service-related registry keys such as ImagePath, FailureCommand, ServiceDll, or Performance/Parameters keys. Defender correlates registry modifications, anomalous service metadata changes, and subsequent service process executions that deviate from baseline configurations.
|
|
Analytic 2008
|
Consider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently modified accounts making numerous connection requests to accounts affiliated with your organization.
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: [Phishing](https://attack.mitre.org/techniques/T1566)).
Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
|
|
Analytic 1966
|
If infrastructure or patterns in tooling have been previously identified, internet scanning may uncover when an adversary has staged tools to make them accessible for targeting.
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle, such as [Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105).
|
|
Analytic 1254
|
Anomalous use of ICMP or UDP by non-network service processes for data exfiltration or remote control, especially if traffic bypasses proxy infrastructure or shows unusual flow patterns.
|
|
Analytic 0520
|
Monitors sequences involving deletion/modification of logs, registry keys, scheduled tasks, or prefetch files following suspicious process activity or elevated access escalation.
|
|
Analytic 1208
|
Detects creation or modification of user-level Launch Agents in monitored directories using `.plist` files with suspicious `ProgramArguments` or `RunAtLoad` keys. Correlates file write activity with execution of `launchctl` or unsigned binaries invoked at login.
|
|
Analytic 1289
|
Detects thread local storage (TLS) callback injection by monitoring memory modifications to PE headers and TLS directory structures during or after process hollowing events, followed by anomalous thread behavior prior to main entry point execution.
|
|
Analytic 0577
|
DLL hijacking behaviors including unexpected DLL loads from non-standard directories, replacement of DLLs, phantom DLL insertion, redirection file creation, and substitution of legitimate DLLs. Defender correlates file system modifications, registry changes, and module load telemetry to detect abnormal DLL behavior in trusted processes.
|
|
Analytic 0572
|
Monitor for execution of hypervisor management commands such as `esxcli vm process list` or `vim-cmd vmsvc/getallvms` that enumerate virtual machines. Defenders observe unexpected users issuing VM listing commands outside normal administrative workflows.
|
|
Analytic 1142
|
Command-line initiated UDP traffic bursts to external reflection amplification ports using built-in scripting or binaries with network anomalies
|
|
Analytic 1636
|
Detects exploitation of IaaS cloud security boundaries to evade defense controls. Defender perspective includes anomalous API calls that bypass audit logging, disable monitoring, or manipulate guardrails (e.g., CloudTrail tampering). Correlation highlights when exploitation attempts precede sudden absence of expected telemetry.
|
|
Analytic 1490
|
Unusual long-running processes consuming high CPU cycles (e.g., via 'top' or 'ps') initiated via cron, shell scripts, or Docker. Connections to known mining pools or DNS over HTTPS usage as evasion.
|
|
Analytic 1237
|
Account creation using 'dscl -create' or via GUI tools. Detection involves command execution and file changes to the local directory services database.
|
|
Analytic 1415
|
Detects abnormal encrypted network connections (via TLS/HTTPS) initiated by non-browser binaries, particularly after sensitive file access or compression events.
|
|
Analytic 1344
|
Behavioral chain: (1) a login from a third-party account or untrusted source network establishes an interactive/remote session; (2) the session acquires elevated privileges or accesses sensitive resources atypical for that account; (3) subsequent lateral movement or data access occurs from the same session/device. Correlate Windows logon events, token elevation/privileged use, and resource access with third-party context.
|
|
Analytic 0985
|
Detects binaries or launch daemons in /System/Library or /Applications with mismatched bundle names, unexpected metadata, or improper installation origin.
|
|
Analytic 0191
|
Phishing via Office documents containing embedded macros or links that spawn processes. Detection relies on correlating Office application logs with suspicious child process execution and outbound network connections.
|
|
Analytic 0587
|
Instance enters degraded/unhealthy state due to abnormal process load or memory exhaustion, often caused by automation or script-based attacks.
|
|
Analytic 1256
|
Unsigned binaries or interpreted scripts initiating non-standard protocols (ICMP, UDP, SOCKS) outside of baseline network behavior.
|
|
Analytic 1325
|
Enumeration of services via native CLI tools (e.g., `sc query`, `tasklist /svc`, `net start`) or API calls via PowerShell and WMI.
|
|
Analytic 1626
|
Detects attempts to modify file timestamps via API usage (e.g., `SetFileTime`), CLI tools (e.g., `w32tm`, PowerShell), or double-timestomp behavior where $SI and $FN timestamps are mismatched or reverted.
|
|
Analytic 1349
|
Behavioral chain: (1) third-party app or admin connects via OAuth/marketplace install; (2) high-privilege scopes granted; (3) anomalous actions (mass read/exports, admin changes).
|
|
Analytic 0155
|
Detection of malicious certificate installation via monitoring execution of the `security add-trusted-cert` command and modifications to system keychains.
|
|
Analytic 0539
|
Use of `esxcli storage` or `vim-cmd vmsvc/getallvms` by unusual sessions or through interactive shells unrelated to administrative maintenance tasks.
|
|
Analytic 1355
|
Execution of system utilities like 'system_profiler' and 'ioreg' to enumerate hardware components or USB devices, particularly if followed by clipboard, file, or network activity.
|
|
Analytic 2041
|
Detects exploitation of cloud-native security boundaries or management components followed by disabled logging, detached agents, changed security groups, policy bypass, or telemetry suppression. Correlates suspicious API activity with reduced control coverage.
|
|
Analytic 0306
|
Monitor for unexpected modifications of plist files in persistence or configuration directories (e.g., ~/Library/LaunchAgents, ~/Library/Preferences, /Library/LaunchDaemons). Detect when modifications are followed by execution of new or unexpected binaries. Track use of utilities such as defaults, plutil, or text editors making changes to Info.plist files. Correlate file modifications with subsequent process launches or service starts that reference the altered plist.
|
|
Analytic 0553
|
Rule manipulation through local email clients (e.g., Evolution, Thunderbird) or server-side filtering scripts (e.g., sieve) creating conditions to move or discard emails with security-related keywords.
|
|
Analytic 1970
|
Once adversaries have provisioned a VPS (ex: for use as a command and control server), internet scans may reveal servers that adversaries have acquired. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
|
|
Analytic 0250
|
Behavioral chain involving suspicious use of GetProcAddress and LoadLibrary following memory allocation and manual mapping, often paired with low entropy strings, abnormal API use without static import tables, or delayed module load behaviors.
|
|
Analytic 0085
|
Adversary uses a tool like Ruler to insert a malicious custom form into the user's Outlook mailbox. The form is designed to auto-execute on Outlook startup or on receipt of a specially crafted email. This results in child processes launched from outlook.exe and possibly network connections or payload loading.
|
|
Analytic 1450
|
Remote knock sequence followed by PF/socketfilterfw rule update or a background process listening on a new port; then a successful TCP session. Also flags WoL magic packets on local segment.
|
|
Analytic 0965
|
Detection of clipboard access via OS utilities (e.g., clip.exe, Get-Clipboard) by non-interactive or abnormal parent processes, potentially chained with staging or exfiltration commands.
|
|
Analytic 1221
|
Detects the creation, modification, or deletion of scheduled tasks through Task Scheduler, WMI, PowerShell, or API-based methods followed by execution from svchost.exe or taskeng.exe. Includes detection of hidden or anomalous scheduled tasks, especially those created under SYSTEM or suspicious user contexts.
|
|
Analytic 1155
|
Unusual access to ~/Library/Keychains, ~/.bash_history, or Terminal command history by unauthorized processes or users.
|
|
Analytic 1583
|
Execution of network enumeration utilities (e.g., net.exe, ping.exe, tracert.exe) in short succession, often chained with lateral movement tools or system enumeration commands.
|
|
Analytic 1301
|
Detects upload of malicious or unusual file types into cloud-shared folders, followed by user downloads or interactions.
|
|
Analytic 1430
|
Detects launch of command-line interpreters via Terminal, Automator, or hidden `osascript`, especially when parent process lineage deviates from user-initiated applications.
|
|
Analytic 0038
|
Unauthorized shell or script-based access to browser config or SQLite history files, typically in ~/.config/google-chrome/, ~/.mozilla/, or ~/.var/app folders, indicating enumeration of bookmarks or saved credentials.
|
|
Analytic 1113
|
Detection of automated tools or scripts periodically transmitting data to external destinations using scheduled tasks or background processes.
|
|
Analytic 1267
|
Router/firewall/syslog logs showing authentication failures with unique usernames and reused credentials from same source IP
|
|
Analytic 0799
|
Cause→effect chain: (1) App crash/abnormal termination in unified logs for Safari/Chrome/Office/Preview, (2) new files/scripts in ~/Library, ~/Downloads, /private/var/folders/*, (3) unexpected child (osascript, zsh, bash, curl) spawned by those apps, (4) new outbound connections.
|
|
Analytic 0374
|
User-mode application uses flock() or NSDistributedLock to gain exclusive access to a resource file (e.g., /tmp/guard.lock), conditional logic alters execution if already locked.
|
|
Analytic 0444
|
Detects Kerberoasting attempts by monitoring for anomalous Kerberos TGS requests (Event ID 4769) with RC4 encryption (etype 0x17), accounts requesting an unusual number of service tickets in a short period, or service accounts targeted outside normal usage baselines. Also correlates suspicious process activity (e.g., Mimikatz invoking LSASS access) with Kerberos ticket anomalies.
|
|
Analytic 1152
|
Monitor VM-level DNS and network traffic logs for adversary-controlled domains or selective response behavior (e.g., dropped requests from security scanners).
|
|
Analytic 1569
|
Detects abnormal HID device enumeration via I/O Registry (ioreg -p IOUSB) and keystroke injection targeting AppleScript, osascript, or PowerShell equivalents. Defender correlates new USB device connections with rapid script execution.
|
|
Analytic 0280
|
Detects Lua script execution via native or 3rd party interpreters, chained with unsigned binaries or unexpected parent lineage.
|
|
Analytic 0440
|
Suspicious SaaS tenant activity involving webhook configurations pointing to external or untrusted domains. Defender perspective: repeated automated exports or suspicious webhook endpoint registrations.
|
|
Analytic 1949
|
Monitoring the content of network traffic can help detect patterns associated with active scanning activities. This can include identifying repeated connection attempts, unusual scanning behaviors, or probing activity targeting multiple IP addresses across a network.
Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.
|
|
Analytic 1979
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0597
|
Outbound connections from non-network-facing processes repeatedly send similarly sized payloads within uniform time intervals.
|
|
Analytic 0364
|
Domain account enumeration using ldapsearch, samba tools (e.g., 'wbinfo -u'), or winbindd lookups.
|
|
Analytic 1126
|
Creation or modification of `.plist` files in /Library/LaunchDaemons/, especially those with suspicious Program or ProgramArguments paths, combined with execution activity under launchd with elevated privileges. Detectable through correlated Unified Logs, file monitoring, and process telemetry.
|
|
Analytic 0747
|
Detects adversarial archiving using libraries (zlib, zip APIs) invoked by scripts or binaries. Correlates process executions of Python, PowerShell, or custom .NET binaries with DLL/module loads linked to compression libraries, followed by archive file creation.
|
|
Analytic 0691
|
CONTAINERS (Docker/K8s/containerd): A user pulls an untrusted image from a public/unknown registry and then creates/starts a container from that image. Shortly after start, the container spawns unexpected utilities (e.g., curl/wget/bash/python), or makes outbound network connections atypical for the namespace/workload. The analytic correlates Image Creation/Download → Container Creation → Container Start → Command Execution/Network activity within a short window and with a consistent image digest.
|
|
Analytic 0878
|
Detects creation of traffic mirroring sessions (e.g., AWS VPC Traffic Mirroring, Azure vTAP) that redirect traffic from critical assets to other virtual instances, often followed by file creation or session establishment.
|
|
Analytic 0694
|
Defenders observe command-line executions or API-based registry reads targeting sensitive paths like HKLM or HKCU with keyword filters such as 'password', 'cred', or 'logon'. Typically performed by Reg.exe, PowerShell, custom binaries, or offensive tools such as Cobalt Strike. Correlation with process ancestry and command-line arguments indicates suspicious credential discovery activity.
|
|
Analytic 0031
|
Outbound traffic with anomalous payload sizes and patterns from non-networking processes, often observed via packet inspection or connection logs.
|
|
Analytic 0702
|
Monitor for anomalies in transmitted data streams, including mismatched file integrity checks, API interception, or man-in-the-middle modifications. Detect unexpected use of APIs that handle network I/O where transmitted data integrity could be manipulated.
|
|
Analytic 0911
|
Execution of virtualization binaries (Parallels, VMware Fusion, VirtualBox) with arguments to hide UI. File monitoring for plist modifications indicating hidden virtualization behavior. Defender perspective: tracking process lineage and file modifications in system configs.
|
|
Analytic 0354
|
Use of command-line like `ip ssh pubkey-chain` to bind SSH keys to privileged accounts on routers or switches.
|
|
Analytic 0701
|
Detects the creation or modification of `.service` unit files in system/user-level directories, combined with execution of `systemctl`, `service`, or dynamically created drop-ins via systemd generators. Detects persistence by analyzing the `ExecStart` path, file entropy, and symlink usage, especially when paired with execution from `/tmp`, `/dev/shm`, or unmounted volumes.
|
|
Analytic 0193
|
Phishing delivered via SaaS services (chat, collaboration platforms) where messages contain malicious URLs or attachments. Detect anomalous link clicks, suspicious file uploads, or token misuse after SaaS-based phishing attempts.
|
|
Analytic 1014
|
Adversary tool/script issuing mass SYN/ACK floods that degrade OS responsiveness and interrupt service response on macOS endpoints.
|
|
Analytic 1986
|
Once adversaries have provisioned software on a compromised VPS (ex: for use as a command and control server), internet scans may reveal VPSs that adversaries have compromised. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021)
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
|
|
Analytic 1549
|
Adversary installs or abuses IDE extensions via CLI or direct write to profile directories and then communicates with marketplaces or remote tunnel services. Chain: auditd execve (code/idea/eclipse) with install/update flags or writes under ~/.vscode/extensions, ~/.config/JetBrains → outbound flows to *.visualstudio.com, marketplace.visualstudio.com, *.jetbrains.com, githubusercontent.com, or SSH/WebSocket tunnel endpoints → optional ssh/node processes spawned by IDE.
|
|
Analytic 0343
|
Detects mounted external devices (via /media or /mnt) followed by large file read or copy operations by shell scripts, unauthorized users, or staging tools (e.g., tar, rsync).
|
|
Analytic 0636
|
VM services or management daemons communicating on ports not defined by VMware defaults, such as vpxa or hostd processes initiating traffic over high-numbered or unexpected ports.
|
|
Analytic 1994
|
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
|
|
Analytic 1235
|
Adversary uses built-in tools like 'net user /add', PowerShell, or WMI to create a local user. Sequence: Account creation event (4720) follows process creation of a suspicious executable (e.g., powershell.exe or net.exe).
|
|
Analytic 1389
|
Detects the execution of non-browser processes establishing outbound encrypted network connections using uncommon symmetric encryption protocols (e.g., AES via PowerShell or custom scripts) to alternate external destinations.
|
|
Analytic 0787
|
Unexpected processes (e.g., powershell.exe, wscript.exe, office apps) initiating HTTP POST/PUT requests to text storage domains like pastebin.com or hastebin.com, particularly when preceded by file access in sensitive directories. Defender perspective: correlation of process lineage, large clipboard/file read operations, and outbound uploads to text storage services.
|
|
Analytic 0091
|
Suspicious use of attrib.exe or PowerShell commands to set hidden attributes on files/directories. Defender view: processes modifying file attributes to 'hidden' or creating files with ADS (alternate data streams).
|
|
Analytic 0953
|
Defenders can detect suspicious reversion of cloud compute instances by monitoring for unusual snapshot restores, rollback actions, or ephemeral storage resets that occur outside expected administrative workflows. From a defender’s perspective, relevant detection chains include: a snapshot restore triggered by a new or rarely used account, a sequence of snapshot creation immediately followed by a restore and instance start, or rollbacks performed from anomalous geographic or network locations. These patterns may indicate attempts to remove forensic evidence or re-establish a clean execution state for persistence.
|
|
Analytic 1330
|
Internal user account accesses shared links outside org followed by mass file download
|
|
Analytic 0749
|
Detects malicious archiving via system or third-party libraries (libz, libarchive) invoked by Python, Swift, or Objective-C binaries. Correlates unified logs of library loads with creation of compressed or encrypted archives (.zip, .gz, .bz2, .dmg).
|
|
Analytic 1956
|
If infrastructure or patterns in malware have been previously identified, internet scanning may uncover when an adversary has staged malware to make it accessible for targeting.
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle, such as [User Execution](https://attack.mitre.org/techniques/T1204) or [Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105) .
|
|
Analytic 0108
|
Executables written or modified in installer directories (e.g., %TEMP% subdirectories or Program Files installer paths) followed by execution under elevated context. Defender observes abnormal file replacement activity, process creation by installer processes pointing to attacker-supplied binaries, and unexpected module loads in elevated processes.
|
|
Analytic 1309
|
Correlates creation of email forwarding rules or header anomalies (e.g., X-MS-Exchange-Organization-AutoForwarded) with suspicious process execution, file access of .pst/.ost files, and network connections to external SMTP servers.
|
|
Analytic 1292
|
Detects DHCP spoofing by monitoring unified logs for unexpected DHCP ACK/OFFER parameters and correlating with packet captures for multiple DHCP servers. Behavioral emphasis is on inconsistent DNS and gateway assignments that redirect traffic.
|
|
Analytic 1321
|
Detects tampering of IIS-based login pages (e.g., default.aspx, login.aspx) tied to VPN, OWA, or SharePoint via script injection or unexpected editor processes modifying web roots.
|
|
Analytic 0973
|
Detects abuse of fileless storage mechanisms such as Registry keys, WMI classes, and Event Logs used to stage payloads, scripts, or encoded content outside traditional files.
|
|
Analytic 1071
|
Adversaries using bash scripts or tools to recursively enumerate user home directories, config files, or SSH keys.
|
|
Analytic 0457
|
Chain: (1) execution of `pwpolicy` or MDM/DirectoryService reads of account policies; (2) optional read of `/Library/Preferences/com.apple.loginwindow` or config profiles; (3) follow-on credential probing or lateral movement by same user/session. Use unified logs and process telemetry.
|
|
Analytic 0237
|
Detection of processes that load or decode encrypted/encoded files in memory and subsequently execute or inject them, indicating payload unpacking or memory-resident malware.
|
|
Analytic 0703
|
Detect alterations of transmitted data via monitoring syscalls (`send`, `recv`, `write`) or middleware interception. Identify mismatched file hashes when compared at origin vs. destination. Watch for anomalous activity from processes interacting with secure transmission services (e.g., OpenSSL, scp).
|
|
Analytic 0403
|
ESXi daemons (hostd, vpxa) unexpectedly using symmetric encryption routines for external connections. Defender identifies logs of service traffic with encrypted payloads inconsistent with VMware management baselines.
|
|
Analytic 1572
|
Processes such as curl, wget, rclone, or custom scripts executing uploads to cloud storage endpoints. Defender perspective: detect chained events where tar/gzip is executed to compress files followed by HTTPS PUT/POST requests to known storage services.
|
|
Analytic 0629
|
Unauthorized creation or modification of DLLs loaded by LSASS, abnormal registry values under LSA extensions, and anomalous DLL load activity into the lsass.exe process context—correlated during boot or logon events.
|
|
Analytic 0785
|
Detection focuses on identifying anomalous regsvr32.exe executions that deviate from normal administrative or system use. Defenders may observe regsvr32.exe loading scriptlets or DLLs from unusual paths (especially temporary directories or remote URLs), command-line arguments invoking /i or /u with suspicious file references, network connections initiated by regsvr32.exe, and unsigned or untrusted DLLs being loaded shortly after regsvr32.exe invocation. Correlated sequences include regsvr32.exe process creation, module load of DLL/scriptlet, and optional outbound network traffic.
|
|
Analytic 2002
|
Consider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently modified accounts making numerous connection requests to accounts affiliated with your organization.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: [Spearphishing via Service](https://attack.mitre.org/techniques/T1566/003)).
Monitor and analyze traffic patterns and packet inspection associated to protocol(s), leveraging SSL/TLS inspection for encrypted traffic, that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
|
|
Analytic 0324
|
Creation or modification of Windows services or scheduled tasks with names or descriptions mimicking legitimate entries, followed by anomalous execution of untrusted binaries or LOLBAS.
|
|
Analytic 1320
|
Detects unauthorized modifications to login-facing web server files (e.g., index.php, login.js) typically tied to VPN, SSO, or intranet portals. Correlates suspicious file changes with remote access artifacts or web shell behavior.
|
|
Analytic 0136
|
Detects firewall rule modifications or reset of logs/connection tables (e.g., `clear logging`, `erase startup-config`, `write erase`) following remote access activity on routers, switches, or VPN appliances.
|
|
Analytic 0054
|
A process loads a non-system .dylib/.so via dyld (dlopen/dlsym) from user-writable locations (~/Library, /tmp) or after the library was recently created/downloaded, often followed by network egress or persistence.
|
|
Analytic 1538
|
Correlate process execution of shutdown/reboot commands (e.g., shutdown.exe, restart-computer) with host status change logs (Event IDs 1074, 6006) and absence of related administrative context (e.g., user not in Helpdesk group).
|
|
Analytic 0056
|
Executable or binary files created without symbol tables or with stripped sections, especially by non-user shell processes or compilers invoked outside standard dev paths.
|
|
Analytic 1521
|
Series of authentication failures (Event ID 4625) targeting the same or similar user accounts over time from one or more remote IPs
|
|
Analytic 1578
|
Detects creation of new container system processes via `docker run --restart`, `kubectl exec` to init containers, or modification of container init specs. Flags container images that override entrypoints to embed persistence behaviors.
|
|
Analytic 1083
|
Detects BusyBox or Ash shell execution from unauthorized logins or remote connections. Focus is on rare shell invocations from DCUI, SSH sessions, or remote management paths. Also watches for payload droppers or persistence artifacts using shell.
|
|
Analytic 1411
|
Adversary mounts external drive to /media or /mnt then accesses or copies targeted data via shell, cp, or tar.
|
|
Analytic 0402
|
Launchd jobs or user processes invoking symmetric crypto APIs from the Security framework and generating outbound connections carrying randomized payloads inconsistent with normal TLS patterns.
|
|
Analytic 1523
|
Series of failed logins from loginwindow or sshd with repeated usernames or password prompts
|
|
Analytic 1431
|
Detects use of 'esxcli system' or direct interpreter commands (e.g., busybox shell) invoked from SSH or host terminal unexpectedly.
|
|
Analytic 1573
|
Applications or scripts invoking cloud storage APIs (Dropbox sync, iCloud, Google Drive client) in unexpected contexts. Defender perspective: detect sensitive file reads by non-standard applications followed by unusual encrypted uploads to external cloud storage domains.
|
|
Analytic 0828
|
Execution of utilities (dd, hdparm, sgdisk) or custom binaries attempting to overwrite disk boot structures (/dev/sda MBR sector or partition tables). Detection correlates shell execution with syscalls writing to sector 0 or disk metadata blocks.
|
|
Analytic 0902
|
Adversaries leverage M365 or Google Workspace APIs to create users, service accounts, or guest accounts. Follow-on behaviors include login activity, role escalation, or service principal token generation.
|
|
Analytic 1548
|
Adversary installs or side-loads an IDE extension (VS Code, IntelliJ/JetBrains, Eclipse) or enables IDE tunneling. Chain: (1) IDE binary starts on a non-developer endpoint or server, often with install/force/tunnel flags → (2) extension files/registrations appear under user profile → (3) browser/IDE initiates outbound connections to extension marketplaces, update endpoints, or IDE remote/tunnel services → (4) optional child tools (ssh, node, powershell) execute under the IDE context.
|
|
Analytic 0639
|
Initial process using NSURLSession or similar APIs reaches out to known staging domains, followed by creation of a reverse shell or RAT connecting to a second unrelated server.
|
|
Analytic 1034
|
Correlates Group Policy updates that configure network logon scripts with subsequent remote file execution behaviors triggered by user logons to identify potential persistence or execution chains tied to adversarial manipulation of logon scripts.
|
|
Analytic 1401
|
Detects memory-based injection by monitoring `task_for_pid`, `mach_vm_write`, and dylib injection patterns through `DYLD_INSERT_LIBRARIES` or manual memory mapping.
|
|
Analytic 0680
|
Unusual or excessive database/table exports from SaaS database platforms (e.g., Snowflake, Firebase, BigQuery, Airtable) by users or apps not in known analytics or dev groups. Defender observes access patterns outside baseline working hours or with new query templates, and correlates those with audit logs or file downloads.
|
|
Analytic 0697
|
Monitors API calls and service-specific logs for enumeration of organizational roles, permissions, and group structure, particularly outside of normal admin behavior baselines.
|
|
Analytic 2037
|
Detects users executing commands copied from chats, tickets, or emails, including curl|bash patterns, shell script launches from temp directories, credential changes, or SSH key additions shortly after communication events.
|
|
Analytic 1452
|
Detection of processes executing system environment inspection operations followed by access to OS configuration APIs or registry locations that expose OS version, architecture, patch level, or hardware characteristics. Defenders observe process execution retrieving system configuration metadata immediately after process startup.
|
|
Analytic 0996
|
Monitors execution of older or legacy interpreters (e.g., python2, bash with restricted history logging), downgrade of TLS/SSL configurations, or forced fallback to unencrypted protocols. Detects suspicious reconfiguration of kernel modules or boot loaders to reduce integrity controls.
|
|
Analytic 1000
|
Detects unauthorized Kerberos ticket injection by correlating service ticket (TGS - 4769) requests with absent corresponding account logons (4624) and prior Ticket Granting Ticket (TGT - 4768) activity. Highlights anomalous service ticket generation chains involving unexpected users, hosts, or times, and suspicious injection of tickets via mimikatz-like tooling into LSASS memory. Behavior also includes network lateral movement using Kerberos authentication absent expected interactive logon patterns.
|
|
Analytic 0783
|
Detects sequential command-line compression utilities (e.g., gzip, tar, zip, 7z) followed by execution of unpacked files, especially in temp directories or under non-standard locations like /dev/shm or /tmp with ELF binaries.
|
|
Analytic 1529
|
Detects abnormal creation of binary files with significant size that are subsequently executed or accessed by non-standard users.
|
|
Analytic 1466
|
Userland processes invoking syscall-heavy libraries (libc, glibc) followed by fork, mmap, or ptrace behavior commonly associated with code injection or memory manipulation.
|
|
Analytic 0272
|
Scripted or binary usage of X11 utilities (e.g., xdotool, wmctrl) or direct /proc/*/window mappings to discover open GUI windows and active desktops.
|
|
Analytic 0630
|
Detects behavior where files with non-executable or misleading extensions (e.g., .jpg, .txt) are created or modified but subsequently executed as binaries based on internal file headers or abnormal parent process lineage. This includes identifying polyglot files or malformed magic bytes indicative of masquerading attempts.
|
|
Analytic 0127
|
Execution of discovery commands or API calls for virtualization artifacts (e.g., registry keys, device drivers, services), sleep/skipped execution behavior, or sandbox evasion DLLs before payload deployment.
|
|
Analytic 0936
|
Execution of `erase`, `format`, and `reload` in immediate sequence from a privileged AAA session
|
|
Analytic 1510
|
Use of ESXi web interface plugins or vSphere extensions to embed persistent malicious scripts or services.
|
|
Analytic 0158
|
Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).
|
|
Analytic 0253
|
Manual or script-based installation of extension-like modules into browser config directories or IDE plugin paths, followed by suspicious network activity
|
|
Analytic 0724
|
Detects file reads across locations followed by writes to temp or staging directories, often compressed or encrypted, indicating local staging behavior.
|
|
Analytic 1322
|
Detects unauthorized changes to locally hosted login pages on macOS (common in developer VPN environments) and links file edits to cron jobs, background scripts, or SUID binaries.
|
|
Analytic 0167
|
Process execution of curl or wget followed by a network connection and a file created in temporary or user-specific directories.
|
|
Analytic 2000
|
Monitor for suspicious network traffic that could be indicative of scanning, such as large quantities originating from a single source (especially if the source is known to be associated with an adversary/botnet).
|
|
Analytic 1982
|
Consider use of services that may aid in the tracking of newly issued certificates and/or certificates in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of certificate information to uncover other adversary infrastructure.(Citation: Splunk Kovar Certificates 2017) Some server-side components of adversary tools may have default values set for SSL/TLS certificates.(Citation: Recorded Future Beacon Certificates) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.
Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.
Monitor for logged network traffic in response to a scan showing both protocol header and body values that may buy and/or steal capabilities that can be used during targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.
Consider analyzing malware for features that may be associated with malware providers, such as compiler used, debugging artifacts, code similarities, or even group identifiers associated with specific Malware-as-a-Service (MaaS) offerings. Malware repositories can also be used to identify additional samples associated with the developers and the adversary utilizing their services. Identifying overlaps in malware use by different adversaries may indicate malware was obtained by the adversary rather than developed by them. In some cases, identifying overlapping characteristics in malware used by different adversaries may point to a shared quartermaster.(Citation: FireEyeSupplyChain) Malware repositories can also be used to identify features of tool use associated with an adversary, such as watermarks in [Cobalt Strike](https://attack.mitre.org/software/S0154) payloads.(Citation: Analyzing CS Dec 2020)
|
|
Analytic 0508
|
Detection of group enumeration using commands like 'id', 'groups', or 'getent group', often followed by privilege escalation or SSH lateral movement.
|
|
Analytic 1383
|
Detects non-standard compilation activity via Xcode CLI tools or bundled GCC/MONO packages writing new executable files and executing them outside dev environments (e.g., user Downloads folder).
|
|
Analytic 1199
|
Detects access to known password store files (e.g., /etc/shadow, GNOME Keyring, KWallet, browser credential databases). Monitors anomalous process read attempts and suspicious API calls that attempt to extract stored credentials.
|
|
Analytic 1491
|
Persistent or background daemons (e.g., plist or launchd jobs) spawning high-CPU processes like xmrig or cpuminer. Outbound encrypted traffic to IPs/domains commonly used by mining proxies.
|
|
Analytic 0829
|
Abnormal invocation of diskutil or asr that modifies partition tables or initializes raw devices. Monitor for IOKit system calls targeting disk headers or EFI boot sectors, correlated with elevated privileges.
|
|
Analytic 1560
|
Processes executing binaries named after legitimate system utilities (e.g., net.exe, findstr.exe, python.exe) from non-standard or application-specific directories, combined with file creation or modification events for such binaries. Defender correlates file writes in vulnerable directories, process execution paths inconsistent with baseline system paths, and abnormal parent-child relationships in process lineage.
|
|
Analytic 1519
|
CLI-based export of private key material (e.g., 'crypto pki export') with anomalous user session or AAA role escalation.
|
|
Analytic 0606
|
Encryption of cloud storage objects (e.g., S3 buckets) via Server-Side Encryption (SSE-C) or by replacing objects with encrypted variants. May include API patterns like PutObject with SSE-C headers.
|
|
Analytic 1953
|
Monitor social media traffic for suspicious activity, including messages requesting information as well as abnormal file or data transfers (especially those involving unknown, or otherwise suspicious accounts).
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.
Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
|
|
Analytic 0113
|
Detects adversary activity that removes persistence artifacts such as services, registry keys, scheduled tasks, user accounts, and binaries through commands like `sc delete`, `schtasks /delete`, or `reg delete`.
|
|
Analytic 0790
|
ESXi services (vmx, hostd) generating outbound HTTPS POST requests to text storage sites. Defender perspective: anomalous datastore or log reads chained with traffic to pastebin-like destinations.
|
|
Analytic 0865
|
Detects unauthorized additions of users or machine accounts to privileged local or domain groups (e.g., Administrators, Remote Desktop Users).
|
|
Analytic 0647
|
Defenders may observe adversary attempts to collect or export full device configurations by detecting unusual SNMP queries, Smart Install (SMI) activity, or CLI/API commands that request running or startup configuration dumps. Correlated behaviors include high-volume read requests for sensitive OIDs, repeated use of 'show running-config' or equivalent commands from untrusted IPs, or unexpected TFTP/SCP/FTP transfers containing configuration files. These behaviors often appear in sequence: anomalous authentication or privilege escalation, followed by bulk configuration retrieval and outbound transfer.
|
|
Analytic 1210
|
Detection centers on DYLD_INSERT_LIBRARIES and DYLD_LIBRARY_PATH abuse. Defender perspective: monitor for modification of these environment variables in shell or plist files, file creation of dylibs in user-controlled paths, and correlation of environment variable usage with unexpected module loads by user applications. Suspicious indicators include processes with DYLD_INSERT_LIBRARIES set, execution of applications loading untrusted dylibs, and anomalies in module load history.
|
|
Analytic 0174
|
Detects Python execution from non-standard user contexts or cron jobs that invoke outbound traffic, access sensitive files, or perform process injection (e.g., ptrace or /proc memory maps).
|
|
Analytic 0102
|
Scripting engines (e.g., osascript, Python) initiating HTTPS requests to social media or content-sharing platforms, paired with automated response handling indicative of two-way communication.
|
|
Analytic 0096
|
Detects execution of common process enumeration utilities (e.g., ps, top, htop) or access to /proc with suspicious ancestry. Correlates command usage with interactive shell context and user role.
|
|
Analytic 1117
|
Startup-based persistence mechanisms within Microsoft Office Suite like template macros and home page redirects being configured through internal automation or client-side settings.
|
|
Analytic 0275
|
Unexpected write operations to BIOS/UEFI firmware regions or EFI boot partitions that do not correlate with legitimate vendor firmware updates. API calls or utilities such as fwupdate.exe or vendor flash tools executed from non-administrative or non-IT management accounts. Suspicious raw disk writes targeting System Firmware GUID partitions followed by abnormal reboot sequences.
|
|
Analytic 1161
|
Command-line tools (e.g., curl, rsync, wget, or custom Python scripts) used to scrape documentation systems or internal REST APIs. Unusual access patterns to knowledge base folders or shared team drives.
|
|
Analytic 0214
|
AppleScript or system calls to activate WiFi/Bluetooth interfaces (`networksetup`, `blueutil`), followed by exfiltration via AirDrop, cloud sync, or network socket.
|
|
Analytic 1189
|
Detects unusual outbound connections to web services from uncommon processes using SSL/TLS, particularly those exhibiting high outbound data volume or persistence.
|
|
Analytic 0648
|
Processes accessing LSASS memory or SAM registry hives outside of trusted security tools, often followed by file creation or lateral movement. Detects unauthorized access to sensitive OS subsystems for credential extraction.
|
|
Analytic 1181
|
Use ESXi syslogs to track abnormal DNS query patterns from management agents or VMs. Identify high-frequency, low-TTL, or unresolvable domains as suspicious. Correlate with unusual management plane process activity.
|
|
Analytic 0515
|
Use of native/mac tools (sharing -l, smbutil view, mount_smbfs) or scripts to enumerate SMB shares across many hosts, followed by outbound SMB connections observed in PF/Zeek logs.
|
|
Analytic 0480
|
Bash, Swift, or Objective-C programs enumerate system profile, I/O registry, or inspect kernel extensions to identify VM artifacts
|
|
Analytic 0325
|
Creation or modification of `systemd` service units or cron jobs using deceptive naming and untrusted command paths, often followed by lateral network activity or privilege escalation.
|
|
Analytic 0619
|
Unusual or unauthorized processes accessing microphone APIs (e.g., winmm.dll, avrt.dll) followed by audio file writes to user-accessible or temp directories.
|
|
Analytic 1484
|
sshd, socat, or custom binaries initiating port forwarding or encapsulating traffic (e.g., RDP, SMB) through SSH or HTTP. Defender sees abnormal connect/bind syscalls, encrypted traffic on ports typically used for non-encrypted services, and outlier traffic volume patterns.
|
|
Analytic 0475
|
Direct write access to /dev/mem or /sys/firmware combined with usage of firmware flashing utilities (e.g., flashrom).
|
|
Analytic 0122
|
Detection of queries to instance metadata services (e.g., AWS IMDS, Azure Metadata Service) for availability zone, region, or network geolocation details. Correlation with non-management accounts or non-standard workloads may indicate adversary reconnaissance.
|
|
Analytic 1222
|
Detection of anomalous registry modifications to Subject Interface Packages (SIPs) or trust provider DLL mappings, unexpected loading of non-Microsoft cryptographic modules, or attempts to redirect WinVerifyTrust validation logic. Defender view focuses on registry tampering, suspicious DLL loads into trusted processes, and abnormal trust validation failures correlated across event streams.
|
|
Analytic 0213
|
Use of `rfkill`, `nmcli`, or low-level tools (e.g., `iw`, `hcitool`, `pppd`) to enable alternate interfaces followed by data transfer via non-primary NICs.
|
|
Analytic 0187
|
Chain: (1) unified logs report IOUSBHost/IOThunderbolt device arrival; (2) diskarbitrationd attaches a new volume; (3) optional: config profile manipulation or new network interface MAC obtains a lease. Correlate unifiedlogs (subsystems: IOUSBHost, IOKit, diskarbitrationd), FSEvents, and DHCP/Zeek.
|
|
Analytic 1182
|
Process execution that probes user activity artifacts (e.g., desktop files, registry history) following recent user login/unlock events.
|
|
Analytic 0443
|
Automated and repetitive triggering of SMS messages through OTP/account verification fields on SaaS platforms, leveraging background messaging APIs such as Twilio, AWS SNS, or Amazon Cognito to generate traffic toward attacker-controlled numbers.
|
|
Analytic 0820
|
User opens a downloaded document/installer leading to EndpointSecurity file create in ~/Downloads or ~/Library paths then an exec of a suspicious utility (osascript, bash/zsh, curl, chmod, open with -a Terminal). Correlates File Creation with subsequent process exec and, optionally, quarantine/LSQuarantine events.
|
|
Analytic 1942
|
Monitor for suspicious network traffic that could be indicative of adversary reconnaissance, such as rapid successions of requests indicative of web crawling and/or large quantities of requests originating from a single source (especially if the source is known to be associated with an adversary). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields.
|
|
Analytic 0268
|
Modifications to SSO/SAML user attributes (e.g., `isAdmin`, `role`, MFA bypass, App assignments) often through CLI, API, or rogue IdP apps.
|
|
Analytic 0419
|
Forged SAML tokens in IaaS environments often manifest as cross-cloud or cross-account authentication without matching STS events. Defenders may see AssumeRole or GetFederationToken API usage without a corresponding SAML assertion log from the trusted IdP.
|
|
Analytic 0793
|
Monitor mail server logs (Postfix, Sendmail, Exim) for anomalous From headers mismatching authenticated SMTP identities. Detect abnormal relay attempts, spoofed envelope-from values, or large-scale outbound campaigns targeting internal users.
|
|
Analytic 1588
|
Detection focuses on monitoring registry modifications under HKLM\SOFTWARE\Microsoft\Netsh that indicate the addition of helper DLLs, followed by anomalous child process activity or module load behavior initiated by netsh.exe. These behaviors are rarely legitimate and may represent an adversary establishing persistence.
|
|
Analytic 0502
|
Adversary uses a tool like Ruler to configure a malicious Outlook folder Home Page that loads a remote or embedded HTML payload upon folder interaction. Execution chain begins with Outlook launching, a specific folder being accessed, and a suspicious child process being spawned or COM-based execution invoked.
|
|
Analytic 1602
|
ESXi shell or scheduled tasks initiating outbound HTTPS to known public services without inbound return or loggable response, used to fetch instructions.
|
|
Analytic 0254
|
Adversary launches built-in system tools (e.g., whoami, query user, net user) or scripts that enumerate user account information via local execution or remote API queries (e.g., WMI, PowerShell).
|
|
Analytic 0420
|
Forged SAML tokens may be used on Windows systems to authenticate to federated apps without normal Kerberos activity. Defenders may detect anomalous event correlation, where access to SaaS/O365 via SAML occurs without prior TGT requests or user logons.
|
|
Analytic 1372
|
Correlates control-plane API actions disabling cloud-native monitoring or sensor agents (CloudTrail, GuardDuty, Security Hub, Defender, monitoring agents), role abuse preceding disablement, or instance agent uninstall events
|
|
Analytic 0690
|
Detects creation of cloud instances, services, or resources in normally unused or unsupported regions, especially following initial account access or credential use from known regions. Correlates resource provisioning across regions with absence of historical usage and alerting from standard logging services (e.g., GuardDuty not enabled in that region).
|
|
Analytic 0286
|
Detects network share disconnection attempts using command-line tools like `net use /delete`, PowerShell `Remove-SmbMapping`, and correlation with process lineage and SMB session teardown activity.
|
|
Analytic 1615
|
Detection of enumeration of identity entities through cloud provider APIs where principals retrieve account metadata such as IAM users or roles in rapid succession.
|
|
Analytic 1060
|
Detects lateral discovery or container breakout attempts using netcat, curl, or custom binaries probing other services within the same namespace or VPC subnet.
|
|
Analytic 0384
|
Unusual direct disk access attempts (e.g., use of \\.\PhysicalDrive notation), abnormal writes to MBR/boot sectors, and installation of kernel drivers that grant raw disk access. Correlate anomalous process creation with disk modification attempts and driver loads.
|
|
Analytic 1467
|
Execution of processes that link to CoreServices or Foundation APIs followed by creation of memory regions, code execution, or abnormal library injection.
|
|
Analytic 0413
|
Destruction via `rm -rf`, overwrite with `dd` or `srm`, often executed by script in /tmp or /private/tmp, may also involve file overwrite to political or decoy image data.
|
|
Analytic 1406
|
Detects use of session cookies or authentication tokens from unusual user agents or locations. Identifies token reuse without reauthentication or attempts to bypass MFA using previously stolen cookies.
|
|
Analytic 0111
|
Inspect unified logs for anomalous DNS resolutions triggered by non-network applications. Flag repeated connections to newly registered or algorithmically generated domains. Correlate with endpoint process telemetry.
|
|
Analytic 0151
|
Outlook or Word used to forward suspicious internal attachments with macro content. Defender observes attachment forwarding, auto-opening behaviors, or macro prompt interactions.
|
|
Analytic 1534
|
Detection focuses on identifying unauthorized file creation or modification within `/etc/emond.d/rules/` or `/private/var/db/emondClients`, which indicate attempts to register a malicious emond rule. Correlate with process execution of `/sbin/emond` and any launched commands it invokes, especially during boot or login events. Anomalies may include rules created by non-root users or unexpected shell commands executed by emond.
|
|
Analytic 1379
|
Outbound traffic from host management services or guest-to-host interactions over unusual interfaces (e.g., backdoor API endpoints or external VPN tunnels).
|
|
Analytic 0993
|
Detect curl/wget commands saving executable/script payloads to /tmp or /var/tmp followed by execution. Monitor packet captures or IDS/IPS alerts for injected responses or mismatched content types.
|
|
Analytic 0188
|
Unusual inbound email activity where attachments or embedded URLs are delivered to users followed by execution of new processes or suspicious document behavior. Detection involves correlating email metadata, file creation, and network activity after a phishing message is received.
|
|
Analytic 1092
|
Detects suspicious gratuitous ARP responses or inconsistent IP-to-MAC mappings using auditd and packet capture. Behavioral focus is on unsolicited replies overriding legitimate ARP ownership.
|
|
Analytic 0347
|
Processes use base64/xxd/openssl/python Objective‑C APIs to encode data (seen in EndpointSecurity exec events or Unified Logs) → quick outbound connections with large bytes_out or HTTP POSTs carrying Base64/MIME bodies.
|
|
Analytic 1336
|
A high volume of authentication failures using a single password (or small set) across many different user accounts within a defined time window
|
|
Analytic 0981
|
Invocation of built-in commands like screencapture or use of undocumented APIs from suspicious parent processes.
|
|
Analytic 1506
|
Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles.
|
|
Analytic 0586
|
Adversary launches high-entropy process or malformed app bundle causing repeated application crashes and system slowdowns.
|
|
Analytic 1078
|
Detects creation or renaming of accounts with names that closely match known service, root, or admin accounts. Behavior often follows account discovery or deletion, attempting to blend into system activity logs using trusted name conventions.
|
|
Analytic 0874
|
Detection of HTML-based downloads via Safari/Chrome that create obfuscated files (e.g., .zip, .app, .js) in user directories and are followed by suspicious executions from preview or launch services.
|
|
Analytic 0510
|
Detection correlates file creation or modification of `.lnk` (shortcut) files in autostart locations with anomalous parent-child process lineage or unsigned binaries. Defenders should watch for LNK creation/modification events outside of known software installations, patch events, or OS updates. Flag shortcut targets pointing to suspicious locations or unknown binaries, particularly those written by script interpreters or spawned from phishing delivery chains.
|
|
Analytic 0077
|
Detects applications such as Automator, AppleScript, or LaunchDaemons invoking HTTP/S traffic to non-standard domains or using suspicious headers (e.g., Base64 in URIs or cookie fields).
|
|
Analytic 0234
|
Defenders can detect suspicious cloud instance deletions by correlating events across authentication, instance lifecycle, and account activity. From a defender’s perspective, behaviors of interest include instances deleted shortly after creation, deletions initiated by new or rarely used accounts, deletions following snapshot creation, and deletions originating from anomalous geolocations or access keys. These may indicate adversarial attempts to destroy forensic evidence or evade detection.
|
|
Analytic 1001
|
Registry modifications to HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList setting user visibility to 0, or creation of user accounts not shown on login screen. Defender view: correlation of account creation with registry edits that mark users hidden.
|
|
Analytic 1581
|
Detects user activity that shares or syncs files with external domains via link generation, OneDrive external sharing, or file transfer actions involving non-whitelisted partner tenants.
|
|
Analytic 0578
|
Detects interactive or scripted abuse of cmd.exe, batch files, or shell invocation chains. Focuses on parent-child relationships (e.g., cmd.exe launched from unusual parents), anomalous command-line parameters, and chaining with discovery, credential access, or lateral movement behaviors.
|
|
Analytic 0427
|
Detects use of unencrypted protocols (e.g., TFTP, FTP, HTTP) to transfer configuration files, routing tables, or logs to untrusted IP addresses, especially using administrative commands like `copy run ftp:`.
|
|
Analytic 0983
|
Detects processes or binaries executed from trusted directories (e.g., System32) or using trusted names (e.g., svchost.exe) where the metadata, hash, or parent process does not align with legitimate activity patterns.
|
|
Analytic 1400
|
Detects ptrace- or memfd-based process injection through audit logs capturing system calls (e.g., ptrace, mmap) targeting running processes along with suspicious file descriptors or memory writes.
|
|
Analytic 1240
|
Account created via CLI using 'username' command or REST API. Detectable through AAA logging or CLI history telemetry.
|
|
Analytic 0503
|
Malicious HTML or script is rendered as a Home Page for a specific Outlook folder. Outlook accesses that folder, loads remote content, and executes embedded JavaScript or ActiveX/COM logic resulting in unauthorized actions or local execution.
|
|
Analytic 1520
|
Anomalous high-volume access to customer records in CRM software by a non-CRM admin user account, especially following initial authentication from a rare location or device. Behavior includes abnormal access to PII fields or data exports within a short time window.
|
|
Analytic 0267
|
Modifications to user accounts via `dscl`, `pwpolicy`, or System Preferences CLI (`sysadminctl`) that alter user groups, enable root, or bypass MDM restrictions.
|
|
Analytic 0580
|
Detects suspicious registry modifications under `HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\*\Driver`, DLL loads by `spoolsv.exe` of non-standard or unsigned modules, and abnormal usage of the `AddMonitor` API by non-installation processes. This pattern often indicates an attempt to persist a malicious DLL via the print monitor mechanism, particularly when correlated with creation of files in `C:\Windows\System32` not tied to known patches or installations.
|
|
Analytic 2065
|
Detection identifies execution of scripts or applications containing invisible Unicode payloads reconstructed at runtime, correlated with abnormal AppleScript, JavaScript for Automation, or shell execution and subsequent process or network behavior inconsistent with visible file content.
|
|
Analytic 1609
|
Unexpected creation or modification of files with `com.apple.ResourceFork` extended attributes containing unusually large or non-standard data. Defender perspective: detection of resource forks in contexts where they are uncommon, especially when paired with process execution or network activity.
|
|
Analytic 0185
|
Chain: (1) a new external device is recognized by Windows (USB/Thunderbolt/PCIe) or a new block device appears; (2) within a short window, the same user/session spawns processes or the OS mounts a new volume; (3) optional follow-on activity such as HID keystroke injection, DMA driver load, or new network interface MAC on DHCP. Correlate Security EID 6416 / Kernel-PnP with sysmon and DHCP/network metadata.
|
|
Analytic 1172
|
Detects file movement or outbound TFTP/FTP transfers from ESXi host initiated via shell commands or injected scripts, particularly from scratch partitions or /tmp.
|
|
Analytic 0139
|
Creation or modification of files in directories known to be excluded from AV scanning (e.g., C:\Windows\Temp, Exchange server directories, or default AV exclusions). Defender perspective: correlate file creation with execution behavior or anomalous parent processes writing to excluded paths.
|
|
Analytic 0673
|
Monitor for security commands and API calls interacting with the Keychain, as well as file access attempts to stored certificates and private keys in ~/Library/Keychains or /Library/Keychains.
|
|
Analytic 0095
|
Identifies adversary behavior that launches commands or invokes APIs to enumerate active processes (e.g., tasklist.exe, Get-Process, or CreateToolhelp32Snapshot). Detects execution combined with parent process lineage, network session context, or remote origin.
|
|
Analytic 0784
|
Identifies archive utilities (e.g., ditto, unzip, xar, pkgutil) used to extract payloads to non-standard paths, then correlates with execution or file permission changes (e.g., `chmod +x`) and process spawns from decompressed location.
|
|
Analytic 1062
|
Abnormal loading of kernel modules, direct tampering with /dev, /proc, or LD_PRELOAD behaviors hiding processes or files.
|
|
Analytic 0166
|
Shell-based tools (curl, wget, scp) initiate connections to external domains followed by creation of executable files on disk.
|
|
Analytic 1019
|
Detection of excessive or programmatic access to Confluence spaces or pages, particularly by privileged users, through a combination of access logs, API usage, and identity context. Correlates logon sessions, user roles, and abnormal document viewing or export behavior. Identifies burst access patterns and tools/scripts abusing the Confluence API for mass enumeration or data scraping.
|
|
Analytic 0309
|
Detection correlates message events in email and collaboration tools (e.g., Outlook, Teams) that contain regex-like patterns resembling credentials, API keys, or tokens. Anomalous forwarding or bulk copy activity of chat/email content containing secrets is flagged. Suspicious behavior includes users pasting secrets into direct messages or attaching config files with passwords.
|
|
Analytic 1627
|
Detects use of timestamp-altering commands like `touch -a -m -t` or `touch -r`, particularly when executed by unusual users or in suspicious directories.
|
|
Analytic 1004
|
Unusual or unauthorized external remote access attempts (e.g., RDP, VPN, Citrix) → repeated failed logins followed by a successful session from uncommon geolocations or outside business hours → subsequent internal lateral movement or data exfiltration activities.
|
|
Analytic 0905
|
Detects shell-based enumeration of active connections using `netstat`, `lsof -i`, or AppleScript-based system discovery.
|
|
Analytic 0026
|
Correlates launchd plist modifications with subsequent unauthorized script execution or anomalous parent-child process trees involving user agents.
|
|
Analytic 0978
|
Monitor for unexpected privilege elevation operations via SAML assertion manipulation, role injection, or changes to identity mappings that result in access escalation.
|
|
Analytic 0246
|
Keylogging on legacy network devices via unauthorized system image modification or remote capture of console keystrokes (telnet, SSH) through altered firmware or man-in-the-middle key sniffing.
|
|
Analytic 0780
|
Monitor launchd service definitions and property list (.plist) modifications for non-standard executables. Detect unauthorized processes registered as launch daemons or agents.
|
|
Analytic 1180
|
Monitor unified DNS logs for abnormal domain queries with low lexical similarity to known domains, repeated failed lookups, and random string structures. Cross-check with process logs to confirm unusual origins (non-browser apps).
|
|
Analytic 0668
|
Detects disabling or reconfiguration of syslog or rsyslog services. Monitors sudden stops in logging daemons and suspicious execution of kill or service stop commands targeting syslog processes.
|
|
Analytic 0931
|
Remote Desktop (RDP) logon by a user followed by unusual process execution, file access, or lateral movement activity within a short timeframe.
|
|
Analytic 1472
|
Detects behavioral sequence where an adversary gains elevated privileges and clears event logs using native binaries (e.g., wevtutil), PowerShell, or direct file deletion of .evtx files.
|
|
Analytic 1483
|
Processes such as plink.exe, ssh.exe, or netsh.exe establishing outbound network connections where traffic patterns show encapsulated protocols (e.g., RDP over SSH). Defender observations include anomalous process-to-network relationships, large asymmetric data flows, and port usage mismatches.
|
|
Analytic 0162
|
Correlate unauthorized or anomalous file modifications, deletions, or metadata changes with suspicious process execution or API calls. Detect abnormal changes to structured data (e.g., database files, logs, financial records) outside expected business process activity.
|
|
Analytic 1981
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0779
|
Detect unusual invocations of systemctl, service, or init scripts creating or modifying daemons. Monitor audit logs for execution of binaries from unexpected paths linked to service start/stop activity.
|
|
Analytic 0756
|
Adversary modifies tenant policy through changes to federation configuration, trust settings, or identity provider additions in Microsoft 365/AzureAD via Portal, PowerShell, or Graph API. Includes setting authentication to federated or updating federated domains.
|
|
Analytic 1553
|
macOS environmental validation behavioral chain: (1) System profiling through system_profiler, sysctl, and hardware discovery commands, (2) Network interface and configuration enumeration for geolocation and network environment validation, (3) Application installation and version discovery for software environment fingerprinting, (4) Security feature detection (SIP, Gatekeeper, XProtect status), (5) Conditional payload execution based on macOS-specific environmental criteria and System Integrity Protection bypass validation
|
|
Analytic 1508
|
Abuse of extensible server modules (e.g., Apache, Nginx, Tomcat) to load rogue plugins that initiate bash, connect to C2, or spawn reverse shells.
|
|
Analytic 1316
|
Cause→effect chain: (1) unified logs show application open/click or crash for Safari/Chrome/Office/Preview/archiver, (2) file write/extraction into ~/Downloads, /private/var/folders/* or ~/Library, (3) parent app spawns osascript/bash/zsh/curl/python or opens a quarantined app with Gatekeeper prompts, (4) network egress from child.
|
|
Analytic 1955
|
Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
Depending on the specific method of phishing, the detections can vary. Monitor for suspicious email activity, such as numerous accounts receiving messages from a single unusual/unknown sender. Filtering based on DKIM+SPF or header analysis can help detect when the email sender is spoofed.(Citation: Microsoft Anti Spoofing)(Citation: ACSC Email Spoofing)
When it comes to following links, monitor for references to uncategorized or known-bad sites. URL inspection within email (including expanding shortened links) can also help detect links leading to known malicious sites.
Monitor social media traffic for suspicious activity, including messages requesting information as well as abnormal file or data transfers (especially those involving unknown, or otherwise suspicious accounts).
Monitor call logs from corporate devices to identify patterns of potential voice phishing, such as calls to/from known malicious phone numbers.
Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.
|
|
Analytic 1462
|
Execution of files with reversed filename extensions using Unicode RTLO character. Frequently used to deceive Gatekeeper and users in Safari or Mail-based phishing.
|
|
Analytic 0778
|
Monitor for abnormal creation or modification of Windows services (e.g., via sc.exe, PowerShell, or API calls) that load non-standard executables. Correlate registry changes in service keys with service creation events and process execution to detect service abuse for persistence or execution.
|
|
Analytic 0210
|
Detects embedded or emulated VBScript/VBA execution via Wine-based apps, Office for Mac abusing cross-platform .NET features, or macros dropped and invoked via AppleScript or third-party automation tools.
|
|
Analytic 0899
|
Adversaries create user accounts via identity provider APIs or admin portals (e.g., Azure AD, Okta). These accounts may be assigned elevated privileges or used in chained authentication. Detection monitors Add User activity from suspicious IPs or automation sources, followed by role/permission escalation.
|
|
Analytic 0319
|
Detects use of dscl or id/group commands to enumerate local system groups, often by post-exploitation tools or persistence checks.
|
|
Analytic 0541
|
Detection of anti-malware quarantining or flagging a tool, followed by a new binary written to disk with a similar function or name and a resumed process chain.
|
|
Analytic 1108
|
Unexpected file creation in web directories followed by web server processes (e.g., w3wp.exe) spawning command shells or script interpreters (e.g., cmd.exe, powershell.exe)
|
|
Analytic 1069
|
Detects rogue Wi-Fi access points broadcasting the same SSID as legitimate APs with stronger signal strength, unexpected MAC/BSSID values, or inconsistent encryption settings. Correlates authentication attempts, captive portal redirections, and anomalous traffic flows through unauthorized APs.
|
|
Analytic 0160
|
Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).
|
|
Analytic 1147
|
Detection of file access from mounted SMB shares followed by copy or exfil commands from Terminal or script interpreter processes.
|
|
Analytic 0349
|
Unusual modification or creation of loginwindow-related plist files in '~/Library/Preferences/ByHost' correlated with unauthorized application paths and execution upon login.
|
|
Analytic 1622
|
Adversary modifies externally-facing web content by accessing and overwriting hosted HTML/JS/CSS files, typically following web shell deployment, credential abuse, or exploitation of web application vulnerabilities.
|
|
Analytic 0616
|
Detects USB device insertion followed by high-volume or sensitive file access and staging activity by suspicious processes or accounts.
|
|
Analytic 0311
|
Monitoring modification and execution of user or system logon scripts such as in registry Run keys or startup folders.
|
|
Analytic 1574
|
Unusual ESXi processes (vmx, hostd) reading datastore files and generating outbound HTTPS traffic toward external cloud storage endpoints. Defender perspective: anomalous datastore activity followed by network transfers to Dropbox, AWS S3, or other storage services.
|
|
Analytic 1443
|
Detects anomalous Kerberos activity such as forged or stolen tickets by correlating malformed fields in logon events, RC4-encrypted TGTs, or TGS requests without corresponding TGT requests. Also detects suspicious processes accessing LSASS memory for ticket extraction.
|
|
Analytic 1413
|
Detects non-browser processes that establish encrypted outbound connections (e.g., TLS/SSL) to unfamiliar or atypical destinations for the host/user, following a data staging or compression event.
|
|
Analytic 1258
|
Non-standard port/protocol pairings or low-entropy ICMP traffic resembling tunneling patterns (e.g., fixed-size pings with delays).
|
|
Analytic 2024
|
Monitor logged domain name system (DNS) data for purchased domains that can be used during targeting. Reputation/category-based detection may be difficult until the categorization is updated. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control.
Domain registration information is, by design, captured in public registration logs. Consider use of services that may aid in tracking of newly acquired domains, such as WHOIS databases and/or passive DNS. In some cases it may be possible to pivot on known pieces of domain registration information to uncover other infrastructure purchased by the adversary. Consider monitoring for domains created with a similar structure to your own, including under a different TLD. Though various tools and services exist to track, query, and monitor domain name registration information, tracking across multiple DNS infrastructures can require multiple tools/services or more advanced analytics.(Citation: ThreatConnect Infrastructure Dec 2020) Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control.
Monitor queried domain name system (DNS) registry data for purchased domains that can be used during targeting. Reputation/category-based detection may be difficult until the categorization is updated. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control.
|
|
Analytic 0989
|
Monitors for processes reading sensitive files then immediately initiating unusual outbound connections or bulk transfer sessions over persistent sockets, particularly with encrypted or binary payloads.
|
|
Analytic 0358
|
Adversary uses renamed container images, injects files into containers with misleading names or metadata (e.g., renamed system binaries), and executes them during startup or scheduled jobs.
|
|
Analytic 0660
|
Detection of changes to /etc/rc.local.d/local.sh or rc.local during post-boot script execution with abnormal commands or additions.
|
|
Analytic 0198
|
Detects remote write activity across cloud VMs or object storage buckets within the same region/account that correlate with data aggregation across hosts.
|
|
Analytic 1040
|
Execution of file enumeration commands (e.g., 'dir', 'tree') from non-standard processes or unusual user contexts, followed by recursive directory traversal or access to sensitive locations.
|
|
Analytic 0560
|
Execution of `ifconfig`, `ip a`, or access to `/proc/net/` indicating collection of local interface and route configuration.
|
|
Analytic 0060
|
Correlates zsh shell configuration file changes (e.g., ~/.zshrc, ~/.zlogin, /etc/zprofile) with execution of unauthorized binaries or unexpected network activity triggered on Terminal.app launch.
|
|
Analytic 1477
|
Detects unauthorized wireless associations by monitoring wpa_supplicant logs, NetworkManager events, and system calls related to interface state changes. Anomalies include repeated association failures, new SSIDs outside baselined values, and rogue AP connections.
|
|
Analytic 1540
|
Identify use of 'shutdown', 'reboot', or 'osascript' system shutdown invocations within unified logs and track unexpected shutdown sequences initiated by GUI or script. Cross-reference with user activity or absence thereof.
|
|
Analytic 0094
|
Defenders can observe suspicious replacement or tampering of system accessibility binaries (e.g., utilman.exe, sethc.exe, osk.exe) and anomalous modifications to registry keys used to redirect accessibility programs (such as IFEO keys). Additionally, execution of cmd.exe or other suspicious binaries triggered from the login screen by SYSTEM can be correlated as part of a behavior chain.
|
|
Analytic 1498
|
Applications or launchd services invoking RSA or public-key routines from the Security framework, followed by outbound SSL/TLS sessions with unrecognized certs or anomalous handshakes. Defender observes unified logs of API calls and suspicious network entropy.
|
|
Analytic 1219
|
Detects firmware or script relocation attempts (e.g., CLI-based `copy`, `move`, or `rename`) between temporary partitions and config startup folders on routers or switches.
|
|
Analytic 0850
|
Exploitation of system or application vulnerability (e.g., CVE-based exploit) followed by service crash, restart, or repeated failure within a short time frame, impacting application/system availability.
|
|
Analytic 1335
|
Identifies abuse of odbcconf.exe to execute malicious DLLs using the REGSVR command flag. Behavior chain: (1) Process creation of odbcconf.exe with /REGSVR or /A {REGSVR ...} arguments → (2) DLL load by odbcconf.exe of non-standard or unsigned modules → (3) Optional follow-on process creation or network activity from loaded DLL.
|
|
Analytic 1544
|
Detection of valid account misuse through SSH logins, sudo/su abuse, and service account anomalies outside expected patterns.
|
|
Analytic 0199
|
Detects adversary use of logon script configuration via Group Policy or user object attributes, followed by script execution post-authentication. Behavior includes modification of script path or file, then process execution under user logon context.
|
|
Analytic 0285
|
Detects web-based credential phishing by analyzing traffic to suspicious URLs that mimic login portals and POST credential content.
|
|
Analytic 1190
|
Detects command-line tools, agents, or scripts making outbound HTTPS connections to popular web services like Discord, Slack, Dropbox, or Graph API in an unusual context.
|
|
Analytic 0746
|
Abuse of cloud messaging platforms to send mass spam or consume quota-based resources.
|
|
Analytic 1033
|
Detects adversary behavior where a file with a benign-looking first extension (e.g., .txt, .jpg) ends with a dangerous second extension (e.g., .exe, .scr), and is subsequently executed. The behavior chain includes file creation with misleading naming and user or system-initiated process execution from the disguised file.
|
|
Analytic 1375
|
A process creates a brand‑new logon session/token (LogonUser*/LsaLogonUser) and then assigns/impersonates it (SetThreadToken/ImpersonateLoggedOnUser) to run actions under that freshly created security context. Chain: (1) suspicious command or script block (e.g., runas /netonly, PowerShell P/Invoke of LogonUser) → (2) ETW/API evidence of LogonUser*/SetThreadToken → (3) Security 4624 New Logon (often LogonType=9 NewCredentials or 2/3 from a non‑interactive parent) with no interactive desktop → (4) sysmon 1 process(es) executing with the new LogonId/SID different from the parent process → (5) optional privileged ops/lateral movement.
|
|
Analytic 0608
|
Detects adversary manipulation of Extra Window Memory (EWM) in a GUI process, where the attacker uses SetWindowLong or SetClassLong to redirect function pointers to injected shellcode stored in shared memory, then triggers execution via a window message like SendNotifyMessage.
|
|
Analytic 0920
|
Detects files or processes where execution results in frequent re-creation or modification of ELF binaries or interpreter scripts, often using chmod + execve with abnormal entropy.
|
|
Analytic 0916
|
Detection of anomalous driver and firmware interactions, including unsigned or unexpected firmware updates, driver loads linked to hardware components, and suspicious use of privileged APIs to read/write firmware or controller memory.
|
|
Analytic 1984
|
Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. In some cases, malware repositories can also be used to identify features of tool use associated with an adversary, such as watermarks in [Cobalt Strike](https://attack.mitre.org/software/S0154) payloads.(Citation: Analyzing CS Dec 2020)
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle.
|
|
Analytic 0248
|
Detection of file write-access to USB-mount directories (e.g., /media/, /run/media/) followed by same-file access or execution on another host.
|
|
Analytic 0274
|
Behavioral chain: (1) An actor creates or modifies a BITS job via bitsadmin.exe, PowerShell BITS cmdlets, or COM; (2) the job performs HTTP(S)/SMB network transfers while the owning user is logged on; (3) upon job completion/error, BITS launches a notify command (SetNotifyCmdLine) from svchost.exe -k netsvcs -s BITS, often establishing persistence by keeping long-lived jobs. The strategy correlates process creation, command/script telemetry, BITS-Client operational events, and network connections initiated by BITS.
|
|
Analytic 1487
|
Detects suspicious OAuth application integrations within Office 365 or Google Workspace environments, such as new app registrations, unexpected consent grants, or privilege assignments. Defenders should correlate between application creation/modification events and associated user or service principal activity to identify persistence via app integrations.
|
|
Analytic 1438
|
Detects log-clearing behavior by correlating suspicious command execution targeting log files under /var/log/, anomalous deletions or truncations of system logs, and unusual child processes (e.g., shell pipelines or redirections).
|
|
Analytic 0846
|
Adversary enumeration of local user accounts using Net.exe, WMI, or PowerShell.
|
|
Analytic 0588
|
Container orchestrator logs show crashlooping pods, repeated resource exhaustion, or malicious binaries with infinite loops consuming systemd/cgroup limits.
|
|
Analytic 2043
|
Detects processes or users modifying Windows Defender Firewall profiles, policies, or rules followed by measurable network exposure changes. Correlates firewall management execution, registry/policy mutation, service state changes, and subsequent inbound or outbound connectivity inconsistent with baseline administration.
|
|
Analytic 0400
|
Processes that typically do not perform cryptographic operations loading symmetric encryption libraries (e.g., bcryptprimitives.dll, aes.dll), then initiating outbound connections with high-entropy payloads. Defender correlates process creation, DLL load, and anomalous encrypted traffic patterns.
|
|
Analytic 1341
|
Repeated failed authentication attempts to container APIs, control planes, or login shells across many user names using same password
|
|
Analytic 0535
|
Detection of attempts to disable or tamper with Windows Event Logging. This includes stopping or disabling the EventLog service, modifying registry keys related to EventLog and Autologger, using `auditpol` or `wevtutil` to disable categories or clear audit policies, and detecting suspicious gaps or resets in event logs. Defenders observe registry changes, service state changes, process execution of disabling commands, and anomalies in event record sequences.
|
|
Analytic 1997
|
Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.
Monitor for suspicious email activity, such as numerous accounts receiving messages from a single unusual/unknown sender. Filtering based on DKIM+SPF or header analysis can help detect when the email sender is spoofed.(Citation: Microsoft Anti Spoofing)(Citation: ACSC Email Spoofing)
Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
|
|
Analytic 0897
|
Office or scripting applications initiating unusual HTTPS traffic to code repository APIs with high outbound-to-inbound ratios. Defender perspective: monitor for sensitive file access in combination with network connections to github.com, gitlab.com, or bitbucket.org.
|
|
Analytic 0532
|
Repeated or automated access to user document directories or clipboard using shell scripts or utilities like xclip/pbpaste. Detectable via auditd syscall logs or osquery file events.
|
|
Analytic 0944
|
Detects usage of `at` command to schedule jobs, followed by job execution and modification of job files under /var/spool/cron/atjobs.
|
|
Analytic 0328
|
Links inbound network access to SSHD/SMB/NFS/Databases or custom daemons with subsequent daemon crash/restart, core dump, or spawning of shells/reverse shells from the service context, indicating remote exploitation.
|
|
Analytic 1424
|
Token retrieval from instance metadata endpoints such as AWS IMDS or Azure IMDS, followed by API usage using the obtained token from non-standard applications.
|
|
Analytic 1951
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1591
|
Creation of email forwarding/redirect rules in Exchange Online via New-InboxRule or transport rule cmdlets, including auto-forwarding address field usage.
|
|
Analytic 0465
|
Defenders may observe unauthorized or anomalous changes to NAT configurations, including the addition of new translation rules or modifications to existing ones. Suspicious behaviors include sudden introduction of NAT mappings bridging segmented networks, new port address translation rules that obscure true source IPs, or traffic flows inconsistent with expected network design. Multi-event correlation includes detecting configuration changes on routers/firewalls, followed by traffic traversing unexpected internal/external address pairs.
|
|
Analytic 0225
|
Adversary exploits public admin services on routers/firewalls/switches. Chain: anomalous HTTP/SNMP/SmartInstall inputs → device syslog errors/restarts → config changes/CLI spawn → egress to attacker C2.
|
|
Analytic 1218
|
Detects movement of binaries to `~/Library/`, `/System/`, or app bundle locations, especially after initial execution or download from Safari or Mail.
|
|
Analytic 0137
|
An adversary writes or drops a malicious Office Add-in (e.g., WLL, XLL, COM) to a trusted directory or modifies registry keys to load malicious add-ins on Office application launch. Upon user opening Word or Excel, the add-in is automatically loaded, triggering execution of the payload, often spawning scripting engines or anomalous child processes.
|
|
Analytic 1145
|
Monitoring of file access to network shares (e.g., C$, Admin$) followed by unusual read or copy operations by processes not typically associated with such activity (e.g., PowerShell, certutil).
|
|
Analytic 1277
|
Password spraying or brute force attempts across user pool within short time intervals
|
|
Analytic 0350
|
Adversary attempts to gain persistence by modifying ~/.ssh/authorized_keys via shell, text editor, echo or redirected output.
|
|
Analytic 0093
|
Use of chflags hidden or SetFile -a V commands to hide files, or creation of hidden files with leading '.'. Defender view: monitoring process execution and file metadata changes setting UF_HIDDEN attribute.
|
|
Analytic 0255
|
Adversary runs commands like `whoami`, `id`, `w`, or `cat /etc/passwd` from non-interactive or scripting contexts to enumerate system user details.
|
|
Analytic 0086
|
Outlook form execution upon message receipt or client launch results in automated code execution within user session. Form definitions deviate from standard templates and include script logic or COM object calls embedded in form fields.
|
|
Analytic 0368
|
Detects file exfiltration using tools like curl, scp, or custom binaries over protocols such as FTP, HTTP/S, or DNS tunneling, especially outside baseline user behavior.
|
|
Analytic 0269
|
Addition of new users or changes to role permissions (e.g., ReadOnly -> Admin) via API or vSphere Client, particularly from non-jumpbox IPs.
|
|
Analytic 1943
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0554
|
Suspicious rule creation within Outlook or Exchange clients, including auto-move or delete conditions tied to incident or security alert keywords. Defender perspective: correlation between missing inbound emails and newly added mailbox rules.
|
|
Analytic 0005
|
Detects pub/sub traffic over unusual ports, high-frequency topic publications, and connections to known-bad or dynamic broker endpoints outside allowlisted infrastructure.
|
|
Analytic 0591
|
Use of domain accounts via sssd or winbind for logon activity outside of typical patterns, especially on sensitive systems or with lateral movement tools.
|
|
Analytic 1299
|
Detects script or binary modification within shared NFS/SMB directories followed by process execution from those paths.
|
|
Analytic 0825
|
Detects unauthorized edits to system configuration profiles, unexpected certificate trust changes, or abnormal ARP/DNS patterns indicative of interception.
|
|
Analytic 0573
|
Detects attempts to enumerate VMs via hypervisor tools like `virsh`, `VBoxManage`, or `qemu-img`. Defender correlates suspicious command invocations with parent process lineage and unexpected users.
|
|
Analytic 0281
|
Detects embedded Lua interpreter execution or script injection on devices supporting Lua scripting (e.g., routers, firewalls), often seen in modified firmware or abused APIs.
|
|
Analytic 0685
|
Monitor Facetime, iMessage, or SIP client logs for anomalous voice call attempts. Link to subsequent user execution events (downloads, RMM installs) triggered post-call.
|
|
Analytic 0200
|
Abuse of systemctl to execute commands or manage systemd services. Defender perspective: correlate suspicious service creation or modification with execution of systemctl subcommands such as start, enable, or status. Detect cases where systemctl is used to load services from unusual locations (e.g., /tmp, /dev/shm) or where new service units are created outside of expected administrative workflows.
|
|
Analytic 0154
|
Detection of unexpected additions or modifications to system-wide certificate stores or execution of commands adding certificates to trusted stores.
|
|
Analytic 0722
|
SaaS platforms may show forged credentials as unusual API keys, tokens, or session cookies being used without corresponding authentication. Correlated patterns include simultaneous valid sessions from multiple geographies, unusual API calls with new tokens, or bypass of expected MFA enforcement.
|
|
Analytic 0767
|
An adversary leverages built-in tools such as certutil.exe, powershell.exe, or copy.exe to decode, reassemble, or extract hidden malicious content from obfuscated containers or encoded formats. The decoding utility often spawns shortly after file staging or download and may be chained with script interpreters or further payload execution.
|
|
Analytic 0316
|
Detects AS-REP roasting attempts by monitoring for Kerberos AS-REQ/AS-REP authentication patterns where preauthentication is disabled (Event ID 4768 with Pre-Auth Type 0). Correlates these requests with subsequent service ticket activity (Event ID 4769) and anomalies such as requests using weak RC4 encryption (etype 0x17). Excessive enumeration of accounts with 'Do not require Kerberos preauthentication' set in Active Directory is another key detection point.
|
|
Analytic 2022
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0813
|
Execution of renamed or dropped files with a trailing space to deceive users or analysts, especially in LaunchAgents or LaunchDaemons.
|
|
Analytic 0416
|
Container process executes destructive file operations inside volume mounts or host paths. Includes `rm -rf /mnt/volumes/`, container breakout followed by host deletion attempts.
|
|
Analytic 1559
|
Detection of CLI commands that disable history logging such as 'no logging'. Anomalous lack of new commands in session logs while activity persists is a strong signal.
|
|
Analytic 1382
|
Detects GCC or Clang invoked on suspicious file paths (e.g., /tmp/, ~/Downloads) with output to executable binaries, followed by execution or outbound traffic from these binaries.
|
|
Analytic 0288
|
Detects modification of PAM configuration files, unauthorized new PAM modules, and suspicious process execution accessing PAM-related binaries. Correlates file modification events in /etc/pam.d/ with process execution of unauthorized binaries.
|
|
Analytic 0715
|
Execution of known or custom VNC/remote desktop daemons or tunneling agents that initiate external communication after launch
|
|
Analytic 0812
|
Detection of file execution where the file name contains a trailing space to masquerade as a known executable. Adversaries may exploit the way command line interpreters handle file names with trailing whitespace.
|
|
Analytic 1482
|
1) pkg/notarization installs from atypical sources or with Gatekeeper/AMFI warnings; 2) new Mach-O written into /Applications or ~/Library paths or substitution of signed components; 3) first run from installer spawns unsigned children or exfil.
|
|
Analytic 1637
|
Detects adversary abuse of SaaS platform vulnerabilities to bypass logging, monitoring, or consent boundaries. Defender perspective focuses on abnormal application integration events, missing audit logs, or API calls from unauthorized service principals that align with exploitation attempts.
|
|
Analytic 1550
|
Adversary adds IDE extensions or plugins (VS Code, JetBrains Toolbox/EAP, Eclipse) via GUI or CLI, possibly via managed profiles. Chain: process start with install/update flags → plist/extension folder changes under ~/Library/Application Support/Code or ~/Library/Application Support/JetBrains → outbound connections to marketplaces/tunnel services → optional helper (ssh/node) spawned.
|
|
Analytic 1290
|
Detects rogue DHCP server activity and anomalous DHCP OFFER/ACK messages assigning unexpected DNS or gateway values. Detection correlates DHCP server role changes, DHCP exhaustion warnings, and sudden network configuration changes across endpoints.
|
|
Analytic 0947
|
Creation or modification of cloud virtual machine images (AMIs, custom images) with persistence mechanisms, followed by infrastructure provisioning that uses these implanted images.
|
|
Analytic 0382
|
Detects hosts transmitting large volumes of SMTP, IMAP, or POP3 traffic to external IPs or relays that aren't associated with the enterprise mail infrastructure.
|
|
Analytic 1447
|
Detects modification of System Integrity Protection (SIP) or code signing enforcement policies through csrutil or kernel variable tampering. Correlates execution of csrutil disable commands with subsequent policy state changes and anomalous unsigned process executions.
|
|
Analytic 0635
|
Applications making outbound connections on non-standard ports or launchd services bound to ports inconsistent with system baselines.
|
|
Analytic 0919
|
Identifies self-modifying executables that exhibit changes in binary hash, entropy, or memory sections during or between executions—often tied to dynamic unpacking or decryption behaviors.
|
|
Analytic 0471
|
Detects use of `clear history` or `clear logging` commands on network device CLI to remove past activity logs.
|
|
Analytic 1423
|
Access and retrieval of container service account tokens followed by unauthorized API requests using those tokens to interact with the Kubernetes API server or internal services.
|
|
Analytic 1252
|
Detects behavioral chains where PowerShell is launched with encoded commands, unusual parent processes, or suspicious modules loaded, potentially followed by network connections or child process spawning. Supports detection of both direct (powershell.exe) and indirect (.NET automation) invocations.
|
|
Analytic 0720
|
On Linux systems, forged credentials may be injected into browser session files, curl/wget headers, or token caches in memory. Detection can leverage auditd to track processes accessing sensitive files (~/.mozilla, ~/.config/chromium, ~/.aws/credentials) and correlate with suspicious outbound connections.
|
|
Analytic 0229
|
Adversary modifies internal UI messages (e.g., login banners, desktop wallpapers) or hosted intranet web pages by creating or altering content files using scripts or unauthorized access. Often preceded by privilege escalation or web shell deployment.
|
|
Analytic 0317
|
Detects attempts to enumerate local groups via Net.exe, PowerShell, or native API calls that precede lateral movement or privilege abuse.
|
|
Analytic 0411
|
Adversary spawns command-line tools (e.g., del, cipher /w, SDelete) or scripts to recursively delete or overwrite user/system files. This may be correlated with abnormal file IO activity, registry writes, or tampering in critical system directories.
|
|
Analytic 0745
|
High CPU usage by unauthorized containers running mining binaries or public proxy tools.
|
|
Analytic 0243
|
Monitors suspicious usage of Windows API calls like SetWindowsHookEx, GetKeyState, or polling functions within non-UI service processes, combined with Registry or driver modifications.
|
|
Analytic 1607
|
Adversary creates users via IAM/IdP API or portal (e.g., Azure AD, Okta). Detection involves monitoring API calls, admin action logs, and correlation with role assignments.
|
|
Analytic 1118
|
Recurring network exfiltration initiated by scheduled or script-based processes exhibiting time-based regularity and consistent external destinations.
|
|
Analytic 0942
|
Detects execution of AutoHotKey or AutoIT interpreters or compiled scripts used for unauthorized automation, command execution, or payload delivery, correlated with anomalous process lineage, command-line arguments, or script creation events.
|
|
Analytic 0910
|
Execution of QEMU, KVM, or VirtualBox processes with unusual flags (e.g., '-nographic', '-snapshot'). File creation of VM images in atypical directories. Defender view: monitoring audit logs for process executions and file modifications linked to hidden virtualization.
|
|
Analytic 0561
|
Execution of `ifconfig`, `networksetup`, or `system_profiler` to query IP/MAC/interface configuration and status.
|
|
Analytic 0144
|
Detects excessive outbound traffic to remote host over HTTP(S) from uncommon or previously unseen processes.
|
|
Analytic 1070
|
Adversaries collecting local files via PowerShell, WMI, or direct file API calls often include recursive file listings, targeted file reads, and temporary file staging.
|
|
Analytic 0283
|
Detects use of tools/scripts accessing input devices like /dev/input/* or evdev via suspicious processes lacking GUI context.
|
|
Analytic 1283
|
Detection of default account usage such as Guest or Administrator performing interactive or remote logons on systems outside of installation or maintenance windows.
|
|
Analytic 0682
|
Detection of persistent login hooks configured via defaults or plist modifications that result in execution of scripts or binaries at user login, breaking expected parent-child process lineage.
|
|
Analytic 1493
|
Unauthorized instance creation in unmonitored or unused regions. Burst of compute-intensive jobs in spot instances or sudden spike in resource usage in legitimate VMs.
|
|
Analytic 0657
|
Phishing attachment detection on macOS through correlation of Mail app logs, file creation in user directories, and abnormal process execution (e.g., Preview.app or Mail.app spawning Terminal or scripting binaries). Network traffic after attachment interaction is also monitored.
|
|
Analytic 1463
|
Execution of user-downloaded or created scripts with hidden extensions due to RTLO character insertion in filename, often present in desktop environments or phishing campaigns.
|
|
Analytic 1471
|
Credential-related configuration changes in productivity apps, such as API key creation in Google Workspace, app tokens in Slack, or user-level OAuth credentials in M365.
|
|
Analytic 0607
|
Detection focuses on unauthorized modification of Mach-O binaries to include LC_LOAD_DYLIB headers pointing to malicious dylibs. Behavior is identified via a chain of file metadata changes, removal of code signatures, and subsequent anomalous dylib loads at runtime. Correlation of file changes with lack of authorized updates and process memory mapping of unrecognized or unsigned libraries is crucial.
|
|
Analytic 1492
|
Ephemeral or unauthorized container instantiation using public images (e.g., from DockerHub) that initiate high CPU usage shortly after startup. Often scheduled via Kubernetes or Docker socket abuse.
|
|
Analytic 1613
|
Enumeration of users and groups through suspicious shell commands or unauthorized access to /etc/passwd or /etc/shadow.
|
|
Analytic 0479
|
Shell script or binary uses multiple system commands (e.g., dmidecode, lscpu, lspci) in quick succession to detect virtualization environment
|
|
Analytic 0692
|
IAAS (Cloud images/VMs): A new VM/instance is launched from a non-approved or newly-seen image (AMI/GCP Image/Azure Image). On first boot, cloud-init/user-data or embedded agents download code, spawn system utilities, or open outbound C2/mining traffic. The analytic correlates Instance/Image Creation → Instance Start → in-guest Process/Command Execution and/or anomalous network traffic.
|
|
Analytic 0847
|
Enumeration of local users or groups via file access (/etc/passwd) or commands like id, groups.
|
|
Analytic 0663
|
Adversary gains shell access or uploads a malicious script to deface hosted web content in Nginx, Apache, or other services.
|
|
Analytic 0485
|
On Linux, defenders may observe forged cookie activity as unauthorized modifications to browser cookie databases (e.g., ~/.mozilla/firefox/*/cookies.sqlite, ~/.config/chromium/Default/Cookies) or scripted injection of session tokens. Suspicious usage includes curl/wget commands embedding forged cookies in headers, correlated with abnormal session activity in SaaS or IaaS logs.
|
|
Analytic 1096
|
Correlation of file creation/modification of `.desktop` files within XDG autostart directories, followed by execution of processes at user login initiated by the desktop environment. Malicious entries typically include suspicious Exec paths or anomalous names and are not associated with installed packages.
|
|
Analytic 1131
|
Configuration changes to virtual TAP/mirror policies that forward traffic to unapproved destinations. Detection correlates management plane API calls with mirrored traffic observation.
|
|
Analytic 0843
|
A source performs a short closed-port sequence; the host then modifies iptables/nftables/ufw rules or starts a daemon binding a new socket, followed by a successful connection from the same source.
|
|
Analytic 0373
|
File lock acquired via open() + flock() or lockf() on predictable path (e.g., /tmp/.lock123) followed by conditional early exit or divergent process behavior.
|
|
Analytic 1346
|
Behavioral chain: (1) third-party interactive login or mobileconfig-based device enrollment; (2) privilege use or admin group change; (3) lateral movement mounts/ssh. Correlate unified logs and network telemetry.
|
|
Analytic 0895
|
Processes such as PowerShell, Git, or curl initiating outbound HTTPS POST requests to known code repository APIs (e.g., github.com, gitlab.com) immediately following large file reads. Defender view: correlation between file access of sensitive directories (e.g., Documents, Finance) and abnormal data uploads to repository domains.
|
|
Analytic 0504
|
Detection of VNC service or executable starting unexpectedly, followed by user session creation and interactive desktop activity (mouse/keyboard simulation).
|
|
Analytic 0040
|
Detects staging of sensitive files into temporary or public directories, compression with 7zip/WinRAR, or batch copy prior to exfiltration.
|
|
Analytic 0109
|
Correlate high-frequency or anomalous DNS query activity with processes that do not normally generate network requests (e.g., Office apps, system utilities). Detect pseudo-random or high-entropy domain lookups indicative of domain generation algorithms (DGAs).
|
|
Analytic 0334
|
Correlated user account modification (reset, disable, deletion) events with anomalous process lineage (e.g., PowerShell or net.exe from an interactive session), especially outside of IT admin change windows or by non-admin users.
|
|
Analytic 0742
|
Abnormal CPU/memory usage by unauthorized processes with outbound connections to known mining pools or using cron jobs/scripts to maintain persistence.
|
|
Analytic 1255
|
ICMP or raw socket traffic generated by user-mode processes like bash, Python, or nc, typically using `ping`, `hping3`, or crafted packets via libpcap or scapy.
|
|
Analytic 0017
|
Cloud login from atypical geolocation or user-agent string, followed by resource enumeration or infrastructure manipulation using cloud CLI/API
|
|
Analytic 0689
|
Processes accessing TCC-protected input APIs or polling HID services without user interaction, or dynamically loaded keylogging frameworks using accessibility privileges
|
|
Analytic 0492
|
Automated or scripted HTTP/TLS flooding from one VM or cloud instance against another service, exploiting compute-based billing or exhaustion of service infrastructure.
|
|
Analytic 1160
|
Programmatic or excessive access to file shares, SharePoint, or database repositories by users not typically interacting with them. This includes abnormal access by privileged accounts, enumeration of large numbers of files, or downloads of sensitive content in bursts.
|
|
Analytic 0098
|
Detects process enumeration using `esxcli system process list` or `ps` on ESXi shell or via unauthorized SSH sessions. Correlates with interactive sessions and abnormal user roles.
|
|
Analytic 1496
|
Processes not typically associated with encryption loading asymmetric crypto libraries (e.g., rsaenh.dll, crypt32.dll) and subsequently initiating outbound TLS/SSL connections with abnormal certificate chains or handshakes. Defender correlates process creation, module load, and unusual encrypted sessions.
|
|
Analytic 0326
|
Creation of LaunchAgents or LaunchDaemons with names resembling known system services but executing non-Apple signed code or scripts.
|
|
Analytic 1177
|
Multi-stage Windows DACL manipulation behavioral chain: (1) Process creation of permission-modifying utilities (icacls.exe, takeown.exe, attrib.exe, cacls.exe) or PowerShell ACL cmdlets, (2) Command-line analysis revealing privilege escalation intent through suspicious parameters (/grant, /takeown, /T, Set-Acl), (3) DACL modification events (4670) correlating with process execution, (4) Subsequent file access attempts (4663) indicating successful permission bypass, (5) Potential follow-on persistence or lateral movement activities
|
|
Analytic 1331
|
Identify repeated DNS resolutions where the same domain name returns multiple IPs in short succession, combined with low TTL values and high query volume from unusual processes. Correlate with process lineage (e.g., Office apps spawning abnormal DNS lookups).
|
|
Analytic 1010
|
Detect abnormal use of email clients (e.g., Outlook, Thunderbird) showing mass arrival of messages or repetitive attachments being locally stored. Correlate message volume with file creation activity in mail cache directories.
|
|
Analytic 0357
|
Adversary creates disguised launch daemons or apps with misleading names and bundle metadata (e.g., Info.plist values inconsistent with binary path or icon). Launch is correlated with user logon or persistence setup.
|
|
Analytic 2038
|
Detects suspicious interactions with security products followed by service crashes, unexpected restarts, driver unloads, telemetry gaps, or tamper-state changes. Correlates exploit precursor behavior with immediate degradation of defensive services and follow-on process execution.
|
|
Analytic 0428
|
Detection of raw access to physical drives, modification of boot records (MBR/VBR), and suspicious file creation or alteration within the EFI System Partition (ESP). Correlates privileged process execution with low-level disk modification and unexpected driver or firmware interactions.
|
|
Analytic 0361
|
Suspicious invocation of GUI utilities or scripts with suppressed or redirected windowing options. Defender view: detection of X11 or Wayland calls to spawn windows that do not appear on active displays, or use of nohup/screen/tmux to mask interactive shells.
|
|
Analytic 0194
|
Detects file transfers or mounting operations from remote hosts followed by write actions into a local staging directory, often using SMB or remote shell activity.
|
|
Analytic 0293
|
Execution of hash cracking binaries or scripts (e.g., john, hashcat) following access to shadow file or dumped hashes
|
|
Analytic 1486
|
VMware daemons or user processes encapsulating traffic (e.g., guest VMs tunneling via hostd). Defender sees network services inside ESXi creating flows inconsistent with management plane traffic, such as SSH forwarding or DNS-over-HTTPS from management interfaces.
|
|
Analytic 0205
|
`socat`, `ssh`, `iptables`, or `ncat` invoked from user space or cron jobs to create port forwarding, reverse shells, or inter-host tunnels between compromised Linux systems. Behavior is typically paired with socket activity and high entropy traffic.
|
|
Analytic 1369
|
Detection of adversary behavior that disables or modifies security tools, including killing AV/EDR processes, stopping services, altering Sysmon registry keys, or tampering with exclusion lists. Defenders observe process/service termination, registry modification, and abnormal absence of expected telemetry.
|
|
Analytic 0957
|
Unusual reuse of OAuth access tokens from different geographic regions, without full login events.
|
|
Analytic 0857
|
File reads or process executions involving insecurely stored credential files (e.g., config files with password fields) by non-root or anomalous users followed by ssh authentication attempts.
|
|
Analytic 1459
|
Detects adversarial archiving activity through invocation of utilities like tar, gzip, bzip2, or openssl used in non-administrative or unusual contexts. Correlates command execution patterns with file creation of compressed/encrypted outputs in staging directories (e.g., /tmp, /var/tmp).
|
|
Analytic 0454
|
Detect user account logon attempts that trigger multiple MFA challenges through enterprise identity integrations, especially if MFA push requests are generated without successful interactive login.
|
|
Analytic 0896
|
Processes like git, curl, or python scripts executing commands that package files (tar, gzip) followed by HTTPS uploads to code repository endpoints. Defender view: detect unusual git push activity or scripted HTTPS requests outside normal developer work hours.
|
|
Analytic 1551
|
Windows environmental validation behavioral chain: (1) Rapid system discovery reconnaissance through WMI queries, registry enumeration, and network share discovery, (2) Environment-specific artifact collection (hostname, domain, IP addresses, installed software, hardware identifiers), (3) Cryptographic operations or conditional logic based on collected environmental values, (4) Selective payload execution contingent on environmental validation results, (5) Temporal correlation between discovery activities and subsequent execution or network communication
|
|
Analytic 0097
|
Monitors execution of ps, top, or launchctl with unusual parent processes or from terminal scripts. Also detects AppleScript-based process listing or `system_profiler SPApplicationsDataType` misuse.
|
|
Analytic 0880
|
Adversaries create the 'Office Test\Special\Perf' registry key and specify a malicious DLL path that is auto-loaded when an Office application starts. This DLL is injected into the Office process memory space and can provide persistent execution without requiring macro enablement.
|
|
Analytic 0761
|
Applications or launchd jobs initiating encrypted TLS traffic to rare external hosts. Defender observes unified logs showing ssl/TLS API calls by processes not baseline-approved, and payload entropy suggesting encrypted C2 sessions.
|
|
Analytic 1585
|
Execution of built-in or AppleScript-based system enumeration via `arp`, `netstat`, `ping`, and discovery of `/etc/hosts` contents.
|
|
Analytic 0654
|
Suspicious modification of file artifacts (e.g., logs, ISO templates) on ESXi datastores, followed by beaconing or POST operations to external IPs potentially hiding payloads in file-like traffic.
|
|
Analytic 2018
|
Monitor call logs from corporate devices to identify patterns of potential voice phishing, such as calls to/from known malicious phone numbers.
|
|
Analytic 0816
|
Detects API calls registering or updating hybrid identity connectors, modification of cloud-to-on-premises federation trust, and unusual token issuance logs.
|
|
Analytic 0182
|
PowerShell or script execution with parameters that suppress errors or ignore user interrupts, such as `-ErrorAction SilentlyContinue`. Defender perspective: detecting discrepancies between suppressed error arguments and continued execution behavior.
|
|
Analytic 0759
|
Processes that normally do not initiate network connections establishing outbound encrypted TLS/SSL sessions, especially with asymmetric traffic volumes (client sending more than receiving) or non-standard certificate chains. Defender observations correlate process creation with unexpected network encryption libraries being loaded.
|
|
Analytic 0072
|
Abuse of Linux Electron binaries by modifying app.asar or config JS files and spawning unexpected child processes (bash, curl, python).
|
|
Analytic 2017
|
Once adversaries have provisioned compromised infrastructure (ex: a server for use in command and control), internet scans may help proactively discover compromised infrastructure. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021)
Consider monitoring for anomalous changes to domain registrant information and/or domain resolution information that may indicate the compromise of a domain. Efforts may need to be tailored to specific domains of interest as benign registration and resolution changes are a common occurrence on the internet.
Monitor for queried domain name system (DNS) registry data that may compromise third-party infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
Monitor for logged domain name system (DNS) data that may compromise third-party infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
Monitor for contextual data about an Internet-facing resource gathered from a scan, such as running services or ports that may compromise third-party infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
|
|
Analytic 0687
|
Behavior chain involving unexpected API calls to capture keyboard input, driver loads for keyloggers, or remote use of smart card authentication via logon sessions not initiated by local user interaction
|
|
Analytic 0218
|
Detection of hijacked VNC or SSH sessions on macOS where adversaries take over an existing session rather than authenticating directly. Indicators include process execution from active sessions without new logon events, manipulation of TTY sessions, or anomalous network activity tied to dormant sessions.
|
|
Analytic 0287
|
Detects modification of LSASS and authentication DLLs, suspicious registry changes to password filter packages, and abnormal process access to lsass.exe. Correlates registry modifications, DLL loads, and process handle access events.
|
|
Analytic 1511
|
Processes that normally do not initiate network communications suddenly making outbound HTTPS connections with high outbound-to-inbound data ratios. Defender view: correlation between process creation logs (e.g., Word, Excel, PowerShell) and subsequent anomalous network traffic volumes toward common web services (Dropbox, Google Drive, OneDrive).
|
|
Analytic 0548
|
Detects suspicious MFA method changes, such as registration of weaker factors (e.g., SMS), or removal of MFA requirements for specific accounts or groups.
|
|
Analytic 0186
|
Chain: (1) udev / kernel logs show hot-plug (USB/Thunderbolt/PCIe); (2) block device created by udisks/diskarbitration; (3) optional: new network interface or DHCP lease observed. Correlate /var/log/messages|syslog, auditd SYSCALL open/creat on /dev, and DHCP/Zeek.
|
|
Analytic 0115
|
Detects deletion of launch agents (~/Library/LaunchAgents/) and launch daemons (/Library/LaunchDaemons/), especially after suspicious process execution or when tied to known persistence methods.
|
|
Analytic 0614
|
Detection of Windows container escape attempts by observing processes accessing host directories, symbolic link abuse, or privilege escalation attempts. Defenders may detect anomalous process execution with access to system-level directories outside of container boundaries.
|
|
Analytic 1968
|
If infrastructure or patterns in the malicious web content related to malvertising have been previously identified, internet scanning may uncover when an adversary has staged malicious web content. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on other phases of the adversary lifecycle, such as [Drive-by Compromise](https://attack.mitre.org/techniques/T1189) or [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203).
|
|
Analytic 1329
|
OAuth token granted to external app followed by download of high-volume files in OneDrive/Google Drive
|
|
Analytic 0450
|
Detect abnormal MFA activity within cloud service provider logs, such as repeated generation of MFA challenges for the same user session or mismatched MFA device and login origin.
|
|
Analytic 1273
|
Hidden file system use through APFS containers or custom plist configuration. Defender view: anomalous use of hdiutil or diskutil to attach hidden partitions, modification of plist entries tied to system volumes, or suspicious raw disk access.
|
|
Analytic 0627
|
Detects central router or switch config management tools (e.g., FortiManager, Cisco Prime) triggering device reboots or config pushes using abnormal accounts or IPs.
|
|
Analytic 0649
|
Processes opening /proc/*/mem or /proc/*/maps targeting credential-storing services like sshd or login. Behavior often includes high privilege escalation and memory inspection tools such as gcore or gdb.
|
|
Analytic 0426
|
Detects shell-based scripts accessing configuration files or snapshots and transmitting them over unencrypted protocols such as FTP or HTTP to non-management IPs.
|
|
Analytic 1446
|
Monitors execution of administrative utilities (e.g., bcdedit.exe) or registry modifications that disable Driver Signature Enforcement (DSE) or enable Test Signing. Correlates command-line activity, registry changes, and subsequent process executions that bypass signing enforcement.
|
|
Analytic 1297
|
ESXi hosts initiating connections from non-standard daemons mimicking HTTP/HTTPS or SNMP traffic, but with irregular payload formats or expired/unsigned TLS certificates.
|
|
Analytic 0422
|
Forged SAML tokens may be leveraged to access O365 apps such as Outlook or SharePoint. Defenders should monitor for token replay across multiple clients or access attempts to privileged mailboxes without prior interactive login.
|
|
Analytic 1120
|
LaunchAgent or launchd recurring jobs initiating data transfer to consistent external IPs or domains with repeat timing signatures.
|
|
Analytic 0992
|
Detect suspicious file creations and process executions triggered by browser activity (e.g., injected payloads written to %AppData% or Temp directories, then executed). Correlate network anomalies with subsequent local process creation or script execution.
|
|
Analytic 0412
|
Massive recursive deletions or overwrites via `rm -rf`, `shred`, `dd`, or wiper binaries. May include unlink syscalls, deletion of known config/data paths, or sequential overwrite patterns.
|
|
Analytic 0114
|
Detects removal of persistence artifacts such as crontab entries, systemd service units, and malicious user accounts through commands like `crontab -r`, `rm /etc/systemd/system/*.service`, or `userdel`.
|
|
Analytic 0231
|
Modification of user desktop backgrounds, login screen messages, or system banners by adversaries using admin privileges or script execution. May coincide with tampering in /Library/Desktop Pictures/ or use of AppleScript.
|
|
Analytic 1057
|
Detects processes performing network enumeration (e.g., port scans, service probing) by correlating process creation, socket connections, and sequential destination IP probing within a time window.
|
|
Analytic 0265
|
Account attribute changes (e.g., password set, group membership, servicePrincipalName, logon hours) correlated with unusual process lineage or timing, indicating privilege escalation or persistence via valid accounts.
|
|
Analytic 0126
|
Inconsistencies between process command-line arguments logged at creation time and subsequent process behavior. Defender perspective: monitoring for processes launched in a suspended state, followed by memory modifications (e.g., WriteProcessMemory targeting the PEB) that overwrite arguments before execution resumes. Detection also includes observing anomalous behaviors from processes whose logged arguments do not align with executed activity (e.g., network connections, file writes, or registry modifications).
|
|
Analytic 1288
|
Execution of Microsoft-signed scripts (e.g., pubprn.vbs, installutil.exe, wscript.exe, cscript.exe) used to proxy execution of untrusted or external binaries. Behavior is detected through command-line process lineage, child process spawning, and unsigned payload execution from signed parent.
|
|
Analytic 0558
|
Execution of control.exe or rundll32.exe with parameters pointing to CPL files, especially from non-standard directories or newly created files, followed by suspicious child process execution or registry modifications registering new Control Panel items.
|
|
Analytic 1476
|
Detects anomalous wireless connections such as unexpected SSID associations, failed or repeated authentication attempts, and connections outside of known geofenced networks. Defenders should monitor wireless connection logs and event codes for network discovery, authentication, and association events.
|
|
Analytic 1454
|
Execution of system info utilities like `systemsetup`, `sw_vers`, `uname`, or `sysctl` by terminal or scripted processes.
|
|
Analytic 1436
|
Adversaries inject VBA macros into Office templates such as Normal.dotm or Personal.xlsb or redirect Office template load path via registry key (GlobalDotName) to gain persistence. Template macros trigger execution of malicious code on application startup.
|
|
Analytic 0773
|
Detection of new admin or role assignment actions within Microsoft 365/O365 environments to elevate access for persistence or lateral movement.
|
|
Analytic 0006
|
Adversary uses built-in tools such as 'net user /add /domain' or PowerShell to create a domain user account. The behavior chain includes: (1) suspicious process execution on a domain controller followed by (2) user account creation event (Event ID 4720) on the same host.
|
|
Analytic 1967
|
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: [Phishing](https://attack.mitre.org/techniques/T1566)).
|
|
Analytic 0345
|
Process invokes a standard encoder (e.g., PowerShell -enc, certutil -encode, base64 via .NET/Invoke-Expression) or emits long Base64/hex literals → shortly followed by outbound network egress with high bytes_out:bytes_in ratio or HTTP headers/payloads containing Base64/MIME blocks.
|
|
Analytic 1599
|
Suspicious process initiating outbound connections to web services without corresponding response or return traffic, indicative of one-way command channels.
|
|
Analytic 0552
|
Alterations to plist configuration files (RulesActiveState.plist, SyncedRules.plist, UnsyncedRules.plist, MessageRules.plist) that define email hiding or filtering rules. Defender perspective: unexpected changes in these files associated with Mail.app processes.
|
|
Analytic 0226
|
Execution of trusted, Microsoft-signed binaries such as `rundll32.exe`, `msiexec.exe`, or `regsvr32.exe` used to execute externally hosted, unsigned, or suspicious payloads through command-line parameters or network retrieval.
|
|
Analytic 1168
|
Automated abuse of cloud-hosted applications (e.g., web apps, REST endpoints, internal APIs) causing compute exhaustion, high 5xx error rates, or frequent autoscaling triggers logged in app insights or cloudwatch.
|
|
Analytic 0482
|
Defenders may observe adversary attempts to alter or replace a network device’s operating system image through anomalous CLI commands, unexpected firmware updates, integrity check failures, or mismatches in version and checksum validation. Suspicious behavior includes modification of image files on storage, OS version output inconsistent with baselines, unexpected reloads or reboots after image replacement, and changes to boot configuration that load non-standard system images.
|
|
Analytic 2013
|
If infrastructure or patterns in the malicious web content related to SEO poisoning or [Drive-by Target](https://attack.mitre.org/techniques/T1608/004) have been previously identified, internet scanning may uncover when an adversary has staged web content supporting a strategic web compromise. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on other phases of the adversary lifecycle, such as [Drive-by Compromise](https://attack.mitre.org/techniques/T1189) or [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203).
|
|
Analytic 0864
|
A tampered app/pkg/notarized update is installed via installer, softwareupdated, Homebrew, or vendor updater; new Mach-O or bundle contents appear in /Applications, /Library, /usr/local or /opt/homebrew; first run spawns sh/zsh/osascript/curl and makes egress to unfamiliar domains; AMFI/Gatekeeper may log signature/notarization problems.
|
|
Analytic 0575
|
Detects VM enumeration attempts using virtualization utilities such as VirtualBox (`VBoxManage`) or Parallels CLI. Defender observes abnormal invocation of VM listing commands correlated with non-admin users or unusual parent processes.
|
|
Analytic 0441
|
Unusual screensaver (.scr) executions correlated with recent registry modifications to HKCU\Control Panel\Desktop values such as SCRNSAVE.exe, ScreenSaveTimeout, and ScreenSaveActive. Detection focuses on PE image paths not consistent with known legitimate screensavers and triggered after user inactivity timeout.
|
|
Analytic 0063
|
Use of launchctl to stop services or kill critical background processes (e.g., securityd, com.apple.*), typically followed by command-line tools like rm or diskutil. Behavioral chain: Terminal or remote shell + launchctl bootout/disable + process termination + follow-on modification.
|
|
Analytic 1481
|
1) Package manager or curl/wget installs/upgrades from non-approved repos or unsigned packages; 2) new ELF written into PATH directories or replacement of existing binaries/libraries; 3) first run leads to unexpected child processes or outbound connections.
|
|
Analytic 1055
|
Track creation or update of SaaS automation scripts (e.g., Google Workspace Apps Script). Detect when these scripts are bound to user events such as file opens or account modifications, and correlate with subsequent abnormal API calls that exfiltrate or modify user data.
|
|
Analytic 1950
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0393
|
Detects deletion of suspicious files (e.g., payloads, temp exes, scripts) via `rm`, `unlink`, or secure deletion tools like `shred`, especially when performed by unexpected users or shortly after execution.
|
|
Analytic 1586
|
ESXi shell or SSH access issuing `esxcli network diag ping` or viewing routing tables to identify connected hosts.
|
|
Analytic 0143
|
Detect sudo activity with NOPASSWD in /etc/sudoers or disabling tty_tickets, followed by immediate privileged commands (e.g., echo 'Defaults !tty_tickets' >> /etc/sudoers).
|
|
Analytic 1941
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1635
|
Detects exploitation of macOS security and integrity services, such as Gatekeeper, XProtect, or EDR agents. Defender observations include unsigned processes attempting privileged operations, abnormal termination of security daemons, or modification of system integrity logs.
|
|
Analytic 0951
|
Monitors binary modification in /Applications and system library paths. Detects unsigned or improperly signed binaries executed after modification. Tracks Gatekeeper or notarization bypass attempts tied to modified binaries.
|
|
Analytic 0675
|
Detects forged Kerberos Silver Tickets by identifying anomalous Kerberos service ticket activity such as malformed fields in logon events, TGS requests without interaction with the KDC, and access attempts using service accounts outside expected hosts/resources. Also monitors suspicious processes accessing LSASS memory for credential dumping.
|
|
Analytic 1194
|
CLI or automated utilities accessing raw device volumes or flash storage directly (e.g., via `copy flash:`, `format`, or `partition` commands).
|
|
Analytic 1386
|
Hidden files via 'chflags hidden' or Apple-specific attributes, LaunchAgents/LaunchDaemons placed in non-standard hidden directories. Defender view: detect command execution modifying file flags and unusual plist creation in hidden paths.
|
|
Analytic 0589
|
Registry read access associated with suspicious or non-interactive processes querying system config, installed software, or security settings.
|
|
Analytic 0832
|
Detects execution of archiving utilities (tar, gzip, bzip2, xz, zip, openssl) followed by suspicious archive file creation. Correlates archive creation in temporary or staging directories with execution of commands involving compression or encryption options.
|
|
Analytic 0340
|
Creation or modification of Login Items using AppleScript or Service Management Framework. Detection focuses on file creation/modification of `backgrounditems.btm`, new executables in `Contents/Library/LoginItems/`, use of `SMLoginItemSetEnabled` API, or suspicious processes triggered post-login without user interaction. Behavioral pivot includes anomalous AppleEvents, suspicious parent-child process pairs, and login-triggered execution chains.
|
|
Analytic 0389
|
Detects credential harvesting via userland API hooking (e.g., SetWindowsHookEx, IAT, or inline patching) by correlating memory modifications with hook installation functions and suspicious module loads in credential-sensitive processes like lsass.exe, explorer.exe, or winlogon.exe.
|
|
Analytic 1332
|
Monitor resolver logs and auditd events for domains resolving to a rotating set of IPs within very short TTL intervals. Correlate high query rates from non-browser applications (e.g., python, curl).
|
|
Analytic 0513
|
Process or script enumerates network shares via CLI (net view/net share, PowerShell Get-SmbShare/WMI) or OS APIs (NetShareEnum/ srvsvc.NetShareEnumAll RPC) → bursts of outbound SMB/RPC connections (445/139, \\host\IPC$ / srvsvc) to many hosts inside a short window → optional follow-on file listing or copy operations.
|
|
Analytic 0754
|
vSphere API logins (vimService) or SSH to ESXi host followed by unauthorized shell commands or lateral remote logins from the ESXi host.
|
|
Analytic 1512
|
Processes (tar, curl, python scripts) accessing large file sets and initiating outbound HTTPS POST requests with payload sizes inconsistent with baseline activity. Defender perspective: detect abnormal sequence of file archival followed by encrypted uploads to external web services.
|
|
Analytic 1989
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0806
|
Detects crontab job additions or modifications via `crontab` utility or direct edits, especially those created by interactive users executing hidden or renamed scripts.
|
|
Analytic 0628
|
Detects anomalous use of COM objects for execution, such as Office applications spawning scripting engines, enumeration of COM interfaces via registry queries, or processes loading atypical DLLs through COM activation. Correlates process creation, module loads, and registry queries to flag suspicious COM-based code execution or persistence.
|
|
Analytic 2003
|
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
Once adversaries have provisioned a server (ex: for use as a command and control server), internet scans may reveal servers that adversaries have acquired. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021)
|
|
Analytic 0230
|
Adversary leverages root or sudo access to alter system banners, web content directories (e.g., /var/www/html), or login configurations (/etc/issue). File creation or overwrites may coincide with suspicious script execution or cron job activity.
|
|
Analytic 1035
|
Detects tampered hardware or firmware via anomalous host status telemetry. Behavioral chain: (1) Pre-OS or firmware components exhibit unexpected version changes, signature failures, or modified boot paths; (2) System management/firmware tools log hardware inventory drift; (3) Sensor health telemetry or boot attestation events fail baseline checks; (4) Follow-on process execution from altered firmware or unknown drivers after boot.
|
|
Analytic 0489
|
High-frequency, repetitive service requests (e.g., HTTP, TLS renegotiation) originating from a single or small set of source IPs targeting endpoint web services or application ports, leading to exhaustion of CPU or memory on targeted Windows services.
|
|
Analytic 0264
|
Adversary adds a new Outlook rule with modified or obfuscated PR_RULE_MSG_NAME and PR_RULE_MSG_PROVIDER attributes using MFCMapi or Ruler. Rule is triggered when email arrives, executing embedded or external code. Mailbox audit logs or Unified Audit Log shows automated rule-triggered action without user interaction.
|
|
Analytic 1077
|
Detects adversary behavior where a newly created or renamed user account closely resembles existing service or administrator accounts to blend in and avoid detection. Common patterns include prefix/suffix modifications, homoglyphs, or use of names like 'admin1', 'adm1n', or 'backup_help'.
|
|
Analytic 0401
|
Unexpected processes (e.g., bash, python, custom binaries) dynamically loading libcrypto or performing AES/RC4 encryption operations, then initiating outbound sessions with abnormal byte entropy or asymmetric traffic patterns.
|
|
Analytic 0235
|
An adversary running with SYSTEM-level privileges executes commands or accesses registry keys to dump the SAM hive or directly reads sensitive local files from the config directory. This behavior often involves sequential access to HKLM\SAM, HKLM\SYSTEM, and creation of .save or .dmp files, enabling offline hash extraction.
|
|
Analytic 0962
|
A user is socially engineered (web page, email, document) to open Run/PowerShell/CMD and paste an obfuscated one-liner. The chain is: (1) user context active in a browser/email/office app → (2) process creation of a command interpreter with suspicious arguments (base64/Invoke-Expression/web download/pipeline to shell) → (3) optional file drop in %TEMP% or %APPDATA% → (4) outbound network connection to an external domain. Events are correlated within a short window and with consistent user/session.
|
|
Analytic 0260
|
Detects creation or alteration of LaunchAgents or LaunchDaemons with corresponding plist modification followed by execution of associated binaries.
|
|
Analytic 0743
|
Background launch agents/daemons with high CPU use and network access to external mining services.
|
|
Analytic 1307
|
macOS environmental keying behavioral chain: (1) System information discovery through native utilities (system_profiler, sw_vers, hostname, dscl) and Security framework queries, (2) Hardware and software enumeration including serial numbers, installed applications, and system versions, (3) Network configuration assessment (networksetup, scutil) and wireless network discovery, (4) Keychain and security context validation, (5) Unified Logs correlation with cryptographic framework usage (CommonCrypto, Security.framework), (6) Application bundle execution following environmental validation
|
|
Analytic 0601
|
Detection of Mach-O binaries or AppleScripts that contain nested, encoded, or run-only embedded payloads dropped at runtime.
|
|
Analytic 0201
|
Anomalous access to cloud web applications using session tokens without corresponding MFA/credential validation, often from unusual locations or device fingerprints.
|
|
Analytic 1280
|
Enumeration of saved Wi-Fi profiles and cleartext password retrieval using `netsh wlan` or API-level access to `wlanAPI.dll`.
|
|
Analytic 0181
|
Execution of processes using nohup or shell redirection to ignore SIGHUP and continue running after session termination. Defender perspective: correlation between commands including nohup, disowned jobs, or `&` suffix with continued process execution after parent terminal exit.
|
|
Analytic 1271
|
Anomalous creation or mounting of hidden partitions or virtual file systems. Defender view: detection of registry modifications linked to non-standard file systems, suspicious disk I/O patterns, or bootkit-like behavior where hidden volumes are accessed outside normal file system APIs.
|
|
Analytic 0370
|
Detects access to cloud APIs or CLI tools to move or sync files from sensitive buckets to external endpoints using protocols like HTTPS or S3 APIs.
|
|
Analytic 0802
|
Disabling or modifying sign-in or audit log collection for user activities. Defender view: policy or configuration updates removing logging coverage for critical accounts.
|
|
Analytic 0744
|
Sudden spikes in cloud VM CPU usage with outbound traffic to mining pools and unauthorized instance creation.
|
|
Analytic 1479
|
Detects rogue or suspicious wireless access attempts by monitoring firewall, WIDS/WIPS, and controller logs. Focus is on firewall rule changes, rogue AP detection, and anomalous MAC addresses connecting to access points.
|
|
Analytic 1558
|
Detection of unset HISTFILE or modified history variables in ESXi shell sessions. Correlation of suspicious shell sessions with no recorded commands despite active usage.
|
|
Analytic 0363
|
Adversary enumeration of domain accounts using net.exe, PowerShell, WMI, or LDAP queries from non-domain controllers or non-admin endpoints.
|
|
Analytic 1327
|
Discovery via launchctl commands, or process enumeration using `ps aux | grep com.apple.` to identify daemons and services.
|
|
Analytic 0599
|
Detection of executables or scripts containing hidden embedded resources or secondary payloads, often with anomalies in file size vs. functionality or dropped child binaries.
|
|
Analytic 0707
|
Detect abnormal access to unified logs via log show or fs_usage targeting system log files. Monitor for execution of shell utilities (cat, grep) against /var/log/system.log and for plist modifications enabling verbose logging.
|
|
Analytic 0387
|
Execution of destructive CLI commands such as 'erase startup-config', 'erase flash:' or 'format disk' on routers/switches. Detect privilege level escalation preceding destructive commands.
|
|
Analytic 0921
|
Tracks modification of executables or interpreter payloads (e.g., Mach-O, dylib) that mutate across runs—using scripting engines, JIT compilers, or side-loaded plugins.
|
|
Analytic 0051
|
Correlated modification of AppCompat registry keys and execution of sdbinst.exe to install custom shim databases. Followed by DLL injection via shim behavior into target application processes.
|
|
Analytic 1192
|
Detects guest VMs or management agents issuing HTTP(S) traffic to external services without a valid patch management or backup justification.
|
|
Analytic 0505
|
Spawning of VNC-related processes (e.g., `x11vnc`, `vncserver`) coupled with authentication logs and port listening behavior on TCP 5900.
|
|
Analytic 0346
|
Shell/utility (base64, xxd -p, od, openssl enc -base64, python/perl base64 libraries) encodes data → subsequent outbound connections (curl/wget/bash TCP, socat, python requests) with high asymmetry or Base64/MIME blobs in HTTP/DNS payloads.
|
|
Analytic 1225
|
Detects suspicious usage of common application-layer protocols (e.g., HTTP, HTTPS, DNS, SMB) by abnormal processes, with high outbound byte counts or irregular ports, possibly indicating command and control or data exfiltration.
|
|
Analytic 0976
|
Monitor audit logs for setuid/setgid bit changes, executions where UID ≠ EUID (indicative of sudo or privilege escalation), and high-integrity binaries launched by unprivileged users.
|
|
Analytic 0748
|
Detects adversarial archiving by scripts or binaries calling compression libraries (libzip, zlib, bzip2). Correlates execution of Python, Perl, or compiled binaries with dynamic linking to archiving libraries and creation of compressed files in /tmp or user directories.
|
|
Analytic 0366
|
Detection of suspicious access to cloud-native secret management systems (AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, HashiCorp Vault). Focuses on abnormal secret retrieval activity, such as secrets being accessed by unusual identities, from unexpected regions, outside business hours, or at high volume. Correlates API calls to secret retrieval with surrounding authentication events, role assumptions, and anomalous execution patterns.
|
|
Analytic 0908
|
Detects enumeration of cloud network interfaces, VPCs, subnets, or peer connections using CLI or SDKs (e.g., AWS CLI, Azure CLI, GCloud CLI).
|
|
Analytic 0960
|
Use of instance metadata tokens across instances or misuse of short-lived tokens issued for different roles.
|
|
Analytic 1405
|
Detects automation macros or VBA scripts in documents that access browser file paths, read cookie data, or attempt to exfiltrate browser session tokens over HTTP.
|
|
Analytic 1557
|
Detection of PowerShell history suppression using Set-PSReadLineOption with SaveNothing or altered HistorySavePath. Correlating these options with PowerShell usage highlights adversarial evasion attempts.
|
|
Analytic 0468
|
Detects adversary clearing shell history using `history -c` or deleting/altering ~/.zsh_history or ~/.bash_history. Focus on sessions with missing or wiped history.
|
|
Analytic 2025
|
If infrastructure or patterns in malicious web content have been previously identified, internet scanning may uncover when an adversary has staged web content to make it accessible for targeting.
