diff --git a/detections/endpoint/jscript_execution_using_cscript_app.yml b/detections/endpoint/jscript_execution_using_cscript_app.yml index 4082fc5412..198f9016e6 100644 --- a/detections/endpoint/jscript_execution_using_cscript_app.yml +++ b/detections/endpoint/jscript_execution_using_cscript_app.yml @@ -1,8 +1,8 @@ name: Jscript Execution Using Cscript App id: 002f1e24-146e-11ec-a470-acde48001122 -version: 14 +version: 15 creation_date: '2021-09-14' -modification_date: '2026-08-31' +modification_date: '2026-10-09' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -13,7 +13,6 @@ description: |- If confirmed malicious, this activity could allow attackers to execute arbitrary scripts, leading to code execution, data exfiltration, or further system compromise. data_source: - Sysmon EventID 1 - - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) as firstTime diff --git a/detections/endpoint/ping_sleep_batch_command.yml b/detections/endpoint/ping_sleep_batch_command.yml index b34b2835a4..2283e1a9af 100644 --- a/detections/endpoint/ping_sleep_batch_command.yml +++ b/detections/endpoint/ping_sleep_batch_command.yml @@ -1,8 +1,8 @@ name: Ping Sleep Batch Command id: ce058d6c-79f2-11ec-b476-acde48001122 -version: 17 +version: 18 creation_date: '2022-01-20' -modification_date: '2026-08-11' +modification_date: '2026-10-09' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -14,7 +14,6 @@ description: |- Because ping is commonly used for legitimate network troubleshooting, findings should be reviewed in the context of the complete command line, parent process, user, and commands executed before or after the delay. data_source: - Sysmon EventID 1 - - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) as firstTime diff --git a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml index 8fe0edf7a6..6b73129ed4 100644 --- a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml +++ b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml @@ -1,8 +1,8 @@ name: Possible Lateral Movement PowerShell Spawn id: cb909b3e-512b-11ec-aa31-3e22fbd008af -version: 17 +version: 18 creation_date: '2021-11-29' -modification_date: '2026-05-13' +modification_date: '2026-10-09' author: Mauricio Velazco, Michael Haag, Splunk status: production type: Anomaly @@ -13,7 +13,6 @@ description: | If confirmed malicious, this behavior could allow attackers to execute code remotely, escalate privileges, or persist within the environment. data_source: - Sysmon EventID 1 - - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) as firstTime diff --git a/detections/endpoint/svchost_lolbas_execution_process_spawn.yml b/detections/endpoint/svchost_lolbas_execution_process_spawn.yml index 2d1937a88b..d0ab2e9869 100644 --- a/detections/endpoint/svchost_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/svchost_lolbas_execution_process_spawn.yml @@ -1,8 +1,8 @@ name: Svchost LOLBAS Execution Process Spawn id: 09e5c72a-4c0d-11ec-aa29-3e22fbd008af -version: 15 +version: 16 creation_date: '2021-11-23' -modification_date: '2026-07-27' +modification_date: '2026-10-09' author: Mauricio Velazco, Splunk status: production type: TTP @@ -11,7 +11,6 @@ description: |- If confirmed malicious, this behavior could allow attackers to execute arbitrary commands, escalate privileges, or maintain persistence within the environment, posing a significant security risk. data_source: - Sysmon EventID 1 - - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) as firstTime diff --git a/detections/endpoint/vbscript_execution_using_wscript_app.yml b/detections/endpoint/vbscript_execution_using_wscript_app.yml index 7ae808c2c9..628db71437 100644 --- a/detections/endpoint/vbscript_execution_using_wscript_app.yml +++ b/detections/endpoint/vbscript_execution_using_wscript_app.yml @@ -1,15 +1,14 @@ name: Vbscript Execution Using Wscript App id: 35159940-228f-11ec-8a49-acde48001122 -version: 13 +version: 14 creation_date: '2021-09-14' -modification_date: '2026-05-13' +modification_date: '2026-10-09' author: Teoderick Contreras, Splunk status: production type: TTP description: The following analytic detects the execution of VBScript using the wscript.exe application. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and command-line telemetry. This activity is significant because wscript.exe is typically not used to execute VBScript, which is usually associated with cscript.exe. This deviation can indicate an attempt to evade traditional process monitoring and antivirus defenses. If confirmed malicious, this technique could allow attackers to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further lateral movement within the network. data_source: - Sysmon EventID 1 - - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE ( diff --git a/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml b/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml index 8ad38fc09d..f9e7d6f0af 100644 --- a/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml +++ b/detections/endpoint/windows_command_shell_dcrat_forkbomb_payload.yml @@ -1,15 +1,14 @@ name: Windows Command Shell DCRat ForkBomb Payload id: 2bb1a362-7aa8-444a-92ed-1987e8da83e1 -version: 14 +version: 15 creation_date: '2022-07-28' -modification_date: '2026-05-13' +modification_date: '2026-10-09' author: Teoderick Contreras, Splunk status: production type: TTP description: The following analytic detects the execution of a DCRat "forkbomb" payload, which spawns multiple cmd.exe processes that launch notepad.exe instances in quick succession. This detection leverages Endpoint Detection and Response (EDR) data, focusing on the rapid creation of cmd.exe and notepad.exe processes within a 30-second window. This activity is significant as it indicates a potential DCRat infection, a known Remote Access Trojan (RAT) with destructive capabilities. If confirmed malicious, this behavior could lead to system instability, resource exhaustion, and potential disruption of services. data_source: - Sysmon EventID 1 - - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` values(Processes.user) as user values(Processes.action) as action values(Processes.parent_process_exec) as parent_process_exec values(Processes.parent_process_guid) as parent_process_guid values(Processes.parent_process_id) as parent_process_id values(Processes.parent_process_path) as parent_process_path values(Processes.process) as process values(Processes.process_exec) as process_exec values(Processes.process_guid) as process_guid values(Processes.process_hash) as process_hash values(Processes.process_id) as process_id values(Processes.process_integrity_level) as process_integrity_level values(Processes.process_path) as process_path values(Processes.user_id) as user_id values(Processes.vendor_product) as vendor_product dc(Processes.parent_process_id) as parent_process_id_count dc(Processes.process_id) as process_id_count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE Processes.parent_process_name= "cmd.exe" (Processes.process_name = "notepad.exe" diff --git a/detections/endpoint/windows_for_loop_usage_within_cmd_exe_to_execute_commands.yml b/detections/endpoint/windows_for_loop_usage_within_cmd_exe_to_execute_commands.yml index a4e9eadf4a..f3dc13d6c8 100644 --- a/detections/endpoint/windows_for_loop_usage_within_cmd_exe_to_execute_commands.yml +++ b/detections/endpoint/windows_for_loop_usage_within_cmd_exe_to_execute_commands.yml @@ -1,8 +1,8 @@ name: Windows For Loop Usage Within Cmd.exe To Execute Commands id: a4ce9079-fc8f-4749-982a-13197c8cf977 -version: 1 +version: 2 creation_date: '2026-09-16' -modification_date: '2026-09-16' +modification_date: '2026-10-09' author: Onur Mustafa Erdogan, Splunk status: production type: Anomaly @@ -11,7 +11,6 @@ description: |- Adversaries and malicious scripts leverage this pattern to programmatically process command output for discovery, data extraction, or execution purposes while evading simpler detection logic. data_source: - Sysmon EventID 1 - - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) as firstTime diff --git a/detections/endpoint/windows_indirect_command_execution_via_forfiles.yml b/detections/endpoint/windows_indirect_command_execution_via_forfiles.yml index 2a70eea3f6..de6a411fc9 100644 --- a/detections/endpoint/windows_indirect_command_execution_via_forfiles.yml +++ b/detections/endpoint/windows_indirect_command_execution_via_forfiles.yml @@ -1,15 +1,14 @@ name: Windows Indirect Command Execution Via forfiles id: 1fdf31c9-ff4d-4c48-b799-0e8666e08787 -version: 11 +version: 12 creation_date: '2022-03-04' -modification_date: '2026-05-13' +modification_date: '2026-10-09' author: Eric McGinnis, Splunk status: production type: TTP description: The following analytic detects the execution of programs initiated by forfiles.exe. This command is typically used to run commands on multiple files, often within batch scripts. The detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process creation events where forfiles.exe is the parent process. This activity is significant because forfiles.exe can be exploited to bypass command line execution protections, making it a potential vector for malicious activity. If confirmed malicious, this could allow attackers to execute arbitrary commands, potentially leading to unauthorized access or further system compromise. data_source: - Sysmon EventID 1 - - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE Processes.parent_process="*forfiles* /c *" diff --git a/detections/endpoint/windows_indirect_command_execution_via_pcalua.yml b/detections/endpoint/windows_indirect_command_execution_via_pcalua.yml index f5060aafe3..296099e1af 100644 --- a/detections/endpoint/windows_indirect_command_execution_via_pcalua.yml +++ b/detections/endpoint/windows_indirect_command_execution_via_pcalua.yml @@ -1,15 +1,14 @@ name: Windows Indirect Command Execution Via pcalua id: 3428ac18-a410-4823-816c-ce697d26f7a8 -version: 11 +version: 12 creation_date: '2022-03-04' -modification_date: '2026-05-13' +modification_date: '2026-10-09' author: Eric McGinnis, Splunk status: production type: TTP description: The following analytic detects programs initiated by pcalua.exe, the Microsoft Windows Program Compatibility Assistant. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and parent process information. While pcalua.exe can start legitimate programs, it is significant because attackers may use it to bypass command line execution protections. If confirmed malicious, this activity could allow attackers to execute arbitrary commands, potentially leading to unauthorized actions, privilege escalation, or persistence within the environment. data_source: - Sysmon EventID 1 - - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE Processes.parent_process="*pcalua* -a*" diff --git a/detections/endpoint/windows_proxy_execution_of__net_utilities_via_scripts.yml b/detections/endpoint/windows_proxy_execution_of__net_utilities_via_scripts.yml index 96aadbd743..c8fcafe4e2 100644 --- a/detections/endpoint/windows_proxy_execution_of__net_utilities_via_scripts.yml +++ b/detections/endpoint/windows_proxy_execution_of__net_utilities_via_scripts.yml @@ -1,8 +1,8 @@ name: Windows Proxy Execution of .NET Utilities via Scripts id: eb59cf01-1874-4d16-b7e4-54a6eb9b3118 -version: 2 +version: 3 creation_date: '2026-04-29' -modification_date: '2026-05-13' +modification_date: '2026-10-09' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -11,8 +11,6 @@ description: |- That pattern is consistent with adversaries using trusted .NET binaries as a proxy to run code while hiding execution behind script parents in low-trust folders, behavior associated with techniques such as signed binary proxy execution. data_source: - Sysmon EventID 1 - - Windows Event Log Security 4688 - - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) as firstTime diff --git a/detections/endpoint/windows_scheduled_task_service_spawned_shell.yml b/detections/endpoint/windows_scheduled_task_service_spawned_shell.yml index 3694b15b21..2da9f7d103 100644 --- a/detections/endpoint/windows_scheduled_task_service_spawned_shell.yml +++ b/detections/endpoint/windows_scheduled_task_service_spawned_shell.yml @@ -1,8 +1,8 @@ name: Windows Scheduled Task Service Spawned Shell id: d8120352-3b62-4e3c-8cb6-7b47584dd5e8 -version: 12 +version: 13 creation_date: '2023-07-11' -modification_date: '2026-05-13' +modification_date: '2026-10-09' author: Steven Dick status: production type: TTP @@ -13,7 +13,6 @@ description: | If confirmed malicious, this could allow attackers to execute arbitrary code, maintain persistence, or escalate privileges within the environment. data_source: - Sysmon EventID 1 - - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) as firstTime diff --git a/detections/endpoint/windows_ssh_proxy_command.yml b/detections/endpoint/windows_ssh_proxy_command.yml index d8d2fc28bf..02812d7a62 100644 --- a/detections/endpoint/windows_ssh_proxy_command.yml +++ b/detections/endpoint/windows_ssh_proxy_command.yml @@ -1,8 +1,8 @@ name: Windows SSH Proxy Command id: ac520039-21f1-4567-b528-5b7133dba76f -version: 6 +version: 7 creation_date: '2025-03-24' -modification_date: '2026-05-13' +modification_date: '2026-10-09' author: Michael Haag, AJ King, Nasreddine Bencherchali, Splunk, Jesse Hunter, Splunk Community Contributor status: production type: Anomaly @@ -12,7 +12,6 @@ description: | This technique can be used by attackers to execute arbitrary commands through SSH proxy configurations, potentially enabling command & control activities or remote code execution. The detection focuses on commonly abused Windows scripting engines and web requests that may indicate malicious activity when spawned through SSH proxy commands. data_source: - Sysmon EventID 1 - - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) as firstTime diff --git a/detections/endpoint/windows_suspicious_react_or_next_js_child_process.yml b/detections/endpoint/windows_suspicious_react_or_next_js_child_process.yml index 7719a175db..667888e72b 100644 --- a/detections/endpoint/windows_suspicious_react_or_next_js_child_process.yml +++ b/detections/endpoint/windows_suspicious_react_or_next_js_child_process.yml @@ -1,8 +1,8 @@ name: Windows Suspicious React or Next.js Child Process id: baa80bc8-7c9c-4395-b458-b69feb92830a -version: 5 +version: 6 creation_date: '2025-12-08' -modification_date: '2026-05-13' +modification_date: '2026-10-09' author: Nasreddine Bencherchali, Splunk status: production type: TTP @@ -13,7 +13,6 @@ description: | Such activity might be a strong indicator of exploitation of the aforementioned vulnerability. data_source: - Sysmon EventID 1 - - CrowdStrike ProcessRollup2 search: | | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes diff --git a/detections/endpoint/windows_time_based_evasion.yml b/detections/endpoint/windows_time_based_evasion.yml index 8356037e58..f8cfd97a98 100644 --- a/detections/endpoint/windows_time_based_evasion.yml +++ b/detections/endpoint/windows_time_based_evasion.yml @@ -1,8 +1,8 @@ name: Windows Time Based Evasion id: 34502357-deb1-499a-8261-ffe144abf561 -version: 14 +version: 15 creation_date: '2023-09-19' -modification_date: '2026-05-13' +modification_date: '2026-10-09' author: Teoderick Contreras, Splunk status: production type: TTP @@ -13,7 +13,6 @@ description: |- If confirmed malicious, this activity could indicate an active infection attempting to evade detection, potentially leading to further compromise and persistence within the environment. data_source: - Sysmon EventID 1 - - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) as firstTime