Skip to content

Commit 7a76c48

Browse files
imays11github-actions[bot]
authored andcommitted
[Rule Tuning] Rule Tunings to add T1078 technique and subtechniques (#2530)
- add sub-techniques and techniques (cherry picked from commit 443478c)
1 parent bbe6a3f commit 7a76c48

3 files changed

+41
-7
lines changed

rules/ml/credential_access_ml_auth_spike_in_logon_events_from_a_source_ip.toml

Lines changed: 23 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
[metadata]
22
creation_date = "2021/06/10"
33
maturity = "production"
4-
updated_date = "2023/01/30"
4+
updated_date = "2023/02/07"
55
min_stack_comments = "New fields added: required_fields, related_integrations, setup"
66
min_stack_version = "8.3.0"
77

@@ -52,7 +52,7 @@ references = ["https://www.elastic.co/guide/en/security/current/prebuilt-ml-jobs
5252
risk_score = 21
5353
rule_id = "e26aed74-c816-40d3-a810-48d6fbd8b2fd"
5454
severity = "low"
55-
tags = ["Elastic", "Authentication", "Threat Detection", "ML", "Credential Access"]
55+
tags = ["Elastic", "Authentication", "Threat Detection", "ML", "Credential Access", "Defense Evasion"]
5656
type = "machine_learning"
5757

5858
[[rule.threat]]
@@ -66,4 +66,24 @@ reference = "https://attack.mitre.org/techniques/T1110/"
6666
[rule.threat.tactic]
6767
id = "TA0006"
6868
name = "Credential Access"
69-
reference = "https://attack.mitre.org/tactics/TA0006/"
69+
reference = "https://attack.mitre.org/tactics/TA0006/"
70+
[[rule.threat]]
71+
framework = "MITRE ATT&CK"
72+
[[rule.threat.technique]]
73+
id = "T1078"
74+
name = "Valid Accounts"
75+
reference = "https://attack.mitre.org/techniques/T1078/"
76+
[[rule.threat.technique.subtechnique]]
77+
id = "T1078.002"
78+
name = "Domain Accounts"
79+
reference = "https://attack.mitre.org/techniques/T1078/002/"
80+
[[rule.threat.technique.subtechnique]]
81+
id = "T1078.003"
82+
name = "Local Accounts"
83+
reference = "https://attack.mitre.org/techniques/T1078/003/"
84+
85+
[rule.threat.tactic]
86+
id = "TA0005"
87+
name = "Defense Evasion"
88+
reference = "https://attack.mitre.org/tactics/TA0005/"
89+

rules/ml/initial_access_ml_auth_rare_user_logon.toml

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
[metadata]
22
creation_date = "2021/06/10"
33
maturity = "production"
4-
updated_date = "2023/01/30"
4+
updated_date = "2023/02/07"
55
min_stack_comments = "New fields added: required_fields, related_integrations, setup"
66
min_stack_version = "8.3.0"
77

@@ -62,7 +62,14 @@ framework = "MITRE ATT&CK"
6262
id = "T1078"
6363
name = "Valid Accounts"
6464
reference = "https://attack.mitre.org/techniques/T1078/"
65-
65+
[[rule.threat.technique.subtechnique]]
66+
id = "T1078.002"
67+
name = "Domain Accounts"
68+
reference = "https://attack.mitre.org/techniques/T1078/002/"
69+
[[rule.threat.technique.subtechnique]]
70+
id = "T1078.003"
71+
name = "Local Accounts"
72+
reference = "https://attack.mitre.org/techniques/T1078/003/"
6673

6774
[rule.threat.tactic]
6875
id = "TA0001"

rules/ml/initial_access_ml_windows_anomalous_user_name.toml

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
[metadata]
22
creation_date = "2020/03/25"
33
maturity = "production"
4-
updated_date = "2022/08/24"
4+
updated_date = "2023/02/07"
55
min_stack_comments = "New fields added: required_fields, related_integrations, setup"
66
min_stack_version = "8.3.0"
77

@@ -50,7 +50,14 @@ framework = "MITRE ATT&CK"
5050
id = "T1078"
5151
name = "Valid Accounts"
5252
reference = "https://attack.mitre.org/techniques/T1078/"
53-
53+
[[rule.threat.technique.subtechnique]]
54+
id = "T1078.002"
55+
name = "Domain Accounts"
56+
reference = "https://attack.mitre.org/techniques/T1078/002/"
57+
[[rule.threat.technique.subtechnique]]
58+
id = "T1078.003"
59+
name = "Local Accounts"
60+
reference = "https://attack.mitre.org/techniques/T1078/003/"
5461

5562
[rule.threat.tactic]
5663
id = "TA0001"

0 commit comments

Comments
 (0)