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on other phases of the adversary lifecycle, such as during [Spearphishing Link](https://attack.mitre.org/techniques/T1598/003) , [Spearphishing Link](https://attack.mitre.org/techniques/T1566/002) , or [Malicious Link](https://attack.mitre.org/techniques/T1204/001) .
|
|
Analytic 1603
|
Detection of unauthorized changes to boot configurations pointing to TFTP servers, unusual firmware loads during netbooting, or suspicious TFTP traffic. Correlation of boot config modifications, command history logs, and unexpected system image hashes provides detection coverage for adversaries attempting to persist via malicious TFTP boot images.
|
|
Analytic 1489
|
Sustained execution of resource-intensive processes (e.g., cryptocurrency miners), often launched via scheduled tasks, WMI, or PowerShell. These processes frequently establish persistent external connections and attempt to evade detection using masqueraded or renamed binaries.
|
|
Analytic 0594
|
Direct login to cloud-hosted virtual machines via cloud-native access methods (e.g., EC2 Instance Connect, Azure Serial Console, SSM), followed by command execution or privilege escalation on the VM
|
|
Analytic 0669
|
Detection of tampering with Apple's Unified Logging framework or modification of system log forwarding settings. Defender observes execution of logd-related commands or defaults write to logging preferences.
|
|
Analytic 0025
|
Detects inotify or auditd configuration changes that monitor system files coupled with execution of script interpreters or binaries by cron or systemd timers.
|
|
Analytic 1983
|
Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
Consider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently created/modified accounts making numerous connection requests to accounts affiliated with your organization.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: [Spearphishing via Service](https://attack.mitre.org/techniques/T1566/003)).
|
|
Analytic 1148
|
Monitor DNS queries, proxy logs, and user-agent strings for anomalous patterns associated with adversary attempts to hide infrastructure. Defenders may observe DNS resolutions to short-lived domains, abnormal WHOIS registration data, or filtering of known defensive/responder IP addresses.
|
|
Analytic 0241
|
Defender observes use of CLI tools (`find`, `grep`, `ls`, `dpkg`, `rpm`, `systemctl`, `ps aux`) to discover backup agents or config files (e.g., rsnapshot, duplicity, veeam). This often includes command lines that recursively search `/etc/`, `/opt/`, or `/var/` directories for keywords like `backup`, and parent-child relationships involving shell or Python scripts.
|
|
Analytic 0421
|
Forged SAML tokens can appear as SaaS logins where authentication succeeded without MFA, or where tokens contain claims inconsistent with the user profile. Look for concurrent sessions across different geographies with the same SAML assertion ID.
|
|
Analytic 1642
|
Suspicious access to password manager vaults (KeePassXC, gnome-keyring, pass) via memory scraping or unauthorized file reads. Detects unusual command execution involving gdb/strace attached to password manager processes.
|
|
Analytic 0024
|
Correlates unexpected modifications to WMI event filters, scheduled task triggers, or registry autorun keys with subsequent execution of non-standard binaries by SYSTEM-level processes.
|
|
Analytic 1248
|
Detection monitors modification of code signing attributes, Gatekeeper/quarantine flags, and insertion of new trust certificates via security add-trusted-cert. Identifies adversary use of xattr to strip quarantine flags from downloaded binaries. Correlates with abnormal module loads bypassing SIP protections.
|
|
Analytic 0667
|
Correlates registry modifications to EventLog or WMI Autologger keys, suspicious use of Set-EtwTraceProvider, and Sysmon configuration changes. Defender sees interruption or redirection of ETW and log event collection.
|
|
Analytic 0156
|
Detects suspicious memory access attempts targeting the `securityd` process. Observes tools invoking process memory read operations (e.g., ptrace, task_for_pid) against `securityd`. Correlates with anomalous parent process lineage, root privilege escalation, or repeated unauthorized attempts.
|
|
Analytic 0979
|
Detect sudden privilege escalations such as IAM role changes, user-assigned privilege boundaries, or elevation via assumed roles beyond normal behavior.
|
|
Analytic 1050
|
Execution of AppleScript, bash, or launchd jobs that invoke delay functions (e.g., sleep, delay in AppleScript) with limited parent interaction and staged follow-on commands.
|
|
Analytic 0625
|
Detects script or binary execution initiated via JAMF, Munki, or custom MDM agents outside of baseline, or JAMF launching new Terminal or osascript processes from remote command payloads.
|
|
Analytic 0404
|
Flows showing encrypted payloads with high entropy not matching TLS handshake patterns, particularly when occurring on non-standard ports. Defender observes NetFlow/IPFIX byte distribution anomalies or IDS/IPS detecting symmetric encryption patterns without associated key exchange.
|
|
Analytic 1263
|
Rapid login failures across different users from a single IP address, targeting SSH or PAM login with distinct username-password pairs
|
|
Analytic 0592
|
Domain logins using network accounts or mobile accounts via Open Directory or Active Directory plugins, especially outside business hours or on atypical endpoints.
|
|
Analytic 0804
|
Disabling or altering security and audit logs in SaaS admin panels (e.g., Slack, Zoom, Salesforce). Defender view: API calls or admin console changes that stop event exports or logging integrations.
|
|
Analytic 0529
|
OAuth token usage for Exchange Online or SharePoint API access without preceding login or from unauthorized clients.
|
|
Analytic 1475
|
Malicious VIB installation for persistence via `esxcli software vib install` using `--force` or `--no-sig-check`, enabling custom startup scripts or firewall rules. Behavior chain: (1) unsigned/suspicious VIB installation → (2) startup script or binary placed in persistent boot path → (3) persistence across reboot via /etc/rc.local.d or other boot hook).
|
|
Analytic 0644
|
Monitors Gatekeeper, spctl, and unified log entries for binaries executed with unexpected or untrusted signatures. Correlates file metadata changes with process launches where signature validation is skipped, altered, or fails but the process still executes.
|
|
Analytic 2027
|
Monitor for contextual data about an Internet-facing resource gathered from a scan, such as running services or ports that may buy, lease, or rent infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
Once adversaries have provisioned infrastructure (ex: a server for use in command and control), internet scans may help proactively discover adversary acquired infrastructure. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021) Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
Monitor for queried domain name system (DNS) registry data that may buy, lease, or rent infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
Monitor for logged domain name system (DNS) data that may buy, lease, or rent infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
Consider use of services that may aid in tracking of newly acquired infrastructure, such as WHOIS databases for domain registration information. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
|
|
Analytic 1286
|
Abuse of system-generated or default privileged accounts such as 'root' or 'vpxuser' logging into ESXi hosts.
|
|
Analytic 0998
|
Linux permission escalation behavioral chain: (1) Process creation of permission modification utilities (chmod, chown, chgrp, setfacl) with suspicious parameters indicating privilege escalation intent, (2) System call analysis revealing direct file metadata manipulation (chmod, fchmod, chown, fchown syscalls), (3) Extended attribute and ACL modifications targeting critical system paths, (4) Temporal correlation with subsequent file access or process execution from modified locations, (5) Anomalous permission patterns deviating from system baselines
|
|
Analytic 0723
|
Forged web credentials in Office Suite contexts may appear as abnormal authentication headers in Outlook or Teams traffic, or unexplained OAuth grants in M365/Azure logs. Defenders should correlate token usage events with missing authentication flows and mismatched device/user context.
|
|
Analytic 1067
|
Identifies transfer of base64, uuencoded, or high-entropy files over HTTP, FTP, or custom protocols in lateral movement or exfiltration streams.
|
|
Analytic 1985
|
Consider analyzing malware for features that may be associated with the adversary and/or their developers, such as compiler used, debugging artifacts, or code similarities. Malware repositories can also be used to identify additional samples associated with the adversary and identify development patterns over time. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.
Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.
Consider use of services that may aid in the tracking of capabilities, such as certificates, in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of information to uncover other adversary infrastructure.(Citation: Splunk Kovar Certificates 2017) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.
|
|
Analytic 0543
|
Detects registry and Group Policy modifications that disable or weaken MFA, suspicious PowerShell usage modifying MFA-related attributes, and anomalous login sessions succeeding without expected MFA challenge.
|
|
Analytic 1978
|
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during exfiltration (ex: [Transfer Data to Cloud Account](https://attack.mitre.org/techniques/T1537)).
|
|
Analytic 1368
|
Electron/GUI or headless RAT execution followed by LaunchAgent/Daemon persistence and persistent external connections; interactive children (osascript/sh/curl) spawned by parent.
|
|
Analytic 0028
|
Correlates Power Automate or similar logic app workflows triggered by SaaS file uploads or email rules with data forwarding or anomalous access patterns.
|
|
Analytic 2035
|
Detects user execution of newly received content or instructions shortly after external communication, including script launches, Office child process spawning, browser-to-script execution chains, or credential prompts followed by new logon sessions.
|
|
Analytic 2010
|
Monitor for suspicious email activity, such as numerous accounts receiving messages from a single unusual/unknown sender. Filtering based on DKIM+SPF or header analysis can help detect when the email sender is spoofed.(Citation: Microsoft Anti Spoofing)(Citation: ACSC Email Spoofing) Monitor for references to uncategorized or known-bad sites. URL inspection within email (including expanding shortened links and identifying obfuscated URLs) can also help detect links leading to known malicious sites.(Citation: Mandiant URL Obfuscation 2023)
Furthermore, monitor browser logs for homographs in ASCII and in internationalized domain names abusing different character sets (e.g. Cyrillic vs Latin versions of trusted sites).
Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.
Monitor and analyze traffic patterns and packet inspection associated to protocol(s), leveraging SSL/TLS inspection for encrypted traffic, that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
Furthermore, monitor network traffic for homographs via the use of internationalized domain names abusing different character sets (e.g. Cyrillic vs Latin versions of trusted sites). Also monitor and analyze traffic patterns and packet inspection for indicators of cloned websites. For example, if adversaries use HTTrack to clone websites, Mirrored from (victim URL) may be visible in the HTML section of packets.
|
|
Analytic 1226
|
Detects suspicious curl, wget, or custom socket traffic that leverages DNS, HTTPS, or IRC-style protocols with unbalanced traffic or beacon-like intervals.
|
|
Analytic 1631
|
Monitoring adversary access to sensitive process memory via the /proc filesystem to extract credential material, often involving multi-step access to /proc/[pid]/mem or /proc/[pid]/maps combined with privilege escalation or credential scraping binaries.
|
|
Analytic 0436
|
Unusual processes (e.g., powershell.exe, wscript.exe, mshta.exe) posting data to webhook endpoints (Discord, Slack, webhook.site) using HTTP POST/PUT requests. Defender perspective: suspicious process lineage followed by outbound HTTPS traffic to webhook domains.
|
|
Analytic 0945
|
Detects user or root invocation of `at` command to schedule a job, followed by job execution using LaunchServices and activity in /usr/lib/cron/at.
|
|
Analytic 0462
|
Adversary installs/uses packet-capture or raw-socket capability (WinPcap/Npcap, wpcap/packet DLLs or raw socket attach) and sets a filter. A crafted inbound packet is observed; within a short window the host process that loaded capture libraries initiates an outbound connection (e.g., reverse shell) to the packet origin.
|
|
Analytic 0700
|
Execution of Homebrew, pip3, npm, or manually downloaded PKGs from Terminal or shell, followed by the creation of startup agents, interpreter spawns, or outbound connections to unfamiliar domains. Defender links Terminal commands to plist creation, unsigned binary launches, and `python3` or `node` processes connecting to remote endpoints.
|
|
Analytic 0729
|
Inspect resolver and audit logs for processes initiating outbound connections to ports calculated from DNS response IPs. Abnormal ephemeral port usage shortly after DNS queries can indicate DNS calculation behavior.
|
|
Analytic 0658
|
Detection of modified or newly created /etc/rc.local or /etc/init.d scripts followed by suspicious execution during system startup.
|
|
Analytic 0738
|
Detects the use of mail utilities like `mail` or `mailx` to delete mailbox content, or file-level deletion of inbox files from `/var/spool/mail/` or `/var/mail/` following suspicious sessions.
|
|
Analytic 0434
|
Non-standard or rare users/locations issue CLI commands like "show clock detail" or "show timezone"; optionally followed by configuration of time/timezone or NTP sources. AAA/TACACS+ accounting and syslog correlate execution to identity, source IP, and privilege level.
|
|
Analytic 0922
|
Unusual process (e.g., `rundll32`, `mshta`, `wscript`, or custom payloads) initiates network connection to external IPs/domains that proxy C2 traffic, often over uncommon ports or high entropy HTTP/S connections.
|
|
Analytic 1408
|
Detects downloaded SVG files followed by execution of browser processes or tools like xdg-open, and rapid follow-on network connections or process spawns to interpreters like python or bash.
|
|
Analytic 1039
|
Detect unauthorized `trap` command registrations in shell startup files (e.g., .zprofile, .bash_profile, .zshrc) followed by execution chains during user terminal interaction. Use Unified Logs and EDR telemetry to correlate shell command parsing and process tree anomalies.
|
|
Analytic 0923
|
`curl`, `wget`, `ncat`, `socat`, or custom binaries initiate outbound traffic to Internet-based proxies (e.g., via VPS or CDN). Behavior may include reverse shell constructs or persistent outbound beacons.
|
|
Analytic 0483
|
Forged cookies in IaaS environments may appear as authentication attempts that bypass MFA, leveraging AssumeRole or session APIs with cookies that were never legitimately issued. Defenders should correlate cloud logs for cookie-based sessions without prior valid authentication, often followed by resource access from unfamiliar IP addresses.
|
|
Analytic 1575
|
Detects command-line or API-based creation/modification of Windows Services via `sc.exe`, `powershell.exe`, `services.exe`, or `ChangeServiceConfig`. Looks for creation/modification of autostart services via registry changes, file drops to `System32\services`, and anomalous parent-child process trees.
|
|
Analytic 1632
|
Detects unauthorized invocation of replication operations (DCSync) via Directory Replication Service (DRS), often executed by threat actors using Mimikatz or similar tools from non-DC endpoints.
|
|
Analytic 1576
|
Detects creation or modification of `systemd` service units, addition of cron jobs that invoke binaries on boot, or suspicious writes to `/etc/init.d/`. Monitors `chmod +x` and `systemctl` execution paths, especially from non-root parent processes.
|
|
Analytic 1412
|
Adversary attaches USB drive and accesses sensitive files using Finder, cp, or bash scripts.
|
|
Analytic 0138
|
Malicious Office add-ins loaded via VSTO, COM, or VBA auto-load paths. Upon launch of Word/Excel/Outlook, the add-in executes code without user action. Add-in resides in trusted directory or registered via Office COM/VBE subsystem. Behavior includes unsigned add-in execution, anomalous load context, or add-in spawning interpreter process.
|
|
Analytic 0950
|
Detects modification of system or application binaries by monitoring /usr/bin, /bin, and other privileged directories. Correlates file integrity monitoring (FIM) events with unexpected process executions or service restarts.
|
|
Analytic 1403
|
Detects access to known browser cookie files (e.g., `~/.mozilla/firefox/*.default/cookies.sqlite`, `~/.config/google-chrome/`) and suspicious reads of browser memory via `/proc/[pid]/mem` or ptrace.
|
|
Analytic 1137
|
Detects anomalous usage of local accounts to log into a system, especially accounts not typically used interactively or outside business hours.
|
|
Analytic 0859
|
Container processes accessing mounted secrets or configuration paths (e.g., /run/secrets, /mnt/config) followed by network access or credential use.
|
|
Analytic 1173
|
Detects internal hosts generating large outbound FTP/TFTP/SMB sessions to external IPs, or file transfers using non-standard ports and application mismatches (e.g., FTP over port 80).
|
|
Analytic 1542
|
Monitor CLI 'reload' commands issued without scheduled maintenance, and correlate to TACACS+/AAA logs for privilege validation.
|
|
Analytic 1639
|
SSH login detected via Unified Logs, followed by unusual process execution, especially outside normal user behavior patterns.
|
|
Analytic 0940
|
Detection of msiexec.exe running installer packages that result in anomalous process creation. Look for unexpected binaries executed by msiexec or custom action DLLs in the temp directory.
|
|
Analytic 0617
|
Detects USB block device mount followed by file access in sensitive directories or high-volume copy operations by user-controlled processes.
|
|
Analytic 1150
|
Monitor unified logs for manipulation of proxy configurations, DNS resolution, or filtering rules. Adversaries may redirect responses or use trusted domains that later resolve to malicious C2 infrastructure.
|
|
Analytic 1954
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1605
|
Adversary invokes 'useradd', 'adduser', or equivalent system commands or scripts to create local users. Detection focuses on command execution and audit trail of passwd/shadow file modifications.
|
|
Analytic 0050
|
Adversary attempts to detect monitoring agents such as Little Snitch, KnockKnock, or other system daemons via process listing (`ps -e`), application folder checks, and system extension listing.
|
|
Analytic 0618
|
Detects external volume mount with Finder, Terminal, or script-initiated file copy from user profiles, sensitive folders, or cloud storage sync directories to USB.
|
|
Analytic 1313
|
Adversaries using WinRM to remotely execute commands, launch child processes, or access WMI. The detection chain includes service use, network activity, remote session logon, and process creation within a short temporal window.
|
|
Analytic 2040
|
Detects crafted activity resulting in crashes or impairment of endpoint security extensions, network filters, launch daemons, or telemetry agents. Correlates process activity, system extension state changes, and telemetry interruption.
|
|
Analytic 1432
|
Identifies CLI interpreter access (e.g., Cisco IOS, Juniper JUNOS) via `enable` mode or scripting-capable sessions used by uncommon accounts or from unknown IPs.
|
|
Analytic 0157
|
Detects adversaries attempting to attach debuggers or memory dump utilities to credential storage daemons analogous to macOS `securityd`. Observes ptrace syscalls, /proc//mem access, or gcore dumps against sensitive processes. Correlates anomalies with privilege escalation or credential dumping attempts.
|
|
Analytic 0064
|
Attacker disables VM-related services or stops VMs forcibly to target vmdk or logs. Behavioral chain: esxcli or vim-cmd stop + audit log showing user privilege use + datastore file manipulation.
|
|
Analytic 1109
|
File creation of unauthorized script (e.g., .php, .sh) in /var/www/html followed by execution of unexpected system utilities (e.g., curl, bash, nc) by apache/nginx
|
|
Analytic 0022
|
Developer or CI invokes package managers/compilers (apt/yum + build-essential, npm/yarn/pnpm, pip/pip3, gem, cargo, go, maven/gradle). These write executable or script files into PATH or project dirs and immediately execute embedded lifecycle hooks (preinstall/postinstall, setup.py, npm scripts) that spawn shells or curl/wget, followed by egress to unfamiliar registries or domains.
|
|
Analytic 1371
|
Detection of adversary disabling endpoint security tools by unloading launch agents/daemons, modifying configuration profiles, or disabling Gatekeeper/XProtect/logging settings, or removing endpoint agents followed by telemetry loss.
|
|
Analytic 1171
|
Detects Automator, AppleScript, or Terminal executing curl, lftp, or TFTP for binary transfer to untrusted IPs or unusual ports.
|
|
Analytic 0415
|
Adversary destroys virtual disks (VMDK), images, or VMs by invoking `vim-cmd`, deleting datastore contents, or purging snapshots.
|
|
Analytic 0633
|
Processes initiating outbound connections on uncommon ports or using protocols inconsistent with the assigned port. Correlating process creation with subsequent network connections reveals anomalies such as svchost.exe or Office applications using high, atypical ports.
|
|
Analytic 2019
|
Internet scanners may be used to look for patterns associated with malicious content designed to collect host hardware information from visitors.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: ATT ScanBox)
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0088
|
Detects suspicious updates to conditional access or MFA enforcement policies in identity providers such as Entra ID, Okta, or JumpCloud. Focus is on removal of policy blocks, addition of broad exclusions, or registration of adversary-controlled MFA methods, followed by anomalous login activity that takes advantage of the modified policies.
|
|
Analytic 2023
|
Monitor for queried domain name system (DNS) registry data that may compromise third-party DNS servers that can be used during targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
Monitor for logged domain name system (DNS) registry data that may compromise third-party DNS servers that can be used during targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
|
|
Analytic 0021
|
Adversary manipulates dependencies/dev tools used by developers or CI: a package manager (npm/yarn/pnpm, pip/pipenv, nuget/dotnet, chocolatey/winget, maven/gradle) or a compiler/IDE downloads or restores content; files are written under project paths and execution paths (node_modules, packages, .nuget, .gradle, .m2, %AppData%\npm, %UserProfile%\.cargo\bin, temp build dirs). First run of newly written components triggers scripts (preinstall/postinstall), shell/PowerShell spawning, or loader DLLs, followed by network egress to non-approved registries/CDNs.
|
|
Analytic 0431
|
A process (often spawned by a shell, interpreter, or malware implant) executes time discovery via commands (date, timedatectl, hwclock, cat /etc/timezone, /proc/uptime) or direct syscalls (time(), clock_gettime) and is (optionally) followed by scheduled task creation/modification (crontab, at) or conditional sleep logic.
|
|
Analytic 0576
|
Cause→effect chain: (1) A user or service launches an indirection utility (e.g., forfiles.exe, pcalua.exe, wsl.exe, scriptrunner.exe, ssh.exe with -o ProxyCommand/LocalCommand). (2) That utility spawns a secondary program/command (PowerShell, cmd, msiexec, regsvr32, curl, arbitrary EXE) and/or opens outbound network connections. (3) Optional precursor modification of SSH config to persist LocalCommand/ProxyCommand. Correlate process creation, command/script content, file access to %USERPROFILE%\.ssh\config, and network connections from the utility or its child.
|
|
Analytic 0615
|
Detection of ESXi escape attempts by monitoring for anomalies in hypervisor logs such as unexpected VM operations, privilege escalation events, or attempts to load malicious kernel modules within the hypervisor environment.
|
|
Analytic 1303
|
Detects suspicious registration of new password filter DLLs into the authentication process. Correlates registry modifications to LSASS Notification Packages with subsequent DLL creation and loading events. Observes anomalous file placement of DLLs in system directories followed by LSASS loading the new filter during logon/password change activity.
|
|
Analytic 0536
|
Drive enumeration using PowerShell (`Get-PSDrive`), `wmic logicaldisk`, or Win32 API indicative of local volume enumeration by non-admin users or executed outside of baseline system inventory scripts.
|
|
Analytic 1298
|
Detects adversary tampering of shared directories via file drops (e.g., malicious LNK, EXE, VBS) followed by user execution or suspicious network activity.
|
|
Analytic 1972
|
Consider use of services that may aid in the tracking of certificates in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of certificate information to uncover other adversary infrastructure.(Citation: Splunk Kovar Certificates 2017)
Detection efforts may be focused on related behaviors, such as [Web Protocols](https://attack.mitre.org/techniques/T1071/001) or [Asymmetric Cryptography](https://attack.mitre.org/techniques/T1573/002).
|
|
Analytic 1425
|
Unusual OAuth app registration followed by user-granted OAuth tokens and subsequent high-privilege resource access via those tokens.
|
|
Analytic 1095
|
Detects DLL injection through correlation of memory allocation and writing to remote process memory (e.g., VirtualAllocEx, WriteProcessMemory), followed by remote thread creation (e.g., CreateRemoteThread) that loads a suspicious or unsigned DLL using LoadLibrary or reflective loading.
|
|
Analytic 0258
|
Detects creation or modification of scheduled tasks using schtasks.exe, at.exe, or COM objects followed by execution of outlier processes tied to the scheduled job.
|
|
Analytic 1130
|
Discovery of connected SaaS applications, APIs, or configurations within platforms like Salesforce, Slack, or Zoom. Defender perspective includes enumeration of available integrations, abnormal querying of service metadata, and follow-on attempts to exploit or persist via discovered services.
|
|
Analytic 0551
|
Suspicious creation or modification of inbox rules through PowerShell (New-InboxRule, Set-InboxRule) to automatically delete, move, or hide emails. Defender perspective: unusual rule activity correlated with mailbox access and filtering patterns.
|
|
Analytic 0376
|
Creation of VSCode tunnel configuration file combined with interactive remote session via code CLI or ssh with JetBrains gateway.
|
|
Analytic 0810
|
Detects login to admin consoles (e.g., Microsoft 365 Admin Center) from unrecognized users, devices, or geolocations followed by non-API data review or configuration read actions that suggest GUI dashboard use.
|
|
Analytic 0474
|
Firmware flash utility invoked with elevated privileges followed by raw access to firmware device path or changes to boot configuration.
|
|
Analytic 1279
|
Excessive login attempts followed by success from SaaS apps like O365, Dropbox, etc.
|
|
Analytic 1102
|
Adversary runs 'system_profiler SPApplicationsDataType' or queries plist files to enumerate software via Terminal or scripts.
|
|
Analytic 0435
|
Detection focuses on adversaries placing or modifying malicious dylibs in locations searched by legitimate applications. From the defender’s perspective, observable patterns include unexpected creation or modification of dylib files in application bundle paths, unusual module loads by processes compared to historical baselines, and execution of applications loading dylibs from suspicious directories (e.g., /tmp, user-controlled paths). Correlation across file system changes, process execution, and module loads provides high-fidelity detection.
|
|
Analytic 1414
|
Detects staged file access (e.g., archive or obfuscation), followed by an encrypted outbound connection (TLS/HTTPS) from unusual processes such as curl/wget, Python scripts, or custom binaries.
|
|
Analytic 1212
|
Detects adversary activity aimed at accessing LSA Secrets, including registry key export of HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets or memory scraping via tools such as Mimikatz or PowerSploit's Invoke-Mimikatz.
|
|
Analytic 1260
|
Adversary adds federated identity provider (IdP) or modifies tenant domain authentication from Managed to Federated. Detected via API, PowerShell, or Admin Portal through federation events like `Set domain authentication`, `Add federated identity provider`, or `Update-MsolFederatedDomain`.
|
|
Analytic 0380
|
Detects non-interactive or script-driven email transmission using tools like `sendmail`, `mailx`, or custom SMTP scripts by background processes, especially when sending attachments or large payloads.
|
|
Analytic 0273
|
Processes that utilize AppleScript, `CGWindowListCopyWindowInfo`, or `NSRunningApplication` APIs to list active application windows and foreground processes.
|
|
Analytic 2064
|
Detection identifies execution of scripts containing high concentrations of invisible Unicode characters followed by decoding or interpretation behaviors (e.g., base64 decode, eval) and subsequent process or network activity. Emphasis is placed on mismatch between file entropy/structure and execution output.
|
|
Analytic 0751
|
SSH session from new source IP followed by interactive shell or privilege escalation (e.g., sudo, su) and outbound lateral connection.
|
|
Analytic 0298
|
Correlation of inbound emails with embedded links followed by user-driven browser navigation to suspicious or obfuscated domains. Detection chain includes malicious URL in email → user click recorded in Office logs → browser process spawning unusual child processes (e.g., PowerShell, cmd) or download activity.
|
|
Analytic 1005
|
Repeated SSH, VPN, or RDP gateway authentication attempts from external IPs → subsequent successful logon → remote shell or lateral movement activity (e.g., scp/sftp).
|
|
Analytic 1387
|
Abuse of VMFS or ESXi shell to hide datastore files, renaming/moving VMDK or VMX files into hidden directories. Defender view: anomalous ESXi shell commands or file operations obscuring VM artifacts.
|
|
Analytic 1296
|
Unsigned or suspicious applications initiating network traffic claiming to be browser, mail, or cloud clients. Detects impersonation via TLS fingerprint and User-Agent string deviation.
|
|
Analytic 1072
|
Adversary use of bash/zsh or AppleScript to locate files and exfil targets like user keychains or documents.
|
|
Analytic 0220
|
Adversary exploits Apache/Nginx/app servers. Chain: (1) suspicious requests in access logs → (2) spike of 5xx or WAF blocks → (3) web server or interpreter (apache2/nginx/php-fpm/node/python) spawns /bin/sh, curl, wget, socat, or writes webshell → (4) outbound callback.
|
|
Analytic 1377
|
Creation of outbound connections on alternate ports or using covert transport (e.g., ICMP, DNS) from non-network-intensive processes, following known disruption or blocked traffic.
|
|
Analytic 0772
|
Behavioral chain of a user being granted elevated privileges or roles in Entra ID or Okta following suspicious login or account creation activity.
|
|
Analytic 0058
|
Inbound binary payloads transferred over HTTP/S with compressed or encoded headers, lacking signature markers or metadata indicative of compiler/toolchain.
|
|
Analytic 0222
|
Adversary exploits containerized app via ingress or service. Chain: (1) suspicious request in ingress/app logs → (2) container process spawns a shell/exec/sidecar (kubectl exec/docker exec) → (3) egress to Internet or metadata service (169.254.169.254).
|
|
Analytic 1220
|
Execution of SyncAppvPublishingServer.vbs through wscript.exe with a command-line containing embedded PowerShell, proxying malicious PowerShell execution through a Microsoft-signed VBScript interpreter to evade detection and restrictions.
|
|
Analytic 0257
|
Adversary executes CLI commands like `show users`, `show ssh`, or attempts to dump AAA user lists from routers or switches.
|
|
Analytic 1028
|
Abuse of Regsvcs.exe or Regasm.exe to execute arbitrary code embedded in .NET assemblies via [ComRegisterFunction]/[ComUnregisterFunction]. Behavioral chain: (1) Process creation of regsvcs/regasm with suspicious assembly paths/flags → (2) Assembly/DLL load inside regsvcs/regasm → (3) Registry writes to HKCR\CLSID/ProgID during COM registration → (4) Optional child process or network activity spawned by installer/registration code.
|
|
Analytic 1388
|
Malicious macros or embedded objects hidden within Office documents by renaming streams or using hidden OLE objects. Defender view: detection of hidden macro streams or objects in documents correlated with anomalous execution.
|
|
Analytic 0318
|
Detects enumeration of local groups using common binaries (groups, getent, cat /etc/group) or scripting with suspicious lineage.
|
|
Analytic 2016
|
Much of this takes place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0153
|
Detection of unauthorized modifications to Windows root certificate stores by monitoring registry keys, certificate installation processes, and creation of new certificate entries not in baseline trusted lists.
|
|
Analytic 0881
|
Office application auto-loads a non-standard DLL during startup triggered via Office Test Registry key, often without macro warning banners. DLL persistence mechanism circumvents traditional macro defenses.
|
|
Analytic 1164
|
Detects AppleScript execution via 'osascript', NSAppleScript/OSAScript APIs, and abnormal application control events across user sessions. Focuses on causal chains such as osascript spawning child processes, script-induced keystrokes, or API-backed dialog spoofing.
|
|
Analytic 1024
|
Encrypted traffic or ICMP tunneling from border routers to internal routers or unknown external IPs. Forwarded traffic shows consistent hop-to-hop relaying without matching configured VPN or expected network topology.
|
|
Analytic 1480
|
1) New or updated software is delivered/installed from atypical sources or with signature/hash mismatches; 2) installer/updater writes binaries to unexpected paths or replaces existing signed files; 3) first run causes unsigned/abnormally signed modules to load or child processes to execute, optionally followed by network egress to new destinations.
|
|
Analytic 1315
|
Cause→effect chain: (1) User app/browser/archiver logs an open/click or abnormal exit, (2) new executable/script/archive extracted into $HOME/Downloads, /tmp, or ~/.cache, (3) parent app spawns shell/interpreter (bash/sh/python/node/curl/wget) or desktop file, and (4) new outbound connection(s) from the child lineage.
|
|
Analytic 1571
|
Unusual processes (e.g., powershell.exe, excel.exe) accessing large local files and subsequently initiating HTTPS POST requests to domains associated with cloud storage services (e.g., dropbox.com, drive.google.com, box.com). Defender perspective: correlation between file reads in sensitive directories and high outbound traffic volume to known storage APIs.
|
|
Analytic 0331
|
Detects execution of image viewers or PowerShell scripts accessing or decoding files with mismatched MIME headers or embedded script-like byte patterns; often correlated with suspicious parent-child process lineage and outbound connections.
|
|
Analytic 0801
|
Cloud API events where logging services are stopped, deleted, or modified in a way that disables audit visibility. Defender view: unauthorized StopLogging, DeleteTrail, or UpdateSink operations correlated with privileged user activity.
|
|
Analytic 0741
|
Persistent high CPU utilization combined with suspicious command-line execution (e.g., mining tools or obfuscated scripts) and outbound connections to mining/proxy networks.
|
|
Analytic 1233
|
Dynamic or static port forwarding rules added to route traffic through an internal host, or configuration changes to proxy firewall rules not aligned with baselined policy.
|
|
Analytic 0894
|
Disabling of security macros or safe mode settings within Word/Excel/Outlook. Detect registry edits or configuration file changes that weaken macro enforcement.
|
|
Analytic 0645
|
Detects adversarial abuse of systemd timers by correlating file creation/modification of .timer and .service units in system directories with the execution of abnormal child processes launched by 'systemd' (PID 1), especially as root.
|
|
Analytic 0948
|
Detects anomalous use of macOS XPC services for code execution. Monitors for processes invoking privileged XPC daemons with abnormal parameters, unexpected binaries communicating over NSXPCConnection, or helper tools executing code outside of their expected parent process lineage. Correlates process access attempts to system-level daemons, privilege escalations via XPC misconfigurations, and injection of malicious payloads through inter-process communication.
|
|
Analytic 0971
|
Excessive outbound traffic via `ping`, `curl`, or custom scripts indicating flooding behavior, especially with no UI context or user interaction.
|
|
Analytic 1285
|
Use of known default service accounts or root-level cloud accounts performing authentication or changes to IAM policy.
|
|
Analytic 0481
|
Defenders should monitor for suspicious enumeration of cloud infrastructure components via APIs or CLI tools. Observable behaviors include repeated listing or description operations for compute instances, snapshots, storage buckets, and volumes. From a defender’s perspective, risky activity is often identified by new or untrusted identities making discovery calls (e.g., DescribeInstances, ListBuckets, az vm list, gcloud compute instances list), enumeration from unusual geolocations or IPs, or rapid multi-service discovery in sequence. Correlating discovery API usage with later snapshot creation or instance modification provides further context of adversary behavior.
|
|
Analytic 0335
|
Password changes or account deletions via 'passwd', 'userdel', or 'chage' preceded by interactive shell or remote command execution from non-privileged accounts.
|
|
Analytic 0970
|
Kernel or userland processes generating high-rate network traffic (ICMP, UDP, TCP SYN) beyond expected interface throughput or user behavior norms.
|
|
Analytic 0176
|
Unquoted service or shortcut paths that contain spaces and allow path interception by higher-level executables. Defender observes registry service configurations with unquoted paths, file creation of executables in parent directories of unquoted paths, and subsequent process execution from unexpected locations.
|
|
Analytic 1353
|
Suspicious enumeration of attached peripherals via WMI, PowerShell, or low-level API calls potentially chained with removable device interactions.
|
|
Analytic 0538
|
Disk enumeration via `diskutil list` or `system_profiler SPStorageDataType` run outside of user login or not associated with system inventory tools
|
|
Analytic 1939
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1099
|
Monitor for runtime manipulation by observing changes in application bundles, unexpected signing modifications, and runtime API calls that inject or alter how data is displayed. Detect alterations in CFNetwork or CoreFoundation frameworks responsible for rendering data.
|
|
Analytic 0764
|
Correlation of registry key modification for Run/RunOnce with abnormal parent-child process relationships and outlier execution at user logon or system startup
|
|
Analytic 1546
|
Detection of valid account abuse in IdP logs via geographic anomalies, impossible travel, risky sign-ins, and multiple MFA attempts or failures.
|
|
Analytic 1015
|
Execution of utilities (e.g., ping, tracert, Test-NetConnection) or scripted methods to test Internet connectivity by interacting with external IPs/domains.
|
|
Analytic 1433
|
Detection focuses on unauthorized manipulation of .NET AppDomainManager behavior. Defenders may observe suspicious creation of new AppDomains within trusted processes, anomalous loading of assemblies via non-standard configuration files, or registry/environment variable changes redirecting AppDomainManager to malicious assemblies. Correlated events include config file tampering, new process creation of .NET host processes (e.g., w3wp.exe, powershell.exe) with modified runtime parameters, and module loads of unusual or unsigned .NET DLLs.
|
|
Analytic 1231
|
AppleScript, LaunchAgents, or remote login services (`ssh`, `networksetup`) establishing proxy tunnels or dynamic port forwards to external IPs or alternate local hosts.
|
|
Analytic 1587
|
Execution of discovery commands like `show cdp neighbors`, `show arp`, and other interface-level introspection on Cisco or Juniper devices.
|
|
Analytic 1043
|
Execution of esxcli commands to enumerate datastore, configuration files, or directory structures by unauthorized or remote users.
|
|
Analytic 0161
|
Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).
|
|
Analytic 1111
|
Detects abuse of AuthorizationExecuteWithPrivileges API to gain elevated privileges via user credential prompts, typically through invocation of /usr/libexec/security_authtrampoline. Detection involves correlation of API usage, binary reputation, and prompt context.
|
|
Analytic 0177
|
Defenders may detect abuse of container administration commands by observing anomalous use of management utilities (`docker exec`, `kubectl exec`, or API calls to kubelet) correlated with unexpected process creation inside containers. Behavioral chains include unauthorized API requests followed by command execution within running pods or containers, often originating from unusual user accounts, automation scripts, or IP addresses outside the expected cluster management plane.
|
|
Analytic 1993
|
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: [Phishing](https://attack.mitre.org/techniques/T1566)).
|
|
Analytic 0967
|
Detection of xclip or xsel access to clipboard buffers outside of user terminal context, especially when chained to staging (gzip, base64) or network exfiltration (curl, scp).
|
|
Analytic 1029
|
Detection of AppCert DLL abuse involves correlating registry modifications to the AppCertDLLs key with subsequent unexpected DLL load behavior during process creation events. Specifically, defenders can observe abnormal DLLs being loaded into standard Windows processes after changes to the 'AppCertDLLs' registry value. Monitoring CreateProcess-family API executions with injected DLLs and linking those DLLs back to recent registry edits is key to identifying misuse. This is often accompanied by elevated privileges and potential lateral movement or discovery behavior.
|
|
Analytic 1239
|
Account created in a running container (e.g., via 'useradd' or by modifying /etc/passwd directly). Detectable via runtime telemetry (e.g., Falco or eBPF hooks).
|
|
Analytic 1505
|
Detects unexpected access or usage of cloud productivity tools (e.g., downloading large numbers of files, creating external shares) by internal users.
|
|
Analytic 1998
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
|
|
Analytic 0891
|
Cloud control plane actions disabling security services (CloudTrail logging, GuardDuty, Security Hub). Detect IAM role abuse correlating with service disable events.
|
|
Analytic 1451
|
Crafted ‘synful knock’ patterns toward routers/switches (same src hits interface/broadcast/network address on same port in short order) followed by ACL/telnet/SSH enablement or module change. Detect device image/ACL updates then a new mgmt session.
|
|
Analytic 0344
|
Detects mounting of external volumes followed by high-volume or sensitive file access via Finder, terminal, or third-party apps (e.g., rsync, zip).
|
|
Analytic 2031
|
Detection of HTTP outbound requests with inconsistent or spoofed User-Agent headers from command-line tools (e.g., curl, wget, python requests) following interactive user shells or scheduled jobs outside of normal user session behavior.
|
|
Analytic 0964
|
User pastes an obfuscated command into Terminal.app/iTerm2 that decodes or downloads code and executes. Detects Terminal/iTerm2 spawning bash/zsh/python with suspicious pipeline/base64 patterns followed by file writes in ~/Library or /tmp and outbound network connections.
|
|
Analytic 0424
|
Detects file access or compression utilities followed by outbound connections using curl, wget, ftp, or custom binaries communicating over unencrypted protocols.
|
|
Analytic 0336
|
Execution of dscl or sysadminctl commands to disable, delete, or modify users combined with anomalous process ancestry or terminal session launch.
|
|
Analytic 1167
|
Repetitive triggering of GUI or backend application workflows that cause increased CPU/memory usage, logged in unified logs as spin reports or crash dumps.
|
|
Analytic 0984
|
Detects renamed binaries or scripts placed into trusted paths like /usr/bin or /lib with mismatched metadata or unexpected creation/modification times.
|
|
Analytic 1105
|
Multiple AWS CloudTrail events indicating temporary privilege escalation via PassRole and AssumeRole targeting newly created services or non-interactive infrastructure.
|
|
Analytic 0932
|
Execution of CMSTP.exe with arguments pointing to suspicious or remote INF/SCT/DLL payloads, optionally followed by outbound network connections to untrusted IPs, process injection via COM interfaces (CMSTPLUA, CMLUAUTIL), registry modifications registering malicious profiles, or creation of suspicious INF/DLL/SCT files prior to execution.
|
|
Analytic 1958
|
Internet scanners may be used to look for patterns associated with malicious content designed to collect host information from visitors.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: ATT ScanBox)
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1311
|
Monitors Mail.app database or maildir file access, automation via AppleScript, and abnormal mail rule creation using scripting or UI automation frameworks.
|
|
Analytic 0455
|
Cause→effect chain: (1) a user or service spawns a shell/PowerShell that queries local/domain password policy via commands/cmdlets (e.g., `net accounts`, `Get-ADDefaultDomainPasswordPolicy`, `secedit /export`); (2) optional directory/LDAP reads from DCs; (3) same principal performs adjacent Discovery or credential-related actions within a short window. Correlate sysmon process creation with PowerShell ScriptBlock and Security logs.
|
|
Analytic 1358
|
Detects abuse of UNIX domain sockets, pipes, or message queues for unauthorized code execution. Correlates unexpected socket creation with suspicious binaries, abnormal shell pipelines, or injected processes establishing IPC channels.
|
|
Analytic 0379
|
Detects unauthorized use of SMTP/IMAP/POP3 by suspicious binaries (e.g., PowerShell, rundll32) to exfiltrate data or beacon via email, often bypassing proxy or content filters.
|
|
Analytic 0734
|
Detects JavaScript for Automation (JXA) via osascript or compiled scripts using OSAKit APIs. Flags execution involving system modification, inter-process scripting, or browser abuse.
|
|
Analytic 0339
|
Deletion or disablement of user accounts in platforms like Okta, Salesforce, or Zoom with anomalies in admin session attributes or mass actions within short duration.
|
|
Analytic 0674
|
Monitor for abnormal certificate enrollment events in identity platforms, unexpected use of token-signing certificates, and unusual CA configuration modifications.
|
|
Analytic 1380
|
Privileged or rarely used accounts performing bulk access to SharePoint files or metadata over a short time window, indicating potential scripted collection of sensitive internal documents.
|
|
Analytic 1625
|
Adversary modifies content in cloud-hosted websites (e.g., AWS S3-backed, Azure Blob-hosted sites) by gaining access to management consoles or APIs and uploading altered HTML/JS files.
|
|
Analytic 0175
|
Detects Python script or interpreter execution on ESXi hosts via embedded BusyBox shells, nested installations, or dropped files via SSH or datastore mount. Flags unusual scripting or post-compromise enumeration behavior.
|
|
Analytic 1191
|
Detects user agents or background services making unauthorized or unscheduled web API calls to cloud/web services over HTTPS.
|
|
Analytic 1419
|
Detects exploitation attempts targeting vulnerable kernel drivers or OS components, often followed by unusual process or token behavior.
|
|
Analytic 0661
|
Detection of modified boot-time configuration scripts that persist malicious CLI commands across reboots.
|
|
Analytic 0084
|
Virtual instances or workloads generating sustained outbound data rates, often to TOR, VPN, or proxy endpoints. Often coincides with unusual IAM usage or deployed scripts (e.g., cron jobs using proxy clients).
|
|
Analytic 1946
|
Monitor for suspicious network traffic that could be indicative of probing for email addresses and/or usernames, such as large/iterative quantities of authentication requests originating from a single source (especially if the source is known to be associated with an adversary/botnet). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields.
|
|
Analytic 0129
|
Execution of scripts or binaries that check for virtualization indicators (e.g., system_profiler, ioreg -l, kextstat), combined with delay functions or anomalous launchd activity.
|
|
Analytic 0300
|
Correlation of Mail.app logs with Safari/Chrome activity. Suspicious behavior includes email links → Safari/Chrome accessing newly registered or lookalike domains → osascript or Terminal spawned unexpectedly.
|
|
Analytic 0961
|
Defenders may observe unauthorized modifications to encryption-related configuration files, firmware, or crypto modules on network devices. Suspicious patterns include changes to cipher suite configurations, unexpected firmware updates affecting crypto libraries, disabling of hardware cryptographic accelerators, or reductions in key length policies. Correlating configuration changes with anomalies in encrypted traffic characteristics (e.g., weaker ciphers or sudden plaintext transmission) strengthens detection.
|
|
Analytic 0392
|
Detects adversary behavior deleting artifacts (e.g., dropped payloads, evidence files) using native or external utilities (e.g., del, erase, SDelete). Detects deletion events correlated with unusual process lineage or timing post-execution.
|
|
Analytic 0011
|
Modification of PATH or HOME environment variables through shell config files, launchctl, or /etc/paths.d entries, combined with process execution from attacker-controlled directories. Defender correlates file changes in /etc/paths.d with process execution resolving to malicious binaries.
|
|
Analytic 0721
|
Forged credentials on macOS may be visible through Unified Logs showing abnormal access to Keychain or browser session files. Correlated with anomalous web session usage from Safari or Chrome processes outside typical user context.
|
|
Analytic 0603
|
Encryption via custom or open-source tools (e.g., openssl, gpg, aescrypt) recursively targeting user or system directories. Also includes overwrite of existing data and ransom note drops.
|
|
Analytic 1470
|
Cloud API usage to create/import SSH keys or generate new access keys (CreateAccessKey, ImportKeyPair, CreateLoginProfile) from non-console access or unusual principals.
|
|
Analytic 1278
|
Multiple failed authentications in unified logs (e.g., loginwindow or sshd)
|
|
Analytic 0247
|
Behavioral sequence where removable media is mounted, files are written/updated, and subsequently read/executed on a separate host, suggesting removable-media relay communication.
|
|
Analytic 0875
|
Detects suspicious execution of network monitoring tools (e.g., Wireshark, tshark, Microsoft Message Analyzer), driver loading indicative of promiscuous mode, or non-admin user privilege escalation to access NICs for capture.
|
|
Analytic 0670
|
Detection of syslog configuration tampering using esxcli system syslog config set or reload. Defender correlates command execution with absence of syslog forwarding activity.
|
|
Analytic 0798
|
Cause→effect chain: (1) Browser/Office/reader process logs crash/segfault or abnormal sandbox message, (2) new executable/script/write occurs in $HOME (Downloads, ~/.cache, /tmp), (3) unexpected child like curl/wget/bash/python opens network connections soon after.
|
|
Analytic 0360
|
Suspicious use of scripting parameters or registry edits to hide process windows (e.g., powershell.exe -WindowStyle Hidden, or registry modifications pushing window positions off screen). Defender view: correlation of hidden execution with anomalous process lineage or hVNC-like CreateDesktop API calls.
|
|
Analytic 0523
|
Monitors tampering with audit logs, volumes, or mounted storage often used for side-channel logging (e.g., /var/log inside containers) post-compromise.
|
|
Analytic 0278
|
Detects execution of Lua interpreters or scripts (.lua), especially when correlated with suspicious parent processes or file drop events, indicating malicious use of embedded scripting.
|
|
Analytic 1495
|
Monitor registry modifications to `HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages` or `...\OSConfig\Security Packages`, especially insertions of new DLL entries. Correlate this with subsequent DLL module loads into `lsass.exe`. Track unsigned or anomalous DLLs loading into LSASS using image load auditing. LSASS loads unsigned DLL due to AuditLevel=8 registry configuration or System reboot followed by DLL load into lsass.exe
|
|
Analytic 0566
|
Unsigned or user-space apps initiate TLS connections with one hostname and HTTP headers requesting a different domain, commonly abused in CDN-resident domain fronting techniques.
|
|
Analytic 1439
|
Detects adversary clearing log files on macOS by correlating calls to shell utilities (e.g., echo >, rm, truncate) targeting files in /var/log/ with unusual context (non-administrative users or abnormal process lineage).
|
|
Analytic 0125
|
Manual or scripted installation of Chrome extensions using user scripts or config files, followed by unexpected network connections from browser processes.
|
|
Analytic 1041
|
Use of file enumeration commands (e.g., 'ls', 'find', 'locate') executed by suspicious users or scripts accessing broad file hierarchies or restricted directories.
|
|
Analytic 0974
|
Detects usage of shared memory directories (/dev/shm, /run/shm) for temporary storage of obfuscated, encoded, or executable data without persistence to disk.
|
|
Analytic 1596
|
Detect attempts to enumerate kernel modules through lsmod, modinfo, or inspection of /proc/modules and /dev entries. Focus on unusual execution contexts such as unprivileged users or processes outside expected administrative workflows.
|
|
Analytic 0883
|
Execution of destructive utilities (dd, shred, wipe) targeting block devices, or processes invoking syscalls to directly overwrite /dev/sd* or /dev/nvme* partitions. Correlate abnormal file write attempts with shell process execution and block device access.
|
|
Analytic 1964
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1350
|
Behavioral chain: (1) delegated administration offers/relationships created or modified by partner tenants; (2) mailbox delegation/impersonation enabled; (3) follow-on access from partner IPs.
|
|
Analytic 0148
|
Delivery of suspicious internal communication (e.g., Thunderbird, Evolution) using compromised internal accounts. Sequence of: unexpected user activity + mail transfer logs + download or execution of attachments.
|
|
Analytic 0643
|
Detects execution of binaries signed with unusual or recently issued certificates, correlation of process execution with abnormal publisher metadata, and mismatched certificate chains. Monitors for revoked or unknown code signing certificates used in high-privilege contexts.
|
|
Analytic 0425
|
Detects abnormal outbound HTTP/FTP connections by local scripts or binaries outside of standard browser activity, following access to local documents or user data.
|
|
Analytic 1568
|
Detects USB HID device enumeration under `/sys/bus/usb/devices/` and rapid keystroke injection resulting in command execution such as bash or Python scripts launched without interactive user activity.
|
|
Analytic 0800
|
Correlates suspicious removal or modification of the com.apple.quarantine extended attribute, manipulation of LSFileQuarantineEnabled values in Info.plist, and unexpected process execution of unsigned or non-notarized binaries. Also monitors abnormal trust validation failures in unified logs and unusual activity in QuarantineEvents database entries.
|
|
Analytic 0863
|
A compromised package/update (deb/rpm/tarball/AppImage/vendor updater) is installed, writing/overwriting files in /usr/local/bin, /usr/bin, /opt, or ~/.local; first run executes unexpected shells/curl/wget and connects to unapproved hosts. Correlate package/updater execution → file writes/replace → first-run child processes → egress.
|
|
Analytic 1579
|
Detects assignment of high-privilege roles to user or service accounts via Kubernetes RoleBinding or ClusterRoleBinding objects, especially outside of CI/CD automation or from unknown IPs.
|
|
Analytic 2029
|
Process execution without GUI context (e.g., powershell.exe, wscript.exe) generates HTTP traffic with a spoofed User-Agent mimicking a legitimate browser. No corresponding UI application (e.g., msedge.exe) is active or in parent lineage. The User-Agent deviates from known enterprise baselines or contains spoofed platform indicators. User-Agent strings can be gathered with API calls such as `ShellExecuteW` to open the default browser on a socket to receive an HTTP reply, or by hard coding the User-Agent string for a specific browser.
