Skip to content

Commit

Permalink
Deprecated IOC rules
Browse files Browse the repository at this point in the history
  • Loading branch information
melenevskyi committed Dec 14, 2023
1 parent dfb06cd commit e3d14a9
Show file tree
Hide file tree
Showing 7 changed files with 5 additions and 5 deletions.
1 change: 0 additions & 1 deletion packs/atlassian.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,6 @@ Description: Group of all Atlassian detections
PackDefinition:
IDs:
- Atlassian.User.LoggedInAsUser
- Confluence.0DayIPs
# Globals used in these detections
- panther_base_helpers
- panther_config
Expand Down
4 changes: 0 additions & 4 deletions packs/panther.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,10 +7,6 @@ PackDefinition:
- Panther.SAML.Modified
- Panther.Sensitive.Role
- Panther.User.Modified
- IOC.SunburstFQDNIOCs
- IOC.SunburstSHA256IOCs
- Confluence.0DayIPs
- IOC.Log4jExploit
# Data Model
- Standard.Panther.Audit
# Helpers
Expand Down
1 change: 1 addition & 0 deletions rules/panther_ioc_rules/atlassian_confluence_ip_iocs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ Tags:
- Cloudflare
- Nginx
- Juniper
- Deprecated
Severity: High
Description: >
Detects IP addresses observed exploiting the 0-Day CVE-2022-26134
Expand Down
1 change: 1 addition & 0 deletions rules/panther_ioc_rules/log4j_exploit_iocs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ Tags:
- Web
- Log4J
- Execution:Exploitation for Client Execution
- Deprecated
Reports:
MITRE ATT&CK:
- TA0002:T1203
Expand Down
1 change: 1 addition & 0 deletions rules/panther_ioc_rules/sunburst_fqdn_iocs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,7 @@ Tags:
- OneLogin
- Osquery
- Initial Access:Trusted Relationship
- Deprecated
Reports:
MITRE ATT&CK:
- TA0001:T1199
Expand Down
1 change: 1 addition & 0 deletions rules/panther_ioc_rules/sunburst_ip_iocs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@ Tags:
- SSH
- OneLogin
- Osquery
- Deprecated
Severity: High
Description: >
Monitors for communication to known Sunburst Backdoor IPs. These IOCs indicate a potential breach and have been associated with a sophisticated nation-state actor.
Expand Down
1 change: 1 addition & 0 deletions rules/panther_ioc_rules/sunburst_sha256_iocs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@ Tags:
- OneLogin
- Osquery
- Initial Access:Trusted Relationship
- Deprecated
Reports:
MITRE ATT&CK:
- TA0001:T1199
Expand Down

0 comments on commit e3d14a9

Please sign in to comment.