Vendor: Splunk

October 24, 2023 · View on GitHub

Product: Splunk ES

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
47201122
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Evasionregistry-write
splunk-ses-kv-app-activity-sendmodaction
splunk-ses-kv-app-activity-searchname
T1564.001 - T1564.001
T1564.002 - T1564.002
  • 2 Rules
Lateral Movementnetwork-connection-successful
microsoft-windows-kv-network-traffic-success-networkconn-1
T1071 - Application Layer Protocol
T1090.003 - Proxy: Multi-hop Proxy
T1190 - Exploit Public Fasing Application
TA0010 - TA0010
TA0011 - TA0011
  • 39 Rules
  • 17 Models
Malwarenetwork-connection-successful
microsoft-windows-kv-network-traffic-success-networkconn-1

registry-write
splunk-ses-kv-app-activity-sendmodaction
splunk-ses-kv-app-activity-searchname
T1112 - Modify Registry
T1547.001 - T1547.001
T1574.010 - T1574.010
T1574.011 - T1574.011
TA0011 - TA0011
  • 9 Rules
  • 3 Models

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Exploit Public Fasing Application

Hijack Execution Flow

Boot or Logon Autostart Execution

Hijack Execution Flow

Boot or Logon Autostart Execution

Hide Artifacts

Modify Registry

Hijack Execution Flow

Proxy: Multi-hop Proxy

Application Layer Protocol

Proxy