|
|
Analytic 1324
|
Detection of token duplication and impersonation attempts by correlating suspicious command-line executions (e.g., runas) with API calls to DuplicateToken, DuplicateTokenEx, ImpersonateLoggedOnUser, or SetThreadToken. The chain includes the initial command execution or in-memory API invocation → token handle duplication or thread token assignment → a new or existing process assuming the impersonated user's context.
|
|
Analytic 1238
|
Account created using esxcli commands. Sequence includes esxcli execution and successful modification to account DB.
|
|
Analytic 0585
|
Malicious script or binary causes repeated kernel panics, OOM kills, or systemd service restarts targeting services like nginx, httpd, sshd.
|
|
Analytic 0391
|
Detects DYLD_INSERT_LIBRARIES abuse to hook credential-sensitive applications by correlating process spawns with unauthorized library injection and monitoring changes to the __TEXT segment (code) of credential handling binaries.
|
|
Analytic 1561
|
Registry access to system language keys (e.g., HKLM\SYSTEM\CurrentControlSet\Control\Nls\Language) or suspicious processes invoking locale-related APIs (e.g., GetUserDefaultUILanguage, GetSystemDefaultUILanguage, GetKeyboardLayoutList). Defender visibility focuses on anomalous or non-standard processes issuing these queries, especially when run by unknown binaries or scripts.
|
|
Analytic 0506
|
Detection of VNC-based remote control via `screensharingd` activity in Unified Logs along with concurrent remote login activity or suspicious user interaction.
|
|
Analytic 0087
|
Detects modifications to IAM conditions or policies that alter authentication behavior, such as adding permissive trusted IPs, removing MFA requirements, or changing regional access restrictions. Behavioral detection focuses on anomalous policy updates tied to privileged accounts and subsequent suspicious logon activity from previously blocked regions or devices.
|
|
Analytic 0927
|
A process/script constructs or references a custom/alphabet translation table (e.g., 64/85/32+ arbitrary chars, XOR/base-N loops) or emits long high-entropy strings that do NOT validate as standard Base64/Hex → shortly after, the same process (or its child) generates outbound traffic with asymmetric bytes_out:bytes_in, fixed-size beacons, or protocol/header mismatches (e.g., Content-Type says JSON but body fails JSON parse / contains non-standard alphabet).
|
|
Analytic 1242
|
Detection focuses on abnormal or unauthorized cloud instance creation events. From a defender’s perspective, suspicious behavior includes VM/instance creation by rarely used or newly created accounts, creation events from unusual geolocations, or rapid sequences of snapshot creation followed by instance creation and mounting. Unexpected network or IAM policy changes applied to new instances can indicate adversarial use rather than legitimate provisioning.
|
|
Analytic 0762
|
VMware management daemons or guest processes initiating encrypted connections outside expected vCenter, update servers, or internal comms. Defender identifies hostd or vpxa initiating outbound TLS flows with uncommon destinations.
|
|
Analytic 1230
|
User-space tools (e.g., `socat`, `ncat`, `iptables`, `ssh`) used in non-standard ways to establish reverse shells, port-forwarding, or inter-host connections. Often chained with uncommon outbound destinations or SSH tunnels.
|
|
Analytic 1022
|
LaunchAgents or LaunchDaemons initiate persistent Tor or relay processes that make encrypted outbound connections. May be paired with sandbox bypasses or unsigned executables communicating over SOCKS proxies.
|
|
Analytic 0681
|
Defenders may observe attempts to alter cryptographic settings on network devices that reduce key strength or allowable cipher suites. Suspicious indicators include configuration changes that downgrade encryption algorithms, key length parameters, or the disabling of strong encryption in favor of legacy ciphers. These activities often appear as CLI commands modifying crypto policies, firmware changes affecting crypto libraries, or unexpected updates to key management files. Correlation across device config logs and traffic analysis showing weaker ciphers provides higher confidence of malicious key space reduction.
|
|
Analytic 0943
|
Detects creation of scheduled tasks via `at.exe` or WMI `Win32_ScheduledJob` class, followed by execution of anomalous processes by svchost.exe or taskeng.exe.
|
|
Analytic 1366
|
Chain of remote access tool behavior: (1) initial execution of remote-control/assist agent or GUI under user context; (2) persistence via service or autorun; (3) long-lived outbound connection/tunnel to external infrastructure; (4) interactive control signals such as shell or file-manager child processes spawned by the RAT parent.
|
|
Analytic 1310
|
Detects file access to mbox/maildir files in conjunction with curl/wget/postfix execution, or anomalous shell scripts harvesting user mail directories.
|
|
Analytic 0994
|
Monitor unified logs for processes spawned from Safari or other browsers that immediately load scripts or executables. Detect file drops in ~/Library/Caches or ~/Downloads that execute shortly after being written.
|
|
Analytic 0338
|
O365 UnifiedAuditLog entries for Remove-Mailbox or Set-Mailbox with account disable or delete actions correlated with suspicious login locations or MFA bypass.
|
|
Analytic 1980
|
Consider use of services that may aid in the tracking of newly issued certificates and/or certificates in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of certificate information to uncover other adversary infrastructure.(Citation: Splunk Kovar Certificates 2017) Some server-side components of adversary tools may have default values set for SSL/TLS certificates.(Citation: Recorded Future Beacon Certificates)
Monitor for logged network traffic in response to a scan showing both protocol header and body values that may buy and/or steal SSL/TLS certificates that can be used during targeting. Detection efforts may be focused on related behaviors, such as [Web Protocols](https://attack.mitre.org/techniques/T1071/001), [Asymmetric Cryptography](https://attack.mitre.org/techniques/T1573/002), and/or [Install Root Certificate](https://attack.mitre.org/techniques/T1553/004).
|
|
Analytic 1159
|
Use of configuration backup utilities or CLI access to dump plaintext passwords, local user hashes, or SNMP strings.
|
|
Analytic 0310
|
Detection monitors SaaS collaboration tools (e.g., Slack, Zoom, Jira) for messages or files containing credential-like patterns, or for suspicious API calls retrieving bulk chat histories by non-admin users. Identifies adversary behavior chains where chat logs are queried via APIs or integration bots to systematically extract sensitive material.
|
|
Analytic 0495
|
Detects exploitation attempts against macOS authentication frameworks such as OpenDirectory or Keychain. Defender perspective includes abnormal crashes in opendirectoryd, unauthorized Keychain API usage, and unusual sudo or login events. Correlation links unexpected process behavior with credential access anomalies.
|
|
Analytic 0826
|
Detects unauthorized firmware or configuration changes enabling adversary-in-the-middle positioning (e.g., route injection, DNS spoofing, SSL downgrade). Behavioral analytics focus on sudden changes to routing tables or image file integrity failures.
|
|
Analytic 0249
|
Correlates removable volume mounts (disk arbitration) with file I/O events on that volume, followed by same file execution shortly after insert.
|
|
Analytic 0696
|
Identifies unauthorized access or enumeration of administrative roles, security groups, or distribution groups via Exchange/SharePoint/Teams APIs or role discovery scripts.
|
|
Analytic 0290
|
Detects suspicious configuration changes in IdP authentication flows such as enabling reversible password encryption, MFA bypass, or policy weakening. Correlates policy modification events with unusual administrative activity.
|
|
Analytic 0624
|
Detects remote scripts or binaries deployed via Puppet, Chef, Ansible, or shell scripts from orchestration servers executing outside maintenance windows or in unmanaged nodes.
|
|
Analytic 0009
|
Abnormal modification of the PATH environment variable or registry keys controlling system paths, combined with execution of binaries named after legitimate system tools from user-writable directories. Defender correlates registry modifications, file creation of suspicious binaries, and process execution paths inconsistent with baseline system directories.
|
|
Analytic 0179
|
Behavioral chain: (1) browser/office/GUI mail client opens a URL, (2) outbound connection to untrusted domain, (3) a new file is saved in $HOME/Downloads, /tmp, or cache immediately after.
|
|
Analytic 1302
|
Detects embedded macros or scripts added to shared documents or use of external references to execute code.
|
|
Analytic 0926
|
Changes to NAT/firewall policies enabling outbound port forwarding from internal IPs to Internet-based proxy endpoints. Log spikes in outbound flows to CDN, VPS, or anomalous ASNs with few return packets.
|
|
Analytic 1391
|
Detects symmetric key-based encryption operations (e.g., AES via Python, AppleScript, or OpenSSL) followed by unusual outbound connections from non-browser applications or scripted tools.
|
|
Analytic 0173
|
Detects native Python or framework-based execution from Terminal, embedded apps, or launchd jobs. Flags network calls, persistence writes, or system enumeration after Python launch.
|
|
Analytic 1076
|
Detects adversary use of suspended process creation, using the CREATE_SUSPENDED flag via CreateProcess, followed by unmapping the memory of the child process (NtUnmapViewOfSection) and replacing it with malicious code via VirtualAllocEx/WriteProcessMemory, then SetThreadContext and ResumeThread to begin execution within the hollowed process.
|
|
Analytic 1638
|
SSH login from a remote system (via sshd), followed by user context execution of suspicious binaries or privilege escalation behavior.
|
|
Analytic 1294
|
Untrusted processes creating outbound TLS/HTTPS connections with malformed certificates or header fields, often mismatched with target service behavior. Detects protocol impersonation attempts via traffic metadata analysis and host process lineage.
|
|
Analytic 0456
|
Chain: (1) interactive/non-interactive `chage -l`, `grep`/`cat` of PAM config (e.g., `/etc/pam.d/common-password`, `/etc/security/pwquality.conf`); (2) optional reads of `/etc/login.defs`; (3) same user performs account enumeration or password change attempts shortly after. Use auditd `execve` and file read events plus shell history collection.
|
|
Analytic 0430
|
Untrusted or unusual process/script (cmd.exe, powershell.exe, w32tm.exe, net.exe, custom binaries) queries system time/timezone (e.g., w32tm /tz, net time \\host, Get-TimeZone, GetTickCount API) and (optionally) is followed within a short window by time-based scheduling or conditional execution (e.g., schtasks /create, at.exe, PowerShell Start-Sleep with large values).
|
|
Analytic 0666
|
Adversary uses compromised instance credentials or web application access to deface content hosted in S3 buckets, Azure Blob Storage, or GCP Buckets.
|
|
Analytic 0014
|
Execution of renamed common utilities (e.g., `bash`, `nc`, `python`, `sh`) from atypical directories or with names intended to deceive defenders or EDRs.
|
|
Analytic 1370
|
Detects kill/systemctl/service commands against EDR, auditd, falco, osquery, rsyslog, journald, or agent processes; configuration edits disabling startup; module unload attempts; abrupt cessation of logs after privileged shell execution.
|
|
Analytic 1016
|
Execution of ping, traceroute, or curl/wget against public IPs/domains to verify Internet reachability.
|
|
Analytic 0929
|
EndpointSecurity/Unified Logs show processes generating custom alphabets or long high-entropy, non-standard tokens → network logs (PF/Zeek/EDR) show asymmetric beacons, protocol mismatches, or periodic fixed-size posts.
|
|
Analytic 0574
|
Detects enumeration of VMs using PowerShell (`Get-VM`), VMware Workstation (`vmrun.exe`), or Hyper-V (`VBoxManage.exe`). Defender observes suspicious command lines executed by unexpected users or outside normal administrative sessions.
|
|
Analytic 1594
|
Detection of suspicious enumeration of cloud storage objects via API calls such as AWS S3 ListObjectsV2, Azure List Blobs, or GCP ListObjects. Correlate access with account role, user context, and prior authentication activity to identify anomalous usage patterns (e.g., unusual account, unexpected regions, or large-scale enumeration in short time windows).
|
|
Analytic 0848
|
Enumeration of macOS local users using dscl, id, dscacheutil, or /etc/passwd access.
|
|
Analytic 1044
|
Execution of file discovery commands (e.g., 'dir', 'show flash', 'nvram:') from CLI interfaces, especially by unauthorized users or from abnormal source IPs.
|
|
Analytic 1620
|
Detection of suspicious use of `tscon.exe` or equivalent methods to hijack legitimate RDP sessions. Defenders can observe anomalies such as session reassignments without corresponding authentication, processes spawned in the context of hijacked sessions, or unusual RDP network traffic flows that deviate from expected baselines.
|
|
Analytic 1169
|
Detects FTP, SMB, or TFTP traffic initiated by suspicious processes like PowerShell, cmd.exe, or rundll32.exe—especially with large outbound file transfers or unbalanced traffic volume.
|
|
Analytic 0818
|
Detects suspicious changes to SAML/OAuth federation configurations, such as new signing certificates, altered endpoints, or claims issuance rules granting elevated privileges.
|
|
Analytic 0152
|
Detection of adversary attempts to enumerate Group Policy settings through suspicious command execution (gpresult), PowerShell enumeration (Get-DomainGPO, Get-DomainGPOLocalGroup), and abnormal LDAP queries targeting groupPolicyContainer objects. Defenders observe unusual process lineage, script execution, or LDAP filter activity against domain controllers.
|
|
Analytic 1293
|
Defenders may observe adversary attempts to patch system images by monitoring for anomalous file transfers (TFTP, SCP, FTP) of image files, unauthorized CLI commands altering boot system variables, integrity check mismatches between running and baseline OS images, and runtime memory manipulation attempts. Suspicious sequences include uploading a new image, modifying boot parameters, and subsequent reload/reboot of the device. In-memory patching attempts may manifest as debug commands or boot loader manipulation inconsistent with normal administrative activity.
|
|
Analytic 0089
|
Execution of binaries with invalid digital signatures, where metadata claims code is signed but validation fails. Behavior is often correlated with suspicious parent processes or unexpected execution paths.
|
|
Analytic 1241
|
Detects the redirection of syscall execution flow via modification of VDSO code stubs or GOT entries to load and execute a malicious shared object through mmap and ptrace.
|
|
Analytic 1202
|
Monitor email message traces and headers for failed SPF, DKIM, or DMARC checks indicating spoofed sender identities. Correlate abnormal sender domains or mismatched return-paths with elevated spoofing likelihood.
|
|
Analytic 1962
|
Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.
Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
|
|
Analytic 0232
|
Adversary modifies ESXi host login banner or MOTD file (/etc/motd), either through SSH or host console access. May involve configuration file overwrite or API calls from compromised vSphere clients.
|
|
Analytic 0390
|
Detects credential interception via malicious LD_PRELOAD-based shared libraries loaded into ssh, sudo, or scp processes. Correlates environment variable injection, unexpected library loads, and memory patching behavior.
|
|
Analytic 0383
|
Detection of unauthorized modification of Active Directory SID-History attributes to escalate privileges. This chain involves: (1) privileged operations or API calls to DsAddSidHistory or related AD modification functions, (2) observed attribute changes in SID-History (Event ID 5136), (3) new logon sessions where the token includes unexpected or privileged SID-History values, and (4) follow-on resource access using elevated privileges derived from SID-History injection.
|
|
Analytic 1474
|
Unauthorized modification of TCC.db followed by elevated process execution under a trusted parent (e.g., Finder, SystemUIServer) or via launchctl environment override. Also includes identification of SIP being disabled, which is highly uncommon and a prerequisite for this abuse path.
|
|
Analytic 1097
|
Monitor for runtime data manipulations by detecting suspicious modification of application binaries, API hooking, or unexpected behavior from processes responsible for rendering or displaying data. Correlate registry edits, process creation, and unexpected binary hash mismatches.
|
|
Analytic 1445
|
Detects attempts to forge or replay Kerberos tickets by monitoring Unified Logs for anomalous kinit/klist activity and correlating unusual authentication sequences.
|
|
Analytic 1100
|
Adversary spawns a process or script to enumerate installed software using WMI, registry, or PowerShell, potentially followed by additional discovery or evasion behavior.
|
|
Analytic 1444
|
Detects suspicious access to SSSD secrets database and Kerberos key material indicating ticket theft or replay attempts. Correlates anomalous file access with unusual Kerberos service ticket requests.
|
|
Analytic 1056
|
Monitor for creation or modification of udev rules files in key directories (/etc/udev/rules.d/, /lib/udev/rules.d/, /usr/lib/udev/rules.d/). Look for RUN+= or IMPORT keys invoking suspicious binaries or scripts. Correlate this with process execution from systemd-udevd context, and file writes near udev reload/restart events. Combine this with unexpected background process spawning from udevd-related forks.
|
|
Analytic 1101
|
Adversary invokes 'dpkg -l', 'rpm -qa', or other package managers via shell or script to enumerate installed software.
|
|
Analytic 0525
|
Detects deletion or hiding of security-related mail rules, audit mailboxes, or calendar/log sync artifacts indicative of tampering post-intrusion.
|
|
Analytic 0823
|
Detects suspicious DNS/ARP poisoning attempts, unauthorized modifications to registry/network configuration, or abnormal TLS downgrade activity. Correlates changes in system configuration with subsequent unusual network flows or authentication events.
|
|
Analytic 0463
|
Process creates a raw/packet socket and attaches a (e)BPF filter (setsockopt SO_ATTACH_FILTER/ATTACH_BPF or bpf(BPF_PROG_LOAD)). Immediately after a matching inbound packet, the same process binds/connects outward to a remote host (reverse shell or beacon).
|
|
Analytic 0207
|
ESXi shell execution of tools/scripts (`nc`, `socat`, `perl`) relaying network traffic to other internal hosts, especially when initiated by unauthorized users or VMs.
|
|
Analytic 1243
|
Monitor kernel module load/unload activity via modprobe, insmod, rmmod, or direct manipulation of /lib/modules. Correlate with installation of kernel headers, compilation commands, or downloads of .ko files. Detect anomalies in unsigned module loading or repeated module load attempts under non-root users.
|
|
Analytic 0341
|
Behavioral correlation of privileged registry key creation under the W32Time TimeProviders path combined with a new DLL written to disk and potential process activity by LocalService. Indicates abuse of Time Providers for persistence.
|
|
Analytic 0037
|
Access to browser artifact locations (e.g., Chrome, Edge, Firefox) by processes like PowerShell, cmd.exe, or unknown tools, followed by file reads, decoding, or export operations indicating enumeration of bookmarks, autofill, or history databases.
|
|
Analytic 1306
|
Linux environmental keying behavioral chain: (1) System information gathering through native commands (uname, hostname, id, whoami, ifconfig/ip) and file system enumeration, (2) Network configuration discovery (route tables, DNS settings, network interfaces), (3) Filesystem and mount point analysis for target-specific directories or devices, (4) Process and service enumeration to identify target-specific software, (5) Cryptographic library usage correlation with collected environmental data, (6) Payload execution following successful environmental validation
|
|
Analytic 1227
|
Detects applications using abnormal protocols or high volume traffic not previously associated with the process image, such as Automator or AppleScript invoking curl or python sockets.
|
|
Analytic 0693
|
Remote/API driven creation **and** start of a container whose image is not on an allow‑list (or is tagged `latest`), executed by a non-admin principal, and/or started with risky runtime attributes (e.g., `--privileged`, host PID/NET namespaces, sensitive host path mounts, capability adds). Correlates *create* ➜ *start* ➜ first network/process actions from that container within a short time window.
|
|
Analytic 1340
|
Authentication failure logs on routers/switches showing repeated use of default or common passwords across multiple accounts
|
|
Analytic 1398
|
Adversary gains high integrity or special privileges (e.g., SeDebugPrivilege), locates a running browser process, opens it with write/inject rights, and modifies it (e.g., CreateRemoteThread / DLL load) to inherit cookies/tokens or establish a browser pivot. Optional step: create a new logon session or use explicit credentials, then drive the victim browser to intranet resources.
|
|
Analytic 0016
|
Adversary uses nltest, PowerShell, or Win32/.NET API to enumerate domain trust relationships (via DSEnumerateDomainTrusts, GetAllTrustRelationships, or LDAP queries), followed by discovery or authentication staging.
|
|
Analytic 0092
|
Creation of files or directories with a leading '.' in privileged directories (/etc, /var, /usr/bin). Defender view: monitoring auditd logs for file creations where name begins with '.' and correlated with unusual user/process context.
|
|
Analytic 0131
|
Detects adversaries accessing remote mail systems (e.g., Exchange Online, O365) using stolen credentials or OAuth tokens, followed by scripted access to mailbox contents via PowerShell, AADInternals, or unattended API queries. Detection focuses on abnormal logon sessions, user agents, IP locations, and scripted or tool-based email data access.
|
|
Analytic 0671
|
Monitor for abnormal certificate enrollment and usage activity in Active Directory Certificate Services (AD CS), registry access to certificate storage locations, and unusual process executions that attempt to export or access private keys.
|
|
Analytic 1197
|
Detects the modification or addition of Launch Agents or Startup Items to establish persistence. Adversaries may write plist or executable files to ~/Library/LaunchAgents/, /Library/StartupItems/, or similar directories and configure them to run at user or system boot. Detection requires correlating file creation or modification events with subsequent user logon or boot-time process execution.
|
|
Analytic 0768
|
The adversary uses native utilities like base64, gzip, tar, or openssl to decode, decompress, or decrypt files that were previously staged or downloaded. These tools may be chained with curl/wget and executed via bash/zsh, often to extract an embedded payload or reverse shell script.
|
|
Analytic 1617
|
Detection of enumeration activity when system processes query ESXi host account configuration or management APIs to retrieve user account listings.
|
|
Analytic 1343
|
SaaS applications receiving authentication failures for dozens of accounts using same password or login signature
|
|
Analytic 0786
|
Detection of suspicious token manipulation chains: use of token-related APIs (e.g., LogonUser, DuplicateTokenEx) or commands (runas) → spawning of a new process under a different security context (e.g., SYSTEM) → mismatched parent-child process lineage or anomalies in Event Tracing for Windows (ETW) token/PPID data → abnormal lateral or privilege escalation activity.
|
|
Analytic 0105
|
Detects unauthorized access to web browser credential stores (e.g., Chrome Login Data, Edge Credential Locker) by processes other than the browser itself. Correlates file reads of credential databases with subsequent API calls to `CryptUnprotectData` or memory inspection attempts.
|
|
Analytic 1441
|
Detects GUI-based credential prompts invoked via zenity/kdialog/dialog or X11 APIs from non-user-facing scripts or background shell sessions, often with authentication-related text.
|
|
Analytic 1228
|
Detects application-layer tunneling or unauthorized app protocols like DNS-over-HTTPS, embedded C2 in TLS/HTTP headers, or misused SMB traffic crossing VLANs.
|
|
Analytic 0684
|
Audit VoIP/SIP logs for suspicious outbound calls or call setup messages to unusual endpoints. Correlate with user activity such as browser execution or package installation following the call.
|
|
Analytic 1348
|
Behavioral chain: (1) cross-account or third-party principal assumes a role into the tenant/subscription/project; (2) privileged API calls are made in short succession; (3) access originates from unfamiliar networks or geos. Correlate assume-role/federation events with sensitive API usage.
|
|
Analytic 0369
|
Detects non-native file transfer via curl, Python scripts, or AppleScript using uncommon protocols like FTP, SMTP, or DNS exfiltration through mDNSResponder abuse.
|
|
Analytic 1630
|
Defenders may observe adversary attempts to extract configuration data from management repositories by monitoring for anomalous SNMP queries, API calls, or protocol requests (e.g., NETCONF, RESTCONF) that enumerate system configuration. Suspicious sequences include repeated queries from untrusted IPs, abnormal query types requesting sensitive configuration data, or repository access occurring outside of normal administrative maintenance windows. Abnormal authentication attempts, sudden enumeration of device inventory, or bulk data transfer of configuration files may also be observed.
|
|
Analytic 1081
|
Detects bash, sh, zsh, or BusyBox shell execution initiated via remote sessions, unauthorized users, or embedded within secondary script interpreters. Focus is on chained behavior: shell > suspicious commands > network discovery or persistence indicators.
|
|
Analytic 0725
|
Detects aggregation of files from different directories into /tmp, /mnt, or user-specified directories with archiving tools like tar or gzip.
|
|
Analytic 0189
|
Monitor for malicious payload delivery through phishing where attachments or URLs in email clients (e.g., Thunderbird, mutt) result in unusual file creation or outbound network connections. Focus on correlation between mail logs, file writes, and execution activity.
|
|
Analytic 0206
|
Execution of AppleScript or Automator services launching `ssh -L`, `socat`, or `launchctl` items that dynamically reroute traffic from one Mac endpoint to another. LaunchAgents used to establish permanent internal tunnels.
|
|
Analytic 0907
|
Detects interactive or automated use of CLI commands like `show ip sockets`, `show tcp brief`, or SNMP queries for active sessions on routers/switches.
|
|
Analytic 1562
|
Processes executing commands to query system locale and language settings, such as 'locale', 'echo $LANG', or parsing environment variables. Suspicious activity is indicated by these commands being run by unusual users, automation scripts, or non-administrative processes.
|
|
Analytic 0080
|
Processes invoking network-intensive child processes or uploading large data volumes, often from non-standard user or system contexts, with evidence of long-duration TCP/UDP sessions to unusual destinations.
|
|
Analytic 0116
|
Detects adversary removal of persistence implants (e.g., rc.local entries or crontab injections) via CLI (`rm`, `sed`, `crontab -r`) and deletion of startup or management scripts.
|
|
Analytic 0414
|
Adversary deletes critical infrastructure: EC2 instances, S3 buckets, snapshots, or volumes using elevated IAM credentials. Frequently includes batch API calls with `Delete*` or `TerminateInstances`.
|
|
Analytic 2039
|
Detects exploitation attempts against security daemons or kernel security modules followed by daemon termination, disabled logging, module unload, audit stoppage, or reduced endpoint telemetry. Correlates local execution or network input with control degradation.
|
|
Analytic 0712
|
Detects extraction or mounting of container/archive files (e.g., .iso, .vhd, .zip) that originated from the Internet but whose contained files lack Zone.Identifier MOTW tagging. Correlates file creation metadata with subsequent execution of unsigned or untrusted binaries launched outside SmartScreen or Protected View.
|
|
Analytic 1149
|
Detect adversaries filtering traffic or modifying server responses to evade scanning. Monitor iptables, nftables, or proxy configurations that deny or redirect requests from known scanning agents or defensive tools.
|
|
Analytic 1988
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1961
|
Once adversaries leverage serverless functions as infrastructure (ex: for command and control), it may be possible to look for unique characteristics associated with adversary software, if known.(Citation: ThreatConnect Infrastructure Dec 2020) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle.
|
|
Analytic 0271
|
Processes using Win32 API calls (e.g., EnumWindows, GetForegroundWindow) or scripting tools (e.g., PowerShell, VBScript) to enumerate open windows. These often appear with reconnaissance or data collection TTPs.
|
|
Analytic 0590
|
Detection of suspicious logon behavior using valid domain accounts across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations.
|
|
Analytic 0490
|
Excessive inbound HTTP or TLS connections to services such as Apache or Nginx, causing worker thread exhaustion or segmentation faults.
|
|
Analytic 1047
|
Detect suspicious calls to sysctl or ptrace API used to determine if a process is being debugged. Monitor for processes that flood OutputDebugString equivalents or generate abnormal exceptions to evade analysis.
|
|
Analytic 0307
|
Correlation of chmod operations setting setuid/setgid bits followed by privileged process execution (EUID != UID), especially from user-writable or abnormal paths.
|
|
Analytic 1284
|
Monitoring for SSH logins from default accounts such as 'root', especially when login is via password and not key-based authentication.
|
|
Analytic 0320
|
Inbound spearphishing attempts delivered via third-party services (e.g., Gmail, LinkedIn messages) leading to malicious file downloads or browser-initiated script execution. Defender view includes correlation of external service logins, unexpected file write operations, and suspicious descendant processes spawned from productivity or browser applications.
|
|
Analytic 1259
|
Adversary modifies Active Directory domain trust settings via `netdom`, `nltest`, or PowerShell to add new domain trust or alter federation. Modifications occur in AD object attributes like trustDirection, trustType, trustAttributes, often paired with SeEnableDelegationPrivilege or certificate injection.
|
|
Analytic 0019
|
Login to M365 or Google Workspace from CLI tools or unexpected source IPs, followed by mailbox or document access
|
|
Analytic 0918
|
Detection of EFI/firmware manipulation attempts via abnormal driver loads, unsigned kexts, or tampered NVRAM variables associated with component firmware configuration.
|
|
Analytic 0808
|
Detects web console login events followed by read-only or metadata retrieval activity from GUI sources (e.g., browser session, mobile client) rather than API/CLI sources. Correlates across CloudTrail, IAM identity logs, and user-agent context.
|
|
Analytic 1354
|
Enumeration of USB and other peripheral hardware via udevadm, lshw, or /sys or /proc interfaces in proximity to collection or mounting behavior.
|
|
Analytic 0183
|
Use of nohup, disown, or AppleScript constructs to suppress process interrupts. Defender perspective: commands containing nohup or hidden background tasks (`osascript` with persistent execution) correlated with processes surviving user logouts.
|
|
Analytic 0169
|
Network device logs show anomalous inbound file transfers or uncharacteristic flows with high payload volume to network devices with storage or automation hooks.
|
|
Analytic 1590
|
Creation or modification of Apple Mail rules by accessing plist files or GUI automation (AppleScript).
|
|
Analytic 0472
|
Adversary registers a malicious Microsoft Exchange transport agent DLL (.NET assembly), configures it via PowerShell or Exchange Management Shell, and persists code execution by manipulating email processing logic based on rules or headers.
|
|
Analytic 1598
|
Detects registration of new or modified network provider DLLs via registry changes, anomalous file creation of DLLs in system directories, and suspicious process activity (mpnotify.exe interacting with non-standard DLLs). Multi-event correlation ties registry modification events to subsequent DLL loads during user logon activity.
|
|
Analytic 1624
|
Adversary modifies web-facing content on macOS via web development environments like MAMP or misconfigured Apache instances, typically with access to the hosting user account or via persistence tools.
|
|
Analytic 0986
|
Detects malicious containers or pods using names, labels, or namespaces that mimic legitimate workloads; also checks for image layer mismatches and unauthorized resource deployments.
|
|
Analytic 0861
|
Detection focuses on identifying unauthorized or anomalous changes to compute infrastructure components. Defender perspective: monitor for creation, deletion, or modification of instances, volumes, and snapshots outside of approved change management windows; correlate abnormal activity such as rapid snapshot creation followed by new instance mounts, or repeated infrastructure changes by rarely used accounts. Flagging activity linked to unusual geolocation, API client, or automation script is suspicious.
|
|
Analytic 2001
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0204
|
Anomalous process (e.g., `rundll32`, `svchost`, `cmd`) initiates connections to internal peer hosts not seen in typical communication baselines, used to proxy or forward traffic internally, often using SMB, RPC, or high ports.
|
|
Analytic 0497
|
Detection of anomalous ROMMON image changes or upgrades, unexpected reboots following firmware updates, and unauthorized use of firmware upgrade commands or TFTP transfers. Correlation of config modification, privilege escalation, and boot cycle anomalies provides visibility into ROMMON tampering attempts.
|
|
Analytic 0683
|
Monitor call log records from corporate devices for unusual or unauthorized numbers, especially repeated calls to/from known malicious phone numbers. Correlate with subsequent system events (e.g., browser navigation, remote management tool execution).
|
|
Analytic 1003
|
User creation or modification via dscl with IsHidden=1, UID<500, or plist edits to com.apple.loginwindow Hide500Users flag. Defender view: correlation of hidden account attributes with login screen exclusion.
|
|
Analytic 1395
|
Detection of shell commands that leverage encoded execution, command chaining, excessive piping, or unusual token patterns indicative of obfuscation.
|
|
Analytic 1257
|
VMCI (Virtual Machine Communication Interface) traffic between guest and host, or between VMs, originating from non-management tools or unauthorized binaries.
|
|
Analytic 1616
|
Detection of identity directory enumeration through API calls or administrative queries retrieving multiple account objects within a short interval.
|
|
Analytic 0305
|
ESXi daemons (e.g., hostd, vpxa) are wrapped or impersonated to send large outbound traffic using gzip/Base64 encoding over SSH or HTTP. These actions follow suspicious logins or shell access.
|
|
Analytic 0562
|
Use of `esxcli network` commands (e.g., `esxcli network nic list`, `esxcli network ip interface ipv4 get`) via SSH or hostd to enumerate adapter and IP information.
|
|
Analytic 0076
|
Detects curl, wget, Python requests, or custom HTTP clients communicating over non-standard ports, with repetitive or beacon-like patterns or POST-heavy behavior to rare domains.
|
|
Analytic 1276
|
Multiple authentication failures for valid or invalid users followed by success from same IP/user
|
|
Analytic 0052
|
A process (often LOLBin or user-launched program) loads a DLL from a user-writable/UNC/Temp path or unsigned/invalid signer. Within a short window the DLL is (a) newly written to disk, (b) spawned as follow-on execution (rundll32/regsvr32), or (c) establishes outbound C2.
|
|
Analytic 1122
|
Detects local daemons or scripts generating outbound DNS queries with long or frequent subdomains, indicative of DNS tunneling via tools like `iodine`, `dnscat2`, or `dig` from cronjobs or reverse shells.
|
|
Analytic 2011
|
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during exfiltration (ex: [Transfer Data to Cloud Account](https://attack.mitre.org/techniques/T1537)).
|
|
Analytic 0739
|
Detects removal of Apple Mail artifacts via AppleScript or direct deletion of mailbox content in ~/Library/Mail/, especially when preceded by Remote Login or C2-related API access.
|
|
Analytic 0119
|
Unusual process or API usage attempting to query system locale, timezone, or keyboard layout (e.g., calls to GetLocaleInfoW, GetTimeZoneInformation). Detection can be enhanced by correlating with processes not typically associated with system configuration queries, such as unknown binaries or scripts.
|
|
Analytic 0924
|
AppleScript or terminal sessions launch tools (`curl`, `nc`, `ssh`) to external IPs not commonly accessed. Outbound connections are made by LaunchAgents/LaunchDaemons, often masquerading as system services.
|
|
Analytic 0641
|
Enumeration of global address lists or email account metadata via PowerShell cmdlets (e.g., Get-GlobalAddressList) or MAPI/RPC from non-admin, non-mailserver systems.
|
|
Analytic 1323
|
Correlate suspicious registry modifications to known COM object CLSIDs with subsequent DLL loads or unexpected binary execution paths. Detect placement of COM CLSID entries under HKEY_CURRENT_USER\Software\Classes\CLSID\ overriding default HKLM paths. Flag anomalous DLL loads traced back to hijacked COM registry changes.
|
|
Analytic 0516
|
Correlate suspicious file transfers over SMB or Admin$ shares with process creation events (e.g., cmd.exe, powershell.exe, certutil.exe) that do not align with normal administrative behavior. Detect remote file writes followed by execution of transferred binaries.
|
|
Analytic 1282
|
Use of the `security` command or Keychain API to extract known Wi-Fi passwords for target SSIDs.
|
|
Analytic 1363
|
Monitor unified logs for access to payment applications, browser plug-ins, or Apple Pay services from non-standard processes. Detect anomalous use of Automator scripts or keychain extraction targeting financial account credentials.
|
|
Analytic 0251
|
Installation or execution of a malicious browser or IDE extension, followed by abnormal registry entries or outbound network connections from the host application
|
|
Analytic 0276
|
Unauthorized firmware uploads to routers, switches, or firewalls via TFTP/FTP/SCP. Logs showing boot variable or startup image path changes redirecting to non-standard firmware images. Abnormal reboots or firmware rollback attempts following configuration modification events.
|
|
Analytic 1012
|
Burst of incomplete TCP handshakes (e.g., SYN floods) or uncorrelated ACK packets targeting the state table resulting in OS resource exhaustion.
|
|
Analytic 0212
|
Execution of file transfer or network access activity through non-primary interfaces (e.g., WiFi, Bluetooth, cellular) by processes not typically associated with such behavior (e.g., rundll32, powershell, regsvr32).
|
|
Analytic 1938
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 2009
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0789
|
Processes such as osascript, curl, or office applications sending data to text storage APIs/domains. Defender perspective: anomalous clipboard or file reads by unexpected applications immediately followed by outbound HTTPS requests to pastebin-like services.
|
|
Analytic 0301
|
Detection of OAuth consent phishing or malicious login attempts initiated through spearphishing links. Behavior chain includes inbound email with OAuth URL → consent page visited → unusual token grants logged in IdP logs.
|
|
Analytic 0839
|
Monitor for in-process mmap + mprotect + execve/execveat activity where memory permissions are changed from writable to executable inside the same process without a corresponding ELF on disk.
|
|
Analytic 1266
|
Multiple sign-in failures against cloud-based applications using username/password combinations leaked from unrelated domains
|
|
Analytic 1342
|
Failed authentication attempts across user mailboxes using identical or common passwords (e.g., OWA brute attempts)
|
|
Analytic 0135
|
Detects removal of Remote Login or Screen Sharing logs in Unified Logging, deletion of `com.apple.UTun`, or suspicious Terminal use of `rm`, `sudo pfctl -F all` to clear network state/config history.
|
|
Analytic 0662
|
Adversary modifies website or application-hosted content via unauthorized file changes or script injections, often by exploiting web servers or CMS access.
|
|
Analytic 0120
|
Detection of commands accessing locale, timezone, or language settings such as 'locale', 'timedatectl', or parsing /etc/timezone. Anomalous execution by unusual users or automation scripts should be flagged.
|
|
Analytic 1545
|
Detection of interactive and remote logins by service accounts or users at unusual times, with unexpected child process activity.
|
|
Analytic 1541
|
Detect commands such as 'esxcli system shutdown' or 'vim-cmd vmsvc/power.shutdown' executed outside of maintenance windows or via unusual users. Reboot logs in hostd.log and shell logs should be correlated.
|
|
Analytic 0546
|
Detects PAM module modifications or removal of MFA hooks in /etc/pam.d/ configurations, correlated with successful authentications lacking MFA prompts.
|
|
Analytic 0048
|
Adversary executes commands to enumerate installed antivirus, EDR, or firewall agents using WMI, registry queries, and built-in tools (e.g., tasklist, netsh, sc query). Correlated with elevated process privileges or scripting engine usage.
|
|
Analytic 0885
|
Execution of CLI commands erasing file systems or storage (erase flash:, format disk, erase nvram:). Detect authentication events followed by destructive commands within the same privileged session.
|
|
Analytic 0598
|
Processes on macOS initiate external connections that consistently transmit data in fixed sizes using LaunchAgents or unexpected users.
|
|
Analytic 0507
|
Detection of adversary enumeration of domain or local group memberships via native tools such as net.exe, PowerShell, or WMI. This activity may precede lateral movement or privilege escalation.
|
|
Analytic 0987
|
Detects VIBs, scripts, or binaries placed into directories like /bin or /etc/vmware with names mimicking standard ESXi components. Also monitors unauthorized creation of services.
|
|
Analytic 0470
|
Detects modification or truncation of `/var/log/shell.log` used to persist ESXi shell command history. Especially suspicious shortly after login or config changes.
|
|
Analytic 0882
|
Processes attempting raw disk access via \\.\PhysicalDrive paths, abnormal file I/O to MBR/boot sectors, or loading of third-party drivers (e.g., RawDisk) that enable disk overwrite. Correlate process creation, privilege usage, and disk modification events within a short time window.
|
|
Analytic 1144
|
Detects anomalous NTLM LogonType 3 authentications that occur without accompanying domain logon events, especially from lateral systems or involving built-in administrative tools. Monitors for mismatches between source user context and system being accessed. Correlates LogonSession creation, NTLM authentications, and process/service initiation to identify suspicious use of stolen password hashes for remote access or service logon without password entry. Detects overpass-the-hash by combining Kerberos ticket issuance with NTLM-based lateral movement.
|
|
Analytic 1038
|
Correlate file modifications in shell startup scripts (e.g., .bashrc, .profile) with embedded `trap` commands and observe if those changes are followed by the unexpected execution of child processes when terminal signals (e.g., SIGINT) are triggered. Use contextual linking with user session activity to detect privilege misuse.
|
|
Analytic 0718
|
Forged web credentials may manifest as anomalous SAML token issuance, OpenID Connect token minting, or Zimbra pre-auth key usage. Defenders may see tokens issued without normal authentication events, multiple valid tokens generated simultaneously, or signing anomalies in IdP logs.
|
|
Analytic 1582
|
Detects use of built-in SaaS sharing mechanisms to transfer ownership or share access of critical data to external tenants or untrusted users through API calls or link generation features.
|
|
Analytic 0869
|
Monitoring for discrepancies between system daemon/service state and reported health messages (e.g., syslog shows AV/IDS daemon stopped, but spoofed messages claim it is still running). Detects userland processes impersonating AV/IDS command-line outputs or modifying log forwarding configurations.
|
|
Analytic 0527
|
OAuth or SAML access tokens reused across multiple sessions or clients without corresponding MFA or login activity.
|
|
Analytic 0261
|
Detects unusual use of `cron` or `sleep` loops inside containers executing unfamiliar scripts or binaries repeatedly.
|
|
Analytic 0423
|
Detects data access or staging events followed by outbound data flows using unencrypted protocols (e.g., FTP, HTTP) initiated by unexpected processes or to rare destinations.
|
|
Analytic 0890
|
Unusual ESXi shell commands disabling syslog forwarding or stopping hostd/vpxa daemons. Detect modifications to firewall rules on ESXi host or disabling of lockdown mode.
|
|
Analytic 1295
|
Detection of binaries spawning encrypted sessions using OpenSSL or curl to external services with mismatched ports/protocols. Identifies behavior where internal services simulate trusted cloud service traffic patterns.
|
|
Analytic 1530
|
Monitors for anomalous binary files written to disk with padded size and subsequent execution by user or service context.
|
|
Analytic 0292
|
Use of hash-cracking tools (e.g., John the Ripper, Hashcat) after credential dumping, combined with high CPU usage or GPU invocation via unsigned binaries accessing password hash files
|
|
Analytic 0849
|
Enumeration of local ESXi accounts using esxcli or vSphere API from unauthorized sessions.
|
|
Analytic 0303
|
Custom scripts or processes encode outbound traffic using gzip, Base64, or hex prior to exfiltration via curl, wget, or custom sockets. Encoding typically occurs before or during outbound connections from non-network daemons.
|
|
Analytic 0033
|
Anomalous traffic from ESXi host management daemons (like hostd or vpxa) embedding non-standard payloads in management protocols (e.g., HTTPS) or beaconing behavior.
|
|
Analytic 0811
|
Detects SaaS web login followed by dashboard or web GUI page views from unfamiliar locations, devices, or access patterns. Identifies use of sensitive reporting or configuration consoles accessed from high-risk accounts.
|
|
Analytic 0583
|
Registry modification of the LSA Authentication Packages key followed by LSASS loading a non-standard or unsigned DLL. This includes unusual write access to `HKLM\SYSTEM\CurrentControlSet\Control\Lsa`, especially during non-installation timeframes. Correlated with `lsass.exe` loading DLLs not present in baseline or lacking valid signatures.
|
|
Analytic 1011
|
Monitor unified logs and Mail.app activity for repetitive incoming messages with attachments. Defenders should look for large volumes of incoming mail stored under ~/Library/Mail with unusual timing or repetitive subjects.
|
|
Analytic 0906
|
Detects shell or API usage of `esxcli network ip connection list` or `netstat` to enumerate ESXi host connections.
|
|
Analytic 0385
|
Processes invoking destructive commands (dd, shred, wipe) with raw device targets (e.g., /dev/sda, /dev/nvme0n1). Detect direct writes to disk partitions and abnormal superblock or bootloader modifications. Correlate shell execution with subsequent block device I/O.
|
|
Analytic 1513
|
Office apps or scripts writing files followed by xattr manipulation (to evade quarantine) and subsequent HTTPS uploads. Defender perspective: anomalous file modification + outbound TLS traffic originating from non-networking apps (Word, Excel, Preview).
|
|
Analytic 1601
|
Process using URLSession or similar API to fetch from web services without any response handling, indicative of one-way C2 channels.
|
|
Analytic 1223
|
Detects anomalous process execution patterns where a process's parent terminates quickly after process creation or is re-parented to 'init' (PID 1), often indicating double-fork or daemon-style detachment. These behaviors sever the parent-child relationship and obscure the execution origin in process tree analysis.
|
|
Analytic 2015
|
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during [Phishing](https://attack.mitre.org/techniques/T1566), [Endpoint Denial of Service](https://attack.mitre.org/techniques/T1499), or [Network Denial of Service](https://attack.mitre.org/techniques/T1498).
|
|
Analytic 1509
|
Malicious use of webserver plugins (e.g., for nginx, PHP, Node.js) that execute AppleScript or open network sockets.
|
|
Analytic 1196
|
Abuse of bind mounts to obscure process directories. Defender perspective: detecting anomalous mount operations where a process’s /proc entry is remapped to another directory, often hiding malicious activity from native utilities (ps, top). Behavior chain includes: (1) execution of `mount` with `-o bind` or `-B` flags, (2) modification of /proc entries inconsistent with expected process lineage, and (3) subsequent anomalous activity from processes whose metadata no longer matches execution context.
|
|
Analytic 0104
|
Adversary registers a Windows device to Entra ID or bypasses conditional access by adding device via Intune registration pipeline using stolen credentials.
|
|
Analytic 1045
|
Monitor for suspicious use of Windows API calls such as IsDebuggerPresent() and NtQueryInformationProcess(), or processes manually checking the BeingDebugged flag in the Process Environment Block (PEB). Detect sequences of OutputDebugStringW() calls in short intervals that may indicate debugger flooding attempts.
|
|
Analytic 0352
|
Abuse of cloud metadata APIs or CLI to push SSH public keys to authorized_keys of virtual machines.
|
|
Analytic 1234
|
Adversaries attempt to read sensitive files such as /etc/passwd and /etc/shadow for credential dumping. This may involve access to the files directly via command-line utilities (e.g., cat, less), creation of backup copies, or parsing through post-exploitation frameworks. Multi-event correlation includes elevated process execution, file access/read on sensitive paths, and anomalous read behaviors tied to non-root or unusual users.
|
|
Analytic 1139
|
Detects abnormal or rare logins via local accounts through system or remote mechanisms such as SSH.
|
|
Analytic 1456
|
Use of cloud API calls (e.g., AWS EC2 DescribeInstances, Azure VM Inventory) to enumerate system configurations across assets.
|
|
Analytic 0912
|
Direct execution of /bin/vmx or presence of rogue .vmx files not registered in vCenter inventory. Defender perspective: anomalous commands in shell history, edits to rc.local.d/local.sh for persistence.
|
|
Analytic 0488
|
A trusted/signed developer utility (parent) is executed in a non-developer context and (a) spawns suspicious children (e.g., powershell.exe, cmd.exe, rundll32.exe, regsvr32.exe, wscript.exe), (b) loads unsigned/user-writable DLLs, (c) writes and then runs a new PE from user-writable paths, and/or (d) immediately makes outbound network connections.
|
|
Analytic 1608
|
Account creation via cloud service APIs or CLI, often associated with key generation. Monitored via CloudTrail or equivalent audit logs.
|
|
Analytic 0460
|
Chain: (1) SaaS admin API or PowerShell remote session reads tenant password/authentication settings (e.g., M365 Unified Audit Log ‘Cmdlet’ with `Get-MsolPasswordPolicy`/`Get-OrganizationConfig` parameters that expose password settings); (2) same session proceeds to mailbox or tenant changes.
|
|
Analytic 0133
|
Detects attempts to clear RDP/network history and modify network configuration artifacts through command execution, registry key deletion, firewall rule changes, and suspicious file deletions (e.g., Default.rdp, registry edits to Terminal Server Client keys).
|
|
Analytic 1392
|
Detects unexpected encrypted egress traffic from management services (e.g., hostd) or guest VMs utilizing symmetric encryption without traditional protocols (e.g., FTP with embedded AES ciphertext).
|
|
Analytic 1153
|
Unusual access to bash history, registry credentials paths, or private key files by unauthorized or scripting tools, with correlated file and process activity.
|
|
Analytic 0903
|
Detects usage of commands or binaries (e.g., netstat, PowerShell Get-NetTCPConnection) and WMI or API calls to enumerate local or remote network connections.
|
|
Analytic 0323
|
Abuse of safe mode via BCD modification, boot configuration utilities (bcdedit.exe, bootcfg.exe), and registry persistence under SafeBoot keys. Defender view: suspicious boot configuration changes correlated with registry edits that enable adversary persistence or disable defenses.
|
|
Analytic 1518
|
Access to user private key directories (e.g., /Users/*/.ssh) via Terminal, scripting engines, or non-default processes.
|
|
Analytic 0438
|
Unexpected apps or scripts (osascript, curl, Automator workflows) exfiltrating data via webhooks. Defender perspective: correlation of clipboard/file read operations followed by HTTPS POST traffic to webhook services.
|
|
Analytic 0297
|
Detects PE injection through a behavioral sequence where one process opens (OpenProcess) a handle to another, allocates remote memory (VirtualAllocEx), writes a PE header (MZ) or shellcode (WriteProcessMemory), then initiates a new thread (CreateRemoteThread or NtCreateThreadEx) in that process—executing injected code in memory without touching disk. Optional: injects a trampoline or shellcode that unpacks/reflectively maps the payload.
|
|
Analytic 1618
|
Account enumeration via bulk access to user directory features or hidden APIs.
|
|
Analytic 0677
|
Database client execution (e.g., sqlcmd.exe, isql.exe) by users or from locations not tied to enterprise automation or backups. Often followed by creation of .sql/.bak/.csv files, registry artifacts for ODBC/JDBC drivers, or encrypted ZIPs. Defender sees SQL tools launched by explorer.exe, Powershell, or odd parent processes, plus file writes in user temp locations.
|
|
Analytic 1390
|
Detects command-line utilities or scripts using encryption libraries or symmetric algorithms (e.g., OpenSSL AES, GPG, Python + PyCrypto) in conjunction with outbound file transfers or traffic to external destinations.
|
|
Analytic 0977
|
Detect execution of `/usr/libexec/security_authtrampoline` or use of AuthorizationExecuteWithPrivileges API, and monitor process lineage for unusual launches of GUI apps with escalated privileges.
|
|
Analytic 1232
|
Direct use of `nc`, `socat`, or reverse tunnel scripts initiated by abnormal user contexts or unauthorized VIBs initiating connections from hypervisor to external systems.
|
|
Analytic 1502
|
Monitor for suspicious use of cloud-native administrative command services (e.g., AWS Systems Manager Run Command, Azure RunCommand, GCP OS Config) to execute code inside VMs. Detect anomalies such as commands/scripts executed by unexpected users, execution outside of maintenance windows, or commands initiated by service accounts not normally tied to administration. Correlate cloud control-plane activity logs with host-level execution (process creation, script execution) to validate if commands materialized inside the guest OS.
|
|
Analytic 0029
|
Detects macros or VBA triggers set to execute on document open or close events, often correlating with embedded payloads or C2 traffic shortly after execution.
|
|
Analytic 0252
|
Installation of configuration profiles or plist entries associated with malicious or unauthorized browser extensions
|
|
Analytic 1367
|
Sequence of RAT agent execution, systemd persistence, and long-lived external egress; optional interactive shells spawned from the agent.
|
|
Analytic 0461
|
Chain: (1) privileged CLI sessions run read-only commands that dump AAA/password policies (e.g., `show aaa`, `show password-policy`); (2) same account changes AAA or user DB shortly after. Use network device AAA/command accounting or syslog.
|
|
Analytic 1393
|
Detects anomalous use of Dynamic Data Exchange (DDE) for code execution, such as Office applications (WINWORD.EXE, EXCEL.EXE) spawning command interpreters, or loading unusual modules through DDEAUTO/DDE formulas. Correlates suspicious parent-child process relationships, registry keys enabling DDE, and module loads inconsistent with normal Office usage.
|
|
Analytic 0830
|
Execution of destructive CLI commands such as format flash:, format disk, or equivalent vendor-specific commands that erase filesystem structures. Detection correlates AAA logs showing privileged access with immediate format/erase commands.
|
|
Analytic 1328
|
Spike in object access from new IAM user or role followed by data exfiltration to external IPs
|
|
Analytic 0579
|
Detects ptrace-based process injection by correlating audit logs of ptrace syscalls, memory modifications (e.g., poketext, pokedata), and suspicious register manipulation on a target process not normally debugged by the originator. Alerts on processes attempting to ptrace non-child or privileged processes, especially those followed by abnormal memory or execution behavior.
|
|
Analytic 1250
|
Detects unauthorized modifications to PAM configuration files or shared object modules. Correlates file modification events under /etc/pam.d/ or /lib/security/ with unusual authentication activity such as multiple simultaneous logins, off-hours logins, or logons without corresponding physical/VPN access.
|
|
Analytic 0870
|
Detection of fake or spoofed macOS Security & Privacy GUIs showing healthy status after XProtect, Gatekeeper, or AV processes are disabled. Correlates user-space UI process creation with terminated or missing security daemons.
|
|
Analytic 1597
|
Detect loading or inspection of kernel extensions (kextstat, kextfind) and file access to /System/Library/Extensions/. Monitor unexpected usage of these utilities by non-administrative users or scripts.
|
|
Analytic 2014
|
Once adversaries leverage the abused web service as infrastructure (ex: for command and control), it may be possible to look for unique characteristics associated with adversary software, if known.(Citation: ThreatConnect Infrastructure Dec 2020)
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control [Web Service](https://attack.mitre.org/techniques/T1102) or [Exfiltration Over Web Service](https://attack.mitre.org/techniques/T1567) .
|
|
Analytic 0245
|
Detects unauthorized TCC access or use of Quartz Event Services (CGEventTapCreate) or IOHID for event tap installation within unexpected processes.
|
|
Analytic 1426
|
Use of OAuth tokens by third-party apps to access user mail, calendar, or SharePoint resources where the token was granted recently or via spearphishing.
|
|
Analytic 0704
|
Monitor system APIs such as CFNetwork and SecureTransport for anomalies in transmitted data streams. Detect mismatches in file hashes or SSL/TLS downgrade attempts that enable manipulation of transmitted data.
|
|
Analytic 0840
|
Suspicious calls to dlopen(), dlsym(), or mmap with RWX flags in processes that do not typically perform dynamic module loading. Monitor anonymous memory regions executed by user processes.
|
|
Analytic 1593
|
Unexpected modification of the KernelCallbackTable in a process’s PEB followed by invocation of modified callback functions (e.g., fnCOPYDATA) through Windows messages. Defender observes suspicious API call chains such as NtQueryInformationProcess → WriteProcessMemory → abnormal GUI callback execution, often correlating to anomalous process behavior such as network activity or code injection.
|
|
Analytic 2020
|
Internet scanners may be used to look for patterns associated with malicious content designed to collect host software information from visitors.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: ATT ScanBox)
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0570
|
A non-whitelisted process receives TCC camera entitlement (kTCCServiceCamera), opens AppleCamera/AVFoundation device handles, writes .mov/.mp4 artifacts to unusual locations, and/or beacons/exfiltrates soon after.
|
|
Analytic 0123
|
Installation of a new browser extension followed by suspicious file writes or outbound network connections to untrusted domains by the browser process.
|
|
Analytic 1275
|
High volume of failed logon attempts followed by a successful one from a suspicious user, host, or timeframe
|
|
Analytic 1990
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0655
|
Detection of spearphishing attachments by correlating suspicious email delivery with subsequent file creation and abnormal process execution (e.g., Office spawning PowerShell or CMD). Behavior chain includes inbound email metadata → attachment stored on disk → process execution → outbound network activity.
|
|
Analytic 0600
|
Detection of shell scripts, ELF binaries, or archives containing embedded secondary payloads, self-extracting components, or unusual compression behavior during runtime.
|
|
Analytic 0634
|
Unusual daemons or user processes binding/listening on ports outside of standard ranges, or initiating client connections using mismatched protocol/port pairings.
|
|
Analytic 1206
|
Suspicious use of NTFS file attributes such as Alternate Data Streams (ADS) or Extended Attributes (EA) to hide data. Defender perspective: anomalous file creations or modifications containing colon syntax (file.ext:ads), API calls like ZwSetEaFile/ZwQueryEaFile, or PowerShell/Windows utilities interacting with -stream parameters. Correlation across file metadata anomalies, process lineage, and command execution provides context.
|
|
Analytic 0240
|
Defender observes execution of commands like `tasklist`, `sc query`, `reg query`, or PowerShell WMI/Registry queries targeting known backup products (e.g., Veeam, Acronis, CrashPlan). Behavior often includes parent-child lineage involving PowerShell or cmd.exe with discovery syntax, and enumeration of services, directories, or registry paths tied to backup software.
|
|
Analytic 1547
|
Detection of containerized service accounts or compromised kubeconfigs being used for cluster access from unexpected nodes or IPs.
|
|
Analytic 0071
|
Abuse of trusted Electron apps (Teams, Slack, Chrome) to spawn child processes or execute payloads via malicious command-line arguments (e.g., --gpu-launcher) and modified app resources (.asar). Behavior chain: suspicious parent process (Electron app) → unusual command-line args → child process creation → optional DLL/network artifacts.
|
|
Analytic 0159
|
Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).
|
|
Analytic 1091
|
Detects anomalous ARP traffic or cache modifications on Windows endpoints that indicate ARP poisoning. Behavioral focus is on multiple IP addresses resolving to a single MAC, or unsolicited ARP replies from unauthorized devices.
|
|
Analytic 0550
|
Abuse of ClickOnce applications where rundll32.exe invokes dfshim.dll with ShOpenVerbApplication or dfsvc.exe spawns unexpected child processes or loads unsigned modules.
|
|
Analytic 1973
|
Monitor for suspicious network traffic that could be indicative of probing for user information, such as large/iterative quantities of authentication requests originating from a single source (especially if the source is known to be associated with an adversary/botnet). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields.
|
|
Analytic 0893
|
Execution of commands disabling AAA, logging, or security features on routers/switches. Detect privilege escalation followed by config changes that disable defense mechanisms.
|
|
Analytic 0146
|
Flags unexpected user applications initiating long-lived HTTP(S) sessions with irregular traffic patterns.
|
|
Analytic 1049
|
Shell scripts or binaries invoking repeated 'sleep', 'ping', or low-level syscalls (e.g., nanosleep) in short-lived execution chains with no user or system interaction. Frequently seen in malicious cron jobs or payload stagers.
|
|
Analytic 1314
|
Cause→effect chain: (1) User-facing app (Office/PDF/archiver/browser) records an open/click or abnormal event, then (2) a downloaded file is created in a user-writable path and/or decompressed, (3) the parent user app spawns a living-off-the-land binary (e.g., powershell/cmd/mshta/rundll32/msiexec/wscript/expand/zip) or installer, and (4) immediate outbound HTTP(S)/DNS/SMB from the same lineage.
|
|
Analytic 1402
|
Detects suspicious access to browser session cookie storage (e.g., Chrome’s `Cookies` SQLite DB) or memory reads of browser processes. Anomalous injection or memory dump utilities targeting browser processes such as `chrome.exe`, `firefox.exe`, or `msedge.exe`.
|
|
Analytic 0788
|
Use of curl, wget, or custom scripts to POST data to pastebin-like services. Defender perspective: identify chained behavior where files are compressed/read followed by HTTPS POST requests to text-sharing endpoints.
|
|
Analytic 0282
|
Monitors for abnormal process behavior and API calls like SetWindowsHookEx, GetAsyncKeyState, or device input polling commonly used for keystroke logging.
|
|
Analytic 0221
|
Adversary targets macOS-hosted public services (e.g., nginx, node). Chain: suspicious inbound request → service crash/5xx → service spawns shell or writes file → new outbound connection.
|
|
Analytic 1606
|
Adversary creates new users using 'dscl' commands, GUI tools, or by modifying user plist files. Detection includes monitoring dscl invocation and user-related plist changes.
|
|
Analytic 0737
|
Detects mailbox manipulation or deletion via PowerShell (e.g., Remove-MailboxExportRequest), file deletion from Outlook data stores (Unistore.db), or tampering with quarantined mail logs.
|
|
Analytic 0946
|
Implantation of malicious code into container images followed by registry push and use in new deployments.
|
|
Analytic 1643
|
Detection of password manager database access (1Password .opvault, LastPass caches, KeePass .kdbx) outside expected parent processes. Identifies memory scraping attempts via suspicious API calls or tools attaching to password manager processes.
|
|
Analytic 1270
|
Burst of failed login attempts across VM instances using leaked credential pairs from single IP in public cloud environments
|
|
Analytic 1198
|
Monitors suspicious access to password stores such as LSASS, DPAPI, Windows Credential Manager, or browser credential databases. Detects anomalous process-to-process access (e.g., Mimikatz accessing LSASS) and correlation of credential store file reads with execution of non-standard processes.
|
|
Analytic 1304
|
Correlate the creation or modification of containers using restart policies (e.g., 'always') or DaemonSets with elevated host access, service account misuse, or privileged container contexts. Watch for manipulation of systemd units involving containers or pod scheduling targeting specific nodes or namespaces.
|
|
Analytic 0711
|
Unusual access to SSH agent sockets in /tmp/ or /private/tmp, process access to another user’s $SSH_AUTH_SOCK, and lateral SSH activity without corresponding login events. Defender view: correlation of socket access with anomalous network flows to internal systems.
|
|
Analytic 0781
|
Behavior chain involving abnormal registry modifications via CLI, PowerShell, WMI, or direct API calls, especially targeting persistence, privilege escalation, or defense evasion keys, potentially followed by service restart or process execution. Such as editing Notify/Userinit/Startup keys, or disabling SafeDllSearchMode.
|
|
Analytic 1977
|
Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle.
