Skip to content

[Rule Tuning] Rule Tunings to add T1078 technique and subtechniques #2530

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conversation

imays11
Copy link
Contributor

@imays11 imays11 commented Feb 8, 2023

Issues

#2529

Link to rule

Rare User Logon - add sub-techniques

Unusual Windows Username - add sub-techniques

Spike in Successful Logon Events from a Source IP - add technique and sub-techniques

Summary

The Mitre Eval Score Analysis - 2022 [ Refer ] identified the following:

  • Valid Accounts (T1078)
  • Valid Accounts: Domain Accounts (T1078.002)
  • Valid Accounts: Local Accounts (T1078.003)

...to be added to the above rules to reflect the techniques above

@imays11 imays11 added the Rule: Tuning tweaking or tuning an existing rule label Feb 8, 2023
@imays11 imays11 self-assigned this Feb 8, 2023
@imays11 imays11 linked an issue Feb 8, 2023 that may be closed by this pull request
@botelastic botelastic bot added the ML machine learning related rule label Feb 8, 2023
@imays11 imays11 merged commit 443478c into main Feb 8, 2023
@imays11 imays11 deleted the 2529-rule-tuning-rule-tunings-to-add-t1078-technique-and-subtechniques branch February 8, 2023 16:18
protectionsmachine pushed a commit that referenced this pull request Feb 8, 2023
…2530)

- add sub-techniques and techniques

(cherry picked from commit 443478c)
protectionsmachine pushed a commit that referenced this pull request Feb 8, 2023
…2530)

- add sub-techniques and techniques

(cherry picked from commit 443478c)
protectionsmachine pushed a commit that referenced this pull request Feb 8, 2023
…2530)

- add sub-techniques and techniques

(cherry picked from commit 443478c)
protectionsmachine pushed a commit that referenced this pull request Feb 8, 2023
…2530)

- add sub-techniques and techniques

(cherry picked from commit 443478c)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport: auto ML machine learning related rule Rule: Tuning tweaking or tuning an existing rule
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[Rule Tuning] Rule Tunings to add T1078 technique and subtechniques
3 participants