Merge PR #5477 from @phantinuss - chore: update MITRE tag t1219 to t1219.002
chore: update MITRE tag t1219 to t1219.002
This commit is contained in:
+1
-1
@@ -10,7 +10,7 @@ author: Dusty Miller
|
||||
date: 2023-02-23
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
- detection.emerging-threats
|
||||
logsource:
|
||||
product: windows
|
||||
|
||||
+1
-1
@@ -10,7 +10,7 @@ author: Luca Di Bartolomeo
|
||||
date: 2024-06-22
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
- detection.emerging-threats
|
||||
logsource:
|
||||
category: image_load
|
||||
|
||||
+1
-1
@@ -25,7 +25,7 @@ author: '@kostastsale'
|
||||
date: 2023-04-13
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
- detection.threat-hunting
|
||||
logsource:
|
||||
category: process_creation
|
||||
|
||||
@@ -16,7 +16,7 @@ tags:
|
||||
- attack.execution
|
||||
- attack.t1203
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: antivirus
|
||||
detection:
|
||||
|
||||
@@ -11,7 +11,7 @@ date: 2023-08-03
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.persistence
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: linux
|
||||
|
||||
+1
-1
@@ -9,7 +9,7 @@ date: 2021-09-01
|
||||
modified: 2022-12-25
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
service: application
|
||||
product: windows
|
||||
|
||||
@@ -9,7 +9,7 @@ date: 2020-05-22
|
||||
modified: 2021-11-27
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
product: windows
|
||||
service: ntlm
|
||||
|
||||
+1
-1
@@ -8,7 +8,7 @@ author: Nasreddine Bencherchali (Nextron Systems)
|
||||
date: 2022-11-28
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
product: windows
|
||||
service: system
|
||||
|
||||
+1
-1
@@ -8,7 +8,7 @@ author: Nasreddine Bencherchali (Nextron Systems)
|
||||
date: 2022-11-28
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
product: windows
|
||||
service: system
|
||||
|
||||
@@ -15,7 +15,7 @@ author: Nasreddine Bencherchali (Nextron Systems)
|
||||
date: 2024-06-24
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
product: windows
|
||||
category: dns_query
|
||||
|
||||
+1
-1
@@ -26,7 +26,7 @@ date: 2022-07-11
|
||||
modified: 2024-12-17
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
product: windows
|
||||
category: dns_query
|
||||
|
||||
@@ -9,7 +9,7 @@ date: 2022-01-30
|
||||
modified: 2023-09-18
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
product: windows
|
||||
category: dns_query
|
||||
|
||||
@@ -12,7 +12,7 @@ date: 2022-02-11
|
||||
modified: 2024-07-20
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: file_event
|
||||
product: windows
|
||||
|
||||
@@ -13,7 +13,7 @@ date: 2022-09-28
|
||||
modified: 2025-02-24
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
product: windows
|
||||
category: file_event
|
||||
|
||||
@@ -11,7 +11,7 @@ author: frack113
|
||||
date: 2022-02-13
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: file_event
|
||||
product: windows
|
||||
|
||||
@@ -11,7 +11,7 @@ date: 2022-10-24
|
||||
modified: 2024-06-27
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
product: windows
|
||||
category: file_event
|
||||
|
||||
@@ -8,7 +8,7 @@ author: Nasreddine Bencherchali (Nextron Systems)
|
||||
date: 2024-06-27
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
product: windows
|
||||
category: file_event
|
||||
|
||||
@@ -8,7 +8,7 @@ author: frack113
|
||||
date: 2022-01-28
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
product: windows
|
||||
category: file_event
|
||||
|
||||
+1
-1
@@ -11,7 +11,7 @@ author: frack113
|
||||
date: 2022-02-13
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: file_event
|
||||
product: windows
|
||||
|
||||
@@ -8,7 +8,7 @@ author: Florian Roth (Nextron Systems)
|
||||
date: 2022-01-30
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
product: windows
|
||||
category: file_event
|
||||
|
||||
@@ -9,7 +9,7 @@ date: 2019-02-21
|
||||
modified: 2021-11-27
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
product: windows
|
||||
category: file_event
|
||||
|
||||
+1
-1
@@ -12,7 +12,7 @@ modified: 2025-02-24
|
||||
tags:
|
||||
- attack.persistence
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: network_connection
|
||||
product: windows
|
||||
|
||||
@@ -10,7 +10,7 @@ date: 2023-04-18
|
||||
modified: 2023-04-30
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
+1
-1
@@ -9,7 +9,7 @@ author: Nasreddine Bencherchali (Nextron Systems)
|
||||
date: 2023-04-18
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
@@ -12,7 +12,7 @@ author: Muhammad Faisal (@faisalusuf)
|
||||
date: 2024-12-19
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
@@ -16,7 +16,7 @@ date: 2022-02-11
|
||||
modified: 2025-02-24
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
+1
-1
@@ -9,7 +9,7 @@ date: 2022-09-28
|
||||
modified: 2023-03-05
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
+1
-1
@@ -10,7 +10,7 @@ date: 2021-08-06
|
||||
modified: 2023-03-05
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
+1
-1
@@ -16,7 +16,7 @@ date: 2022-05-20
|
||||
modified: 2025-02-24
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
@@ -12,7 +12,7 @@ date: 2022-02-13
|
||||
modified: 2023-03-05
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
@@ -12,7 +12,7 @@ date: 2022-02-11
|
||||
modified: 2023-03-05
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
+1
-1
@@ -12,7 +12,7 @@ author: '@Kostastsale'
|
||||
date: 2024-09-22
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
product: windows
|
||||
category: process_creation
|
||||
|
||||
@@ -12,7 +12,7 @@ date: 2022-09-25
|
||||
modified: 2023-03-06
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
+1
-1
@@ -12,7 +12,7 @@ date: 2022-02-13
|
||||
modified: 2023-03-05
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
+1
-1
@@ -16,7 +16,7 @@ date: 2022-02-25
|
||||
modified: 2024-02-28
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
product: windows
|
||||
category: process_creation
|
||||
|
||||
+1
-1
@@ -11,7 +11,7 @@ author: Nasreddine Bencherchali (Nextron Systems)
|
||||
date: 2024-02-23
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
+1
-1
@@ -12,7 +12,7 @@ date: 2022-09-25
|
||||
modified: 2024-03-14
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
@@ -11,7 +11,7 @@ date: 2023-08-02
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.persistence
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
@@ -11,7 +11,7 @@ date: 2018-03-17
|
||||
modified: 2022-05-27
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
@@ -8,7 +8,7 @@ author: frack113
|
||||
date: 2022-10-02
|
||||
tags:
|
||||
- attack.command-and-control
|
||||
- attack.t1219
|
||||
- attack.t1219.002
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
|
||||
Reference in New Issue
Block a user