Consider analyzing malware for features that may be associated with malware providers, such as compiler used, debugging artifacts, code similarities, or even group identifiers associated with specific MaaS offerings. Malware repositories can also be used to identify additional samples associated with the developers and the adversary utilizing their services. Identifying overlaps in malware use by different adversaries may indicate malware was obtained by the adversary rather than developed by them. In some cases, identifying overlapping characteristics in malware used by different adversaries may point to a shared quartermaster.(Citation: FireEyeSupplyChain)
|
|
Analytic 1564
|
Detection of Office or document viewer processes (e.g., winword.exe) initiating network connections to remote templates or executing scripts due to manipulated template references (e.g., embedded in .docx, .rtf, or .dotm files), followed by suspicious child process creation (e.g., PowerShell).
|
|
Analytic 0990
|
Detects unauthorized applications or scripts accessing sensitive data followed by establishing encrypted outbound communication to rare external destinations or with abnormal byte ratios.
|
|
Analytic 0933
|
Process chains that use native utilities (vssadmin, wbadmin, diskshadow, bcdedit, REAgentC, wmic) with arguments to delete shadow copies, disable recovery, or remove backup catalogs
|
|
Analytic 0406
|
Detection of firewall tampering by monitoring processes executing netsh, PowerShell Set-NetFirewallProfile, or sc stop mpssvc. Registry modifications under HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy also indicate adversarial actions.
|
|
Analytic 0858
|
Terminal-based grep or open of plist/config files containing credentials, correlated with Keychain or system login attempts.
|
|
Analytic 0476
|
EFI updates executed via system processes or binaries outside of expected patch windows or using unsigned firmware packages.
|
|
Analytic 0753
|
Use of cloud-based bastion or VM console session followed by commands that initiate outbound SSH or RDP sessions from the cloud instance to other environments.
|
|
Analytic 0528
|
Application access tokens used to call APIs (e.g., Google Workspace, Salesforce) without interactive logins, often with unusual scopes or elevated permissions.
|
|
Analytic 1073
|
Collection of device configuration via CLI commands (e.g., `show running-config`, `copy flash`, `more`), often followed by TFTP/SCP transfers.
|
|
Analytic 0740
|
Detects Exchange Online or on-prem transport rule changes (e.g., header stripping) and mailbox export cleanup via `Remove-MailboxExportRequest`, as well as admin actions via Exchange PowerShell sessions.
|
|
Analytic 1384
|
Abuse of file/registry attributes to hide malicious files, directories, or services. Defender view: detection of attrib.exe setting hidden/system flags, creation of Alternate Data Streams, or registry keys altering file visibility.
|
|
Analytic 0565
|
Applications such as `curl`, `wget`, or custom binaries initiate HTTPS connections where the TLS SNI is mismatched or absent while HTTP Host targets CDN-available C2 endpoints.
|
|
Analytic 0299
|
Detection of spearphishing links through mail logs and browser activity. Behavior includes email with suspicious URLs → user click recorded in mail/web proxy logs → shell or interpreter launched from browser process.
|
|
Analytic 0555
|
Identify unauthorized creation, deletion, or modification of business-critical stored data such as Office documents, database files, and log archives. Detect anomalous processes modifying stored data outside of expected workflows (e.g., non-database processes modifying database files).
|
|
Analytic 0642
|
Suspicious querying of organization-wide directory data via Google Workspace Directory API or Outlook GAL sync in high volume from abnormal users, service accounts, or unknown device contexts.
|
|
Analytic 0821
|
User or desktop application writes a new file to ~/Downloads, /tmp, or mounted removable media followed by execve of a risky interpreter/loader (bash, sh, python, perl, php, node, curl|wget piping to sh, ld.so, rdesktop, xdg-open - with unusual args). Uses auditd PATH+SYSCALL (open/creat/write/rename) with execve event linking.
|
|
Analytic 0815
|
Detects registration of new PTA agents, conditional access changes disabling hybrid MFA enforcement, or suspicious updates to AD FS token-signing configurations.
|
|
Analytic 0106
|
Detects attempts to access browser credential stores (e.g., Firefox `logins.json`, Chrome SQLite DB) or processes (e.g., gnome-keyring-daemon). Observes unauthorized file reads and memory inspection of browser processes using ptrace or gdb.
|
|
Analytic 1075
|
Correlates file enumeration of XML files in the SYSVOL share with suspicious process execution that decodes or reads encrypted credentials embedded in Group Policy Preference files (e.g., Get-GPPPassword.ps1, gpprefdecrypt.py, Metasploit). Detects abnormal access to \DOMAIN\SYSVOL combined with XML file parsing or decryption logic.
|
|
Analytic 0898
|
ESXi host processes (vmx, hostd) initiating HTTPS sessions toward external code repositories. Defender perspective: detect datastore reads followed by outbound web traffic inconsistent with administrative baselines.
|
|
Analytic 1345
|
Behavioral chain: (1) sshd or federated SSO logins from third-party networks or identities; (2) rapid sudo/su privilege elevation; (3) access to sensitive paths or east-west SSH. Correlate auth logs, process execution, and network flows.
|
|
Analytic 0446
|
Detection of USB-based remote access hardware (e.g., TinyPilot, PiKVM) attached to the host via drive or peripheral enumeration, triggering vendor identifiers or unusual EDID announcements.
|
|
Analytic 2021
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0610
|
Adversary manipulation of shared library paths, environment variables, or replacement of service binaries. Defender observes suspicious modifications in /etc/ld.so.preload, service config changes, or file writes replacing existing executables.
|
|
Analytic 0442
|
Monitor for unauthorized or unusual modifications to cloud resource hierarchies such as AWS Organizations or Azure Management Groups. Defenders may observe anomalous calls to APIs like `LeaveOrganization`, `CreateAccount`, `MoveAccount`, or Azure subscription transfers. Correlate account activity with administrative role assignments, tenant transfers, or new subscription creation that deviates from organizational baselines. Multi-event correlation should track role elevation followed by hierarchy modifications within a short time window.
|
|
Analytic 1535
|
MSBuild.exe is invoked outside expected developer/build contexts or with anomalous arguments (e.g., non-canonical paths, remote shares, Base64/obfuscated property values). Within a short window, it (a) spawns high-risk LOLBins/script interpreters, (b) writes new PE/DLL/script artifacts into user-writable paths and executes them, (c) loads unsigned/user-writable modules, (d) performs memory injection/thread creation into other processes, and/or (e) initiates outbound network connections.
|
|
Analytic 0752
|
Remote login via ARD or SSH followed by screensharingd process activity or modification of TCC-protected files.
|
|
Analytic 0835
|
Behavioral sequence of unauthorized privilege escalation via permission modification: (1) chmod/chown/setfacl process execution with suspicious parameters, (2) Targeting of critical system files or unusual permission values, (3) Correlation with non-privileged user context or unusual timing patterns, (4) Follow-on file access indicating successful permission bypass
|
|
Analytic 0774
|
Unusual modification of boot records (MBR, VBR) or EFI partitions not associated with legitimate patch cycles or OS upgrades. Registry or WMI events associated with firmware update tools executed from unexpected parent processes. API calls (e.g., DeviceIoControl) writing directly to raw disk sectors. Subsequent abnormal boot configuration changes followed by unsigned driver loads.
|
|
Analytic 1128
|
Enumeration of directories, applications, or service principals through APIs such as Microsoft Graph or Okta API. Defender perspective includes unexpected listing of users, roles, applications, and abnormal access to identity management endpoints.
|
|
Analytic 1098
|
Detect runtime manipulation by monitoring system calls for modifications to shared libraries, ELF binaries, or environment variables that affect how data is displayed. Look for suspicious writes to application directories and mismatch in binary integrity baselines.
|
|
Analytic 0949
|
Monitors for unexpected modifications of system or application binaries, particularly signed executables. Correlates file write events with subsequent unsigned or anomalously signed process execution, and checks for tampered binaries outside normal patch cycles.
|
|
Analytic 1264
|
Burst of failed authentications with rotating usernames against loginwindow or remote management service using reused breached credentials
|
|
Analytic 0935
|
ESXi shell or vim-cmd execution that deletes all VM snapshots using vmsvc/snapshot.removeall or rm on snapshot paths
|
|
Analytic 0713
|
Defender observes unauthorized modification or creation of Python hook files such as `.pth`, `sitecustomize.py`, or `usercustomize.py` in Python `site-packages`, `dist-packages`, or user paths. This is often correlated with subsequent unexpected interpreter execution (e.g., python3 running without user interaction), changes in interpreter behavior (e.g., malicious imports), and outbound connections initiated from Python. Defender links write/modify actions on hook files with execve of python process and/or anomalous child process or network activity.
|
|
Analytic 0375
|
Detection of the creation of VSCode or JetBrains CLI tunneling profiles followed by persistent remote access via IDE-integrated tunnels, potentially authenticated via GitHub or JetBrains accounts.
|
|
Analytic 0452
|
Monitor PAM and syslog entries for unusual frequency of login attempts that trigger MFA prompts, particularly when MFA challenges do not match expected user behavior.
|
|
Analytic 1184
|
API usage or filesystem access revealing user state or browser artifacts (e.g., Safari bookmarks, CGEventState).
|
|
Analytic 1175
|
Detect execution of system utilities (systemctl, systemd-inhibit, systemdsleep) modifying sleep or hibernate behavior. Abnormal edits to system configuration files (e.g., /etc/systemd/sleep.conf) should be correlated with process execution to identify persistence techniques.
|
|
Analytic 0242
|
Defender detects execution of `mdfind`, `launchctl`, or GUI-based enumeration (e.g., `/Applications/Time Machine.app`) along with command-line usage of `find`, `grep`, or `system_profiler` to identify installed backup tools like Time Machine, Carbon Copy Cloner, or Backblaze. Often triggered from Terminal sessions or within post-exploitation scripts.
|
|
Analytic 0355
|
Adversary renames LOLBINs or deploys binaries with spoofed file names, internal PE metadata, or misleading icons to appear legitimate. File creation is followed by execution or service registration inconsistent with known usage.
|
|
Analytic 0862
|
Adversary ships a tampered application or update: an updater/installer (msiexec/setup/update.exe/vendor service) writes or replaces binaries; on first run it spawns scripts/shells or unsigned DLLs and beacons to non-approved update CDNs/hosts. Detection correlates: (1) process creation of installer/updater → (2) file metadata changes in program paths → (3) first-run children and module/signature anomalies → (4) outbound connections to unexpected hosts within a short window.
|
|
Analytic 1262
|
Multiple failed authentication attempts using distinct username/password pairs from a single IP address or session within a short time window, targeting common services like RDP or SMB
|
|
Analytic 0792
|
Monitor for anomalous email activity originating from Windows-hosted applications (e.g., Outlook) where the sending account name or display name does not match the underlying SMTP address. Detect abnormal volume of outbound messages containing sensitive keywords (e.g., 'payment', 'wire transfer') or anomalous login locations for accounts associated with email sending activity.
|
|
Analytic 0803
|
Disabling mailbox or tenant-level audit logging, often using Set-MailboxAuditBypassAssociation or downgrading license tiers. Defender view: sudden absence of mailbox activity logging for monitored users.
|
|
Analytic 1947
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1046
|
Monitor access to /proc/self/status where TracerPID field is queried, as this is a common technique for debugger detection. Detect processes that attempt to trigger exceptions intentionally and monitor whether exception handling indicates presence of a debugger.
|
|
Analytic 1974
|
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the potential use of generative artificial intelligence (i.e. [Phishing](https://attack.mitre.org/techniques/T1566), [Phishing for Information](https://attack.mitre.org/techniques/T1598)).
|
|
Analytic 0233
|
Execution of container orchestration commands (e.g., `docker exec`, `kubectl exec`) or API-driven interactions with running containers from unauthorized hosts or non-standard user contexts. Defender sees programmatic or interactive command execution within containers outside expected CI/CD tools or automation frameworks, often followed by file writes, privilege escalation, or lateral discovery.
|
|
Analytic 0937
|
Cloud API calls disabling snapshot scheduling, backup policies, versioning, followed by DeleteSnapshot/DeleteVolume operations
|
|
Analytic 0930
|
ESXi shell or scripts produce long, high-entropy tokens (non-standard alphabets) in shell.log/hostd, followed by outbound flows (NSX/Zeek) with asymmetric ratios or protocol mismatches to non-management endpoints.
|
|
Analytic 1374
|
Detects disabling AAA, syslog, SNMP traps, ACL logging, or security features on routers/switches/firewalls; correlates privileged login followed by configuration commit reducing visibility.
|
|
Analytic 0836
|
macOS-specific permission modification behavioral chain: (1) chmod/chown/chflags process execution, (2) System Integrity Protection (SIP) bypass attempts, (3) Extended attribute (xattr) modifications, (4) Unified log correlation with file system events, (5) Subsequent access to previously restricted resources
|
|
Analytic 1612
|
Detection of processes performing local or domain account enumeration by invoking account directory queries or security APIs followed by structured output of account lists. The defender observes command execution or API invocation patterns that retrieve account information and produce enumeration artifacts shortly afterward.
|
|
Analytic 0044
|
Detects snapshots or data stored in VMFS volumes from root CLI or remote agents.
|
|
Analytic 1110
|
Web servers (e.g., httpd) spawning abnormal processes post file upload into /Library/WebServer/Documents or /usr/local/var/www
|
|
Analytic 0262
|
Detects modification of ESXi cron jobs, local.sh scripts, or scheduled API calls to persist custom binaries or shell scripts.
|
|
Analytic 0353
|
Direct modification of /etc/ssh/keys-/authorized_keys or enabling SSH in sshd_config to support public key auth.
|
|
Analytic 1633
|
Detects exploitation attempts targeting defensive security software or OS services. Defender observation includes abnormal process behavior (e.g., AV or EDR crashing unexpectedly), unsigned/untrusted modules loaded into defensive processes, or privilege escalation from security agent services. Multi-event correlation ties exploitation attempts to subsequent evasive behavior like service termination or missing logs.
|
|
Analytic 0564
|
Suspicious outbound HTTPS connections where the TLS Server Name Indication (SNI) does not match the HTTP Host header, indicating potential use of domain fronting to mask C2 traffic via CDNs.
|
|
Analytic 0638
|
Shell script or binary initiates curl/wget request to staging domain, writes output to disk or memory, and shortly afterward launches another process that establishes new outbound connection to a different IP or hostname.
|
|
Analytic 1397
|
Detection of mshta.exe execution where command-line arguments reference remote or local HTA/script content (VBScript/JScript) followed by subsequent file creation, network retrieval, or process spawning that indicates payload execution outside standard Internet Explorer security context. Correlation includes parent process lineage, command-line inspection, and network connection creation to untrusted or anomalous endpoints.
|
|
Analytic 0901
|
Adversaries create SaaS accounts via admin dashboards or integrations (e.g., Zoom, Salesforce, Slack). Monitor lifecycle.create or account provisioning events from non-standard sources or times.
|
|
Analytic 0995
|
Detection of processes launching downgraded PowerShell versions (e.g., v2) or other legacy binaries that lack logging or security features. Correlates command-line arguments, process metadata, and version fields. Monitors registry changes to Defender or HVCI keys that could indicate intentional downgrades.
|
|
Analytic 0043
|
Detects virtual disk expansion or file copy operations to cloud buckets or mounted volumes from isolated instances.
|
|
Analytic 1116
|
Office-based persistence via Office template macros, Outlook forms/rules/homepage, or registry-persistent scripts. Adversary modifies registry keys or Office application directories to load malicious scripts at startup.
|
|
Analytic 0777
|
Unexpected firmware image uploads via TFTP/FTP/SCP. Configuration changes modifying boot image pointers. Logs showing boot variable redirection to non-standard images. Anomalous reboots immediately following firmware changes not tied to patch schedules.
|
|
Analytic 2028
|
Once adversaries leverage the web service as infrastructure (ex: for command and control), it may be possible to look for unique characteristics associated with adversary software, if known.(Citation: ThreatConnect Infrastructure Dec 2020) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control ([Web Service](https://attack.mitre.org/techniques/T1102)) or [Exfiltration Over Web Service](https://attack.mitre.org/techniques/T1567).
|
|
Analytic 0066
|
Detection of unpacking behavior through abnormal memory allocation, followed by executable code injection and execution from non-image sections.
|
|
Analytic 0852
|
Application crash or repeated restart cycle triggered by malformed input or exploit file, observed via unified logs and process crash monitoring.
|
|
Analytic 0464
|
Process opens /dev/bpf* (libpcap) or loads NetworkExtension filter, then after a crafted inbound packet the same process initiates an outbound connection to the trigger origin.
|
|
Analytic 1394
|
Detection of command-line activity exhibiting syntactic obfuscation patterns, such as excessive escape characters, base64 encoding, command concatenation, or outlier command length and entropy.
|
|
Analytic 0622
|
Abuse of mmc.exe to execute non-Microsoft or user-staged .msc files and malicious COM CLSIDs. Behavioral chain: (1) suspicious mmc.exe invocation with /a or -Embedding and non-standard .msc path → (2) COM activation of non-baseline CLSIDs by mmc.exe → (3) mmc.exe loads non-baseline DLLs (user-writable/UNC/unsigned) → (4) optional network/DNS activity from mmc.exe.
|
|
Analytic 1318
|
Cause→effect chain in cloud consoles: (1) user clicks link then invokes instance/image creation via API, (2) instance/image originates from external AMI or unknown image, (3) instance immediately egresses or retrieves payloads.
|
|
Analytic 0659
|
Detection of edits or additions to /etc/rc.common, /Library/StartupItems, or /System/Library/StartupItems and associated script execution during login or reboot.
|
|
Analytic 1464
|
Execution of PubPrn.vbs via cscript.exe using the 'script:' moniker to load and execute a remote .sct scriptlet file, bypassing signature validation and proxying remote payloads through a signed Microsoft script host.
|
|
Analytic 1205
|
Correlates Office 365 or Google Workspace audit logs for spoofed sender addresses, failed email authentication, and anomalies in message delivery metadata. Defender observes failed SPF/DKIM checks and domain mismatches tied to suspicious campaigns.
|
|
Analytic 0055
|
Executable or script payloads lacking symbol information and readable strings that are created or dropped by unusual or short-lived processes.
|
|
Analytic 0651
|
Detect the creation or modification of common media file formats (e.g., .jpg, .png, .wav) following suspicious process activity like compression or encryption, especially when paired with lateral movement or exfiltration behavior.
|
|
Analytic 0954
|
Use of stolen Kerberos tickets or token impersonation resulting in logon sessions from accounts without expected interactive logon events.
|
|
Analytic 0563
|
CLI-based execution of interface and routing discovery commands (e.g., `show ip interface`, `show arp`, `show route`) over Telnet, SSH, or console.
|
|
Analytic 2034
|
Detects consent grants, password resets, role changes, external sharing, or token creation shortly after user interaction with messages, invites, or help desk workflows. Emphasis is placed on unusual requester relationships, new device context, or off-hours approvals.
|
|
Analytic 1600
|
Curl, wget, or custom HTTP clients initiated by uncommon user accounts or cron jobs to popular web services, with no observed response parsing logic.
|
|
Analytic 1133
|
Monitor Windows Registry modifications to Winlogon keys (Shell, Userinit, Notify) that introduce new executable or DLL paths. Correlate these changes with subsequent DLL loading, image loads, or process creation originating from winlogon.exe or userinit.exe. Abnormal child process lineage or unauthorized binaries in C:\Windows\System32 may indicate abuse.
|
|
Analytic 0007
|
Adversary with access to domain management tools (e.g., `realmd`, `samba-tool`, `ldapmodify`) creates a new domain user via command-line utilities. Behavior chain: LDAP command or script triggers → user entry added in AD via Kerberos/LDAP traffic.
|
|
Analytic 1032
|
Correlation of Registry key creation/modification events under known Run/Startup keys with new or unusual binary paths or script-based payloads. Multi-event detection includes registry modification followed by process execution from non-standard directories or abnormal parent-child process relationships.
|
|
Analytic 1536
|
Registry key modification to AppInit_DLLs value followed by anomalous DLL loading by processes importing user32.dll, especially unsigned or uncommon DLLs, suggesting unauthorized AppInit persistence or privilege escalation.
|
|
Analytic 0640
|
CLI-based or API-based network call from the hypervisor to external staging host, shortly followed by a connection to a second external IP by a spawned process or scheduled task.
|
|
Analytic 0611
|
Abuse of DYLD_INSERT_LIBRARIES or hijacking framework paths for malicious libraries. Defender observes processes invoking abnormal dylibs, modified plist files, or persistence entries pointing to altered binaries.
|
|
Analytic 1469
|
Addition of credentials (keys, app passwords, x.509 certs) to existing cloud accounts, service principals, or OAuth apps via portal or API by non-standard identities or IP ranges.
|
|
Analytic 0730
|
Use unified logs to detect unusual DNS responses correlated with subsequent connections to calculated or non-standard ports. Monitor non-browser apps making repeated outbound connections that deviate from expected patterns.
|
|
Analytic 0453
|
Detect anomalous OAuth or SSO logins that repeatedly generate MFA challenges, particularly where MFA approvals are denied or timed out by the user.
|
|
Analytic 1975
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 0631
|
Detects when a script or binary is named with misleading or benign-looking extensions (.jpg, .doc) and is then executed via command line or a scheduled task. Includes ELF header mismatches and content-type inconsistencies on disk.
|
|
Analytic 0238
|
Detection of suspicious use of shell utilities or scripts that decode or decrypt a payload and execute it without writing to disk.
|
|
Analytic 0041
|
Detects script or user activity copying files to a central temp or /mnt directory followed by archive/compression utilities.
|
|
Analytic 0118
|
Detects abuse of verclsid.exe to execute COM objects by monitoring process creation, CLSID arguments, DLLs or scriptlet engines loaded into memory, and If the CLSID points to remote SCT/HTA content, verclsid.exe makes outbound connections.
|
|
Analytic 1440
|
Detects suspicious use of PowerShell, .NET, or script interpreters to spawn processes that mimic UAC prompts, often with credential capture dialogue boxes invoked from non-standard parent processes.
|
|
Analytic 1507
|
Installation of malicious IIS/Apache/SQL server modules that later execute command-line interpreters or establish outbound connections.
|
|
Analytic 0062
|
Adversary executes systemctl or service stop targeting high-value services (e.g., mysql, sshd), possibly followed by rm or shred against data stores. Behavioral chain: sudo/su usage + stop command + /var/log/messages or syslog entries + file access/delete.
|
|
Analytic 1163
|
Access of mounted cloud shares or document repositories via browser, terminal, or Finder by users not typically interacting with those resources. Includes script-based enumeration or mass download.
|
|
Analytic 1086
|
A process or terminal command outside of standard shell utilities reads the user's .bash_history file. On macOS, unified logs or telemetry tools like EndpointSecurity (ESF) may observe file read APIs or terminal process lineage that shows non-user-initiated access.
|
|
Analytic 1458
|
Detects adversarial archiving of files prior to exfiltration by correlating execution of compression/encryption utilities (e.g., makecab.exe, rar.exe, 7z.exe, powershell Compress-Archive) with subsequent creation of large compressed or encrypted files. Identifies abnormal process lineage involving crypt32.dll usage, command-line arguments invoking compression switches, and file write operations to temporary or staging directories.
|
|
Analytic 1274
|
Detects anomalous network traffic on UDP 5355 (LLMNR) and UDP 137 (NBT-NS) combined with unauthorized SMB relay attempts, registry modifications re-enabling multicast name resolution, or suspicious service creation indicative of adversary-in-the-middle credential interception.
|
|
Analytic 0766
|
Observes creation or modification of LaunchAgent/LaunchDaemon property list files combined with anomalous plist payload execution after user logon
|
|
Analytic 0270
|
Role escalation (e.g., Editor → Owner) in cloud collaboration tools (Google Workspace, O365) or file sharing apps to maintain elevated access.
|
|
Analytic 0333
|
Detects manipulation of PNG, JPG, or GIF files by user-initiated scripts followed by script execution or exfiltration behavior, especially from `osascript`, `python`, or `bash`, in combination with LaunchAgent persistence or curl activity.
|
|
Analytic 1516
|
A process (non-system or user-initiated) accesses private key files in user profile paths or system certificate stores followed by potential network connections or compression activity.
|
|
Analytic 0653
|
Abnormal usage of Preview, ImageMagick, or binary editors to alter images/documents, followed by exfiltration or outbound connections with mismatched file MIME types or payload structure.
|
|
Analytic 1141
|
Spoofed outbound packets sent to amplification services from command-line tools or scripts, combined with abnormal outbound packet volume on known reflector ports
|
|
Analytic 1082
|
Identifies use of sh/bash/zsh in suspicious context, such as user scripts launched from non-standard apps (e.g., Preview.app), embedded in LaunchDaemons, or executed outside Terminal.app. Looks for misuse in Automator, LaunchAgents, or NSAppleScript-executed shell.
|
|
Analytic 0831
|
Detects adversarial archiving using built-in or third-party utilities (makecab, diantz, xcopy, certutil, 7z, WinRAR, WinZip). Correlates suspicious process creation events with command-line arguments for compression/encoding, followed by creation of archive files (.cab, .zip, .7z, .rar). Identifies anomalous loading of crypt32.dll for encryption operations or execution of diantz.exe to compress remotely staged files.
|
|
Analytic 0012
|
Execution of binaries where the on-disk filename does not match PE metadata such as OriginalFilename or InternalName. Often observed with renamed LOLBAS or system binaries like rundll32, powershell, or psexec.
|
|
Analytic 0854
|
Adversary modifies GPO containers or files under SYSVOL using LDAP, ADSI, PowerShell (e.g., New-GPOImmediateTask) or GUI tools. This includes directory object changes (e.g., gPCFileSysPath), delegation assignments (SeEnableDelegationPrivilege), and SYSVOL file writes (ScheduledTasks.xml, GptTmpl.inf).
|
|
Analytic 1453
|
Execution of system enumeration commands such as `uname`, `df`, `uptime`, `hostname`, `lscpu`, and `cat /etc/os-release` through local terminal or scripts.
|
|
Analytic 0018
|
Federated login using SSO or OAuth grant to cloud control plane, followed by directory or permissions enumeration
|
|
Analytic 1053
|
Correlate creation or modification of serverless functions (e.g., AWS Lambda, GCP Cloud Functions, Azure Functions) with anomalous IAM role assignments or permissions escalation events. Detect subsequent executions of newly created functions that perform unexpected actions such as spawning outbound network connections, accessing sensitive resources, or creating additional credentials.
|
|
Analytic 1634
|
Detects kernel- or user-space exploitation attempts targeting auditd, AV daemons, or security monitoring agents. Defender observation includes unexpected segfaults, privilege escalation attempts from low-privileged processes, or modifications to security binaries. Correlates exploitation attempts with subsequent gaps in logging or terminated processes.
|
|
Analytic 0559
|
Execution of built-in tools (e.g., ipconfig, route, netsh) or PowerShell/WMI queries to enumerate IP, MAC, interface status, or routing configuration.
|
|
Analytic 1236
|
Local user accounts are created via binaries like 'useradd', 'adduser', or by editing passwd/shadow. Behavior chain includes execution of user management binaries or modification of user database files.
|
|
Analytic 0289
|
Detects unauthorized additions or changes to /Library/Security/SecurityAgentPlugins and suspicious process activity attempting to hook authentication APIs. Correlates file modifications with abnormal plugin loads in authentication flows.
|
|
Analytic 0706
|
Monitor for suspicious use of commands such as cat, less, grep, or journalctl accessing /var/log/ files. Abnormal enumeration of authentication logs (auth.log, secure) or bulk access to multiple logs in short time windows should be flagged.
|
|
Analytic 0002
|
Detects non-standard processes (e.g., PowerShell, python.exe, rundll32.exe) making outbound connections using publish/subscribe protocols (e.g., MQTT, AMQP) over non-browser, encrypted channels, often beaconing to message brokers.
|
|
Analytic 1178
|
Correlate DNS queries that generate domains with high entropy or gibberish patterns, combined with short-lived connections from unusual processes. Monitor Sysmon DNS events and Windows Security logs for abnormal query rates and failed lookups.
|
|
Analytic 1188
|
Creation, deletion, or modification of security groups and firewall rules in cloud control plane logs that expand access to cloud resources beyond expected baselines. Defender view: unexpected ingress/egress rules permitting 0.0.0.0/0 or opening atypical ports, often correlated with privileged role or API key activity.
|
|
Analytic 0321
|
Use of non-enterprise email or messaging services in Thunderbird, Evolution, or browsers leading to suspicious file downloads and subsequent execution. Defender view includes browser-initiated downloads of unexpected content and shell or interpreter processes launched post-download.
|
|
Analytic 0695
|
Detects adversarial use of cloud-native APIs (e.g., AWS IAM, Azure RBAC, GCP Identity) to enumerate cloud group memberships or policy mappings via unauthorized sessions or scripts.
|
|
Analytic 0365
|
Domain group and user enumeration via dscl or dscacheutil, or queries to directory services from non-admin endpoints.
|
|
Analytic 1018
|
Execution of `ping`, `vmkping`, or `curl` from shell or through automation jobs/scripts to verify Internet egress.
|
|
Analytic 0509
|
Group membership checks via 'dscl', 'dscacheutil', or 'id', typically executed via terminal or automation scripts.
|
|
Analytic 1362
|
Monitor server and endpoint logs for unusual outbound network connections to cryptocurrency nodes, unauthorized scripts accessing financial systems, or automation targeting payment file formats. Detect curl/wget activity aimed at exfiltrating transaction data or credentials from financial apps.
|
|
Analytic 0760
|
Processes like curl, wget, python, socat, or custom binaries initiating TLS/SSL sessions to non-standard destinations. Defender sees abnormal syscalls for connect(), loading of libssl libraries, and persistent outbound encrypted traffic from daemons not normally communicating externally.
|
|
Analytic 1347
|
Behavioral chain: (1) delegated admin or external identity establishes session (e.g., partner/reseller DAP, B2B guest, SAML/OAuth trust); (2) role elevation or app consent/permission grant; (3) downstream privileged actions in the tenant. Correlate IdP sign-in, admin/role assignment, and consent/admin-on-behalf events.
|
|
Analytic 0277
|
Detects malicious injection behavior involving memory allocation, remote thread queuing via APC (e.g., QueueUserAPC), and altered thread context within another live process to execute unauthorized code under legitimate context.
|
|
Analytic 0637
|
Initial process initiates outbound connection to first-stage C2, receives payloads or commands, then spawns or injects into a second process that establishes a new outbound connection to an unrelated destination (second-stage C2).
|
|
Analytic 1539
|
Detect 'shutdown', 'reboot', or 'systemctl poweroff' executions with auditd/syslog and absence of scheduled maintenance windows or approved user context.
|
|
Analytic 0853
|
Cloud workload exploitation leads to repeated container, service, or VM termination/restart, typically associated with CVE-based crash triggers or fuzzed payloads.
|
|
Analytic 1957
|
If infrastructure or patterns in the malicious web content utilized to deliver a [Drive-by Compromise](https://attack.mitre.org/techniques/T1189) have been previously identified, internet scanning may uncover when an adversary has staged web content for use in a strategic web compromise.
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on other phases of the adversary lifecycle, such as [Drive-by Compromise](https://attack.mitre.org/techniques/T1189) or [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203).
|
|
Analytic 1068
|
Detects encoded PowerCLI or Base64-encoded payloads staged via datastore uploads or shell access (e.g., ESXi Shell or backdoored VIBs).
|
|
Analytic 1515
|
ESXi guest OS or management interface processes establishing unexpected external HTTPS connections. Defender perspective: monitor vmx or hostd processes making outbound web requests with significant data transfer.
|
|
Analytic 0065
|
Adversary stages a lure that references a remote resource (e.g., LNK/SCF/Office template). When the user opens/renders the file or a shell enumerates icons, the host automatically attempts SMB or WebDAV authentication to the attacker host. The chain is: (1) lure file is created or modified in a user-exposed location → (2) user or system accesses the lure → (3) host makes outbound NTLM (SMB 139/445 or WebDAV over 80/443) to an untrusted destination → (4) repeated attempts from multiple users/hosts or from privileged workstations.
|
|
Analytic 0165
|
Unusual or uncommon processes initiate network connections to external destinations followed by file creation (tools downloaded).
|
|
Analytic 2033
|
Detects suspicious inbound communications or collaboration requests followed by rapid sensitive user actions such as file sharing changes, macro enablement, OAuth consent, credential submission, or financial workflow approvals that deviate from historical relationships or normal approval patterns.
|
|
Analytic 0646
|
Detects anomalous usage of ESXi Guest Operations APIs such as StartProgramInGuest, ListProcessesInGuest, ListFileInGuest, or InitiateFileTransferFromGuest. Defender perspective focuses on unusual frequency of guest API calls, invocation from unexpected management accounts, or execution outside of business hours. These correlated signals indicate adversarial abuse of ESXi administrative services to run commands on guest VMs.
|
|
Analytic 0445
|
Detection of msiexec.exe execution where command-line arguments reference remote MSI packages, UNC paths, HTTP/HTTPS URLs, or DLLs, correlated with subsequent module loads and/or network connections to previously unseen destinations. The behavioral chain links process creation of msiexec.exe with suspicious parameters, network activity to retrieve payloads, and module loading indicative of malicious installation or DLL execution.
|
|
Analytic 1361
|
Monitor for anomalous access to financial applications, browser-based banking sessions, or enterprise ERP systems from Windows endpoints. Detect mass emailing of payment instructions, sudden rule changes in Outlook for financial staff, or use of clipboard data exfiltration tied to cryptocurrency wallet addresses.
|
|
Analytic 0582
|
Detects abuse of container orchestration platforms (e.g., Kubernetes) where adversaries create CronJobs to maintain persistence or execute malicious Jobs across the cluster.
|
|
Analytic 0073
|
Abuse of macOS Electron apps by modifying app.asar bundles and spawning child processes (osascript, curl, sh) from Electron executables.
|
|
Analytic 1999
|
Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.
|
|
Analytic 0581
|
Execution of XSL scripts via msxsl.exe or wmic.exe using embedded JScript or VBScript for proxy execution. Detection correlates process creation, command-line patterns, and module load behavior of scripting components (e.g., jscript.dll).
|
|
Analytic 1577
|
Detects creation or modification of `LaunchDaemon` or `LaunchAgent` plist files under `/Library/LaunchDaemons/`, `~/Library/LaunchAgents/`, or similar. Monitors execution of `launchctl`, property list edits, and file permission changes.
|
|
Analytic 0388
|
Execution of InstallUtil.exe from .NET framework directories with arguments specifying non-standard or attacker-supplied assemblies, especially when followed by suspicious child process creation or script execution. Detection also includes correlation of newly created binaries prior to InstallUtil invocation and anomalous command-line usage compared to historical baselines.
|
|
Analytic 0172
|
Detects Python execution via python.exe or py.exe with anomalous parent lineage (e.g., Office macros, LOLBAS), execution from unusual directories, or chained network/PowerShell/system-level activity.
|
|
Analytic 1135
|
Abuse of extended attributes (xattrs) to embed hidden payloads into legitimate files. Defender perspective: detect anomalous use of setfattr or getfattr commands, or direct syscalls (setxattr, getxattr) where attributes are unusually large or contain encoded data. Behavior chain includes: (1) execution of setfattr with suspicious namespaces (user., trusted.), (2) file metadata modification inconsistent with file size/hash, and (3) subsequent process execution reading attributes followed by decoding activity.
|
|
Analytic 0569
|
A process opens/reads /dev/video* (V4L2), performs ioctl/read loops, writes large/continuous video artifacts to disk, and/or quickly establishes outbound connections for exfiltration.
|
|
Analytic 0359
|
Adversary places scripts or binaries with misleading names in /etc/rc.local.d or /var/spool/cron, or registers services with legitimate-sounding names not present in default ESXi builds.
|
|
Analytic 0755
|
Adversary modifies Group Policy Objects (GPOs), domain trust, or directory service objects via GUI, CLI, or programmatic APIs. Behavior includes creation/modification of GPOs, delegation permissions, trust objects, or rogue domain controller registration.
|
|
Analytic 1373
|
Detects disabling container runtime security controls, removing sidecar sensors, modifying seccomp/AppArmor profiles, mounting host proc/sys paths to interfere with host logging, or killing in-container monitoring agents.
|
|
Analytic 2042
|
Detects exploitation or abuse of SaaS security workflows resulting in disabled alerts, reduced retention, bypassed enforcement, role escalation, or tokenized persistence that weakens monitoring. Correlates unusual admin/API activity with visibility reduction.
|
|
Analytic 0728
|
Monitor DNS query results where subsequent connections use derived or unusual port numbers not explicitly resolved, especially when tied to suspicious processes. Correlate Sysmon DNS logs (Event ID 22) with process creation and socket activity.
|
|
Analytic 0001
|
Detects access attempts to cloud instance metadata endpoints (e.g., 169.254.169.254) from virtual machines or containerized workloads. This includes both direct access and SSRF exploitation patterns.
|
|
Analytic 0449
|
Monitor for excessive or anomalous MFA push notifications or token requests, especially when login attempts originate from unusual IPs or geolocations and do not correspond to legitimate user-initiated sessions.
|
|
Analytic 1524
|
Multiple failed sign-in attempts from external sources across many users followed by success from the same IP
|
|
Analytic 1261
|
Detection of container image build activity directly on the host using Docker or Kubernetes APIs. Defenders may observe Docker build requests, anomalous Dockerfile instructions (such as downloading code from unknown IPs), or creation of new images followed by immediate deployment. This behavior chain typically consists of an unexpected image creation event correlated with outbound network communication to non-standard or untrusted destinations.
|
|
Analytic 1136
|
Abuse of extended attributes (xattrs) to hide payloads in com.apple.* or custom keys. Defender perspective: monitor suspicious use of xattr command with -w (write) and -p (print) flags, especially when followed by execution of interpreters like bash, Python, or osascript. Behavior chain includes: (1) suspicious file modification with new com.apple.* attributes, (2) attribute content inconsistent with expected metadata tags (e.g., high entropy), (3) subsequent process execution correlated with extraction of the attribute.
|
|
Analytic 0709
|
Monitor ESXi shell or API access to host logs under /var/log/. Abnormal enumeration of vmkernel.log, hostd.log, or vpxa.log by unauthorized accounts should be flagged.
|
|
Analytic 0914
|
Detects ELF binaries written to disk that demonstrate anomalous file size or entropy, quickly followed by execution or memory region writes into remote processes (e.g., using ptrace).
|
|
Analytic 0099
|
Monitors CLI-based execution of `show process` or equivalent on routers/switches. Correlates unusual device access, unauthorized roles, or config mode changes.
|
|
Analytic 0533
|
Use of pbpaste, AppleScript, or third-party automation frameworks (e.g., Automator) to collect clipboard or file content in bursts. Observable via unified logs.
|
|
Analytic 0117
|
Adversary with write access to storage modifies lifecycle policies (e.g., via PutBucketLifecycle) to schedule rapid object deletion across one or more storage buckets. This is often used to trigger impact (destruction), remove logs (defense evasion), or force extortion (ransomware).
|
|
Analytic 1087
|
Enumeration of identity roles and users via API calls such as `Get-MsolRoleMember`, `az ad user list`, or Graph API tokens from unauthorized users or automation accounts.
|
|
Analytic 1584
|
Use of bash scripts or interactive shells to issue sequential ping, arp, or traceroute commands to map remote hosts.
|
|
Analytic 0621
|
Processes invoking AVFoundation or CoreAudio frameworks, accessing input devices via TCC logs or Unified Logs, followed by writing AIFF/WAV/MP3 files to disk.
|
|
Analytic 0047
|
Detects unauthorized termination of system daemons or commands issued through launchctl or kill to stop competing services or malware processes. Defenders should monitor unified logs and EDR telemetry for unusual service modifications or terminations.
|
|
Analytic 1054
|
Monitor for creation of new Power Automate flows or equivalent automation scripts that trigger on user or file events. Detect anomalous actions performed by these automations, such as email forwarding, anonymous link creation, or unexpected API calls to external endpoints.
|
|
Analytic 0332
|
Detects access to media files followed by execution of scripts (bash, Python, etc.) referencing those same files, or outbound traffic triggered shortly after file read. Correlates unusual use of tools like `steghide`, `exiftool`, or image libraries.
|
|
Analytic 0519
|
Identify lateral transfer via datastore file uploads or internal scp/ssh sessions that result in new VMX/VMDK or script files. Correlate transfer with VM execution or datastore modification.
|
|
Analytic 0991
|
Detects VMs sending outbound traffic through non-standard services or to unknown destinations. Exfiltration over reverse shells tunneled via VMkernel or custom payloads routed via hostd/vpxa.
|
|
Analytic 0487
|
Forged cookies in SaaS environments manifest as valid web sessions without matching login activity, MFA enforcement bypass, or cookies reused across multiple devices/IPs. Defenders should look for cookie replay, concurrent sessions from multiple geographies, or session tokens generated by unrecognized apps.
|
|
Analytic 0327
|
Correlates inbound network access to remote service ports (e.g., SMB/RPC 445/135, RDP 3389, WinRM 5985/5986) with near-time instability in the target service (crash, abnormal restart), suspicious child process creation under the service, and post-access lateral-movement behaviors. The chain indicates likely exploitation rather than normal administration.
|
|
Analytic 0279
|
Detects invocation of lua or luajit interpreters by users or services outside of expected packages, chained with script drop or memory artifacts.
|
|
Analytic 1528
|
Detects the creation or execution of padded binary files (e.g., large size but minimal legitimate content) followed by process execution or lateral movement from the host.
|
|
Analytic 0593
|
Login to vSphere or ESXi hosts using domain accounts, especially those associated with vpxuser or unexpected group memberships.
|
|
Analytic 0909
|
Unusual execution of virtualization binaries (VBoxManage.exe, vmware-vmx.exe, vmwp.exe) with headless or suppressed notification arguments. Registry and service modifications linked to virtualization installs. Defender view: anomalies in process creation, service metadata, and registry writes tied to enabling hidden VMs.
|
|
Analytic 1334
|
Monitor ESXi syslog and esxcli outputs for abnormal DNS resolver behavior, such as frequent domain-to-IP changes or unauthorized modifications of DNS settings used by management agents. Correlate domain lookups with short TTL values.
|
|
Analytic 0302
|
Atypical processes (e.g., powershell.exe, regsvr32.exe) encode large outbound traffic using Base64 or other character encodings; this traffic is sent over uncommon ports or embedded in protocol fields (e.g., HTTP cookies or headers).
|
|
Analytic 0524
|
Tracks suspicious use of ESXi shell commands or PowerCLI to delete logs, rotate system files, or tamper with hostd/vpxa history.
|
|
Analytic 1543
|
Detection of compromised or misused valid accounts via anomalous logon patterns, abnormal logon types, and inconsistent geographic or time-based activity across Windows endpoints.
|
|
Analytic 0035
|
Execution of Wine or LibreOffice macros with inconsistent VBA metadata. Defender perspective: file analysis showing p-code embedded without matching source streams.
|
|
Analytic 0511
|
Creation or modification of stored procedures invoking xp_cmdshell or CLR assemblies for command execution and persistence.
|
|
Analytic 0952
|
Detects unauthorized modification of host binaries, modules, or services within ESXi. Correlates tampered files with subsequent unexpected service behavior or malicious module load attempts.
|
|
Analytic 0168
|
Command line interface or vCLI triggers remote transfer using wget or curl, writing files into datastore paths or local tmp directories.
|
|
Analytic 0020
|
Remote access to third-party SaaS with OAuth or API tokens post-initial compromise, followed by sensitive data access or configuration changes
|
|
Analytic 1461
|
Execution of files containing right-to-left override characters (U+202E) to masquerade true file extensions. Often found in phishing payloads or file downloads.
|
|
Analytic 0888
|
Execution of commands or APIs that disable Gatekeeper, XProtect, or system integrity protections. Detect configuration changes through unified logs. Monitor termination of system security daemons (e.g., syspolicyd).
|
|
Analytic 1080
|
Monitors for the creation of accounts inside containers using names that resemble legitimate orchestrator or backup identities to mask adversary persistence.
|
|
Analytic 0215
|
Detects adversarial use of cloud APIs for command execution, resource control, or reconnaissance. Focuses on CLI/SDK/scripting language abuse via stolen credentials or in-browser Cloud Shells. Monitors for anomalous API calls chained with authentication context shifts (e.g., stolen token -> privileged action) and cross-service impacts.
|
|
Analytic 0217
|
Detection of SSH/Telnet session hijacking via discrepancies between authentication logs and active session tables. Adversary behavior includes reusing or stealing active PTY sessions, attaching to screen/tmux, or issuing commands without corresponding login events.
|
|
Analytic 0398
|
Use of `usleep`, `nanosleep`, or `NSTimer` calls in executables or binaries with no GUI interaction, especially followed by disk/network activity.
|
|
Analytic 0955
|
Access tokens or SSH keys used without corresponding login shell or PAM module activity, particularly for remote execution.
|
|
Analytic 2036
|
Detects user-authorized execution of downloaded content or scripts after communication prompts, including browser downloads followed by osascript, shell, or installer execution and subsequent network activity.
|
|
Analytic 0448
|
Attachment of hardware-backed USB KVM devices (e.g., TinyPilot) that enumerate new HID or serial communication interfaces with identifiable metadata.
|
|
Analytic 1504
|
Detects cloud account use for API calls that exceed normal scope, such as IAM changes or access to services never used before.
|
|
Analytic 0612
|
Detection of container escape attempts via bind mounts, privileged containers, or abuse of docker.sock. Defenders may observe anomalous volume mount configurations (e.g., hostPath to / or /proc), unexpected privileged container launches, or use of container administration commands to access host resources. These events typically correlate with subsequent process execution on the host outside of normal container isolation.
|
|
Analytic 0717
|
Defenders may detect adversaries forging web credentials in IaaS environments by monitoring for anomalous API activity such as AssumeRole or GetFederationToken being executed by unusual principals. These events often correlate with sudden logon sessions from unfamiliar IP addresses or regions. The chain is usually secret material misuse (stolen private key or password) → API request generating a new token → access to high-value resources.
|
|
Analytic 1376
|
Establishing network connections on uncommon ports or protocols following C2 disruption or blocking. Often executed by processes that typically exhibit no network activity.
|
|
Analytic 0915
|
Identifies Mach-O binaries dropped into temporary directories with abnormally high binary size or padding patterns, followed by privilege escalation, `exec`, or memory mapping of other processes.
|
|
Analytic 0405
|
Detects forged Kerberos Golden Tickets by correlating anomalous Kerberos ticket lifetimes, unexpected encryption types (e.g., RC4 in modern domains), malformed fields in logon/logoff events, and TGS requests without preceding TGT requests. Also monitors for abnormal patterns of access associated with elevated privileges across multiple systems.
|
|
Analytic 1996
|
Once adversaries leverage serverless functions as infrastructure (ex: for command and control), it may be possible to look for unique characteristics associated with adversary software, if known.(Citation: ThreatConnect Infrastructure Dec 2020) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle.
|
|
Analytic 0140
|
Adversaries writing or moving payloads into directories configured as AV/EDR exclusion paths (e.g., /tmp, /var/lib, or custom directories from auditd exclusion rules). Defender perspective: detect file creation in paths matching known exclusions correlated with unusual parent processes.
|
|
Analytic 1013
|
Flood of spoofed SYN or ACK packets causing exhaustion of OS TCP state table, potentially via user-space utilities or kernel-level DoS agents.
|
|
Analytic 1140
|
Outbound spoofed traffic to known amplification protocols (e.g., DNS, NTP, Memcached) combined with abnormal network traffic volume targeting remote reflectors, resulting in disproportionate traffic returned to a victim
|
|
Analytic 1409
|
Detects SVGs downloaded via browser that invoke AppleScript, osascript, or JavaScriptCore processes, followed by network egress or file drop to LaunchAgents or ~/Library.
|
|
Analytic 0714
|
Adversary installation or use of RMM software (e.g., TeamViewer, AnyDesk, ScreenConnect) followed by outbound beaconing or remote session establishment
|
|
Analytic 1589
|
Creation of inbox rules via PowerShell (New-InboxRule) or transport rules using Exchange cmdlets. Correlates user behavior, cmdlet usage, and rule properties.
|
|
Analytic 1124
|
Detects clients issuing DNS queries with high volume, long subdomain lengths, encoded payload patterns, or to known malicious infrastructure; indicative of DNS-based C2 channels.
|
|
Analytic 0845
|
Router/switch receives a knock pattern (same src touches device unicast, broadcast, and network-address on same or stepped ports) followed by ACL/line-vty/service enable and the first mgmt session success.
|
|
Analytic 1127
|
Unusual enumeration of services and resources through cloud APIs such as AWS CLI `describe-*`, Azure Resource Manager queries, or GCP project listings. Defender perspective includes anomalous API calls, unexpected volume of service enumeration, and correlation of discovery with recently compromised sessions.
|
|
Analytic 0886
|
Unusual service stop events, termination of AV/EDR processes, registry modifications disabling security tools, and firewall/defender configuration changes. Correlate process creation with service stop requests and registry edits.
|
|
Analytic 1945
|
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.
Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
|
|
Analytic 1185
|
Detection focuses on abnormal service executions initiated via service control manager APIs, sc.exe, net.exe, or PsExec creating temporary services. Defenders observe process creation of services.exe spawning non-standard binaries, registry changes in service keys followed by rapid execution, and network connections originating from processes tied to transient services. Correlation across process lineage, registry activity, and service logs provides strong signals of malicious service execution.
|
|
Analytic 1428
|
Detects the execution of scripting or command interpreters (e.g., powershell.exe, cmd.exe, wscript.exe) outside expected administrative time windows or from abnormal user contexts, often followed by encoded/obfuscated arguments or secondary execution events.
|
|
Analytic 0719
|
Forged web credentials on Windows endpoints may be detected by anomalous browser cookie files, local token cache manipulations, or tools injecting tokens into sessions. Defenders may observe processes accessing LSASS or browser credential stores unexpectedly, followed by unusual logon sessions.
|
|
Analytic 0866
|
Detects unexpected use of usermod, gpasswd, or direct modification of /etc/group to elevate user group membership.
|
|
Analytic 1527
|
Detects creation or modification of Windows Services through command-line tools (e.g., `sc.exe`, `powershell.exe`), Registry key changes under `HKLM\System\CurrentControlSet\Services`, and service execution under SYSTEM with unsigned or anomalous binary paths. Detects privilege escalation via driver installation or `CreateServiceW` usage. Correlates parent-child lineage, startup behavior, and rare service names.
|
|
Analytic 1563
|
Execution of commands to query system locale and language settings, such as 'defaults read -g AppleLocale' or 'systemsetup -gettimezone'. Unusual parent processes or execution contexts of these commands may indicate adversarial discovery.
|
|
Analytic 0074
|
Correlated registry modifications under Print Processors path, followed by DLL file creation within the system print processor directory, and DLL load by spoolsv.exe. Malicious execution often occurs during service restart or system boot, with SYSTEM-level privileges.
|
|
Active Directory Credential Request
|
Requests for authentication credentials via Kerberos or other methods like NTLM and LDAP queries. Examples:
- Kerberos TGT and Service Tickets (Event IDs 4768, 4769)
- NTLM Authentication Events
- LDAP Bind Requests.
|
|
WMI Creation
|
Initial construction of a WMI object, such as a filter, consumer, subscription, binding, or providers.
|
|
Group Modification
|
Changes made to a group, such as membership, name, or permissions (ex: Windows EID 4728 or 4732, AWS IAM UpdateGroup). Examples:
- Active Directory:
- Event ID 4728: Member added to a global group.
- Event ID 4732: Member added to a local group.
- Azure AD: `Set-AzureADGroup -ObjectId -DisplayName "New Name"`
- AWS IAM: `aws iam update-group --group-name --new-path "/admin/"`
- Google Workspace: Modify permissions via Admin SDK API: `PATCH https://admin.googleapis.com/admin/directory/v1/groups/`
- Office 365: Modify groups via Graph API: `PATCH https://graph.microsoft.com/v1.0/groups/`
*Data Collection Measures:*
- Directory Logging:
- Windows: Log EIDs 4728 (add), 4729 (remove).
- Azure AD: Enable "Audit logs."
- Google Workspace: Enable Admin Activity logs.
- Office 365: Use Unified Audit Logs.
- Cloud Monitoring:
- AWS: Log `UpdateGroup`, `AttachGroupPolicy`, `RemoveUserFromGroup`.
- Azure: Track modifications via Audit logs.
- API Monitoring: Log Google Admin SDK and Microsoft Graph API calls.
- SIEM Integration: Centralize and monitor group modification logs.
|
|
Image Modification
|
Changes made to a virtual machine image, including setting and/or control data (ex: Azure Compute Service Images PATCH)
|
|
Pod Enumeration
|
Extracting a list of running or existing pods within a containerized cluster environment. Pods are the smallest deployable units in a Kubernetes cluster and typically represent an application or workload. Enumeration of pods provides insight into the structure and state of applications running in the cluster, such as the names of pods, their namespaces, and their associated metadata.
*Data Collection Measures:*
- Kubernetes API Server Audit Logs:
- Enable Audit Logging in Kubernetes to capture API requests, such as GET `/api/v1/pods`.
- Container Runtime Logs:
- Collect runtime-level logs from tools like CRI-O, containerd, or Docker, which might show relevant API calls for pod enumeration.
- EDR and SIEM:
- Endpoint Detection and Response (EDR) tools, if configured with cluster-level visibility, can monitor user commands like `kubectl get pods`.
- SIEM platforms (e.g., Splunk) can ingest Kubernetes API logs to detect enumeration patterns.
- Host-Based Monitoring:
- Monitor processes and commands executed on nodes where `kubectl` is installed using tools like auditd, Sysmon for Linux, or kernel modules.
|
|
Response Content
|
Captured network traffic that provides details about responses received during an internet scan. This data includes both protocol header values (e.g., HTTP status codes, IP headers, or DNS response codes) and response body content (e.g., HTML, JSON, or raw data). Examples:
- HTTP Scan: A web server responds to a probe with an HTTP 200 status code and an HTML body indicating the default page is accessible.
- DNS Scan: A DNS server replies to a query with a resolved IP address for a domain, along with details like Time-To-Live (TTL) and authoritative information.
- TCP Banner Grab: A service listening on a port (e.g., SSH or FTP) responds with a banner containing service name, version, or other metadata.
|
|
Volume Metadata
|
Contextual data about a cloud volume and activity around it, such as id, type, state, and size
|
|
Response Metadata
|
Contextual information about an Internet-facing resource collected during a scan, including details such as open ports, running services, protocols, and versions. This metadata is typically derived from interpreting scan results and helps build a profile of the targeted system. Examples:
- Port and Service Details:
- Open ports (e.g., 22, 80, 443).
- Identified services running on those ports (e.g., SSH, HTTP, HTTPS).
- Service Versions: Detected software version information (e.g., Apache 2.4.41, OpenSSH 8.2).
- Operating System Information: OS fingerprinting data (e.g., Linux Kernel 5.4.0).
- TLS/SSL Certificate Data: Information about the TLS/SSL certificate, such as the expiration date, issuer, and cipher suites.
*Data Collection Measures:*
- Scanning Tools:
- Nmap: Collects port, service, and version information using commands like nmap -sV .
- Masscan: High-speed scanning tool for discovering open ports and active services.
- Zmap: Focused on large-scale Internet scanning, collecting metadata about discovered services.
- Shodan API: Retrieves scan metadata for publicly exposed devices and services.
- Network Logs:
- Use logs from firewalls, intrusion detection systems (IDS), or intrusion prevention systems (IPS) to gather metadata from scan attempts. Example: Zeek or Suricata logs for incoming scan traffic.
- OSINT Platforms: Platforms like Censys, GreyNoise, or Shodan provide aggregated metadata about Internet-facing resources.
- Cloud Metadata Services: AWS Security Hub, Azure Monitor, or GCP Security Command Center can collect and centralize scan-related metadata for Internet-facing resources in cloud environments.
|
|
Windows Registry Key Deletion
|
The removal of a registry key within the Windows operating system.
*Data Collection Measures:*
- Windows Event Logs
- Event ID 4658 - Registry Key Handle Closed: Captures when a handle to a registry key is closed, which may indicate deletion.
- Event ID 4660 - Object Deleted: Logs when a registry key is deleted.
- Sysmon (System Monitor) for Windows
- Sysmon Event ID 12 - Registry Key Deleted: Logs when a registry key is removed.
- Sysmon Event ID 13 - Registry Value Deleted: Captures removal of specific registry values.
- Endpoint Detection and Response (EDR) Solutions
- Monitor registry deletions for suspicious behavior.
|
|
Instance Stop
|
The deactivation or shutdown of a virtual machine instance within a cloud infrastructure. This action typically involves stopping a running instance, which halts its operation and releases certain associated resources, such as CPU and memory. Examples:
- Google Cloud Platform (GCP): `instance.stop` events recorded in GCP Audit Logs indicate the deactivation of an instance.
- Amazon Web Services (AWS): `StopInstances` actions in AWS CloudTrail indicate EC2 instances being stopped.
- Microsoft Azure: `Microsoft.Compute/virtualMachines/deallocate` or `stop` events in Azure Activity Logs represent a virtual machine being stopped or deallocated.
|
|
Malware Content
|
Code, strings, signatures, and other identifying characteristics of a malicious payload stored within a malware repository. It includes both static (file-based) and dynamic (behavioral or execution-based) components that can be analyzed for threat intelligence, detection, and prevention purposes. Examples:
- Static Analysis:
- Executable Code: Analyze binary data to identify unique patterns, obfuscated code, or embedded resources.
- Strings Extraction: Use tools like strings or YARA rules to identify hardcoded URLs, IPs, filenames, or suspicious function calls.
- Signatures: Extract cryptographic hashes (MD5, SHA256) of files to track known malware variants or detect previously unseen samples.
- Dynamic Analysis:
- Behavioral Observations: Monitor execution traces to capture API calls, registry modifications, or network traffic patterns indicative of malicious behavior.
- Memory Analysis: Examine memory dumps to uncover injected code or runtime-decrypted payloads.
- Artifacts: Record file system changes, process creation events, and command-line arguments.
- Threat Intelligence Integration:
- Campaign Attribution: Associate observed code snippets or signatures with known APT campaigns or ransomware families.
- Indicator Sharing: Share identified Indicators of Compromise (IOCs) with threat intelligence platforms (e.g., MISP, OpenCTI).
- Examples of Malware Content:
- Embedded C2 domains (e.g., malicious-domain.com hardcoded in the payload).
- Fileless malware indicators, such as PowerShell scripts invoking Invoke-Mimikatz.
- Malware-specific signatures, such as unique PE header values for a particular strain.
*Data Collection Measures:*
- Collection from Public Malware Repositories:
- VirusTotal: Obtain samples for static analysis.
- Hybrid Analysis: Gather execution data from sandbox analysis.
- Any.Run: Access interactive malware execution traces.
- MalwareBazaar: Download malware samples for research and signature generation.
- Automate data extraction using repository APIs (e.g., VirusTotal API for hash lookups or sample retrieval).
- Internal Malware Labs:
- Sandbox Environments: Use dynamic malware analysis tools such as Cuckoo Sandbox or Joe Sandbox to execute and monitor malware in a controlled environment. Capture runtime behavior logs, memory dumps, and file system changes.
- Reverse Engineering: Disassemble binaries with tools like IDA Pro, Ghidra, or Radare2 to identify malicious functionality and extract code patterns.
- EDR/Endpoint Telemetry:
- Collect samples of malicious binaries or scripts from infected endpoints using tools like CrowdStrike, Carbon Black, or SentinelOne.
- Extract memory-resident payloads from live systems for analysis.
- Threat Intelligence Platforms:
- Gather contextual metadata for identified malware using tools like OpenCTI, Recorded Future, or ThreatConnect. Participate in intelligence-sharing groups such as ISACs (e.g., FS-ISAC, IT-ISAC).
- Custom Data Collection Pipelines: Use open-source tools like malwoverview or Maltrail to automate sample downloads, hash extraction, and IOC generation.
|
|
Snapshot Deletion
|
The removal of a point-in-time backup of a cloud storage volume, virtual machine (VM), or database.
*Data Collection Measures:*
- AWS CloudTrail
- Logs `DeleteSnapshot` API calls in EC2, RDS, and EBS services.
- Azure Monitor Logs
- Tracks snapshot deletions via `Microsoft.Compute/snapshots/delete` API calls.
- Google Cloud Logging
- Detects snapshot removal through `compute.disks.deleteSnapshot` events.
|
|
Network Connection Creation
|
The initial establishment of a network session, where a system or process initiates a connection to a local or remote endpoint. This typically involves capturing socket information (source/destination IP, ports, protocol) and tracking session metadata. Monitoring these events helps detect lateral movement, exfiltration, and command-and-control (C2) activities.
*Data Collection Measures:*
- Windows:
- Event ID 5156 – Filtering Platform Connection - Logs network connections permitted by Windows Filtering Platform (WFP).
- Sysmon Event ID 3 – Network Connection Initiated - Captures process, source/destination IP, ports, and parent process.
- Linux/macOS:
- Netfilter (iptables), nftables logs - Tracks incoming and outgoing network connections.
- AuditD (`connect` syscall) - Logs TCP, UDP, and ICMP connections.
- Zeek (`conn.log`) - Captures protocol, duration, and bytes transferred.
- Cloud & Network Infrastructure:
- AWS VPC Flow Logs / Azure NSG Flow Logs - Logs IP traffic at the network level in cloud environments.
- Zeek (conn.log) or Suricata (network events) - Captures packet metadata for detection and correlation.
- Endpoint Detection & Response (EDR):
- Detect anomalous network activity such as new C2 connections or data exfiltration attempts.
|
|
Process Access
|
Refers to an event where one process attempts to open another process, typically to inspect or manipulate its memory, access handles, or modify execution flow. Monitoring these access attempts can provide valuable insight into both benign and malicious behaviors, such as debugging, inter-process communication (IPC), or process injection.
*Data Collection Measures:*
- Endpoint Detection and Response (EDR) Tools:
- EDR solutions that provide telemetry on inter-process access and memory manipulation.
- Sysmon (Windows):
- Event ID 10: Captures process access attempts, including:
- Source process (initiator)
- Target process (victim)
- Access rights requested
- Process ID correlation
- Windows Event Logs:
- Event ID 4656 (Audit Handle to an Object): Logs access attempts to system objects.
- Event ID 4690 (Attempted Process Modification): Can help identify unauthorized process changes.
- Linux/macOS Monitoring:
- AuditD: Monitors process access through syscall tracing (e.g., `ptrace`, `open`, `read`, `write`).
- eBPF/XDP: Used for low-level monitoring of kernel process access.
- OSQuery: Query process access behavior via structured SQL-like logging.
- Procmon (Process Monitor) and Debugging Tools:
- Windows Procmon: Captures real-time process interactions.
- Linux strace / ptrace: Useful for tracking process behavior at the system call level.
|
|
Active Directory Object Creation
|
Creating new objects in AD, such as user accounts, groups, organizational units (OUs), or trust relationships. Logged as Event ID 5137. Examples:
- User Account Creation: New user account.
- Group Creation: New security/distribution group.
- OU Creation: New organizational unit.
- Service Account Creation: New service account for automation or malicious tasks.
- Trust Object Creation: Trust relationship with another domain.
|
|
Certificate Registration
|
Certificate Registration refers to the collection and analysis of information about digital certificates, including current, revoked, and expired certificates. Sources such as Certificate Transparency logs and other public resources provide visibility into certificates issued for specific domains or organizations. Monitoring certificate registrations can help identify potential misuse, such as unauthorized certificates or signs of adversary reconnaissance. Examples:
- Certificate Transparency Logs: These logs record the issuance of SSL/TLS certificates by trusted Certificate Authorities (CAs).
- Revoked Certificates: Information about certificates that have been invalidated before their expiration date.
- Expired Certificates: Reports of expired certificates for a domain, which may indicate lax security practices or opportunities for adversaries to exploit expired credentials.
- Domain Monitoring for Certificates: Maps SSL/TLS certificates to domains and subdomains, helping to identify any rogue certificates.
- Public Certificate Directories: Services providing APIs to query issued certificates for analysis.
This data component can be collected through the following measures:
Use Certificate Transparency Monitors
- Tools like crt.sh, CertStream, or APIs provided by certificate authorities (CAs) allow you to monitor issued certificates in real-time.
- Example: Use CertStream to stream certificate issuance logs and filter for domains of interest.
Analyze Certificate Revocation Sources
- Monitor CRLs or query OCSP responders to detect revoked certificates.
- Configure tools like OpenSSL or browsers to validate certificate revocation status automatically.
Leverage Public Scanning Tools
- Use tools such as SSL Labs, Censys, or Shodan to scan for certificate details related to your domain or network.
Automate Certificate Monitoring
- Set up automated scripts or services to parse Certificate Transparency logs for anomalies.
- Example: Automate searches on crt.sh to identify certificates issued for typo-squatted domains.
Integrate with Threat Intelligence
- Enrich certificate data with threat intelligence feeds to detect connections to known adversary-controlled infrastructure.
- Tools like VirusTotal can identify malicious certificates based on associated indicators.
|
|
File Access
|
To events where a file is opened or accessed, making its contents available to the requester. This includes reading, executing, or interacting with files by authorized or unauthorized entities. Examples include logging file access events (e.g., Windows Event ID 4663), monitoring file reads, and detecting unusual file access patterns. Examples:
- File Read Operations: A user opens a sensitive document (e.g., financial_report.xlsx) on a shared drive.
- File Execution: A script or executable file is accessed and executed (e.g., malware.exe is run from a temporary directory).
- Unauthorized File Access: An unauthorized user attempts to access a protected configuration file (e.g., `/etc/passwd` on Linux or `System32` files on Windows).
- File Access Patterns: Bulk access to multiple files in a short time (e.g., mass access to documents on a file server).
- File Access via Network: Files on a network share are accessed remotely (e.g., logs of SMB file access).
|
|
Kernel Module Load
|
The process of loading a kernel module into the operating system kernel. Kernel modules are object files that extend the kernel’s functionality, such as adding support for device drivers, new filesystems, or additional system calls. This action can be legitimate (e.g., loading a driver) or malicious (e.g., adding a rootkit).
*Data Collection Measures:*
- Linux:
- Auditd: Enable auditing of kernel module loading. Example rule: `-a always,exit -F arch=b64 -S init_module,delete_module`.
- Syslog: Monitor `/var/log/syslog` or `/var/log/messages` for entries related to kernel module loads.
- Systemd Journal: Use `journalctl` to query logs for module loading events: `journalctl -k | grep "Loading kernel module"`
- macOS:
- Unified Logs: Use the `log` command to query kernel module events: `log show --predicate 'eventMessage contains "kextload"' --info`
- Endpoint Security Framework (ESF): Monitor for `ES_EVENT_TYPE_AUTH_KEXTLOAD` (kernel extension loading events).
- Kernel-Specific Tools:
- Lsmod: Use `lsmod` to list loaded kernel modules in real-time.
- Kprobe/eBPF: Use extended Berkeley Packet Filter (eBPF) or Kernel Probes (kprobes) to monitor kernel events, including module loading. Example using eBPF tools like BCC:
`sudo python /path/to/bcc/tools/kprobe -v do_init_module`
- Enable EDR Monitoring:
- Configure alerts for: Suspicious kernel module loads from non-standard paths (e.g., /tmp). Unexpected or unsigned kernel modules.
- Review detailed telemetry data provided by the EDR for insight into who initiated the module load, the file path, and whether the module was signed.
|
|
Instance Enumeration
|
The process of retrieving or querying a list of virtual machine instances or compute instances within a cloud infrastructure. This activity provides a view of all available or running instances, typically including their associated metadata such as instance ID, name, state, and configuration details. Examples:
- AWS: instance enumeration involves the `DescribeInstances` API call, which retrieves information about running or stopped EC2 instances.
- Azure: VM enumeration can be monitored via the `Microsoft.Compute/virtualMachines/read` operation.
- GCP: instance enumeration is logged as an `instance.list` operation within GCP Audit Logs.
*Data Collection Measures:*
- AWS CloudTrail: CloudTrail logs stored in S3 or forwarded to CloudWatch.
- Azure Activity Logs: Accessible via Azure Monitor or exported to a storage account.
- GCP Audit Logs: Logs Explorer or BigQuery.
|
|
File Creation
|
A new file is created on a system or network storage. This action often signifies an operation such as saving a document, writing data, or deploying a file. Logging these events helps identify legitimate or potentially malicious file creation activities. Examples include logging file creation events (e.g., Sysmon Event ID 11 or Linux auditd logs).
|
|
Active DNS
|
"Domain Name: Active DNS" data component captures queried DNS registry data that highlights current domain-to-IP address resolutions. This data includes both direct queries to DNS servers and records that provide mappings between domain names and associated IP addresses. It serves as a critical resource for tracking active infrastructure and understanding the network footprint of an organization or adversary. Examples:
- DNS Query Example: `nslookup example.com`, `dig example.com A`
- PTR Record Example: `dig -x 192.168.1.1`
- Tracking Malicious Domains: DNS logs reveal repeated queries to suspicious domains like malicious-site.com. The IPs resolved by these domains may be indicators of compromise (IOCs).
- DNS Record Types
- A/AAAA Record: Maps domain names to IP addresses (IPv4/IPv6).
- CNAME Record: Canonical name records, often used for redirects.
- MX Record: Mail exchange records, used to route emails.
- TXT Record: Can include security information like SPF or DKIM policies.
- SOA Record: Start of authority record for domain management.
- NS Record: Lists authoritative name servers for the domain.
This data component can be collected through the following measures:
- System Utilities: Use built-in tools like `nslookup`, `dig`, or host on Linux, macOS, and Windows to perform active DNS queries.
- DNS Logging
- Windows DNS Server: Enable DNS Analytical Logging to capture DNS queries and responses.
- Bind DNS: Enable query logging in the named.conf file.
- Cloud Provider DNS Logging
- AWS Route 53: Enable query logging through CloudWatch or S3:
- Google Cloud DNS: Enable logging for Cloud DNS queries through Google Cloud Logging.
- Network Traffic Monitoring: Use tools like Wireshark or Zeek to analyze DNS queries within network traffic.
- Security Information and Event Management (SIEM) Integration: Aggregate DNS logs in a SIEM like Splunk to create alerts and monitor patterns.
- Public OSINT Tools: Use OSINT platforms like VirusTotal, or PassiveTotal to collect information on domains and their associated IP addresses.
|
|
Driver Load
|
The process of attaching a driver, which is a software component that allows the operating system and applications to interact with hardware devices, to either user-mode or kernel-mode of a system. This can include benign actions (e.g., hardware drivers) or malicious behavior (e.g., rootkits or unsigned drivers). Examples:
- Legitimate Driver Loading: A new graphics driver from a vendor like NVIDIA or AMD is loaded into the system.
- Unsigned Driver Loading: A driver without a valid digital signature is loaded into the kernel.
- Rootkit Installation: A malicious rootkit driver is loaded to manipulate kernel-mode processes.
- Anti-Virus or EDR Driver Loading: An Endpoint Detection and Response (EDR) solution loads its driver to monitor system activities.
- Driver Misuse: A legitimate driver is loaded and exploited to execute malicious actions, such as using vulnerable drivers for bypassing defenses (e.g., Bring Your Own Vulnerable Driver (BYOVD) attacks).
|
|
Network Traffic Content
|
The full packet capture (PCAP) or session data that logs both protocol headers and payload content. This allows analysts to inspect command and control (C2) traffic, exfiltration, and other suspicious activity within network communications. Unlike metadata-based logs, full content analysis enables deeper protocol inspection, payload decoding, and forensic investigations.
*Data Collection Measures:*
- Network Packet Capture (Full Content Logging)
- Wireshark / tcpdump / tshark
- Full packet captures (PCAP files) for manual analysis or IDS correlation. `tcpdump -i eth0 -w capture.pcap`
- Zeek (formerly Bro)
- Extracts protocol headers and payload details into structured logs. `echo "redef Log::default_store = Log::ASCII;" > local.zeek | zeek -Cr capture.pcap local.zeek`
- Suricata / Snort (IDS/IPS with PCAP Logging)
- Deep packet inspection (DPI) with signature-based and behavioral analysis. `suricata -c /etc/suricata/suricata.yaml -i eth0 -l /var/log/suricata`
- Host-Based Collection
- Sysmon Event ID 22 – DNS Query Logging, Captures DNS requests made by processes, useful for detecting C2 domains.
- Sysmon Event ID 3 – Network Connection Initiated, Logs process-to-network connection relationships.
- AuditD (Linux) – syscall=connect, Monitors outbound network requests from processes. `auditctl -a always,exit -F arch=b64 -S connect -k network_activity`
- Cloud & SaaS Traffic Collection
- AWS VPC Flow Logs / Azure NSG Flow Logs / Google VPC Flow Logs, Captures metadata about inbound/outbound network traffic.
- Cloud IDS (AWS GuardDuty, Azure Sentinel, Google Chronicle), Detects malicious activity in cloud environments by analyzing network traffic patterns.
|
|
Logon Session Metadata
|
Contextual data about a logon session, such as username, logon type, access tokens (security context, user SIDs, logon identifiers, and logon SID), and any activity associated within it
|
|
Volume Deletion
|
The removal of a cloud-based or on-premise block storage volume. This action permanently deletes the allocated storage and may result in data loss if not backed up.
*Data Collection Measures:*
- Cloud Logging & APIs
- AWS CloudTrail Logs
- `eventName: DeleteVolume` (tracks volume deletions)
- Azure Monitor Logs
- `operationName: Microsoft.Compute/disks/delete`
- `status: Success | Failure` (flag unauthorized delete attempts)
- Google Cloud Audit Logs
- `protoPayload.methodName: "v1.compute.disks.delete"`
- `authenticationInfo.principalEmail` (identifies the user deleting the volume)
- System & Host-Based Logging
- Linux & macOS Logs:
- `/var/log/syslog` or `/var/log/messages` for volume detach/deletion actions
- Windows Event Logs:
- Event ID 98 (Storage Class Memory)
- Event ID 225 (Volume Removal Detected)
- Event ID 12 (Disk Removal Notification)
|
|
Process Creation
|
Refers to the event in which a new process (executable) is initialized by an operating system. This can involve parent-child process relationships, process arguments, and environmental variables. Monitoring process creation is crucial for detecting malicious behaviors, such as execution of unauthorized binaries, scripting abuse, or privilege escalation attempts..
|
|
Drive Creation
|
The activity of assigning a new drive letter or creating a mount point for a data storage device, such as a USB, network share, or external hard drive, enabling access to its content on a host system. Examples:
- USB Drive Insertion: A USB drive is plugged in and automatically assigned the letter `E:\` on a Windows machine.
- Network Drive Mapping: A network share `\\server\share` is mapped to the drive `Z:\`.
- Virtual Drive Creation: A virtual disk is mounted on `/mnt/virtualdrive` using an ISO image or a virtual hard disk (VHD).
- Cloud Storage Mounting: Google Drive is mounted as `G:\` on a Windows machine using a cloud sync tool.
- External Storage Integration: An external HDD or SSD is connected and assigned `/mnt/external` on a Linux system..
|
|
Snapshot Creation
|
The process of taking a point-in-time copy of a cloud storage volume (files, settings, configurations, etc.), virtual machine (VM), or database that can be created and deployed in cloud environments.
|
|
Cloud Storage Modification
|
Cloud Storage Modification involves tracking changes made to cloud storage infrastructure, including updates to settings, permissions, or stored data. Examples include modifying object access control lists (ACLs), uploading new objects, or updating bucket policies. Examples:
AWS S3: An object is uploaded or its ACL is modified.
- Azure Blob Storage: A blob's metadata or permissions are updated.
- Google Cloud Storage: An object's lifecycle policy is updated, or a bucket policy is changed.
- OpenStack Swift: Modifications to container settings or uploading of new objects.
|
|
Instance Modification
|
Changes made to a virtual machine (VM) or compute instance, including alterations to its configuration, metadata, attached policies, or operational state. Such modifications can include updating metadata, attaching or detaching resource policies, resizing instances, or modifying network configurations. Examples:
- AWS: instance modifications include API actions like `ModifyInstanceAttribute`, `ModifyInstanceMetadataOptions`, or `RebootInstances`.
- Azure: modifications can be tracked through operations like `Microsoft.Compute/virtualMachines/write`.
- GCP: instance modification events include operations like `instances.setMetadata`, `instances.addResourcePolicies`, or `instances.resize`.
*Data Collection Measures:*
- AWS CloudTrail: Log Location: Stored in S3 or forwarded to CloudWatch.
- Azure Activity Logs: Log Location: Accessible via Azure Monitor or exported to a storage account.
- GCP Audit Logs: Log Location: Logs Explorer or BigQuery.
|
|
Instance Metadata
|
Contextual data about an instance and activity around it such as name, type, or status
|
|
Cloud Storage Deletion
|
Cloud Storage Deletion refers to the removal or destruction of cloud storage infrastructure, such as buckets, containers, or directories, within a cloud environment. Monitoring this activity is critical to detecting potential unauthorized or malicious actions, such as data destruction by adversaries or accidental deletions that may lead to data loss. Examples:
- AWS S3 Bucket Deletion: An AWS user deletes an S3 bucket using the `DeleteBucket` API call.
- Azure Blob Storage Container Deletion: A user deletes a container in Azure Blob Storage using the `Delete Container` operation.
- Google Cloud Storage Bucket Deletion: A Google Cloud user deletes a bucket using the `storage.buckets.delete` API.
- OpenStack Swift Container Deletion: A user deletes a container in OpenStack Swift using the `DELETE` method.
This data component can be collected through the following measures:
Enable Logging for Cloud Storage Services
- AWS S3: Enable AWS CloudTrail to log DeleteBucket API actions.
- Azure Blob Storage: Enable Azure Monitor and Diagnostic Logs to capture Delete Container operations. Use Azure Event Grid to capture and trigger alerts for container deletion.
- Google Cloud Storage: Enable Data Access logs in Cloud Audit Logs to monitor storage.buckets.delete API calls.
- OpenStack Swift: Configure Swift logging to capture DELETE requests for containers.
Centralized Logging and Analysis
- Use platforms like Splunk or native SIEMs to forward and analyze logs for anomalies in cloud storage deletions.
|
|
Drive Modification
|
The alteration of a drive letter, mount point, or other attributes of a data storage device, which could involve reassignment, renaming, permissions changes, or other modifications. Examples:
- Drive Letter Reassignment: A USB drive previously assigned `E:\` is reassigned to `D:\` on a Windows machine.
- Mount Point Change: On a Linux system, a mounted storage device at `/mnt/external` is moved to `/mnt/storage`.
- Drive Permission Changes: A shared drive's permissions are modified to allow write access for unauthorized users or processes.
- Renaming of a Drive: A network drive labeled "HR_Share" is renamed to "Shared_Resources."
- Modification of Cloud-Integrated Drives: A cloud storage mount such as Google Drive is modified to sync only specific folders.
This data component can be collected through the following measures:
Windows Event Logs
- Relevant Events:
- Event ID 98: Indicates changes to a volume (e.g., drive letter reassignment).
- Event ID 1006: Logs permission modifications or changes to removable storage.
- Configuration: Enable "Storage Operational Logs" in the Event Viewer:
`Applications and Services Logs > Microsoft > Windows > Storage-Tiering > Operational`
Linux System Logs
- Auditd Configuration: Add audit rules to track changes to mounted drives: `auditctl -w /mnt/ -p w -k drive_modification`
- Command-Line Monitoring: Use `dmesg` or `journalctl` to observe drive modifications.
macOS System Logs
- Unified Logs: Collect mount or drive modification events: `log show --info | grep "Volume modified"`
- Command-Line Monitoring: Use `diskutil` to track changes:
Endpoint Detection and Response (EDR) Tools
- Configure policies in EDR solutions to monitor and log changes to drive configurations or attributes.
SIEM Tools
- Aggregate logs from multiple systems into a centralized platform like Splunk to correlate events and alert on suspicious drive modification activities.
|
|
Pod Creation
|
The initial deployment or instantiation of a new pod in a containerized environment. This includes creating a pod manually, through orchestration tools (Kubernetes), or via Infrastructure-as-Code (IaC) configurations. A Pod is the smallest deployable unit in Kubernetes, typically containing one or more containers. Creation methods include:
- Direct pod deployment (`kubectl run`, `kubectl apply`)
- Automated deployment via CI/CD pipelines (e.g., ArgoCD, Jenkins, GitOps)
- Infrastructure-as-Code (IaC) templates (e.g., Terraform, Helm Charts)
- API-based deployments via Kubernetes control plane (create_pod API calls)
- Pods can be ephemeral (short-lived) or persistent (part of a StatefulSet or Deployment).
*Data Collection Measures:*
- Kubernetes Audit Logs
- Captures all API requests, including pod `create` events.
- Kube-api server Logs
- Monitors API calls related to pod deployments and modifications. Related Events: `PodSandboxChanged`, `SyncLoop`, `Created pod`
- Container Runtime Logs
- Logs from CRI-O, containerd, or Docker capture pod creation events. Related Events: `container start`, `container create`
- Cloud Provider Logs
- GKE, EKS, AKS logs provide insights into Kubernetes API interactions.
- SIEM & Log Aggregation
- Integrates Kubernetes logs into SIEM solutions.
- EDR/XDR Solutions
- Monitors container-based activity for anomalous pod creations.
|
|
Service Creation
|
The registration of a new service or daemon on an operating system.
*Data Collection Measures:*
- Windows Event Logs
- Event ID 4697 - Captures the creation of a new Windows service.
- Event ID 7045 - Captures services installed by administrators or adversaries.
- Event ID 7034 - Could indicate malicious service modification or exploitation.
- Sysmon Logs
- Sysmon Event ID 1 - Process Creation (captures service executables).
- Sysmon Event ID 4 - Service state changes (detects service installation).
- Sysmon Event ID 13 - Registry modifications (captures service persistence changes).
- PowerShell Logging
- Monitor `New-Service` and `Set-Service` PowerShell cmdlets in Event ID 4104 (Script Block Logging).
- Linux/macOS Collection Methods
- AuditD & Syslog Daemon Logs (`/var/log/syslog`, `/var/log/messages`, `/var/log/daemon.log`)
- AuditD Rules:
- `auditctl -w /etc/systemd/system -p wa -k service_creation`
- Detects changes to `systemd` service configurations.
- Systemd Journals (`journalctl -u `)
- Captures newly created systemd services.
- LaunchDaemons & LaunchAgents (macOS)
- Monitor `/Library/LaunchDaemons/` and `/Library/LaunchAgents/` for new plist files.
|
|
Cloud Storage Access
|
Cloud storage access refers to the retrieval or interaction with data stored in cloud infrastructure. This data component includes activities such as reading, downloading, or accessing files and objects within cloud storage systems. Common examples include API calls like GetObject in AWS S3, which retrieves objects from cloud buckets. Examples:
- AWS S3 Access: An adversary uses the `GetObject` API to retrieve sensitive data from an AWS S3 bucket.
- Azure Blob Storage Access: A user accesses a blob in Azure Storage using `Get Blob` or `Get Blob Properties`.
- Google Cloud Storage Access: An adversary uses `storage.objects.get` to download objects from - OpenStack Swift Storage Access: A user retrieves an object from OpenStack Swift using the `GET` method.
|
|
Cloud Storage Creation
|
Cloud Storage Creation refers to the initial creation of a new cloud storage resource, such as buckets, containers, or directories, within a cloud environment. This action is critical to track as it might indicate the legitimate provisioning of resources or unauthorized actions taken by adversaries to stage, store, or exfiltrate data. Examples:
- AWS S3 Bucket Creation: An AWS user creates a new S3 bucket using the `CreateBucket` API call.
- Azure Blob Storage Container Creation: A user creates a new container in Azure Blob Storage using the `Create Container` operation.
- Google Cloud Storage Bucket Creation: A Google Cloud user creates a new bucket using `storage.buckets.create`.
- OpenStack Swift Container Creation: A user creates a new container in OpenStack Swift using the `PUT` method.
|
|
Active Directory Object Modification
|
Changes to AD objects (e.g., users, groups, OUs) are logged as Event ID 5136 (Object Modification) or 5163 (Attribute Changes). Examples:
- User Account: Modifying attributes (e.g., group membership, enabling/disabling accounts).
- Group Membership: Adding/removing members.
- OU: Changing properties/permissions (e.g., delegation).
- Service Account: Modifying SPNs or other attributes.
- Object Attributes: Changes to passwords, logon hours, or control flags.
|
|
Active Directory Object Access
|
Object access refers to activities where AD objects (e.g., user accounts, groups, policies) are accessed or queried. Example: Windows Event ID 4661 logs object access attempts. Examples:
- Attribute Access: e.g., `userPassword`, `memberOf`, `securityDescriptor`.
- Group Enumeration: Enumerating critical group members (e.g., Domain Admins).
- User Attributes: Commonly accessed attributes like `samAccountName`, `lastLogonTimestamp`.
- Policy Access: Accessing GPOs to understand security settings.
*Data Collection Measures:*
- Audit Policies:
- Enable "Audit Directory Service Access" under Advanced Audit Policies (Success and Failure).
- Path: `Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Object AccessEnable: Audit Directory Service Access` (Success and Failure).
- Captured Events: IDs 4661, 4662.
- Event Forwarding: Use WEF to centralize logs for SIEM analysis.
- SIEM Integration: Collect and parse logs (e.g., 4661, 4662) using tools like Splunk or Azure Sentinel.
- Log Filtering:
- Focus on sensitive objects/attributes like:
- `Domain Admins` group.
- `userPassword`, `ntSecurityDescriptor`.
- Enable EDR Monitoring:
- Detect processes accessing sensitive AD objects (e.g., samAccountName, securityDescriptor).
- Log all attempts to enumerate critical groups (e.g., "Domain Admins").
|
|
Web Credential Creation
|
Initial construction of new web credential material (ex: Windows EID 1200 or 4769)
|
|
Container Start
|
"Container Start" data component captures events related to the activation or invocation of a container within a containerized environment. This includes starting a previously stopped container, restarting an existing container, or initializing a container for runtime. Monitoring these activities is critical for identifying unauthorized or unexpected container activations, which may indicate potential adversarial activity or misconfigurations. Examples:
- Docker Example: `docker start `, `docker restart `
- Kubernetes Example: Kubernetes automatically restarts containers as part of pod lifecycle management (e.g., due to health checks or configuration changes).
- Cloud-Native Example
- AWS ECS: API Call: StartTask to activate a stopped ECS task.
- Azure Container Instances: Command to restart a container group instance.
- GCP Kubernetes Engine: Automatic restarts as part of node or pod management.
This data component can be collected through the following measures:
- Docker Audit Logging: Enable Docker logging to capture start and restart events. Use tools like auditd to monitor terminal activity involving container lifecycle commands.
- Kubernetes Audit Logs: Enable Kubernetes API server audit logging.
- Cloud Provider Logs
- AWS CloudTrail: Capture StartTask or related API calls for ECS.
- Azure Monitor: Track activity in container groups that indicate start or restart events.
- GCP Cloud Logging: Record logs related to pod restarts or scaling events in Kubernetes Engine.
- SIEM Integration: Collect logs from Docker, Kubernetes, and cloud services to correlate container start events.
|
|
Process Termination
|
The exit or termination of a running process on a system. This can occur due to normal operations, user-initiated commands, or malicious actions such as process termination by malware to disable security controls.
|
|
File Metadata
|
contextual information about a file, including attributes such as the file's name, size, type, content (e.g., signatures, headers, media), user/owner, permissions, timestamps, and other related properties. File metadata provides insights into a file's characteristics and can be used to detect malicious activity, unauthorized modifications, or other anomalies. Examples:
- File Ownership and Permissions: Checking the owner and permissions of a critical configuration file like /etc/passwd on Linux or C:\Windows\System32\config\SAM on Windows.
- Timestamps: Analyzing the creation, modification, and access timestamps of a file.
- File Content and Signatures: Extracting the headers of an executable file to verify its signature or detect packing/obfuscation.
- File Attributes: Analyzing attributes like hidden, system, or read-only flags in Windows.
- File Hashes: Generating MD5, SHA-1, or SHA-256 hashes of files to compare against threat intelligence feeds.
- File Location: Monitoring files located in unusual directories or paths, such as temporary or user folders.
|
|
Service Modification
|
Changes made to an existing service or daemon, such as modifying the service name, start type, execution parameters, or security configurations.
|
|
Pod Modification
|
Changes made to a pod’s configuration or control data within a containerized cluster. This can include updating settings such as resource limits, environment variables, annotations, labels, or even the containers running within the pod. Pod modifications are often executed using commands like kubectl set, kubectl patch, or kubectl edit.
*Data Collection Measures:*
- Kubernetes API Server Audit Logs:
- Capture all API calls related to pod modification, such as PATCH, PUT, or UPDATE methods on v1/pods.
- Runtime Security Tools:
- Tools like Falco, Sysdig, and Kube-bench can monitor pod modifications at runtime and alert on policy violations.
- Container Orchestration Logs:
- Monitor events logged by Kubernetes itself (e.g., `kubectl logs -n kube-system kube-controller-manager`).
- SIEM and EDR Solutions:
- Use SIEM platforms (e.g., Splunk) to aggregate API server logs and detect patterns of unauthorized or suspicious pod modifications.
- Endpoint Detection and Response (EDR) tools configured with container visibility can monitor commands like `kubectl` set or `kubectl patch`.
- Host-Based Monitoring:
- Collect and analyze logs for processes executing `kubectl` commands or interacting with Kubernetes configuration files (e.g., `.kube/config`).
|
|
Command Execution
|
Command Execution involves monitoring and capturing the execution of textual commands (including shell commands, cmdlets, and scripts) within an operating system or application. These commands may include arguments or parameters and are typically executed through interpreters such as `cmd.exe`, `bash`, `zsh`, `PowerShell`, or programmatic execution. Examples:
- Windows Command Prompt
- dir – Lists directory contents.
- net user – Queries or manipulates user accounts.
- tasklist – Lists running processes.
- PowerShell
- Get-Process – Retrieves processes running on a system.
- Set-ExecutionPolicy – Changes PowerShell script execution policies.
- Invoke-WebRequest – Downloads remote resources.
- Linux Shell
- ls – Lists files in a directory.
- cat /etc/passwd – Reads the user accounts file.
- curl http://malicious-site.com – Retrieves content from a malicious URL.
- Container Environments
- docker exec – Executes a command inside a running container.
- kubectl exec – Runs commands in Kubernetes pods.
- macOS Terminal
- open – Opens files or URLs.
- dscl . -list /Users – Lists all users on the system.
- osascript -e – Executes AppleScript commands.
|
|
Drive Access
|
Refers to the act of accessing a data storage device, such as a hard drive, SSD, USB, or network-mounted drive. This data component logs the opening or mounting of drives, capturing activities such as reading, writing, or executing files within an assigned drive letter (e.g., `C:\`, `/mnt/drive`) or mount point. Examples:
- Removable Drive Insertion: A USB drive is inserted, assigned the letter `F:\`, and files are accessed.
- Network Drive Mounting: A network share `\\server\share` is mapped to the drive `Z:\`.
- External Hard Drive Access: An external drive is connected, mounted at `/mnt/backup`, and accessed for copying files.
- System Volume Access: The system volume `C:\` is accessed for modifications to critical files.
- Cloud-Synced Drives: Cloud storage drives like OneDrive or Google Drive are accessed via local mounts.
|
|
Firewall Metadata
|
Contextual information about firewalls, including their configurations, policies, status, and other details such as names and associated rules. This metadata provides valuable insights into the operational state and configurations of firewalls, both in cloud control planes and host systems. Examples:
- Firewall Name and Configuration: The name, type, and purpose of a firewall such as "Azure Firewall - Production Environment."
- Policy Details: Capturing firewall policy details, such as "Allow inbound TCP 443 to web servers."
- Firewall Status: Status indicators like "Active," "Disabled," or "Pending Updates."
- Audit Log Metadata: Log entries showing administrative changes, such as "Policy modified by admin@domain.com."
- Rules Associated with Firewalls: Rules specifying source/destination IP ranges, protocols, and ports.
- Tagging Information: Tags like "Environment: Production" or "Owner: NetworkOps."
This data component can be collected through the following measures:
Cloud Control Plane
- Azure: Use Azure Activity Logs and Network Watcher to collect metadata for Azure Firewall.
- Example: `az network firewall show --name `
- AWS: Use AWS CloudTrail and describe commands: `aws ec2 describe-security-groups`
- Google Cloud: Use gcloud commands to extract metadata: `gcloud compute firewall-rules list --format=json`
Host-Based Firewalls
- Windows: Use PowerShell to gather metadata: `Get-NetFirewallRule -PolicyStore PersistentStore`
- Linux: Query iptables or nftables rulesets: `iptables -S`
- macOS: Use pfctl to extract metadata: `sudo pfctl -sr`
SIEM Integration
- Collect logs from cloud platforms, host systems, and network appliances.
API Monitoring
- Monitor API calls for metadata requests. Example (AWS): `Capture DescribeSecurityGroups or DescribeNetworkAcls` calls via CloudTrail.
Endpoint Detection and Response (EDR)
- Use EDR solutions to monitor firewall management tools for configuration changes or queries.
|
|
Service Metadata
|
Contextual data about a service/daemon, which may include information such as name, service executable, start type, etc.
|
|
Instance Deletion
|
Removal of a virtual machine (VM) or compute instance within a cloud infrastructure. This activity results in the termination and deletion of the allocated resources (e.g., CPU, memory, storage), making the instance unavailable for future use. Examples:
- AWS: instance deletion involves the `TerminateInstances` API call, which is recorded in CloudTrail logs.
- Azure: VM deletion can be monitored via Azure Activity Logs, showing the `Microsoft.Compute/virtualMachines/delete` operation.
- GCP: instance deletion is logged as an instance.delete operation within GCP Audit Logs.
|
|
Scheduled Job Metadata
|
Contextual data about a scheduled job, which may include information such as name, timing, command(s), etc.
|
|
Windows Registry Key Creation
|
Initial construction of a new registry key within the Windows operating system.
|
|
File Modification
|
Changes made to a file, including updates to its contents, metadata, access permissions, or attributes. These modifications may indicate legitimate activity (e.g., software updates) or unauthorized changes (e.g., tampering, ransomware, or adversarial modifications). Examples:
- Content Modifications: Changes to the content of a configuration file, such as modifying `/etc/ssh/sshd_config` on Linux or `C:\Windows\System32\drivers\etc\hosts` on Windows.
- Permission Changes: Altering file permissions to allow broader access, such as changing a file from `644` to `777` on Linux or modifying NTFS permissions on Windows.
- Attribute Modifications: Changing a file's attributes to hidden, read-only, or system on Windows.
- Timestamp Manipulation: Adjusting a file's creation or modification timestamp using tools like `touch` in Linux or timestomping tools on Windows.
- Software or System File Changes: Modifying system files such as `boot.ini`, kernel modules, or application binaries.
|
|
Host Status
|
Logging, messaging, and other artifacts that highlight the health and operational state of host-based security sensors, such as Endpoint Detection and Response (EDR) agents, antivirus software, logging services, and system monitoring tools. Monitoring sensor health is essential for detecting misconfigurations, sensor failures, tampering, or deliberate security control evasion by adversaries.
*Data Collection Measures:*
- Windows Event Logs:
- Event ID 1074 (System Shutdown): Detects unexpected system reboots/shutdowns.
- Event ID 6006 (Event Log Stopped): Logs when Windows event logging is stopped.
- Event ID 16 (Sysmon): Detects configuration state changes that may indicate log tampering.
- Event ID 12 (Windows Defender Status Change) – Detects changes in Windows Defender state.
- Linux/macOS Monitoring:
- `/var/log/syslog`, `/var/log/auth.log`, `/var/log/kern.log`
- Journald (journalctl) for kernel and system alerts.
- Endpoint Detection and Response (EDR) Tools:
- Monitor agent health status, detect sensor tampering, and alert on missing telemetry.
- Mobile Threat Intelligence Logs:
- Samsung Knox, SafetyNet, iOS Secure Enclave provide sensor health status for mobile endpoints.
|
|
Image Deletion
|
Removal of a virtual machine image in a cloud infrastructure (ex: Azure Compute Service Images DELETE) Examples:
- Azure Compute Service Image Deletion
- Example: Deleting a virtual machine image using Azure CLI: `az image delete --name MyImage --resource-group MyResourceGroup`
- AWS EC2 AMI (Amazon Machine Image) Deletion
- Example: Deregistering an AMI in AWS: `aws ec2 deregister-image --image-id ami-1234567890abcdef0`
- Google Cloud Compute Engine Image Deletion
- Example: Deleting a custom image in Google Cloud: `gcloud compute images delete my-custom-image`
- VMware vSphere
- Example: Deleting a VM image/template from a vSphere environment:
This data component can be collected through the following measures:
Enable Cloud Platform Logging
- Azure: Enable "Activity Logs" to capture DELETE requests to `Microsoft.Compute/images`.
- AWS: Use AWS CloudTrail to monitor `DeregisterImage` or `DeleteSnapshot` API calls.
- Google Cloud: Enable "Cloud Audit Logs" to track image deletion events under `compute.googleapis.com/images`.
API Monitoring
- Monitor API activity to track the deletion of images using:
- AWS SDK/CLI `DeregisterImage` or `DeleteSnapshot`.
- Azure REST API DELETE operations for images.
- Google Cloud Compute Engine APIs for image deletion.
Cloud SIEM Integration
- Ingest logs into a centralized SIEM platform for monitoring and alerting:
Event Correlation
- Correlate image deletion events with unusual account activity or concurrent unauthorized operations.
|
|
Snapshot Metadata
|
Contextual data about a snapshot, which may include information such as ID, type, and status
|
|
Cloud Service Enumeration
|
Cloud service enumeration involves listing or querying available cloud services in a cloud control plane. This activity is often performed to identify resources such as virtual machines, storage buckets, compute clusters, or other services within a cloud environment. Examples include API calls like `AWS ECS ListServices`, `Azure ListAllResources`, or `Google Cloud ListInstances`. Examples:
AWS Cloud Service Enumeration: The adversary gathers details about existing ECS services to identify opportunities for privilege escalation or exfiltration.
- Azure Resource Enumeration: The adversary collects information about virtual machines, resource groups, and other Azure assets for reconnaissance purposes.
- Google Cloud Resource Enumeration: The attacker seeks to map the environment and find misconfigured or underutilized resources for exploitation.
- Office 365 Service Enumeration: The attacker may look for data repositories or collaboration tools to exfiltrate sensitive information.
|
|
Group Metadata
|
Group metadata includes attributes like name, permissions, purpose, and associated user accounts or roles, which adversaries may exploit for privilege escalation. Examples:
- Active Directory: `Get-ADGroup -Identity "Domain Admins" -Properties Members, Description`
- Azure AD: `Get-AzureADGroup -ObjectId `
- Google Workspace: `GET https://admin.googleapis.com/admin/directory/v1/groups/`
- AWS IAM: `aws iam list-group-policies --group-name `
- Office 365: `GET https://graph.microsoft.com/v1.0/groups/`
*Data Collection Measures:*
- Cloud Logging:
- AWS CloudTrail for IAM group-related activities.
- Azure AD Sign-In/Audit logs for metadata changes.
- Google Admin Activity logs for API calls.
- Directory Logging: Log metadata access (e.g., Windows Event ID 4662).
- API Monitoring: Log API calls to modify group metadata (e.g., Microsoft Graph API).
- SIEM Integration: Centralize group metadata logs for analysis.
|
|
Group Enumeration
|
Extracting group lists from identity systems identifies permissions, roles, or configurations. Adversaries may exploit high-privilege groups or misconfigurations. Examples:
- AWS CLI: `aws iam list-groups`
- PowerShell: `Get-ADGroup -Filter *`
- (Saas) Google Workspace: Admin SDK Directory API
- Azure: `Get-AzureADGroup`
- Microsoft 365: Graph API `GET https://graph.microsoft.com/v1.0/groups`
*Data Collection Measures:*
- Cloud Logging: Enable AWS CloudTrail, Azure Activity Logs, and Google Workspace Admin Logs for group-related actions.
- Directory Monitoring: Track logs like AD Event ID 4662 (object operations).
- API Monitoring: Log API activity like AWS IAM queries.
- SaaS Monitoring: Use platform logs (e.g., Office 365 Unified Audit Logs).
- SIEM Integration: Centralize group query tracking.
|
|
Social Media
|
Established, compromised, or otherwise acquired by adversaries to conduct reconnaissance, influence operations, social engineering, or other cyber threats.
*Data Collection Measures:*
- API Monitoring
- Social media APIs (e.g., Twitter API, Facebook Graph API) can extract behavioral patterns of accounts.
- Web Scraping
- Extracts public profile data, friend lists, or interactions to identify impersonation attempts.
- Threat Intelligence Feeds
- External feeds track malicious personas linked to disinformation campaigns or phishing.
- OSINT Tools
- Maltego, SpiderFoot, and OpenCTI can map social media persona relationships.
- Endpoint Detection
- EDR logs user behavior and alerts on suspicious social media interactions.
- SIEM Logging
- Detects access to known phishing pages or social media abuse via proxy logs.
- Dark Web Monitoring
- Identifies compromised social media credentials being sold.
|
|
Active Directory Object Deletion
|
Object deletion in AD (e.g., user accounts, groups, OUs) is logged as Event ID 5141. Examples:
- User Account: Deleted user.
- Group: Deleted security/distribution group.
- Organizational Unit (OU): Loss of configurations or policies.
- Service Account: Disrupted operations or cover tracks.
- Trust Object: Removed domain trust, disrupting connectivity.
*Data Collection Measures:*
- Audit Policy:
- Enable "Audit Directory Service Changes" (Success and Failure).
- Path: `Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Directory Service Changes`.
- Key Event: Event ID 5141.
- Log Forwarding: Use WEF to centralize logs for SIEM tools (e.g., Splunk).
- Enable EDR Monitoring:
- Detect processes or users that initiate unauthorized object deletions.
- Monitor tools and scripts that may delete key directory objects.
|
|
Container Enumeration
|
"Container Enumeration" data component captures events and actions related to listing and identifying active or available containers within a containerized environment. This includes information about running, stopped, or configured containers, such as their names, IDs, statuses, or associated images. Monitoring this activity is crucial for detecting unauthorized discovery or reconnaissance efforts. Examples:
- Docker Example: `docker ps`, `docker ps -a`
- Kubernetes Example: `kubectl get pods`, `kubectl get deployments`
- Cloud Container Services Example
- AWS ECS: API Call: ListTasks or ListContainers
- Azure Kubernetes Service: API Call: List pod or container instances.
- Google Kubernetes Engine (GKE): API Call: Retrieve deployments and their associated containers.
|
|
Malware Metadata
|
Contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information
|
|
OS API Execution
|
Calls made by a process to operating system-provided Application Programming Interfaces (APIs). These calls are essential for interacting with system resources such as memory, files, and hardware, or for performing system-level tasks. Monitoring these calls can provide insight into a process's intent, especially if the process is malicious.
|
|
Application Log Content
|
Application Log Content refers to logs generated by applications or services, providing a record of their activity. These logs may include metrics, errors, performance data, and operational alerts from web, mail, or other applications. These logs are vital for monitoring application behavior and detecting malicious activities or anomalies. Examples:
- Web Application Logs: These logs include information about requests, responses, errors, and security events (e.g., unauthorized access attempts).
- Email Application Logs: Logs contain metadata about emails sent, received, or blocked (e.g., sender/receiver addresses, message IDs).
- SaaS Application Logs: Activity logs include user logins, configuration changes, and access to sensitive resources.
- Cloud Application Logs: Logs detail control plane activities, including API calls, instance modifications, and network changes.
- System/Application Monitoring Logs: Logs provide insights into application performance, errors, and anomalies.
|
|
Logon Session Creation
|
The successful establishment of a new user session following a successful authentication attempt. This typically signifies that a user has provided valid credentials or authentication tokens, and the system has initiated a session associated with that user account. This data is crucial for tracking authentication events and identifying potential unauthorized access. Examples:
- Windows Systems
- Event ID: 4624
- Logon Type: 2 (Interactive) or 10 (Remote Interactive via RDP).
- Account Name: JohnDoe
- Source Network Address: 192.168.1.100
- Authentication Package: NTLM
- Linux Systems
- /var/log/utmp or /var/log/wtmp:
- Log format: login user [tty] from [source_ip]
- User: jane
- IP: 10.0.0.5
- Timestamp: 2024-12-28 08:30:00
- macOS Systems
- /var/log/asl.log or unified logging framework:
- Log: com.apple.securityd: Authentication succeeded for user 'admin'
- Cloud Environments
- Azure Sign-In Logs:
- Activity: Sign-in successful
- Client App: Browser
- Location: Unknown (Country: X)
- Google Workspace
- Activity: Login
- Event Type: successful_login
- Source IP: 203.0.113.55
|
|
Script Execution
|
The execution of a text file that contains code via the interpreter.
|
|
Container Creation
|
"Container Creation" data component captures details about the initial construction of a container in a containerized environment. This includes events where a new container is instantiated, such as through Docker, Kubernetes, or other container orchestration platforms. Monitoring these events helps detect unauthorized or potentially malicious container creation. Examples:
- Docker Example: `docker create my-container`, `docker run --name=my-container nginx:latest`
- Kubernetes Example: `kubectl run my-pod --image=nginx`, `kubectl create deployment my-deployment --image=nginx`
- Cloud Container Services Example
- AWS ECS: Task or service creation (`RunTask` or `CreateService`).
- Azure Container Instances: Deployment of a container group.
- Google Kubernetes Engine (GKE): Creation of new pods via GCP APIs.
|
|
Network Traffic Flow
|
Summarized network packet data that captures session-level details such as source/destination IPs, ports, protocol types, timestamps, and data volume, without storing full packet payloads. This is commonly used for traffic analysis, anomaly detection, and network performance monitoring.
|
|
User Account Authentication
|
An attempt (successful and failed login attempts) by a user, service, or application to gain access to a network, system, or cloud-based resource. This typically involves credentials such as passwords, tokens, multi-factor authentication (MFA), or biometric validation.
|
|
Image Creation
|
Initial construction of a virtual machine image within a cloud environment. Virtual machine images are templates containing an operating system and installed applications, which can be deployed to create new virtual machines. Monitoring the creation of these images is important because adversaries may create custom images to include malicious software or misconfigurations for later exploitation. Examples:
- Azure Compute Service Image Creation
- Example: Creating a virtual machine image in Azure using Azure CLI: `az image create --resource-group MyResourceGroup --name MyImage --source MyVM`
- AWS EC2 AMI (Amazon Machine Image) Creation
- Example: Creating an AMI from an EC2 instance: `aws ec2 create-image --instance-id i-1234567890abcdef0 --name "MyAMI" --description "An AMI for my app"`
- Google Cloud Compute Engine Image Creation
- Example: Creating a custom image using gcloud: `gcloud compute images create my-custom-image --source-disk my-disk --source-disk-zone us-central1-a`
- VMware vSphere
- Example: Exporting a VM to create an OVF (Open Virtualization Format) template: This could later be imported into other environments with potential tampering.
|
|
Cloud Service Metadata
|
Cloud service metadata refers to the contextual and descriptive information about cloud services, including their name, type, purpose, configuration, and activity around them. This metadata is essential for understanding the roles and functions of cloud services, their operational status, and their potential misuse. Examples:
- Azure Service Metadata: Metadata describing a resource in Azure, such as an Azure Storage Account or a Virtual Machine.
- AWS Cloud Service Metadata: Metadata for an AWS EC2 instance collected using the `DescribeInstances` API call.
- Google Cloud Service Metadata: Metadata for a Google Compute Engine instance collected using `gcloud compute instances describe`.
- Office 365 Metadata: Metadata about an Office 365 SharePoint site.
|
|
Image Metadata
|
contextual information associated with a virtual machine image, such as its name, resource group, status (active or inactive), type (custom or prebuilt), size, creation date, and permissions. This metadata is critical for understanding the state and configuration of virtual machine images in cloud environments. Examples:
- Azure Compute Service Image Metadata Example:
- Name: MyCustomImage
- Resource Group: MyResourceGroup
- State: Available
- Type: Managed Image
- AWS EC2 AMI Metadata Example:
- Image ID: ami-1234567890abcdef0
- Name: ProdImage
- State: Available
- Platform: Windows
- Google Cloud Compute Engine Image Metadata Example:
- Image Name: webserver-image
- Project: my-project-id
- Family: webserver
- Source Disk: my-disk-id
- VMware vSphere Template Metadata Example:
- Name: LinuxTemplate
- Disk Size: 40GB
- Network Adapter: VM Network
|
|
Instance Creation
|
The initial provisioning and construction of a virtual machine (VM) or compute instance within a cloud infrastructure environment. This activity involves defining and allocating resources such as CPU, memory, storage, and networking to spin up a new compute instance. Examples:
- AWS: creating an EC2 instance using RunInstances API calls.
- Azure, creating a VM through the Azure Resource Manager (ARM).
- GCP, an `instance.insert` action recorded.
|
|
User Account Metadata
|
Contextual data about an account, which may include a username, user ID, environmental data, etc.
|
|
Named Pipe Metadata
|
Contextual data about a named pipe on a system, including pipe name and creating process (ex: Sysmon EIDs 17-18)
*Data Collection Measures:*
- Windows:
- Sysmon Event ID 17: Logs the creation of a named pipe.
- Sysmon Event ID 18: Logs connection attempts to a named pipe.
- Windows Security Event ID 5145: Logs access attempts to named pipes via SMB shares.
- ETW (Event Tracing for Windows): Provides deep telemetry into named pipe interactions.
- Linux/macOS:
- AuditD (`mkfifo`, `open`, `read`, `write` syscalls): Tracks FIFO (named pipe) creation and usage.
- Lsof (`lsof -p ` or `lsof | grep PIPE`): Lists active named pipes and associated processes.
- Strace (`strace -e open `): Monitors named pipe interactions.
- Endpoint Detection & Response (EDR):
- Capture named pipe events as part of process tracking.
- Memory Forensics:
- Volatility Plugin (`pipescan`): Enumerates named pipes in system memory.
- Rekall Framework: Identifies active named pipes and associated processes.
|
|
Firmware Modification
|
Changes made to firmware, which may include its settings, configurations, or underlying data. This can encompass alterations to the Master Boot Record (MBR), Volume Boot Record (VBR), or other firmware components critical to system boot and functionality. Such modifications are often indicators of adversary activity, including malware persistence and system compromise. Examples:
- Changes to Master Boot Record (MBR): Modifying the MBR to load malicious code during the boot process.
- Changes to Volume Boot Record (VBR): Altering the VBR to redirect boot processes to malicious locations.
- Firmware Configuration Changes: Modifying BIOS/UEFI settings such as disabling Secure Boot.
- Firmware Image Tampering: Updating firmware with a malicious or unauthorized image.
- Logs or Errors Indicating Firmware Changes: Logs showing unauthorized firmware updates or checksum mismatches.
This data component can be collected through the following measures:
- BIOS/UEFI Logs: Enable and monitor BIOS/UEFI logs to capture settings changes or firmware updates.
- Firmware Integrity Monitoring: Use tools or firmware security features to detect changes to firmware components.
- Endpoint Detection and Response (EDR) Solutions: Many EDR platforms can detect abnormal firmware activity, such as changes to MBR/VBR or unauthorized firmware updates.
- File System Monitoring: Monitor changes to MBR/VBR-related files using tools like Sysmon or auditd.
- Windows Example (Sysmon): Monitor Event ID 7 (Raw disk access).
- Linux Example (auditd): `auditctl -w /dev/sda -p wa -k firmware_modification`
- Network Traffic Analysis: Capture firmware updates downloaded over the network, particularly from untrusted sources. Use network monitoring tools like Zeek or Wireshark to analyze firmware-related traffic.
- Secure Boot Logs: Collect and analyze Secure Boot logs for signs of tampering or unauthorized configurations. Example: Use PowerShell to retrieve Secure Boot settings on Windows: `Confirm-SecureBootUEFI`
- Vendor-Specific Firmware Tools: Many hardware vendors provide tools for firmware integrity checks.Examples:
- Intel Platform Firmware Resilience (PFR).
- Lenovo UEFI diagnostics.
|
|
Firewall Enumeration
|
Querying and extracting a list of available firewalls or their associated configurations and rules. This activity can occur across host systems and cloud control planes, providing insight into the state and configuration of firewalls that protect the environment. Examples:
- Querying Host-Based Firewalls: Using Windows PowerShell commands like `Get-NetFirewallRule` or Linux commands such as `iptables -L` or `firewalld --list-all`.
- Cloud Firewall Rule Listing: Running commands like `az network firewall list` for Azure or `aws ec2 describe-security-groups` for AWS.
- Using Management APIs: Leveraging APIs like Google Cloud Firewall's `list` API method or AWS's DescribeSecurityGroups API.
Identifying Misconfigurations: Extracting firewall rules to identify “allow all” policies or rules that lack logging.
- Enumerating with CLI Tools: Using CLI commands like `gcloud compute firewall-rules list` to extract firewall settings in Google Cloud.
|
|
Module Load
|
When a process or program dynamically attaches a shared library, module, or plugin into its memory space. This action is typically performed to extend the functionality of an application, access shared system resources, or interact with kernel-mode components.
|
|
Pod Metadata
|
Contextual data about a pod and activity around it such as name, ID, namespace, or status
|
|
Firewall Disable
|
The deactivation, misconfiguration, or complete stoppage of firewall services, either on a host or in a cloud control plane. Such activity may involve turning off firewalls, modifying rules to disable protection, or deleting firewall-related configurations and activity logs. Examples:
- Disabling Host-Based Firewalls: Stopping the Windows Defender Firewall service or using `iptables -F` to flush all rules on a Linux system.
- Cloud Firewall Modification or Deactivation: Modifying or deleting security group rules in AWS or disabling a network firewall in Azure.
- Activity Log Deletion: Writing or deleting entries in Azure Firewall Activity Logs to hide unauthorized firewall changes.
- Temporary Disable for Malicious Operations: Temporarily disabling a firewall to allow malicious files or traffic, then re-enabling it to avoid detection.
- Using Command-Line Tools to Stop Firewalls: Running commands like `Set-NetFirewallProfile -Enabled False on Windows or systemctl stop ufw` on Linux.
This data component can be collected through the following measures:
Cloud Control Plane
- Azure Activity Logs:
- Enable logging of administrative actions, such as stopping or modifying Azure Firewall configurations.
- Use Azure Monitor to track specific firewall-related actions, including disabling or rule deletion.
- AWS CloudTrail Logs:
- Monitor `RevokeSecurityGroupIngress` or `RevokeSecurityGroupEgress` events to detect rule changes in AWS Security Groups.
- Google Cloud Platform Logs:
- Collect logs from the Firewall Rules resource in Google Cloud Operations Suite to detect rule deletions or modifications.
Host-Level Firewalls
- Windows Firewall Event Logs:
- Enable logging of firewall state changes:
- Security Event ID 2004: Firewall service stopped.
- Security Event ID 2005: Firewall service started.
- Use Sysmon for process creation events tied to firewall commands or scripts (Sysmon Event ID 1).
- Linux Firewall Logs: Use auditd to track commands like iptables, firewalld, or ufw: `auditctl -a always,exit -F arch=b64 -S execve -k firewall_disable`
- macOS Firewall: Monitor changes to the macOS Application Firewall using the log show command.
Network-Level Monitoring
- IDS/IPS Alerts: Deploy IDS/IPS systems to monitor abnormal traffic flows that could indicate firewall disablement.
- NetFlow Data: Analyze NetFlow or packet capture data for traffic patterns inconsistent with firewall enforcement.
SIEM and CSPM Tools
- SIEM Integration: Use tools like Splunk or QRadar to centralize and analyze firewall disablement events from both hosts and cloud platforms.
- Cloud Security Posture Management (CSPM): Use CSPM solutions to monitor misconfigurations and track deactivation of critical cloud services like firewalls.
|
|
Passive DNS
|
"Domain Name: Passive DNS" captures logged historical and real-time domain name system (DNS) data. This includes records of domain-to-IP address resolutions over time, enabling analysts to track the evolution of domain infrastructure, uncover historical patterns of use, and detect malicious activities tied to domains and their associated IP addresses. Examples:
- Historical Resolutions
- Shared IP Usage
- Temporal Patterns
- Malicious Domain Clustering
- Historical Lookback
This data component can be collected through the following measures:
- Passive DNS Platforms: Use platforms that specialize in passive DNS collection and analysis:
- Tools: Farsight DNSDB, RiskIQ PassiveTotal, PassiveDNS.
- Threat Intelligence Feeds: Integrate passive DNS data from commercial or open-source threat intelligence providers.
- Custom DNS Collectors: Deploy custom tools to capture DNS traffic at the network level for analysis.
- Cloud DNS Services: Leverage cloud DNS services (e.g., AWS Route 53, Azure DNS) that maintain DNS query logs.
|
|
User Account Modification
|
Changes made to an existing user, service, or machine account, including alterations to attributes, permissions, roles, authentication methods, or group memberships.
|
|
Firewall Rule Modification
|
The creation, deletion, or alteration of firewall rules to allow or block specific network traffic. Monitoring changes to these rules is critical for detecting misconfigurations, unauthorized access, or malicious attempts to bypass network protections. Examples:
- Rule Creation: Adding a new rule to allow inbound traffic on port 3389 (RDP).
- Rule Deletion: Deleting a rule that blocks inbound traffic from untrusted IP ranges.
- Rule Modification: Changing a rule to allow traffic from "any" source IP instead of a specific trusted range.
- Audit Log Metadata: Logs indicating "Firewall rule modified by admin@domain.com."
- Platform-Specific Scenarios
- Azure: Altering rules in an Azure Network Security Group (NSG).
- AWS: Modifying Security Group rules to allow traffic.
- Windows: Changes tracked in Security Event Logs (EID 4950 or 4951).
This data component can be collected through the following measures:
Cloud Control Plane
- Azure: Collect rule modification logs from Azure Firewall Activity Logs.
- Example Command: `az network firewall policy rule-collection-group rule-collection list --policy-name `
- AWS: Use CloudTrail to track `AuthorizeSecurityGroupIngress` or `RevokeSecurityGroupIngress` actions.
Example: `aws ec2 describe-security-groups`
- Google Cloud: Use gcloud commands to extract firewall rules: `gcloud compute firewall-rules list --format=json`
Host-Based Firewalls
- Windows:
- Collect events from the Windows Security Event Log (EID 4950: A rule has been modified).
- Use PowerShell to track rule changes: `Get-NetFirewallRule -PolicyStore PersistentStore`
- Linux:
- Monitor iptables or nftables rule modifications: `iptables -L -v`
- Use auditd for real-time monitoring: `auditctl -w /etc/iptables.rules -p wa`
- macOS: Use pfctl to monitor rule changes: `sudo pfctl -sr`
SIEM Integration
- Collect logs from cloud platforms, host systems, and network appliances for centralized monitoring.
API Monitoring
- Monitor API calls for firewall rule modifications.
|
|
Volume Modification
|
Changes made to a cloud volume, including its settings and control data (ex: AWS modify-volume)
|
|
Process Modification
|
Changes made to a running process, such as writing data into memory, modifying execution behavior, or injecting code into an existing process. Adversaries frequently modify processes to execute malicious payloads, evade detection, or gain escalated privileges.
|
|
User Account Deletion
|
The removal of a user, service, or machine account from an operating system, cloud identity management system, or directory service.
|
|
Windows Registry Key Modification
|
Changes made to an existing registry key or its values. These modifications can include altering permissions, modifying stored data, or updating configuration settings.
*Data Collection Measures:*
- Windows Event Logs
- Event ID 4657 - Registry Value Modified: Logs changes to registry values, including modifications to startup entries, security settings, or system configurations.
- Sysmon (System Monitor) for Windows
- Sysmon Event ID 13 - Registry Value Set: Captures changes to specific registry values.
- Sysmon Event ID 14 - Registry Key & Value Renamed: Logs renaming of registry keys, which may indicate evasion attempts.
- Endpoint Detection and Response (EDR) Solutions
- Monitor registry modifications for suspicious behavior.
|
|
Volume Creation
|
The initial provisioning of block storage volumes in cloud or on-prem environments, typically used for data storage, backup, or workload scaling.
|
|
User Account Creation
|
The initial establishment of a new user, service, or machine account within an operating system, cloud environment, or identity management system.
|
|
Container Metadata
|
Contextual data about a container and activity around it such as name, ID, image, or status
|
|
Cloud Storage Metadata
|
Cloud Storage Metadata provides contextual information about cloud storage infrastructure and its associated activity. This data may include attributes such as storage name, size, owner, permissions, creation date, region, and activity metadata. It is essential for monitoring, auditing, and identifying anomalies in cloud storage environments. Examples:
- AWS S3 Bucket Metadata: Metadata about an S3 bucket includes the bucket name, region, creation date, owner, storage class, and permissions.
- Azure Blob Storage Metadata: Metadata for an Azure Blob container includes container name, access level (e.g., private or public), size, and tags.
- Google Cloud Storage Metadata: Metadata includes bucket name, storage class, location, labels, lifecycle policies, and versioning status.
- OpenStack Swift Metadata: Metadata for a Swift container includes name, access level, quota, and custom attributes.
|
|
Cloud Service Modification
|
Cloud service modification refers to changes made to the configuration, settings, or data of a cloud service. These modifications can include administrative changes such as enabling or disabling features, altering permissions, or deleting critical components. Monitoring these changes is critical to detect potential misconfigurations or malicious activity. Examples:
- AWS Cloud Service Modifications: A user disables AWS CloudTrail logging (StopLogging) or deletes a CloudWatch configuration rule (DeleteConfigRule).
- Azure Cloud Service Modifications: Changes to Azure Role-Based Access Control (RBAC) roles, such as adding a new Contributor role to a sensitive resource.
- Google Cloud Service Modifications: Deletion of a Google Cloud Storage bucket or disabling a Google Cloud Function.
- Office 365 Cloud Service Modifications: Altering mailbox permissions or disabling auditing in Microsoft 365.
|
|
File Deletion
|
Refers to events where files are removed from a system or storage device. These events can indicate legitimate housekeeping activities or malicious actions such as attackers attempting to cover their tracks. Monitoring file deletions helps organizations identify unauthorized or suspicious activities.
|
|
Cloud Service Disable
|
This data component refers to monitoring actions that deactivate or stop a cloud service in a cloud control plane. Examples include disabling essential logging services like AWS CloudTrail (`StopLogging` API call), Microsoft Azure Monitor Logs, or Google Cloud's Operations Suite (formerly Stackdriver). Disabling such services can hinder visibility into adversary activities within the cloud environment. Examples:
- AWS CloudTrail StopLogging: This action stops logging of API activity for a particular trail, effectively reducing the monitoring and visibility of AWS resources and activities.
- Microsoft Azure Monitor Logs: Disabling these logs hinders the organization’s ability to detect anomalous activities and trace malicious actions.
- Google Cloud Logging: Disabling cloud logging removes visibility into resource activity, preventing monitoring of service access or configuration changes.
- SaaS Applications: Stopping logging removes visibility into user activities, such as email access or file downloads, enabling undetected malicious behavior.
|
|
Volume Enumeration
|
An extracted list of available volumes within a cloud environment (ex: AWS describe-volumes)
|
|
Windows Registry Key Access
|
The action of opening a specific Windows Registry key, typically to read its associated value. This activity can be used for system configuration, application settings retrieval, and security policies.
|
|
Process Metadata
|
Contextual data about a running process, which may include information such as environment variables, image name, user/owner, etc.
|
|
Snapshot Modification
|
Changes made to a cloud snapshot's metadata, attributes, or control settings. These modifications may involve adjusting access permissions, changing retention policies, or altering encryption settings.
*Data Collection Measures:*
- AWS CloudTrail
- Tracks API calls such as `ModifySnapshotAttribute`, `ResetSnapshotAttribute`, and `ModifySnapshotTier`.
- Azure Monitor Logs
- Logs changes via `Microsoft.Compute/snapshots/write`.
- Google Cloud Logging
- Captures modifications through `compute.snapshots.setIamPolicy` and `compute.snapshots.patch`.
|
|
Scheduled Job Creation
|
The establishment of a task or job that will execute at a predefined time or based on specific triggers.
|
|
Network Share Access
|
Opening a network share, which makes the contents available to the requestor (ex: Windows EID 5140 or 5145)
|
|
Driver Metadata
|
to contextual data about a driver, including its attributes, functionality, and activity. This can involve details such as the driver's origin, integrity, cryptographic signature, issues reported during its use, and runtime behavior. Examples include metadata captured during driver integrity checks, hash validation, or error reporting. Examples:
- Driver Signature Validation: A driver is validated to ensure it is signed by a trusted Certificate Authority (CA).
- Driver Hash Verification: The hash of a driver is compared to a known good hash stored in a database.
- Driver Compatibility Issues: A driver error is logged due to compatibility issues with a particular version of the operating system.
- Vulnerable Driver Identification: Metadata indicates the driver version is outdated or contains a known vulnerability.
- Monitoring Driver Integrity: Drivers are monitored for any unauthorized modifications to their binary or associated files.
This data component can be collected through the following measures:
Windows
- Windows Event Logs:
- Event ID 3000-3006: Logs metadata about driver signature validation.
- Event ID 2000-2011 (Windows Defender Application Control): Tracks driver integrity and policy enforcement.
- Sysmon Logs: Configure Sysmon to capture driver loading metadata (Event ID 6).
- Driver Verifier: Use Driver Verifier to collect diagnostic and performance data about drivers, including stability and compatibility metrics.
- PowerShell: Use commands to retrieve metadata about installed drivers:
`Get-WindowsDriver -Online | Select-Object Driver, ProviderName, Version`
Linux
- Auditd: Configure audit rules to monitor driver interactions and collect metadata: `auditctl -w /lib/modules/ -p rwxa -k driver_metadata`
- dmesg: Use `dmesg` to extract kernel logs with driver metadata: `dmesg | grep "module"`
- lsmod and modinfo: Commands to list loaded modules and retrieve metadata about drivers: `lsmod` | `modinfo `
macOS
- Unified Logs: Collect metadata from system logs about kernel extensions (kexts): `log show --predicate 'eventMessage contains "kext load"' --info`
- kextstat: Command to retrieve information about loaded kernel extensions: `kextstat`
SIEM Tools
- Ingest Driver Metadata: Collect driver metadata logs from Sysmon, Auditd, or macOS logs into SIEMs like Splunk or Elastic.
Vulnerability Management Tools
- Use these tools to collect metadata about vulnerable drivers across enterprise systems.
|
|
Instance Start
|
The initiation or activation of a virtual machine instance within a cloud infrastructure. This action typically involves starting an existing instance that had been stopped or paused, allowing it to resume operation. Examples:
- Google Cloud Platform (GCP): Starting an instance through `instance.start` API activity.
- AWS: Logging of `StartInstances` in AWS CloudTrail for EC2 instances.
- Azure: `Microsoft.Compute/virtualMachines/start` entries indicate a VM instance being started.
|
|
Scheduled Job Modification
|
Changes made to an existing scheduled job, including modifications to its execution parameters, command payload, or execution timing.
|
|
Cluster Metadata
|
Contextual data about a cluster and activity around it such as name, namespace, age, or status
|
|
Cloud Storage Enumeration
|
Cloud Storage Enumeration involves retrieving a list of available cloud storage infrastructure, such as buckets, containers, or objects, within a cloud environment. This activity may be performed for legitimate administrative purposes or malicious reconnaissance by adversaries seeking to identify accessible storage resources.Examples:
- AWS S3 Bucket Enumeration: An AWS user lists all buckets using the `ListBuckets` API call.
- Azure Blob Storage Container Enumeration: A user retrieves a list of all containers within a storage account using the Azure Storage SDK or API.
- Google Cloud Storage Bucket Enumeration: A Google Cloud user lists all buckets within a project using the `storage.buckets.list` API.
- OpenStack Swift Container Enumeration: A user retrieves a list of containers in OpenStack Swift using the `GET` method on the storage endpoint.
|
|
Web Credential Usage
|
An attempt by a user to gain access to a network or computing resource by providing web credentials (ex: Windows EID 1202)
|
|
Domain Registration
|
"Domain Name: Domain Registration" data component captures information about the assignment, ownership, and metadata of domain names. This information is often sourced from registries like WHOIS and includes details such as registrant names, contact information, registration dates, expiration dates, and registrar details. This data is invaluable for tracking domain ownership, detecting malicious domain registrations, and identifying trends in adversary behavior. Examples:
- Registrant Information: WHOIS lookup of example.com
- Registration and Expiration Dates: A domain registered a week before being used in phishing attacks.
- Domain Status: Status codes like clientTransferProhibited or serverHold indicate domain restrictions or potential hijacking activity.
- Name Server Information: Name servers point to a public DNS provider often associated with malicious campaigns.
- Privacy Protection: A domain uses WHOIS privacy protection to hide registrant details.
This data component can be collected through the following measures:
- WHOIS Services: Use tools or services to perform WHOIS lookups:
- WHOIS APIs: Automate domain registration lookups with APIs:
- Registrar Platforms: Directly query domain registrars (e.g., GoDaddy, Namecheap) for detailed registration data.
- Threat Intelligence Platforms: Integrate domain registration data from services like Recorded Future, RiskIQ, or PassiveTotal for enriched analysis.
|
|
Snapshot Enumeration
|
The process of listing or retrieving metadata about existing snapshots in a cloud environment.
*Data Collection Measures:*
- AWS CloudTrail
- Logs API calls such as `DescribeSnapshots`, `ListSnapshots`, and `GetSnapshotAttributes`.
- Azure Monitor Logs
- Tracks snapshot enumeration via `Microsoft.Compute/snapshots/read`.
- Google Cloud Logging
- Detects snapshot listing through `compute.disks.listSnapshots`.
|
|
Behavioral Detection of Network Share Connection Removal via CLI and SMB Disconnects
|
Behavioral Detection of Network Share Connection Removal via CLI and SMB Disconnects
|
|
Detect Abuse of vSphere Installation Bundles (VIBs) for Persistent Access
|
Detect Abuse of vSphere Installation Bundles (VIBs) for Persistent Access
|
|
Detection of Kernel/User-Level Rootkit Behavior Across Platforms
|
Detection of Kernel/User-Level Rootkit Behavior Across Platforms
|
|
Detect Remote Email Collection via Abnormal Login and Programmatic Access
|
Detect Remote Email Collection via Abnormal Login and Programmatic Access
|
|
Detection of Malicious Control Panel Item Execution via control.exe or Rundll32
|
Detection of Malicious Control Panel Item Execution via control.exe or Rundll32
|
|
Detect Suspicious or Malicious Code Signing Abuse
|
Detect Suspicious or Malicious Code Signing Abuse
|
|
Detection of Link Target
|
Detection of Link Target
|
|
Detection of Botnet
|
Detection of Botnet
|
|
Detect Archiving and Encryption of Collected Data (T1560)
|
Detect Archiving and Encryption of Collected Data (T1560)
|
|
Multi-Event Detection for SMB Admin Share Lateral Movement
|
Multi-Event Detection for SMB Admin Share Lateral Movement
|
|
Detection Strategy for T1546.016 - Event Triggered Execution via Installer Packages
|
Detection Strategy for T1546.016 - Event Triggered Execution via Installer Packages
|
|
Detection of Malware
|
Detection of Malware
|
|
Behavioral Detection of User Discovery via Local and Remote Enumeration
|
Behavioral Detection of User Discovery via Local and Remote Enumeration
|
|
Detection Strategy for Plist File Modification (T1647)
|
Detection Strategy for Plist File Modification (T1647)
|
|
Detection Strategy for Impair Defenses Indicator Blocking
|
Detection Strategy for Impair Defenses Indicator Blocking
|
|
Detection Strategy for Accessibility Feature Hijacking via Binary Replacement or Registry Modification
|
Detection Strategy for Accessibility Feature Hijacking via Binary Replacement or Registry Modification
|
|
Detection of Msiexec Abuse for Local, Network, and DLL Execution
|
Detection of Msiexec Abuse for Local, Network, and DLL Execution
|
|
Detection Strategy for Dynamic API Resolution via Hash-Based Function Lookups
|
Detection Strategy for Dynamic API Resolution via Hash-Based Function Lookups
|
|
Detection Strategy for Hijack Execution Flow across OS platforms.
|
Detection Strategy for Hijack Execution Flow across OS platforms.
|
|
Detection Strategy for Hijack Execution Flow using Executable Installer File Permissions Weakness
|
Detection Strategy for Hijack Execution Flow using Executable Installer File Permissions Weakness
|
|
Detection Strategy for Event Triggered Execution via Trap (T1546.005)
|
Detection Strategy for Event Triggered Execution via Trap (T1546.005)
|
|
Behavioral Detection of Mailbox Data and Log Deletion for Anti-Forensics
|
Behavioral Detection of Mailbox Data and Log Deletion for Anti-Forensics
|
|
Detection Strategy for Encrypted Channel across OS Platforms
|
Detection Strategy for Encrypted Channel across OS Platforms
|
|
Detection Strategy for NTFS File Attribute Abuse (ADS/EAs)
|
Detection Strategy for NTFS File Attribute Abuse (ADS/EAs)
|
|
Detection of Establish Accounts
|
Detection of Establish Accounts
|
|
User-Initiated Malicious Library Installation via Package Manager (T1204.005)
|
User-Initiated Malicious Library Installation via Package Manager (T1204.005)
|
|
Detection Strategy for System Binary Proxy Execution: Regsvr32
|
Detection Strategy for System Binary Proxy Execution: Regsvr32
|
|
Detecting Steganographic Command and Control via File + Network Correlation
|
Detecting Steganographic Command and Control via File + Network Correlation
|
|
Behavior-chain detection for T1134.001 Access Token Manipulation: Token Impersonation/Theft on Windows
|
Behavior-chain detection for T1134.001 Access Token Manipulation: Token Impersonation/Theft on Windows
|
|
User Execution – Malicious Copy & Paste (browser/email → shell with obfuscated one-liner) – T1204.004
|
User Execution – Malicious Copy & Paste (browser/email → shell with obfuscated one-liner) – T1204.004
|
|
Detect Adversary-in-the-Middle via Network and Configuration Anomalies
|
Detect Adversary-in-the-Middle via Network and Configuration Anomalies
|
|
Detection Strategy for Resource Forking on macOS
|
Detection Strategy for Resource Forking on macOS
|
|
Detection of Botnet
|
Detection of Botnet
|
|
Detection Strategy for SQL Stored Procedures Abuse via T1505.001
|
Detection Strategy for SQL Stored Procedures Abuse via T1505.001
|
|
Detecting Malicious Browser Extensions Across Platforms
|
Detecting Malicious Browser Extensions Across Platforms
|
|
Detection of Registry Query for Environmental Discovery
|
Detection of Registry Query for Environmental Discovery
|
|
Detect Compromise of Host Software Binaries
|
Detect Compromise of Host Software Binaries
|
|
Detection Strategy for Hidden Windows
|
Detection Strategy for Hidden Windows
|
|
Multi-Platform Cloud Storage Exfiltration Behavior Chain
|
Multi-Platform Cloud Storage Exfiltration Behavior Chain
|
|
Detect Suspicious Access to Windows Credential Manager
|
Detect Suspicious Access to Windows Credential Manager
|
|
Detection of Data Staging Prior to Exfiltration
|
Detection of Data Staging Prior to Exfiltration
|
|
Detection Strategy for Disable or Modify Cloud Firewall
|
Detection Strategy for Disable or Modify Cloud Firewall
|
|
Detection of Network Topology
|
Detection of Network Topology
|
|
Suspicious Addition to Local or Domain Groups
|
Suspicious Addition to Local or Domain Groups
|
|
Detection Strategy for Exploitation for Credential Access
|
Detection Strategy for Exploitation for Credential Access
|
|
Credential Dumping from SAM via Registry Dump and Local File Access
|
Credential Dumping from SAM via Registry Dump and Local File Access
|
|
Brute Force Authentication Failures with Multi-Platform Log Correlation
|
Brute Force Authentication Failures with Multi-Platform Log Correlation
|
|
Detect LSA Authentication Package Persistence via Registry and LSASS DLL Load
|
Detect LSA Authentication Package Persistence via Registry and LSASS DLL Load
|
|
Detection of Command and Control Over Application Layer Protocols
|
Detection of Command and Control Over Application Layer Protocols
|
|
Detection Strategy for Lateral Tool Transfer across OS platforms
|
Detection Strategy for Lateral Tool Transfer across OS platforms
|
|
Detection of Digital Certificates
|
Detection of Digital Certificates
|
|
Detection Strategy for Modify Cloud Compute Infrastructure: Create Snapshot
|
Detection Strategy for Modify Cloud Compute Infrastructure: Create Snapshot
|
|
Masquerading via Space After Filename - Behavioral Detection Strategy
|
Masquerading via Space After Filename - Behavioral Detection Strategy
|
|
Behavioral Detection of Publish/Subscribe Protocol Misuse for C2
|
Behavioral Detection of Publish/Subscribe Protocol Misuse for C2
|
|
Detection of Spearphishing Service
|
Detection of Spearphishing Service
|
|
Detection Strategy for Log Enumeration
|
Detection Strategy for Log Enumeration
|
|
Detection of Social Media Accounts
|
Detection of Social Media Accounts
|
|
Behavioral Detection of System Network Configuration Discovery
|
Behavioral Detection of System Network Configuration Discovery
|
|
Detection Strategy for Exfiltration Over Web Service
|
Detection Strategy for Exfiltration Over Web Service
|
|
Detection Strategy for ListPlanting Injection on Windows
|
Detection Strategy for ListPlanting Injection on Windows
|
|
Detection Strategy of Transmitted Data Manipulation
|
Detection Strategy of Transmitted Data Manipulation
|
|
Credential Access via /etc/passwd and /etc/shadow Parsing
|
Credential Access via /etc/passwd and /etc/shadow Parsing
|
|
Behavioral Detection of Windows Command Shell Execution
|
Behavioral Detection of Windows Command Shell Execution
|
|
Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps)
|
Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps)
|
|
Behavioral detection for Supply Chain Compromise (package/update tamper → install → first-run)
|
Behavioral detection for Supply Chain Compromise (package/update tamper → install → first-run)
|
|
Suspicious Database Access and Dump Activity Across Environments (T1213.006)
|
Suspicious Database Access and Dump Activity Across Environments (T1213.006)
|
|
Cross-Platform Behavioral Detection of Python Execution
|
Cross-Platform Behavioral Detection of Python Execution
|
|
Detect Credentials Access from Password Stores
|
Detect Credentials Access from Password Stores
|
|
Detection Strategy for Endpoint DoS via Service Exhaustion Flood
|
Detection Strategy for Endpoint DoS via Service Exhaustion Flood
|
|
Detection Strategy for Extra Window Memory (EWM) Injection on Windows
|
Detection Strategy for Extra Window Memory (EWM) Injection on Windows
|
|
Detection Strategy for T1218.012 Verclsid Abuse
|
Detection Strategy for T1218.012 Verclsid Abuse
|
|
Detection Strategy for Disable or Modify Linux Audit System Log
|
Detection Strategy for Disable or Modify Linux Audit System Log
|
|
Detection Strategy for Exclusive Control
|
Detection Strategy for Exclusive Control
|
|
Detection Strategy for Disk Structure Wipe via Boot/Partition Overwrite
|
Detection Strategy for Disk Structure Wipe via Boot/Partition Overwrite
|
|
Detection Strategy for Impersonation
|
Detection Strategy for Impersonation
|
|
Traffic Signaling (Port-knock / magic-packet → firewall or service activation) – T1205
|
Traffic Signaling (Port-knock / magic-packet → firewall or service activation) – T1205
|
|
Detection of Code Signing Certificates
|
Detection of Code Signing Certificates
|
|
Behavior-chain detection for T1132.001 Data Encoding: Standard Encoding (Base64/Hex/MIME) across Windows, Linux, macOS, ESXi
|
Behavior-chain detection for T1132.001 Data Encoding: Standard Encoding (Base64/Hex/MIME) across Windows, Linux, macOS, ESXi
|
|
Detection of Cloud Accounts
|
Detection of Cloud Accounts
|
|
Detection of File Transfer Protocol-Based C2 (FTP, FTPS, SMB, TFTP)
|
Detection of File Transfer Protocol-Based C2 (FTP, FTPS, SMB, TFTP)
|
|
Detection Strategy for Junk Code Obfuscation with Suspicious Execution Patterns
|
Detection Strategy for Junk Code Obfuscation with Suspicious Execution Patterns
|
|
Behavioral Detection of Log File Clearing on Linux and macOS
|
Behavioral Detection of Log File Clearing on Linux and macOS
|
|
Detection of Remote Data Staging Prior to Exfiltration
|
Detection of Remote Data Staging Prior to Exfiltration
|
|
Detection Strategy for Reflection Amplification DoS (T1498.002)
|
Detection Strategy for Reflection Amplification DoS (T1498.002)
|
|
Detection Strategy for Temporary Elevated Cloud Access Abuse (T1548.005)
|
Detection Strategy for Temporary Elevated Cloud Access Abuse (T1548.005)
|
|
Detection Strategy for Network Address Translation Traversal
|
Detection Strategy for Network Address Translation Traversal
|
|
Local Account Enumeration Across Host Platforms
|
Local Account Enumeration Across Host Platforms
|
|
Detection Strategy for Cloud Infrastructure Discovery
|
Detection Strategy for Cloud Infrastructure Discovery
|
|
T1136.001 Detection Strategy - Local Account Creation Across Platforms
|
T1136.001 Detection Strategy - Local Account Creation Across Platforms
|
|
Cross-Platform Detection of Data Transfer to Cloud Account
|
Cross-Platform Detection of Data Transfer to Cloud Account
|
|
Detection Strategy for Debugger Evasion (T1622)
|
Detection Strategy for Debugger Evasion (T1622)
|
|
Detection Strategy for Application Shimming via sdbinst.exe and Registry Artifacts (Windows)
|
Detection Strategy for Application Shimming via sdbinst.exe and Registry Artifacts (Windows)
|
|
Email Collection via Local Email Access and Auto-Forwarding Behavior
|
Email Collection via Local Email Access and Auto-Forwarding Behavior
|
|
Behavioral Detection of Internet Connection Discovery
|
Behavioral Detection of Internet Connection Discovery
|
|
Endpoint Resource Saturation and Crash Pattern Detection Across Platforms
|
Endpoint Resource Saturation and Crash Pattern Detection Across Platforms
|
|
Detect Mark-of-the-Web (MOTW) Bypass via Container and Disk Image Files
|
Detect Mark-of-the-Web (MOTW) Bypass via Container and Disk Image Files
|
|
Detection Strategy for Dynamic Resolution using Domain Generation Algorithms.
|
Detection Strategy for Dynamic Resolution using Domain Generation Algorithms.
|
|
Detection Strategy for Role Addition to Cloud Accounts
|
Detection Strategy for Role Addition to Cloud Accounts
|
|
Container CLI and API Abuse via Docker/Kubernetes (T1059.013)
|
Container CLI and API Abuse via Docker/Kubernetes (T1059.013)
|
|
Detection of Bluetooth-Based Data Exfiltration
|
Detection of Bluetooth-Based Data Exfiltration
|
|
Detection Strategy for Hijack Execution Flow through Path Interception by Unquoted Path
|
Detection Strategy for Hijack Execution Flow through Path Interception by Unquoted Path
|
|
Detection of Web Session Cookie Theft via File, Memory, and Network Artifacts
|
Detection of Web Session Cookie Theft via File, Memory, and Network Artifacts
|
|
Detection of Remote Service Session Hijacking for RDP.
|
Detection of Remote Service Session Hijacking for RDP.
|
|
Detection Strategy for Process Argument Spoofing on Windows
|
Detection Strategy for Process Argument Spoofing on Windows
|
|
Detection Strategy for T1505 - Server Software Component
|
Detection Strategy for T1505 - Server Software Component
|
|
Internal Proxy Behavior via Lateral Host-to-Host C2 Relay
|
Internal Proxy Behavior via Lateral Host-to-Host C2 Relay
|
|
Detection Strategy for Endpoint DoS via Application or System Exploitation
|
Detection Strategy for Endpoint DoS via Application or System Exploitation
|
|
Detection Strategy for Ignore Process Interrupts
|
Detection Strategy for Ignore Process Interrupts
|
|
Detection of Phishing for Information
|
Detection of Phishing for Information
|
|
Multi-Platform Shutdown or Reboot Detection via Execution and Host Status Events
|
Multi-Platform Shutdown or Reboot Detection via Execution and Host Status Events
|
|
Behavioral Detection Strategy for Use Alternate Authentication Material (T1550)
|
Behavioral Detection Strategy for Use Alternate Authentication Material (T1550)
|
|
Detection of Non-Application Layer Protocols for C2
|
Detection of Non-Application Layer Protocols for C2
|
|
Cross-host C2 via Removable Media Relay
|
Cross-host C2 via Removable Media Relay
|
|
Defacement via File and Web Content Modification Across Platforms
|
Defacement via File and Web Content Modification Across Platforms
|
|
Detect LLMNR/NBT-NS Poisoning and SMB Relay on Windows
|
Detect LLMNR/NBT-NS Poisoning and SMB Relay on Windows
|
|
Detection Strategy for SNMP (MIB Dump) on Network Devices
|
Detection Strategy for SNMP (MIB Dump) on Network Devices
|
|
macOS AuthorizationExecuteWithPrivileges Elevation Prompt Detection
|
macOS AuthorizationExecuteWithPrivileges Elevation Prompt Detection
|
|
Detection of Digital Certificates
|
Detection of Digital Certificates
|
|
Detect Network Logon Script Abuse via Multi-Event Correlation on Windows
|
Detect Network Logon Script Abuse via Multi-Event Correlation on Windows
|
|
Detection Strategy for Container and Resource Discovery
|
Detection Strategy for Container and Resource Discovery
|
|
Detect abuse of Trusted Relationships (third-party and delegated admin access)
|
Detect abuse of Trusted Relationships (third-party and delegated admin access)
|
|
Detection Strategy for Weaken Encryption: Disable Crypto Hardware on Network Devices
|
Detection Strategy for Weaken Encryption: Disable Crypto Hardware on Network Devices
|
|
Detection Strategy for T1547.009 – Shortcut Modification (Windows)
|
Detection Strategy for T1547.009 – Shortcut Modification (Windows)
|
|
Detection of DNS
|
Detection of DNS
|
|
Detection of Adversarial Process Discovery Behavior
|
Detection of Adversarial Process Discovery Behavior
|
|
Behavioral Detection Strategy for Abuse of Sudo and Sudo Caching
|
Behavioral Detection Strategy for Abuse of Sudo and Sudo Caching
|
|
Detection of Network Devices
|
Detection of Network Devices
|
|
Unix-like File Permission Manipulation Behavioral Chain Detection Strategy
|
Unix-like File Permission Manipulation Behavioral Chain Detection Strategy
|
|
Detection of Employee Names
|
Detection of Employee Names
|
|
Detection Strategy for T1505.004 - Malicious IIS Components
|
Detection Strategy for T1505.004 - Malicious IIS Components
|
|
Detection Strategy for Encrypted Channel via Symmetric Cryptography across OS Platforms
|
Detection Strategy for Encrypted Channel via Symmetric Cryptography across OS Platforms
|
|
Detection of Email Addresses
|
Detection of Email Addresses
|
|
Recursive Enumeration of Files and Directories Across Privilege Contexts
|
Recursive Enumeration of Files and Directories Across Privilege Contexts
|
|
Behavioral Detection of External Website Defacement across Platforms
|
Behavioral Detection of External Website Defacement across Platforms
|
|
Detection of Domain Trust Discovery via API, Script, and CLI Enumeration
|
Detection of Domain Trust Discovery via API, Script, and CLI Enumeration
|
|
Detecting Suspicious Access to CRM Data in SaaS Environments
|
Detecting Suspicious Access to CRM Data in SaaS Environments
|
|
Detection of Domains
|
Detection of Domains
|
|
Detect Kerberos Ticket Theft or Forgery (T1558)
|
Detect Kerberos Ticket Theft or Forgery (T1558)
|
|
Behavioral Detection of Native API Invocation via Unusual DLL Loads and Direct Syscalls
|
Behavioral Detection of Native API Invocation via Unusual DLL Loads and Direct Syscalls
|
|
Detection of Local Data Collection Prior to Exfiltration
|
Detection of Local Data Collection Prior to Exfiltration
|
|
Detection of Unauthorized DCSync Operations via Replication API Abuse
|
Detection of Unauthorized DCSync Operations via Replication API Abuse
|
|
Detection Strategy for Polymorphic Code Mutation and Execution
|
Detection Strategy for Polymorphic Code Mutation and Execution
|
|
Detection Strategy for System Services across OS platforms.
|
Detection Strategy for System Services across OS platforms.
|
|
Detection Strategy for Hijack Execution Flow through the AppDomainManager on Windows.
|
Detection Strategy for Hijack Execution Flow through the AppDomainManager on Windows.
|
|
Detection of Business Relationships
|
Detection of Business Relationships
|
|
Detection Strategy for Disk Content Wipe via Direct Access and Overwrite
|
Detection Strategy for Disk Content Wipe via Direct Access and Overwrite
|
|
Detection of Unauthorized Network Firewall Rule Modification
|
Detection of Unauthorized Network Firewall Rule Modification
|
|
Detection of Defense Impairment
|
Detection of Defense Impairment
|
|
Detect Domain Controller Authentication Process Modification (Skeleton Key)
|
Detect Domain Controller Authentication Process Modification (Skeleton Key)
|
|
Detection of Search Open Websites/Domains
|
Detection of Search Open Websites/Domains
|
|
Detection of Systemd Service Creation or Modification on Linux
|
Detection of Systemd Service Creation or Modification on Linux
|
|
Detection of SEO Poisoning
|
Detection of SEO Poisoning
|
|
Programmatic and Excessive Access to Confluence Documentation
|
Programmatic and Excessive Access to Confluence Documentation
|
|
Detection Strategy for AppCert DLLs Persistence via Registry Injection
|
Detection Strategy for AppCert DLLs Persistence via Registry Injection
|
|
Detection of Local Browser Artifact Access for Reconnaissance
|
Detection of Local Browser Artifact Access for Reconnaissance
|
|
Detection of Drive-by Target
|
Detection of Drive-by Target
|
|
Detection of Domain or Tenant Policy Modifications via AD and Identity Provider
|
Detection of Domain or Tenant Policy Modifications via AD and Identity Provider
|
|
Detection Strategy for Scheduled Transfer and Recurrent Exfiltration Patterns
|
Detection Strategy for Scheduled Transfer and Recurrent Exfiltration Patterns
|
|
IDE Tunneling Detection via Process, File, and Network Behaviors
|
IDE Tunneling Detection via Process, File, and Network Behaviors
|
|
Detect Logon Script Modifications and Execution
|
Detect Logon Script Modifications and Execution
|
|
Detect Abuse of Dynamic Data Exchange (T1559.002)
|
Detect Abuse of Dynamic Data Exchange (T1559.002)
|
|
Detection of Search Closed Sources
|
Detection of Search Closed Sources
|
|
Detection Strategy for Hidden Files and Directories
|
Detection Strategy for Hidden Files and Directories
|
|
Detection of Malware Relocation via Suspicious File Movement
|
Detection of Malware Relocation via Suspicious File Movement
|
|
Detection Strategy for Power Settings Abuse
|
Detection Strategy for Power Settings Abuse
|
|
Multi-hop Proxy Behavior via Relay Node Chaining, Onion Routing, and Network Tunneling
|
Multi-hop Proxy Behavior via Relay Node Chaining, Onion Routing, and Network Tunneling
|
|
Behavioral Detection of Masquerading Across Platforms via Metadata and Execution Discrepancy
|
Behavioral Detection of Masquerading Across Platforms via Metadata and Execution Discrepancy
|
|
Detection Strategy for T1546.017 - Udev Rules (Linux)
|
Detection Strategy for T1546.017 - Udev Rules (Linux)
|
|
Detection of Malvertising
|
Detection of Malvertising
|
|
Detection Strategy for Runtime Data Manipulation.
|
Detection Strategy for Runtime Data Manipulation.
|
|
Detection of Serverless
|
Detection of Serverless
|
|
Application Exhaustion Flood Detection Across Platforms
|
Application Exhaustion Flood Detection Across Platforms
|
|
Detect malicious IDE extension install/usage and IDE tunneling
|
Detect malicious IDE extension install/usage and IDE tunneling
|
|
Detection of Firmware
|
Detection of Firmware
|
|
Resource Hijacking Detection Strategy
|
Resource Hijacking Detection Strategy
|
|
Detection Strategy for Forged Web Credentials
|
Detection Strategy for Forged Web Credentials
|
|
Detection Strategy for /proc Memory Injection on Linux
|
Detection Strategy for /proc Memory Injection on Linux
|
|
Behavioral Detection of Asynchronous Procedure Call (APC) Injection via Remote Thread Queuing
|
Behavioral Detection of Asynchronous Procedure Call (APC) Injection via Remote Thread Queuing
|
|
Detection Strategy for Dynamic Resolution using Fast Flux DNS
|
Detection Strategy for Dynamic Resolution using Fast Flux DNS
|
|
Detection of Masqueraded Tasks or Services with Suspicious Naming and Execution
|
Detection of Masqueraded Tasks or Services with Suspicious Naming and Execution
|
|
Behavioral Detection of Network History and Configuration Tampering
|
Behavioral Detection of Network History and Configuration Tampering
|
|
Clipboard Data Access with Anomalous Context
|
Clipboard Data Access with Anomalous Context
|
|
Behavioral Detection of Thread Execution Hijacking via Thread Suspension and Context Switching
|
Behavioral Detection of Thread Execution Hijacking via Thread Suspension and Context Switching
|
|
Template Injection Detection - Windows
|
Template Injection Detection - Windows
|
|
Detect Windows Firewall
|
Detect Windows Firewall
|
|
Detect Social Engineering
|
Detect Social Engineering
|
|
Detection Strategy for Compile After Delivery - Source Code to Executable Transformation
|
Detection Strategy for Compile After Delivery - Source Code to Executable Transformation
|
|
Abuse of Information Repositories for Data Collection
|
Abuse of Information Repositories for Data Collection
|
|
Detection Strategy for Network Sniffing Across Platforms
|
Detection Strategy for Network Sniffing Across Platforms
|
|
Detect XSL Script Abuse via msxsl and wmic
|
Detect XSL Script Abuse via msxsl and wmic
|
|
Detect Remote Access via USB Hardware (TinyPilot, PiKVM)
|
Detect Remote Access via USB Hardware (TinyPilot, PiKVM)
|
|
Behavioral Detection of Visual Basic Execution (VBS/VBA/VBScript)
|
Behavioral Detection of Visual Basic Execution (VBS/VBA/VBScript)
|
|
Behavioral Detection of Unix Shell Execution
|
Behavioral Detection of Unix Shell Execution
|
|
Detection Strategy for Hijack Execution Flow using Path Interception by PATH Environment Variable.
|
Detection Strategy for Hijack Execution Flow using Path Interception by PATH Environment Variable.
|
|
Detection of Acquire Access
|
Detection of Acquire Access
|
|
Detection of Exploits
|
Detection of Exploits
|
|
Detection of Email Accounts
|
Detection of Email Accounts
|
|
Detection of Digital Certificates
|
Detection of Digital Certificates
|
|
Detect Conditional Access Policy Modification in Identity and Cloud Platforms
|
Detect Conditional Access Policy Modification in Identity and Cloud Platforms
|
|
Detection of Purchase Technical Data
|
Detection of Purchase Technical Data
|
|
Detection of Launch Agent Creation or Modification on macOS
|
Detection of Launch Agent Creation or Modification on macOS
|
|
Hardware Supply Chain Compromise Detection via Host Status & Boot Integrity Checks
|
Hardware Supply Chain Compromise Detection via Host Status & Boot Integrity Checks
|
|
Detecting Remote Script Proxy Execution via PubPrn.vbs
|
Detecting Remote Script Proxy Execution via PubPrn.vbs
|
|
Detection of Obtain Capabilities
|
Detection of Obtain Capabilities
|
|
Detection Strategy for LC_LOAD_DYLIB Modification in Mach-O Binaries on macOS
|
Detection Strategy for LC_LOAD_DYLIB Modification in Mach-O Binaries on macOS
|
|
Detection of Credentials
|
Detection of Credentials
|
|
Domain Account Enumeration Across Platforms
|
Domain Account Enumeration Across Platforms
|
|
Detection Strategy for Dynamic Resolution through DNS Calculation
|
Detection Strategy for Dynamic Resolution through DNS Calculation
|
|
Detection Strategy for Downgrade System Image on Network Devices
|
Detection Strategy for Downgrade System Image on Network Devices
|
|
Detection of Search Victim-Owned Websites
|
Detection of Search Victim-Owned Websites
|
|
Detection Strategy for ESXi Hypervisor CLI Abuse
|
Detection Strategy for ESXi Hypervisor CLI Abuse
|
|
Detect Persistence via Malicious Office Add-ins
|
Detect Persistence via Malicious Office Add-ins
|
|
Behavioral Detection of Remote SSH Logins Followed by Post-Login Execution
|
Behavioral Detection of Remote SSH Logins Followed by Post-Login Execution
|
|
Detection Strategy for Modify System Image on Network Devices
|
Detection Strategy for Modify System Image on Network Devices
|
|
Detection Strategy for Subvert Trust Controls using SIP and Trust Provider Hijacking.
|
Detection Strategy for Subvert Trust Controls using SIP and Trust Provider Hijacking.
|
|
Detect User Activity Based Sandbox Evasion via Input & Artifact Probing
|
Detect User Activity Based Sandbox Evasion via Input & Artifact Probing
|
|
Detection Strategy for Email Hiding Rules
|
Detection Strategy for Email Hiding Rules
|
|
Detect Network Provider DLL Registration and Credential Capture
|
Detect Network Provider DLL Registration and Credential Capture
|
|
Detection Strategy for T1136 - Create Account across platforms
|
Detection Strategy for T1136 - Create Account across platforms
|
|
Detection Strategy for Hidden Virtual Instance Execution
|
Detection Strategy for Hidden Virtual Instance Execution
|
|
Detection of IP Addresses
|
Detection of IP Addresses
|
|
Behavioral Detection of Cloud Group Enumeration via API and CLI Access
|
Behavioral Detection of Cloud Group Enumeration via API and CLI Access
|
|
Detection of Acquire Infrastructure
|
Detection of Acquire Infrastructure
|
|
Detection Strategy for T1550.002 - Pass the Hash (Windows)
|
Detection Strategy for T1550.002 - Pass the Hash (Windows)
|
|
Detecting Bulk or Anomalous Access to Private Code Repositories via SaaS Platforms
|
Detecting Bulk or Anomalous Access to Private Code Repositories via SaaS Platforms
|
|
Detection of Vulnerability Scanning
|
Detection of Vulnerability Scanning
|
|
Detection Strategy for T1528 - Steal Application Access Token
|
Detection Strategy for T1528 - Steal Application Access Token
|
|
Detection of Determine Physical Locations
|
Detection of Determine Physical Locations
|
|
Detection of Stage Capabilities
|
Detection of Stage Capabilities
|
|
Detect persistence via reopened application plist modification (macOS)
|
Detect persistence via reopened application plist modification (macOS)
|
|
Detect Adversary Deobfuscation or Decoding of Files and Payloads
|
Detect Adversary Deobfuscation or Decoding of Files and Payloads
|
|
Detection of Identify Roles
|
Detection of Identify Roles
|
|
Virtualization/Sandbox Evasion via System Checks across Windows, Linux, macOS
|
Virtualization/Sandbox Evasion via System Checks across Windows, Linux, macOS
|
|
Detection of Malware
|
Detection of Malware
|
|
Detect Kerberos Ccache File Theft or Abuse (T1558.005)
|
Detect Kerberos Ccache File Theft or Abuse (T1558.005)
|
|
Detection of Proxy Infrastructure Setup and Traffic Bridging
|
Detection of Proxy Infrastructure Setup and Traffic Bridging
|
|
Detection of Remote Service Session Hijacking
|
Detection of Remote Service Session Hijacking
|
|
Behavioral Detection Strategy for Exfiltration Over Symmetric Encrypted Non-C2 Protocol
|
Behavioral Detection Strategy for Exfiltration Over Symmetric Encrypted Non-C2 Protocol
|
|
Detection Strategy for Multi-Factor Authentication Request Generation (T1621)
|
Detection Strategy for Multi-Factor Authentication Request Generation (T1621)
|
|
Automated File and API Collection Detection Across Platforms
|
Automated File and API Collection Detection Across Platforms
|
|
Detection Strategy for T1550.003 - Pass the Ticket (Windows)
|
Detection Strategy for T1550.003 - Pass the Ticket (Windows)
|
|
Behavior-chain detection strategy for T1127.001 Trusted Developer Utilities Proxy Execution: MSBuild (Windows)
|
Behavior-chain detection strategy for T1127.001 Trusted Developer Utilities Proxy Execution: MSBuild (Windows)
|
|
Detection of Social Media Accounts
|
Detection of Social Media Accounts
|
|
Linux Python Startup Hook Persistence via .pth and Customize Files (T1546.018)
|
Linux Python Startup Hook Persistence via .pth and Customize Files (T1546.018)
|
|
Detect Default File Association Hijack via Registry & Execution Correlation on Windows
|
Detect Default File Association Hijack via Registry & Execution Correlation on Windows
|
|
Detect Access to Cloud Instance Metadata API (IaaS)
|
Detect Access to Cloud Instance Metadata API (IaaS)
|
|
Detecting Code Injection via mavinject.exe (App-V Injector)
|
Detecting Code Injection via mavinject.exe (App-V Injector)
|
|
Detection Strategy for Build Image on Host
|
Detection Strategy for Build Image on Host
|
|
Detect Gatekeeper Bypass via Quarantine Flag and Trust Control Manipulation
|
Detect Gatekeeper Bypass via Quarantine Flag and Trust Control Manipulation
|
|
Credential Stuffing Detection via Reused Breached Credentials Across Services
|
Credential Stuffing Detection via Reused Breached Credentials Across Services
|
|
Detect Winlogon Helper DLL Abuse via Registry and Process Artifacts on Windows
|
Detect Winlogon Helper DLL Abuse via Registry and Process Artifacts on Windows
|
|
Detect Multi-Stage Command and Control Channels
|
Detect Multi-Stage Command and Control Channels
|
|
Detecting Downgrade Attacks
|
Detecting Downgrade Attacks
|
|
Detection Strategy for Exploitation for Privilege Escalation
|
Detection Strategy for Exploitation for Privilege Escalation
|
|
Detect Access and Parsing of .bash_history Files for Credential Harvesting
|
Detect Access and Parsing of .bash_history Files for Credential Harvesting
|
|
Account Access Removal via Multi-Platform Audit Correlation
|
Account Access Removal via Multi-Platform Audit Correlation
|
|
Behavioral Detection of PE Injection via Remote Memory Mapping
|
Behavioral Detection of PE Injection via Remote Memory Mapping
|
|
Detect Ingress Tool Transfers via Behavioral Chain
|
Detect Ingress Tool Transfers via Behavioral Chain
|
|
Detection Strategy for Addition of Email Delegate Permissions
|
Detection Strategy for Addition of Email Delegate Permissions
|
|
Behavior-chain detection strategy for T1127.003 Trusted Developer Utilities Proxy Execution: JamPlus (Windows)
|
Behavior-chain detection strategy for T1127.003 Trusted Developer Utilities Proxy Execution: JamPlus (Windows)
|
|
Multi-Platform File and Directory Permissions Modification Detection Strategy
|
Multi-Platform File and Directory Permissions Modification Detection Strategy
|
|
Behavioral Detection of Permission Groups Discovery
|
Behavioral Detection of Permission Groups Discovery
|
|
Port-knock → rule/daemon change → first successful connect (T1205.001)
|
Port-knock → rule/daemon change → first successful connect (T1205.001)
|
|
Boot or Logon Initialization Scripts Detection Strategy
|
Boot or Logon Initialization Scripts Detection Strategy
|
|
Detect Access and Decryption of Group Policy Preference (GPP) Credentials in SYSVOL
|
Detect Access and Decryption of Group Policy Preference (GPP) Credentials in SYSVOL
|
|
Detection Strategy for Traffic Duplication via Mirroring in IaaS and Network Devices
|
Detection Strategy for Traffic Duplication via Mirroring in IaaS and Network Devices
|
|
Behavioral Detection of Domain Group Discovery
|
Behavioral Detection of Domain Group Discovery
|
|
Detection of DNS Server
|
Detection of DNS Server
|
|
Detection Strategy for Login Hook Persistence on macOS
|
Detection Strategy for Login Hook Persistence on macOS
|
|
Detection Strategy for Indicator Removal from Tools - Post-AV Evasion Modification
|
Detection Strategy for Indicator Removal from Tools - Post-AV Evasion Modification
|
|
Detection Strategy for Exfiltration to Text Storage Sites
|
Detection Strategy for Exfiltration to Text Storage Sites
|
|
Detection of Search Threat Vendor Data
|
Detection of Search Threat Vendor Data
|
|
Registry and LSASS Monitoring for Security Support Provider Abuse
|
Registry and LSASS Monitoring for Security Support Provider Abuse
|
|
Detect Hybrid Identity Authentication Process Modification
|
Detect Hybrid Identity Authentication Process Modification
|
|
Cross-Platform Detection of Cron Job Abuse for Persistence and Execution
|
Cross-Platform Detection of Cron Job Abuse for Persistence and Execution
|
|
Detection of Server
|
Detection of Server
|
|
Detection Strategy for SVG Smuggling with Script Execution and Delivery Behavior
|
Detection Strategy for SVG Smuggling with Script Execution and Delivery Behavior
|
|
Detect Credential Discovery via Windows Registry Enumeration
|
Detect Credential Discovery via Windows Registry Enumeration
|
|
Detection Strategy for VBA Stomping
|
Detection Strategy for VBA Stomping
|
|
Cross-Platform Detection of JavaScript Execution Abuse
|
Cross-Platform Detection of JavaScript Execution Abuse
|
|
Detection Strategy for Email Spoofing
|
Detection Strategy for Email Spoofing
|
|
Detection Strategy for MFA Interception via Input Capture and Smart Card Proxying
|
Detection Strategy for MFA Interception via Input Capture and Smart Card Proxying
|
|
Direct Network Flood Detection across IaaS, Linux, Windows, and macOS
|
Direct Network Flood Detection across IaaS, Linux, Windows, and macOS
|
|
Detection of Virtual Private Server
|
Detection of Virtual Private Server
|
|
Detection Strategy for Event Triggered Execution: AppInit DLLs (Windows)
|
Detection Strategy for Event Triggered Execution: AppInit DLLs (Windows)
|
|
Detection Strategy for Web Service: Dead Drop Resolver
|
Detection Strategy for Web Service: Dead Drop Resolver
|
|
User Execution – multi-surface behavior chain (documents/links → helper/unpacker → LOLBIN/child → egress)
|
User Execution – multi-surface behavior chain (documents/links → helper/unpacker → LOLBIN/child → egress)
|
|
Detect Office Startup-Based Persistence via Macros, Forms, and Registry Hooks
|
Detect Office Startup-Based Persistence via Macros, Forms, and Registry Hooks
|
|
Detection of Web Services
|
Detection of Web Services
|
|
Behavioral Detection of Indicator Removal Across Platforms
|
Behavioral Detection of Indicator Removal Across Platforms
|
|
Multi-event Detection Strategy for RDP-Based Remote Logins and Post-Access Activity
|
Multi-event Detection Strategy for RDP-Based Remote Logins and Post-Access Activity
|
|
Password Policy Discovery – cross-platform behavior-chain analytics
|
Password Policy Discovery – cross-platform behavior-chain analytics
|
|
Abuse of PowerShell for Arbitrary Execution
|
Abuse of PowerShell for Arbitrary Execution
|
|
Detection Strategy for Command Obfuscation
|
Detection Strategy for Command Obfuscation
|
|
Detection of Generate Content
|
Detection of Generate Content
|
|
Detect Subversion of Trust Controls via Certificate, Registry, and Attribute Manipulation
|
Detect Subversion of Trust Controls via Certificate, Registry, and Attribute Manipulation
|
|
Detection Strategy for File Creation or Modification of Boot Files
|
Detection Strategy for File Creation or Modification of Boot Files
|
|
System Discovery via Native and Remote Utilities
|
System Discovery via Native and Remote Utilities
|
|
Detect Persistence via Outlook Custom Forms Triggered by Malicious Email
|
Detect Persistence via Outlook Custom Forms Triggered by Malicious Email
|
|
Behavioral Detection of Systemd Timer Abuse for Scheduled Execution
|
Behavioral Detection of Systemd Timer Abuse for Scheduled Execution
|
|
Detect browser session hijacking via privilege, handle access, and remote thread into browsers
|
Detect browser session hijacking via privilege, handle access, and remote thread into browsers
|
|
Suspicious Use of Web Services for C2
|
Suspicious Use of Web Services for C2
|
|
Detection Strategy for System Services: Launchctl
|
Detection Strategy for System Services: Launchctl
|
|
Behavior-chain detection for T1134 Access Token Manipulation on Windows
|
Behavior-chain detection for T1134 Access Token Manipulation on Windows
|
|
Detecting Protocol or Service Impersonation via Anomalous TLS, HTTP Header, and Port Mismatch Correlation
|
Detecting Protocol or Service Impersonation via Anomalous TLS, HTTP Header, and Port Mismatch Correlation
|
|
Compromised software/update chain (installer/write → first-run/child → egress/signature anomaly)
|
Compromised software/update chain (installer/write → first-run/child → egress/signature anomaly)
|
|
Detect Forged Kerberos Silver Tickets (T1558.002)
|
Detect Forged Kerberos Silver Tickets (T1558.002)
|
|
Windows COM Hijacking Detection via Registry and DLL Load Correlation
|
Windows COM Hijacking Detection via Registry and DLL Load Correlation
|
|
Behavior-chain detection for T1134.002 Create Process with Token (Windows)
|
Behavior-chain detection for T1134.002 Create Process with Token (Windows)
|
|
Detection of Credential Dumping from LSASS Memory via Access and Dump Sequence
|
Detection of Credential Dumping from LSASS Memory via Access and Dump Sequence
|
|
Detection Strategy for Data from Network Shared Drive
|
Detection Strategy for Data from Network Shared Drive
|
|
Detection Strategy for Content Injection
|
Detection Strategy for Content Injection
|
|
Obfuscated Binary Unpacking Detection via Behavioral Patterns
|
Obfuscated Binary Unpacking Detection via Behavioral Patterns
|
|
Detection Strategy for Serverless Execution (T1648)
|
Detection Strategy for Serverless Execution (T1648)
|
|
Detection of Group Policy Modifications via AD Object Changes and File Activity
|
Detection of Group Policy Modifications via AD Object Changes and File Activity
|
|
Detection of Data Exfiltration via Removable Media
|
Detection of Data Exfiltration via Removable Media
|
|
Detection Strategy for T1136.003 - Cloud Account Creation across IaaS, IdP, SaaS, Office
|
Detection Strategy for T1136.003 - Cloud Account Creation across IaaS, IdP, SaaS, Office
|
|
Detection of Develop Capabilities
|
Detection of Develop Capabilities
|
|
Detection Strategy for Steal or Forge Authentication Certificates
|
Detection Strategy for Steal or Forge Authentication Certificates
|
|
Detection of Active Scanning
|
Detection of Active Scanning
|
|
Detection of Selective Exclusion
|
Detection of Selective Exclusion
|
|
Suspicious RoleBinding or ClusterRoleBinding Assignment in Kubernetes
|
Suspicious RoleBinding or ClusterRoleBinding Assignment in Kubernetes
|
|
Detection of System Network Connections Discovery Across Platforms
|
Detection of System Network Connections Discovery Across Platforms
|
|
Detection Strategy for Hijack Execution Flow through Services File Permissions Weakness.
|
Detection Strategy for Hijack Execution Flow through Services File Permissions Weakness.
|
|
Detect Modification of macOS Startup Items
|
Detect Modification of macOS Startup Items
|
|
Detection Strategy for Phishing across platforms.
|
Detection Strategy for Phishing across platforms.
|
|
Detection Strategy for Hijack Execution Flow through the KernelCallbackTable on Windows.
|
Detection Strategy for Hijack Execution Flow through the KernelCallbackTable on Windows.
|
|
Detection of Compromise Infrastructure
|
Detection of Compromise Infrastructure
|
|
Detection Strategy for T1497 Virtualization/Sandbox Evasion
|
Detection Strategy for T1497 Virtualization/Sandbox Evasion
|
|
Detection of Malicious Code Execution via InstallUtil.exe
|
Detection of Malicious Code Execution via InstallUtil.exe
|
|
Behavioral Detection of WinRM-Based Remote Access
|
Behavioral Detection of WinRM-Based Remote Access
|
|
Detection of Vulnerabilities
|
Detection of Vulnerabilities
|
|
Detection of Upload Tool
|
Detection of Upload Tool
|
|
Detection of Persistence Artifact Removal Across Host Platforms
|
Detection of Persistence Artifact Removal Across Host Platforms
|
|
Behavioral Detection of T1498 – Network Denial of Service Across Platforms
|
Behavioral Detection of T1498 – Network Denial of Service Across Platforms
|
|
Detect persistent or elevated container services via container runtime or cluster manipulation
|
Detect persistent or elevated container services via container runtime or cluster manipulation
|
|
Removable Media Execution Chain Detection via File and Process Activity
|
Removable Media Execution Chain Detection via File and Process Activity
|
|
Detection Strategy for Hijack Execution Flow using the Windows COR_PROFILER.
|
Detection Strategy for Hijack Execution Flow using the Windows COR_PROFILER.
|
|
Detection Strategy for Hidden File System Abuse
|
Detection Strategy for Hidden File System Abuse
|
|
Behavioral Detection Strategy for Network Service Discovery Across Platforms
|
Behavioral Detection Strategy for Network Service Discovery Across Platforms
|
|
Remote Desktop Software Execution and Beaconing Detection
|
Remote Desktop Software Execution and Beaconing Detection
|
|
Detection Strategy for Process Doppelgänging on Windows
|
Detection Strategy for Process Doppelgänging on Windows
|
|
Behavioral Detection Strategy for WMI Execution Abuse on Windows
|
Behavioral Detection Strategy for WMI Execution Abuse on Windows
|
|
Detect Persistence via Malicious Outlook Rules
|
Detect Persistence via Malicious Outlook Rules
|
|
Detect Suspicious Access to Private Key Files and Export Attempts Across Platforms
|
Detect Suspicious Access to Private Key Files and Export Attempts Across Platforms
|
|
Distributed Password Spraying via Authentication Failures Across Multiple Accounts
|
Distributed Password Spraying via Authentication Failures Across Multiple Accounts
|
|
Detection Strategy for Defense Impairment via Prevent Command History Logging across OS platforms.
|
Detection Strategy for Defense Impairment via Prevent Command History Logging across OS platforms.
|
|
Behavioral Detection of Command and Scripting Interpreter Abuse
|
Behavioral Detection of Command and Scripting Interpreter Abuse
|
|
Detection Strategy for Virtual Machine Discovery
|
Detection Strategy for Virtual Machine Discovery
|
|
Detection Strategy for Escape to Host
|
Detection Strategy for Escape to Host
|
|
Detection of Client Configurations
|
Detection of Client Configurations
|
|
Cloud Account Enumeration via API, CLI, and Scripting Interfaces
|
Cloud Account Enumeration via API, CLI, and Scripting Interfaces
|
|
Detection Strategy for System Services: Systemctl
|
Detection Strategy for System Services: Systemctl
|
|
Detect Modification of Network Device Authentication via Patched System Images
|
Detect Modification of Network Device Authentication via Patched System Images
|
|
Detection of Script-Based Proxy Execution via Signed Microsoft Utilities
|
Detection of Script-Based Proxy Execution via Signed Microsoft Utilities
|
|
Detection of Credential Harvesting via Web Portal Modification
|
Detection of Credential Harvesting via Web Portal Modification
|
|
Credential Dumping via Sensitive Memory and Registry Access Correlation
|
Credential Dumping via Sensitive Memory and Registry Access Correlation
|
|
Detection Strategy for Cloud Application Integration
|
Detection Strategy for Cloud Application Integration
|
|
Behavior-chain detection for T1132.002 Data Encoding: Non-Standard Encoding across Windows, Linux, macOS, ESXi
|
Behavior-chain detection for T1132.002 Data Encoding: Non-Standard Encoding across Windows, Linux, macOS, ESXi
|
|
Local Storage Discovery via Drive Enumeration and Filesystem Probing
|
Local Storage Discovery via Drive Enumeration and Filesystem Probing
|
|
Detection Strategy for Safe Mode Boot Abuse
|
Detection Strategy for Safe Mode Boot Abuse
|
|
Detect Abuse of Container APIs for Credential Access
|
Detect Abuse of Container APIs for Credential Access
|
|
Detecting Mshta-based Proxy Execution via Suspicious HTA or Script Invocation
|
Detecting Mshta-based Proxy Execution via Suspicious HTA or Script Invocation
|
|
Detect Use of Stolen Web Session Cookies Across Platforms
|
Detect Use of Stolen Web Session Cookies Across Platforms
|
|
Detection Strategy for Netsh Helper DLL Persistence via Registry and Child Process Monitoring (Windows)
|
Detection Strategy for Netsh Helper DLL Persistence via Registry and Child Process Monitoring (Windows)
|
|
Detection Strategy for Spearphishing Attachment across OS Platforms
|
Detection Strategy for Spearphishing Attachment across OS Platforms
|
|
Detection Strategy for Process Hollowing on Windows
|
Detection Strategy for Process Hollowing on Windows
|
|
Detection Strategy for Overwritten Process Arguments Masquerading
|
Detection Strategy for Overwritten Process Arguments Masquerading
|
|
Detection Strategy for T1542.005 Pre-OS Boot: TFTP Boot
|
Detection Strategy for T1542.005 Pre-OS Boot: TFTP Boot
|
|
Detect Local Email Collection via Outlook Data File Access and Command Line Tooling
|
Detect Local Email Collection via Outlook Data File Access and Command Line Tooling
|
|
Detect Registry and Startup Folder Persistence (Windows)
|
Detect Registry and Startup Folder Persistence (Windows)
|
|
Detect Suspicious Access to Browser Credential Stores
|
Detect Suspicious Access to Browser Credential Stores
|
|
Detection of Gather Victim Network Information
|
Detection of Gather Victim Network Information
|
|
Detection Strategy for Hijack Execution Flow using Path Interception by Search Order Hijacking
|
Detection Strategy for Hijack Execution Flow using Path Interception by Search Order Hijacking
|
|
Behavioral Detection of Spoofed GUI Credential Prompts
|
Behavioral Detection of Spoofed GUI Credential Prompts
|
|
Detection of Cached Domain Credential Dumping via Local Hash Cache Access
|
Detection of Cached Domain Credential Dumping via Local Hash Cache Access
|
|
Detect Time-Based Evasion via Sleep, Timer Loops, and Delayed Execution
|
Detect Time-Based Evasion via Sleep, Timer Loops, and Delayed Execution
|
|
Detection Strategy for T1505.002 - Transport Agent Abuse (Windows/Linux)
|
Detection Strategy for T1505.002 - Transport Agent Abuse (Windows/Linux)
|
|
Domain Fronting Behavior via Mismatched TLS SNI and HTTP Host Headers
|
Domain Fronting Behavior via Mismatched TLS SNI and HTTP Host Headers
|
|
Detection of Exfiltration Over Alternate Network Interfaces
|
Detection of Exfiltration Over Alternate Network Interfaces
|
|
Behavior-chain, platform-aware detection strategy for T1129 Shared Modules
|
Behavior-chain, platform-aware detection strategy for T1129 Shared Modules
|
|
Detection of WHOIS
|
Detection of WHOIS
|
|
Detection Strategy for Double File Extension Masquerading
|
Detection Strategy for Double File Extension Masquerading
|
|
Detecting Odbcconf Proxy Execution of Malicious DLLs
|
Detecting Odbcconf Proxy Execution of Malicious DLLs
|
|
Detection of Wordlist Scanning
|
Detection of Wordlist Scanning
|
|
Detecting Abnormal SharePoint Data Mining by Privileged or Rare Users
|
Detecting Abnormal SharePoint Data Mining by Privileged or Rare Users
|
|
Detection Strategy for Abuse Elevation Control Mechanism (T1548)
|
Detection Strategy for Abuse Elevation Control Mechanism (T1548)
|
|
Detection of Software
|
Detection of Software
|
|
Detection of Serverless
|
Detection of Serverless
|
|
Detect Abuse of Component Object Model (T1559.001)
|
Detect Abuse of Component Object Model (T1559.001)
|
|
Behavioral Detection of Process Injection Across Platforms
|
Behavioral Detection of Process Injection Across Platforms
|
|
Behavior-chain, platform-aware detection strategy for T1124 System Time Discovery
|
Behavior-chain, platform-aware detection strategy for T1124 System Time Discovery
|
|
Detection Strategy for Dynamic Resolution across OS Platforms
|
Detection Strategy for Dynamic Resolution across OS Platforms
|
|
Detection Strategy for Embedded Payloads
|
Detection Strategy for Embedded Payloads
|
|
Behavior-chain detection for T1610 Deploy Container across Docker & Kubernetes control/node planes
|
Behavior-chain detection for T1610 Deploy Container across Docker & Kubernetes control/node planes
|
|
Detect ARP Cache Poisoning Across Linux, Windows, and macOS
|
Detect ARP Cache Poisoning Across Linux, Windows, and macOS
|
|
Multi-Platform Execution Guardrails Environmental Validation Detection Strategy
|
Multi-Platform Execution Guardrails Environmental Validation Detection Strategy
|
|
Detect WMI Event Subscription for Persistence via WmiPrvSE Process and MOF Compilation
|
Detect WMI Event Subscription for Persistence via WmiPrvSE Process and MOF Compilation
|
|
Detection Strategy for Email Bombing
|
Detection Strategy for Email Bombing
|
|
Detect Malicious Modification of Pluggable Authentication Modules (PAM)
|
Detect Malicious Modification of Pluggable Authentication Modules (PAM)
|
|
Detecting .NET COM Registration Abuse via Regsvcs/Regasm
|
Detecting .NET COM Registration Abuse via Regsvcs/Regasm
|
|
Detection Strategy for Obfuscated Files or Information: Binary Padding
|
Detection Strategy for Obfuscated Files or Information: Binary Padding
|
|
Detection Strategy for Resource Hijacking: SMS Pumping via SaaS Application Logs
|
Detection Strategy for Resource Hijacking: SMS Pumping via SaaS Application Logs
|
|
Detect Abuse of Windows Time Providers for Persistence
|
Detect Abuse of Windows Time Providers for Persistence
|
|
Detection Strategy for System Language Discovery
|
Detection Strategy for System Language Discovery
|
|
Detection Strategy for System Location Discovery
|
Detection Strategy for System Location Discovery
|
|
Detection of Trust Relationship Modifications in Domain or Tenant Policies
|
Detection of Trust Relationship Modifications in Domain or Tenant Policies
|
|
Detection Strategy for Remote System Enumeration Behavior
|
Detection Strategy for Remote System Enumeration Behavior
|
|
Detect DHCP Spoofing Across Linux, Windows, and macOS
|
Detect DHCP Spoofing Across Linux, Windows, and macOS
|
|
Detection of Code Repositories
|
Detection of Code Repositories
|
|
Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189)
|
Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189)
|
|
Detection Strategy for TLS Callback Injection via PE Memory Modification and Hollowing
|
Detection Strategy for TLS Callback Injection via PE Memory Modification and Hollowing
|
|
Detection of DNS Server
|
Detection of DNS Server
|
|
Detection of Abused or Compromised Cloud Accounts for Access and Persistence
|
Detection of Abused or Compromised Cloud Accounts for Access and Persistence
|
|
Windows DACL Manipulation Behavioral Chain Detection Strategy
|
Windows DACL Manipulation Behavioral Chain Detection Strategy
|
|
Detection of Compromise Accounts
|
Detection of Compromise Accounts
|
|
Detection of Malicious Kubernetes CronJob Scheduling
|
Detection of Malicious Kubernetes CronJob Scheduling
|
|
Detection of Defense Impairment through Disabled or Modified Tools across OS Platforms.
|
Detection of Defense Impairment through Disabled or Modified Tools across OS Platforms.
|
|
Detection of Audio-Visual Content
|
Detection of Audio-Visual Content
|
|
Backup Software Discovery via CLI, Registry, and Process Inspection (T1518.002)
|
Backup Software Discovery via CLI, Registry, and Process Inspection (T1518.002)
|
|
Detect Archiving via Library (T1560.002)
|
Detect Archiving via Library (T1560.002)
|
|
Detection Strategy for Hijack Execution Flow through Service Registry Premission Weakness.
|
Detection Strategy for Hijack Execution Flow through Service Registry Premission Weakness.
|
|
Detection Strategy for T1218.011 Rundll32 Abuse
|
Detection Strategy for T1218.011 Rundll32 Abuse
|
|
Detection Strategy for T1542.002 Pre-OS Boot: Component Firmware
|
Detection Strategy for T1542.002 Pre-OS Boot: Component Firmware
|
|
Detect Unauthorized Access to Password Managers
|
Detect Unauthorized Access to Password Managers
|
|
Detection Strategy for Steganographic Abuse in File & Script Execution
|
Detection Strategy for Steganographic Abuse in File & Script Execution
|
|
Detection of Data Access and Collection from Removable Media
|
Detection of Data Access and Collection from Removable Media
|
|
Environmental Keying Discovery-to-Decryption Behavioral Chain Detection Strategy
|
Environmental Keying Discovery-to-Decryption Behavioral Chain Detection Strategy
|
|
Detection of Valid Account Abuse Across Platforms
|
Detection of Valid Account Abuse Across Platforms
|
|
Detection Strategy for T1547.010 – Port Monitor DLL Persistence via spoolsv.exe (Windows)
|
Detection Strategy for T1547.010 – Port Monitor DLL Persistence via spoolsv.exe (Windows)
|
|
Detection of Exfiltration Over Unencrypted Non-C2 Protocol
|
Detection of Exfiltration Over Unencrypted Non-C2 Protocol
|
|
Detection Strategy for HTML Smuggling via JavaScript Blob + Dynamic File Drop
|
Detection Strategy for HTML Smuggling via JavaScript Blob + Dynamic File Drop
|
|
Detect Abuse of XPC Services (T1559.003)
|
Detect Abuse of XPC Services (T1559.003)
|
|
Detection Strategy for Cloud Service Discovery
|
Detection Strategy for Cloud Service Discovery
|
|
Detection Strategy for AutoHotKey & AutoIT Abuse
|
Detection Strategy for AutoHotKey & AutoIT Abuse
|
|
Boot or Logon Autostart Execution Detection Strategy
|
Boot or Logon Autostart Execution Detection Strategy
|
|
Detection of NTDS.dit Credential Dumping from Domain Controllers
|
Detection of NTDS.dit Credential Dumping from Domain Controllers
|
|
Detect Unsecured Credentials Shared in Chat Messages
|
Detect Unsecured Credentials Shared in Chat Messages
|
|
Detect Screen Capture via Commands and API Calls
|
Detect Screen Capture via Commands and API Calls
|
|
T1136.002 Detection Strategy - Domain Account Creation Across Platforms
|
T1136.002 Detection Strategy - Domain Account Creation Across Platforms
|
|
Firmware Modification via Flash Tool or Corrupted Firmware Upload
|
Firmware Modification via Flash Tool or Corrupted Firmware Upload
|
|
Web Shell Detection via Server Behavior and File Execution Chains
|
Web Shell Detection via Server Behavior and File Execution Chains
|
|
Detection Strategy for T1542 Pre-OS Boot
|
Detection Strategy for T1542 Pre-OS Boot
|
|
Detection Strategy for Exfiltration to Code Repository
|
Detection Strategy for Exfiltration to Code Repository
|
|
Detection of Disabled or Modified System Firewalls across OS Platforms.
|
Detection of Disabled or Modified System Firewalls across OS Platforms.
|
|
Internal Spearphishing via Trusted Accounts
|
Internal Spearphishing via Trusted Accounts
|
|
Detection of Spoofed User-Agent
|
Detection of Spoofed User-Agent
|
|
Detection of Install Digital Certificate
|
Detection of Install Digital Certificate
|
|
Behavioral Detection for Service Stop across Platforms
|
Behavioral Detection for Service Stop across Platforms
|
|
Detection Strategy for LNK Icon Smuggling
|
Detection Strategy for LNK Icon Smuggling
|
|
Detection Strategy for Fileless Storage via Registry, WMI, and Shared Memory
|
Detection Strategy for Fileless Storage via Registry, WMI, and Shared Memory
|
|
Detection Strategy for Modify Cloud Compute Infrastructure
|
Detection Strategy for Modify Cloud Compute Infrastructure
|
|
Detection of AppleScript-Based Execution on macOS
|
Detection of AppleScript-Based Execution on macOS
|
|
Behavioral Detection Strategy for Use Alternate Authentication Material: Application Access Token (T1550.001)
|
Behavioral Detection Strategy for Use Alternate Authentication Material: Application Access Token (T1550.001)
|
|
Detection of Local Account Abuse for Initial Access and Persistence
|
Detection of Local Account Abuse for Initial Access and Persistence
|
|
Behavioral Detection for T1490 - Inhibit System Recovery
|
Behavioral Detection for T1490 - Inhibit System Recovery
|
|
Detection of Gather Victim Host Information
|
Detection of Gather Victim Host Information
|
|
Detect Access to Unsecured Credential Files Across Platforms
|
Detect Access to Unsecured Credential Files Across Platforms
|
|
Detect Evil Twin Wi-Fi Access Points on Network Devices
|
Detect Evil Twin Wi-Fi Access Points on Network Devices
|
|
Detect Abuse of Inter-Process Communication (T1559)
|
Detect Abuse of Inter-Process Communication (T1559)
|
|
Password Guessing via Multi-Source Authentication Failure Correlation
|
Password Guessing via Multi-Source Authentication Failure Correlation
|
|
Detect Forced SMB/WebDAV Authentication via lure files and outbound NTLM
|
Detect Forced SMB/WebDAV Authentication via lure files and outbound NTLM
|
|
Socket-filter trigger → on-host raw-socket activity → reverse connection (T1205.002)
|
Socket-filter trigger → on-host raw-socket activity → reverse connection (T1205.002)
|
|
Detection Strategy for VDSO Hijacking on Linux
|
Detection Strategy for VDSO Hijacking on Linux
|
|
Detection of Gather Victim Identity Information
|
Detection of Gather Victim Identity Information
|
|
Windows Detection Strategy for T1547.012 - Print Processor DLL Persistence
|
Windows Detection Strategy for T1547.012 - Print Processor DLL Persistence
|
|
Detection Strategy for Masquerading via Legitimate Resource Name or Location
|
Detection Strategy for Masquerading via Legitimate Resource Name or Location
|
|
Detection Strategy for Forged SAML Tokens
|
Detection Strategy for Forged SAML Tokens
|
|
Detection Strategy for Bind Mounts on Linux
|
Detection Strategy for Bind Mounts on Linux
|
|
Detect Modification of Authentication Process via Reversible Encryption
|
Detect Modification of Authentication Process via Reversible Encryption
|
|
Behavioral Detection of Malicious File Deletion
|
Behavioral Detection of Malicious File Deletion
|
|
User Execution – Malicious Link (click → suspicious egress → download/write → follow-on activity)
|
User Execution – Malicious Link (click → suspicious egress → download/write → follow-on activity)
|
|
Detection Strategy for Hide Infrastructure
|
Detection Strategy for Hide Infrastructure
|
|
Detecting PowerShell Execution via SyncAppvPublishingServer.vbs Proxy Abuse
|
Detecting PowerShell Execution via SyncAppvPublishingServer.vbs Proxy Abuse
|
|
Abuse of Domain Accounts
|
Abuse of Domain Accounts
|
|
Detect Active Setup Persistence via StubPath Execution
|
Detect Active Setup Persistence via StubPath Execution
|
|
Behavioral Detection of Wi-Fi Discovery Activity
|
Behavioral Detection of Wi-Fi Discovery Activity
|
|
Detecting Junk Data in C2 Channels via Behavioral Analysis
|
Detecting Junk Data in C2 Channels via Behavioral Analysis
|
|
Behavioral Detection of Unauthorized VNC Remote Control Sessions
|
Behavioral Detection of Unauthorized VNC Remote Control Sessions
|
|
Detection of Written Content
|
Detection of Written Content
|
|
Suspicious Device Registration via Entra ID or MFA Platform
|
Suspicious Device Registration via Entra ID or MFA Platform
|
|
Setuid/Setgid Privilege Abuse Detection (Linux/macOS)
|
Setuid/Setgid Privilege Abuse Detection (Linux/macOS)
|
|
Detection of Mail Protocol-Based C2 Activity (SMTP, IMAP, POP3)
|
Detection of Mail Protocol-Based C2 Activity (SMTP, IMAP, POP3)
|
|
Detection of Domain Properties
|
Detection of Domain Properties
|
|
Detection Strategy for Weaken Encryption: Reduce Key Space on Network Devices
|
Detection Strategy for Weaken Encryption: Reduce Key Space on Network Devices
|
|
Detection Strategy for Modify Cloud Compute Infrastructure: Create Cloud Instance
|
Detection Strategy for Modify Cloud Compute Infrastructure: Create Cloud Instance
|
|
Detection Strategy for Hidden Artifacts Across Platforms
|
Detection Strategy for Hidden Artifacts Across Platforms
|
|
Detection Strategy for Hijack Execution Flow for DLLs
|
Detection Strategy for Hijack Execution Flow for DLLs
|
|
Detection Strategy for SSH Session Hijacking
|
Detection Strategy for SSH Session Hijacking
|
|
Endpoint DoS via OS Exhaustion Flood Detection Strategy
|
Endpoint DoS via OS Exhaustion Flood Detection Strategy
|
|
Multi-Platform Behavioral Detection for Compute Hijacking
|
Multi-Platform Behavioral Detection for Compute Hijacking
|
|
Detection Strategy for Boot or Logon Initialization Scripts: RC Scripts
|
Detection Strategy for Boot or Logon Initialization Scripts: RC Scripts
|
|
Detection Strategy for Lua Scripting Abuse
|
Detection Strategy for Lua Scripting Abuse
|
|
Detection Strategy for Exfiltration Over C2 Channel
|
Detection Strategy for Exfiltration Over C2 Channel
|
|
External Proxy Behavior via Outbound Relay to Intermediate Infrastructure
|
External Proxy Behavior via Outbound Relay to Intermediate Infrastructure
|
|
Detection Strategy for T1525 – Implant Internal Image
|
Detection Strategy for T1525 – Implant Internal Image
|
|
Detect Excessive or Unauthorized Bandwidth Usage for Botnet, Proxyjacking, or Scanning Purposes
|
Detect Excessive or Unauthorized Bandwidth Usage for Botnet, Proxyjacking, or Scanning Purposes
|
|
Detection Strategy for ESXi Administration Command
|
Detection Strategy for ESXi Administration Command
|
|
Detection of Malicious Profile Installation via CMSTP.exe
|
Detection of Malicious Profile Installation via CMSTP.exe
|
|
Renamed Legitimate Utility Execution with Metadata Mismatch and Suspicious Path
|
Renamed Legitimate Utility Execution with Metadata Mismatch and Suspicious Path
|
|
Linux Detection Strategy for T1547.013 - XDG Autostart Entries
|
Linux Detection Strategy for T1547.013 - XDG Autostart Entries
|
|
Behavioral Detection of DNS Tunneling and Application Layer Abuse
|
Behavioral Detection of DNS Tunneling and Application Layer Abuse
|
|
Detection Strategy for Ptrace-Based Process Injection on Linux
|
Detection Strategy for Ptrace-Based Process Injection on Linux
|
|
Detection of LSA Secrets Dumping via Registry and Memory Extraction
|
Detection of LSA Secrets Dumping via Registry and Memory Extraction
|
|
Detection of Exploits
|
Detection of Exploits
|
|
Detection of Server
|
Detection of Server
|
|
Detection Strategy for T1542.004 Pre-OS Boot: ROMMONkit
|
Detection Strategy for T1542.004 Pre-OS Boot: ROMMONkit
|
|
Right-to-Left Override Masquerading Detection via Filename and Execution Context
|
Right-to-Left Override Masquerading Detection via Filename and Execution Context
|
|
Detection Strategy for Hidden User Accounts
|
Detection Strategy for Hidden User Accounts
|
|
Detection Strategy for Cloud Storage Object Discovery
|
Detection Strategy for Cloud Storage Object Discovery
|
|
Detection of Data Destruction Across Platforms via Mass Overwrite and Deletion Patterns
|
Detection of Data Destruction Across Platforms via Mass Overwrite and Deletion Patterns
|
|
Behavioral Detection of Event Triggered Execution Across Platforms
|
Behavioral Detection of Event Triggered Execution Across Platforms
|
|
Detecting Unauthorized Collection from Messaging Applications in SaaS and Office Environments
|
Detecting Unauthorized Collection from Messaging Applications in SaaS and Office Environments
|
|
Behavioral Detection Strategy for T1123 Audio Capture Across Windows, Linux, macOS
|
Behavioral Detection Strategy for T1123 Audio Capture Across Windows, Linux, macOS
|
|
Detection of Suspicious Scheduled Task Creation and Execution on Windows
|
Detection of Suspicious Scheduled Task Creation and Execution on Windows
|
|
Detection of Windows Service Creation or Modification
|
Detection of Windows Service Creation or Modification
|
|
Detection Strategy for Exfiltration to Cloud Storage
|
Detection Strategy for Exfiltration to Cloud Storage
|
|
Detection of Code Signing Certificates
|
Detection of Code Signing Certificates
|
|
Internal Website and System Content Defacement via UI or Messaging Modifications
|
Internal Website and System Content Defacement via UI or Messaging Modifications
|
|
Behavioral Detection of Input Capture Across Platforms
|
Behavioral Detection of Input Capture Across Platforms
|
|
Detection of Spearphishing Link
|
Detection of Spearphishing Link
|
|
Detection Strategy for Patch System Image on Network Devices
|
Detection Strategy for Patch System Image on Network Devices
|
|
Cross-Platform Detection of Scheduled Task/Job Abuse via `at` Utility
|
Cross-Platform Detection of Scheduled Task/Job Abuse via `at` Utility
|
|
Behavioral Detection of CLI Abuse on Network Devices
|
Behavioral Detection of CLI Abuse on Network Devices
|
|
Detection of Scanning IP Blocks
|
Detection of Scanning IP Blocks
|
|
Detection Strategy for Poisoned Pipeline Execution via SaaS CI/CD Workflows
|
Detection Strategy for Poisoned Pipeline Execution via SaaS CI/CD Workflows
|
|
Detect Persistence via Office Test Registry DLL Injection
|
Detect Persistence via Office Test Registry DLL Injection
|
|
Detection of Tool
|
Detection of Tool
|
|
Detect Forged Kerberos Golden Tickets (T1558.001)
|
Detect Forged Kerberos Golden Tickets (T1558.001)
|
|
Detect Access to macOS Keychain for Credential Theft
|
Detect Access to macOS Keychain for Credential Theft
|
|
Detection Strategy for Non-Standard Ports
|
Detection Strategy for Non-Standard Ports
|
|
Detection Strategy for Data Manipulation
|
Detection Strategy for Data Manipulation
|
|
Detection Strategy for Additional Cloud Credentials in IaaS/IdP/SaaS
|
Detection Strategy for Additional Cloud Credentials in IaaS/IdP/SaaS
|
|
Detection of Gather Victim Org Information
|
Detection of Gather Victim Org Information
|
|
Detection of Tainted Content Written to Shared Storage
|
Detection of Tainted Content Written to Shared Storage
|
|
Detection of Proxy Execution via Trusted Signed Binaries Across Platforms
|
Detection of Proxy Execution via Trusted Signed Binaries Across Platforms
|
|
Detection of Spearphishing Voice
|
Detection of Spearphishing Voice
|
|
Detection Strategy for Modify Cloud Compute Infrastructure: Delete Cloud Instance
|
Detection Strategy for Modify Cloud Compute Infrastructure: Delete Cloud Instance
|
|
Detection of Search Engines
|
Detection of Search Engines
|
|
Detection Strategy for SSH Key Injection in Authorized Keys
|
Detection Strategy for SSH Key Injection in Authorized Keys
|
|
Behavior-Based Registry Modification Detection on Windows
|
Behavior-Based Registry Modification Detection on Windows
|
|
Detection of Virtual Private Server
|
Detection of Virtual Private Server
|
|
Detection of Lifecycle Policy Modifications for Triggered Deletion in IaaS Cloud Storage
|
Detection of Lifecycle Policy Modifications for Triggered Deletion in IaaS Cloud Storage
|
|
Detect Disabled Windows Event Log
|
Detect Disabled Windows Event Log
|
|
Detection of Default Account Abuse Across Platforms
|
Detection of Default Account Abuse Across Platforms
|
|
Detection of Multi-Platform File Encryption for Impact
|
Detection of Multi-Platform File Encryption for Impact
|
|
Detection of Social Media
|
Detection of Social Media
|
|
Detection of Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
|
Detection of Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
|
|
Detect Access or Search for Unsecured Credentials Across Platforms
|
Detect Access or Search for Unsecured Credentials Across Platforms
|
|
Detection of Mutex-Based Execution Guardrails Across Platforms
|
Detection of Mutex-Based Execution Guardrails Across Platforms
|
|
Detection of Application Window Enumeration via API or Scripting
|
Detection of Application Window Enumeration via API or Scripting
|
|
Behavior-chain detection for T1134.005 Access Token Manipulation: SID-History Injection (Windows)
|
Behavior-chain detection for T1134.005 Access Token Manipulation: SID-History Injection (Windows)
|
|
Behavioral Detection Strategy for Remote Service Logins and Post-Access Activity
|
Behavioral Detection Strategy for Remote Service Logins and Post-Access Activity
|
|
Detection of Event Log Clearing on Windows via Behavioral Chain
|
Detection of Event Log Clearing on Windows via Behavioral Chain
|
|
Detect Screensaver-Based Persistence via Registry and Execution Chains
|
Detect Screensaver-Based Persistence via Registry and Execution Chains
|
|
Detecting Electron Application Abuse for Proxy Execution
|
Detecting Electron Application Abuse for Proxy Execution
|
|
Detection Strategy for Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations
|
Detection Strategy for Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations
|
|
Detection of Network Trust Dependencies
|
Detection of Network Trust Dependencies
|
|
Detection of Email Accounts
|
Detection of Email Accounts
|
|
Detect Modification of Authentication Processes Across Platforms
|
Detect Modification of Authentication Processes Across Platforms
|
|
Detection Strategy for IFEO Injection on Windows
|
Detection Strategy for IFEO Injection on Windows
|
|
Detection Strategy for T1548.002 – Bypass User Account Control (UAC)
|
Detection Strategy for T1548.002 – Bypass User Account Control (UAC)
|
|
Detection of Artificial Intelligence
|
Detection of Artificial Intelligence
|
|
Account Manipulation Behavior Chain Detection
|
Account Manipulation Behavior Chain Detection
|
|
Detection of Hardware
|
Detection of Hardware
|
|
Encrypted or Encoded File Payload Detection Strategy
|
Encrypted or Encoded File Payload Detection Strategy
|
|
Detection Strategy for Data Encoding in C2 Channels
|
Detection Strategy for Data Encoding in C2 Channels
|
|
Detect AS-REP Roasting Attempts (T1558.004)
|
Detect AS-REP Roasting Attempts (T1558.004)
|
|
Detection of System Service Discovery Commands Across OS Platforms
|
Detection of System Service Discovery Commands Across OS Platforms
|
|
Detection Strategy for T1505.005 – Terminal Services DLL Modification (Windows)
|
Detection Strategy for T1505.005 – Terminal Services DLL Modification (Windows)
|
|
Detection of Credential Harvesting via API Hooking
|
Detection of Credential Harvesting via API Hooking
|
|
Detection Strategy for Data Transfer Size Limits and Chunked Exfiltration
|
Detection Strategy for Data Transfer Size Limits and Chunked Exfiltration
|
|
Behavior‑chain detection for T1134.003 Make and Impersonate Token (Windows)
|
Behavior‑chain detection for T1134.003 Make and Impersonate Token (Windows)
|
|
Detection Strategy for Subvert Trust Controls via Install Root Certificate.
|
Detection Strategy for Subvert Trust Controls via Install Root Certificate.
|
|
Detection Strategy for Disk Wipe via Direct Disk Access and Destructive Commands
|
Detection Strategy for Disk Wipe via Direct Disk Access and Destructive Commands
|
|
Detection Strategy for Exploitation for Stealth
|
Detection Strategy for Exploitation for Stealth
|
|
Detection Strategy for Hijack Execution Flow: Dynamic Linker Hijacking
|
Detection Strategy for Hijack Execution Flow: Dynamic Linker Hijacking
|
|
Automated Exfiltration Detection Strategy
|
Automated Exfiltration Detection Strategy
|
|
Detection of System Process Creation or Modification Across Platforms
|
Detection of System Process Creation or Modification Across Platforms
|
|
Multi-Event Behavioral Detection for DCOM-Based Remote Code Execution
|
Multi-Event Behavioral Detection for DCOM-Based Remote Code Execution
|
|
Detecting OS Credential Dumping via /proc Filesystem Access on Linux
|
Detecting OS Credential Dumping via /proc Filesystem Access on Linux
|
|
Detection Strategy for Reflective Code Loading
|
Detection Strategy for Reflective Code Loading
|
|
Detection of Search Open Technical Databases
|
Detection of Search Open Technical Databases
|
|
Detection Strategy for Launch Daemon Creation or Modification (macOS)
|
Detection Strategy for Launch Daemon Creation or Modification (macOS)
|
|
Detection Strategy for Exfiltration Over Webhook
|
Detection Strategy for Exfiltration Over Webhook
|
|
Behavioral Detection of Command History Clearing
|
Behavioral Detection of Command History Clearing
|
|
Detection of Domains
|
Detection of Domains
|
|
Detect Bidirectional Web Service C2 Channels via Process & Network Correlation
|
Detect Bidirectional Web Service C2 Channels via Process & Network Correlation
|
|
Detection Strategy for Spearphishing via a Service across OS Platforms
|
Detection Strategy for Spearphishing via a Service across OS Platforms
|
|
Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress)
|
Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress)
|
|
Behavioral Detection of Local Group Enumeration Across OS Platforms
|
Behavioral Detection of Local Group Enumeration Across OS Platforms
|
|
Detection Strategy for Weaken Encryption on Network Devices
|
Detection Strategy for Weaken Encryption on Network Devices
|
|
Detect abuse of Windows BITS Jobs for download, execution and persistence
|
Detect abuse of Windows BITS Jobs for download, execution and persistence
|
|
Detection of Threat Intel Vendors
|
Detection of Threat Intel Vendors
|
|
Detection Strategy for Invisible Unicode
|
Detection Strategy for Invisible Unicode
|
|
Cross-Platform Behavioral Detection of Scheduled Task/Job Abuse
|
Cross-Platform Behavioral Detection of Scheduled Task/Job Abuse
|
|
Detection Strategy for Kernel Modules and Extensions Autostart Execution
|
Detection Strategy for Kernel Modules and Extensions Autostart Execution
|
|
Detection of Cloud Accounts
|
Detection of Cloud Accounts
|
|
Detect Persistence via Office Template Macro Injection or Registry Hijack
|
Detect Persistence via Office Template Macro Injection or Registry Hijack
|
|
Detect Obfuscated C2 via Network Traffic Analysis
|
Detect Obfuscated C2 via Network Traffic Analysis
|
|
Detection Strategy for Forged Web Cookies
|
Detection Strategy for Forged Web Cookies
|
|
User Execution – Malicious File via download/open → spawn chain (T1204.002)
|
User Execution – Malicious File via download/open → spawn chain (T1204.002)
|
|
Security Software Discovery Across Platforms
|
Security Software Discovery Across Platforms
|
|
Detection of Cloud Service Dashboard Usage via GUI-Based Cloud Access
|
Detection of Cloud Service Dashboard Usage via GUI-Based Cloud Access
|
|
Detection of Query Public AI Services
|
Detection of Query Public AI Services
|
|
Detection Strategy for Masquerading via File Type Modification
|
Detection Strategy for Masquerading via File Type Modification
|
|
Enumeration of Global Address Lists via Email Account Discovery
|
Enumeration of Global Address Lists via Email Account Discovery
|
|
Detection Strategy for Extended Attributes Abuse
|
Detection Strategy for Extended Attributes Abuse
|
|
Detect One-Way Web Service Command Channels
|
Detect One-Way Web Service Command Channels
|
|
Behavioral Detection of Obfuscated Files or Information
|
Behavioral Detection of Obfuscated Files or Information
|
|
Detection Strategy for Stored Data Manipulation across OS Platforms.
|
Detection Strategy for Stored Data Manipulation across OS Platforms.
|
|
Detection Strategy for Stripped Payloads Across Platforms
|
Detection Strategy for Stripped Payloads Across Platforms
|
|
Detection Strategy for Encrypted Channel via Asymmetric Cryptography across OS Platforms
|
Detection Strategy for Encrypted Channel via Asymmetric Cryptography across OS Platforms
|
|
Detect Persistence via Outlook Home Page Exploitation
|
Detect Persistence via Outlook Home Page Exploitation
|
|
Detection strategy for Group Policy Discovery on Windows
|
Detection strategy for Group Policy Discovery on Windows
|
|
Detection of Spearphishing Attachment
|
Detection of Spearphishing Attachment
|
|
Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets
|
Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets
|
|
Detection Strategy for Financial Theft
|
Detection Strategy for Financial Theft
|
|
Detection Strategy for Cloud Service Hijacking via SaaS Abuse
|
Detection Strategy for Cloud Service Hijacking via SaaS Abuse
|
|
Behavior-chain detection for T1135 Network Share Discovery across Windows, Linux, and macOS
|
Behavior-chain detection for T1135 Network Share Discovery across Windows, Linux, and macOS
|
|
Detection of DNS/Passive DNS
|
Detection of DNS/Passive DNS
|
|
Behavioral Detection of Malicious Cloud API Scripting
|
Behavioral Detection of Malicious Cloud API Scripting
|
|
Detect Archiving via Utility (T1560.001)
|
Detect Archiving via Utility (T1560.001)
|
|
Detect unauthorized or suspicious Hardware Additions (USB/Thunderbolt/Network)
|
Detect unauthorized or suspicious Hardware Additions (USB/Thunderbolt/Network)
|
|
Detection Strategy for Impair Defenses Across Platforms
|
Detection Strategy for Impair Defenses Across Platforms
|
|
Detection Strategy for T1542.001 Pre-OS Boot: System Firmware
|
Detection Strategy for T1542.001 Pre-OS Boot: System Firmware
|
|
Detection of Local Data Staging Prior to Exfiltration
|
Detection of Local Data Staging Prior to Exfiltration
|
|
Behavior-chain detection for T1133 External Remote Services across Windows, Linux, macOS, Containers
|
Behavior-chain detection for T1133 External Remote Services across Windows, Linux, macOS, Containers
|
|
Multi-Platform Detection Strategy for T1678 - Delay Execution
|
Multi-Platform Detection Strategy for T1678 - Delay Execution
|
|
Detection Strategy for Container Administration Command Abuse
|
Detection Strategy for Container Administration Command Abuse
|
|
Behavioral Detection of DLL Injection via Windows API
|
Behavioral Detection of DLL Injection via Windows API
|
|
Behavior-chain, platform-aware detection strategy for T1125 Video Capture
|
Behavior-chain, platform-aware detection strategy for T1125 Video Capture
|
|
Detection of Adversary Abuse of Software Deployment Tools
|
Detection of Adversary Abuse of Software Deployment Tools
|
|
Detection of Malicious or Unauthorized Software Extensions
|
Detection of Malicious or Unauthorized Software Extensions
|
|
Behavior-chain detection for T1134.004 Access Token Manipulation: Parent PID Spoofing (Windows)
|
Behavior-chain detection for T1134.004 Access Token Manipulation: Parent PID Spoofing (Windows)
|
|
Detection Strategy for Spearphishing Voice across OS platforms
|
Detection Strategy for Spearphishing Voice across OS platforms
|
|
Detection of Adversary Use of Unused or Unsupported Cloud Regions (IaaS)
|
Detection of Adversary Use of Unused or Unsupported Cloud Regions (IaaS)
|
|
Behavior-Chain Detection for Remote Access Tools (Tool-Agnostic)
|
Behavior-Chain Detection for Remote Access Tools (Tool-Agnostic)
|
|
Behavior-chain detection strategy for T1127.002 Trusted Developer Utilities Proxy Execution: ClickOnce (Windows)
|
Behavior-chain detection strategy for T1127.002 Trusted Developer Utilities Proxy Execution: ClickOnce (Windows)
|
|
Supply-chain tamper in dependencies/dev-tools (manager→write/install→first-run→egress)
|
Supply-chain tamper in dependencies/dev-tools (manager→write/install→first-run→egress)
|
|
Detection Strategy for Hijack Execution Flow: Dylib Hijacking
|
Detection Strategy for Hijack Execution Flow: Dylib Hijacking
|
|
Detect MFA Modification or Disabling Across Platforms
|
Detect MFA Modification or Disabling Across Platforms
|
|
Detection Strategy for Masquerading via Breaking Process Trees
|
Detection Strategy for Masquerading via Breaking Process Trees
|
|
Detection Strategy for Spearphishing Links
|
Detection Strategy for Spearphishing Links
|
|
Behavioral Detection Strategy for Exfiltration Over Alternative Protocol
|
Behavioral Detection Strategy for Exfiltration Over Alternative Protocol
|
|
Detection of CDNs
|
Detection of CDNs
|
|
Detect Archiving via Custom Method (T1560.003)
|
Detect Archiving via Custom Method (T1560.003)
|
|
Post-Credential Dump Password Cracking Detection via Suspicious File Access and Hash Analysis Tools
|
Post-Credential Dump Password Cracking Detection via Suspicious File Access and Hash Analysis Tools
|
|
Behavioral Detection of Fallback or Alternate C2 Channels
|
Behavioral Detection of Fallback or Alternate C2 Channels
|
|
Detection of Direct Volume Access for File System Evasion
|
Detection of Direct Volume Access for File System Evasion
|
|
Exploitation of Remote Services – multi-platform lateral movement detection
|
Exploitation of Remote Services – multi-platform lateral movement detection
|
|
User Execution – Malicious Image (containers & IaaS) – pull/run → start → anomalous behavior (T1204.003)
|
User Execution – Malicious Image (containers & IaaS) – pull/run → start → anomalous behavior (T1204.003)
|
|
Detect Code Signing Policy Modification (Windows & macOS)
|
Detect Code Signing Policy Modification (Windows & macOS)
|
|
Detection Strategy for System Services Service Execution
|
Detection Strategy for System Services Service Execution
|
|
Detection Strategy for Rogue Domain Controller (DCShadow) Registration and Replication Abuse
|
Detection Strategy for Rogue Domain Controller (DCShadow) Registration and Replication Abuse
|
|
Detection Strategy for Disable or Modify Cloud Log
|
Detection Strategy for Disable or Modify Cloud Log
|
|
Detect Suspicious Access to securityd Memory for Credential Extraction
|
Detect Suspicious Access to securityd Memory for Credential Extraction
|
|
Detect Shell Configuration Modification for Persistence via Event-Triggered Execution
|
Detect Shell Configuration Modification for Persistence via Event-Triggered Execution
|
|
Detection Strategy for Event Triggered Execution via emond on macOS
|
Detection Strategy for Event Triggered Execution via emond on macOS
|
|
Detection Strategy for Network Boundary Bridging
|
Detection Strategy for Network Boundary Bridging
|
|
Multi-Platform Software Discovery Behavior Chain
|
Multi-Platform Software Discovery Behavior Chain
|
|
Detection Strategy for Masquerading via Account Name Similarity
|
Detection Strategy for Masquerading via Account Name Similarity
|
|
TCC Database Manipulation via Launchctl and Unprotected SIP
|
TCC Database Manipulation via Launchctl and Unprotected SIP
|
|
Detect Kerberoasting Attempts (T1558.003)
|
Detect Kerberoasting Attempts (T1558.003)
|
|
Peripheral Device Enumeration via System Utilities and API Calls
|
Peripheral Device Enumeration via System Utilities and API Calls
|
|
Detection Strategy for PowerShell Profile Persistence via profile.ps1 Modification
|
Detection Strategy for PowerShell Profile Persistence via profile.ps1 Modification
|
|
Detection of Web Services
|
Detection of Web Services
|
|
Detection Strategy for Network Device Configuration Dump via Config Repositories
|
Detection Strategy for Network Device Configuration Dump via Config Repositories
|
|
Indirect Command Execution – Windows utility abuse behavior chain
|
Indirect Command Execution – Windows utility abuse behavior chain
|
|
Detection Strategy for T1547.015 – Login Items on macOS
|
Detection Strategy for T1547.015 – Login Items on macOS
|
|
Detection Strategy for Compressed Payload Creation and Execution
|
Detection Strategy for Compressed Payload Creation and Execution
|
|
Detection of Direct VM Console Access via Cloud-Native Methods
|
Detection of Direct VM Console Access via Cloud-Native Methods
|
|
Detecting MMC (.msc) Proxy Execution and Malicious COM Activation
|
Detecting MMC (.msc) Proxy Execution and Malicious COM Activation
|
|
Behavior-chain, platform-aware detection strategy for T1127 Trusted Developer Utilities Proxy Execution (Windows)
|
Behavior-chain, platform-aware detection strategy for T1127 Trusted Developer Utilities Proxy Execution (Windows)
|
|
Detection Strategy for Input Injection
|
Detection Strategy for Input Injection
|
|
Detection of Identify Business Tempo
|
Detection of Identify Business Tempo
|
|
Detection Strategy for Modify Cloud Compute Infrastructure: Revert Cloud Instance
|
Detection Strategy for Modify Cloud Compute Infrastructure: Revert Cloud Instance
|
|
Email Forwarding Rule Abuse Detection Across Platforms
|
Email Forwarding Rule Abuse Detection Across Platforms
|
|
Detect Unauthorized Access to Cloud Secrets Management Stores
|
Detect Unauthorized Access to Cloud Secrets Management Stores
|
|
Detection of USB-Based Data Exfiltration
|
Detection of USB-Based Data Exfiltration
|
|
Behavioral Detection of Remote Cloud Logins via Valid Accounts
|
Behavioral Detection of Remote Cloud Logins via Valid Accounts
|
|
Detect Malicious Password Filter DLL Registration
|
Detect Malicious Password Filter DLL Registration
|
|
Detection Strategy for File/Path Exclusions
|
Detection Strategy for File/Path Exclusions
|
|
Detection Strategy for Wi-Fi Networks
|
Detection Strategy for Wi-Fi Networks
|
|
Cross-Platform Behavioral Detection of File Timestomping via Metadata Tampering
|
Cross-Platform Behavioral Detection of File Timestomping via Metadata Tampering
|
|
Detection of Scan Databases
|
Detection of Scan Databases
|
|
Detection of Upload Malware
|
Detection of Upload Malware
|
|
Detection of Suspicious Compiled HTML File Execution via hh.exe
|
Detection of Suspicious Compiled HTML File Execution via hh.exe
|
|
Detection of Network Security Appliances
|
Detection of Network Security Appliances
|
|
Detect unauthorized LSASS driver persistence via LSA plugin abuse (Windows)
|
Detect unauthorized LSASS driver persistence via LSA plugin abuse (Windows)
|
|
Invalid Code Signature Execution Detection via Metadata and Behavioral Context
|
Invalid Code Signature Execution Detection via Metadata and Behavioral Context
|
|
Detection Strategy for Cloud Administration Command
|
Detection Strategy for Cloud Administration Command
|
|
Detection Strategy for Modify Cloud Resource Hierarchy
|
Detection Strategy for Modify Cloud Resource Hierarchy
|
|
Enumeration of User or Account Information Across Platforms
|
Enumeration of User or Account Information Across Platforms
|
|
Behavioral Detection of Keylogging Activity Across Platforms
|
Behavioral Detection of Keylogging Activity Across Platforms
|
|
Detection for Spoofing Tool UI across OS Platforms
|
Detection for Spoofing Tool UI across OS Platforms
|
|
Detection Strategy for Device Driver Discovery
|
Detection Strategy for Device Driver Discovery
|
|
Detection Strategy for Data from Configuration Repository on Network Devices
|
Detection Strategy for Data from Configuration Repository on Network Devices
|
|
Detection Strategy for Protocol Tunneling accross OS platforms.
|
Detection Strategy for Protocol Tunneling accross OS platforms.
|
1.1 References
1.2 Identified Requirements
1.3 Related Regulations
2. Identified Requirements
Requirements
| Source |
Requirement |
3. Related Regulations
Regulations
| Source |
Regulation |
Linked Issues
- MITREATTACK -
© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. https://attack.mitre.org/
Terms of Use
The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use ATT&CK® for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
"© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation."
MITRE does not claim ATT&CK enumerates all possibilities for the types of actions and behaviors documented as part of its adversary model and framework of techniques. Using the information contained within ATT&CK to address or cover full categories of techniques will not guarantee full defensive coverage as there may be undisclosed techniques or variations on existing techniques not documented by ATT&CK.
ALL DOCUMENTS AND THE INFORMATION CONTAINED THEREIN ARE PROVIDED ON AN "AS IS" BASIS AND THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE MITRE CORPORATION, ITS BOARD OF TRUSTEES, OFFICERS, AGENTS, AND EMPLOYEES, DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION THEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.
See our FAQ for more information on how to use and represent the ATT&CK name.
|