From d6cf36f2bfbce435f8439ddfb739534b6bea9542 Mon Sep 17 00:00:00 2001 From: Varshith Puli Date: Thu, 24 Sep 2026 15:10:06 +0000 Subject: [PATCH] Fix stale TA field names in XML WinEventLog detections The Splunk Add-on for Microsoft Windows extracts snake_case field names (Logon_Type, Target_User_Name) from XmlWinEventLog events via its REPORT extractions; the PascalCase names (LogonType, TargetUserName) are stale. 35 detections still referenced the stale names, so they silently stopped matching on current TA versions. Rename LogonType -> Logon_Type and TargetUserName -> Target_User_Name in search and drilldown SPL across 35 detections, following the convention already used by migrated detections (e.g. windows_rdp_login_session_was_established, the 4648 Target_User_Name detections). EventCode 4781's OldTargetUserName / NewTargetUserName have no snake_case variant in the TA and are left untouched. Prose documentation is unchanged to keep the diff reviewable. Version bumped and modification_date updated per repo convention. Fixes #2869. Signed-off-by: Varshith Puli --- .../detect_new_local_admin_account.yml | 6 ++--- ...on_flag_disabled_in_useraccountcontrol.yml | 6 ++--- .../endpoint/kerberos_user_enumeration.yml | 8 +++---- ...tpotam_suspicious_kerberos_tgt_request.yml | 8 +++---- ...icious_kerberos_service_ticket_request.yml | 8 +++---- ...picious_ticket_granting_ticket_request.yml | 10 ++++----- ...ss_token_manipulation_sedebugprivilege.yml | 6 ++--- ...s_ad_suspicious_attribute_modification.yml | 6 ++--- ...r_account_changed_to_domain_controller.yml | 6 ++--- ...ter_account_requesting_kerberos_ticket.yml | 8 +++---- .../windows_dnsadmins_new_member_added.yml | 8 +++---- ...s_domain_admin_impersonation_indicator.yml | 22 +++++++++---------- ...x_admins_group_creation_security_event.yml | 8 +++---- ...dentify_powershell_web_access_iis_pool.yml | 6 ++--- ...indows_kerberos_local_successful_logon.yml | 6 ++--- ..._of_computer_service_tickets_requested.yml | 12 +++++----- ...ocal_administrator_credential_stuffing.yml | 8 +++---- ...rs_failed_to_authenticate_wth_kerberos.yml | 8 +++---- ...rs_fail_to_authenticate_using_kerberos.yml | 8 +++---- ...sers_failed_to_authenticate_using_ntlm.yml | 8 +++---- ...d_to_authenticate_from_host_using_ntlm.yml | 8 +++---- ...rs_failed_to_authenticate_from_process.yml | 6 ++--- ..._failed_to_authenticate_using_kerberos.yml | 8 +++---- ...otely_failed_to_authenticate_from_host.yml | 6 ++--- .../windows_privileged_group_modification.yml | 8 +++---- ...rapid_authentication_on_multiple_hosts.yml | 8 +++---- ...ion_certificates___esc1_authentication.yml | 6 ++--- ...s_suspicious_burst_of_password_changes.yml | 10 ++++----- ...abled_users_failed_auth_using_kerberos.yml | 8 +++---- ...alid_users_fail_to_auth_using_kerberos.yml | 8 +++---- ...nvalid_users_failed_to_auth_using_ntlm.yml | 8 +++---- ...of_users_failed_to_auth_using_kerberos.yml | 8 +++---- ...rs_failed_to_authenticate_from_process.yml | 6 ++--- ...sers_failed_to_authenticate_using_ntlm.yml | 8 +++---- ...sers_remotely_failed_to_auth_from_host.yml | 6 ++--- 35 files changed, 139 insertions(+), 139 deletions(-) diff --git a/detections/endpoint/detect_new_local_admin_account.yml b/detections/endpoint/detect_new_local_admin_account.yml index 10c569305e..bb311e417a 100644 --- a/detections/endpoint/detect_new_local_admin_account.yml +++ b/detections/endpoint/detect_new_local_admin_account.yml @@ -1,8 +1,8 @@ name: Detect New Local Admin account id: b25f6f62-0712-43c1-b203-083231ffd97d -version: 13 +version: 14 creation_date: '2020-04-29' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: David Dorsey, Splunk status: production type: TTP @@ -21,7 +21,7 @@ search: | ( Group_Name=Administrators OR - TargetUserName=Administrators + Target_User_Name=Administrators ) ) ) diff --git a/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml b/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml index 39925f0c7a..10bbcffd3c 100644 --- a/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml +++ b/detections/endpoint/kerberos_pre_authentication_flag_disabled_in_useraccountcontrol.yml @@ -1,8 +1,8 @@ name: Kerberos Pre-Authentication Flag Disabled in UserAccountControl id: 0cb847ee-9423-11ec-b2df-acde48001122 -version: 12 +version: 13 creation_date: '2022-02-23' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: TTP @@ -11,7 +11,7 @@ data_source: - Windows Event Log Security 4738 search: > `wineventlog_security` EventCode=4738 UserAccountControl="*%%2096*" - | rename TargetUserName as user, SubjectUserName as actor | stats count earliest(_time) as firstTime latest(_time) as lastTime by actor, user, dest + | rename Target_User_Name as user, SubjectUserName as actor | stats count earliest(_time) as firstTime latest(_time) as lastTime by actor, user, dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `kerberos_pre_authentication_flag_disabled_in_useraccountcontrol_filter` diff --git a/detections/endpoint/kerberos_user_enumeration.yml b/detections/endpoint/kerberos_user_enumeration.yml index 2b48cbb543..5abc0598d2 100644 --- a/detections/endpoint/kerberos_user_enumeration.yml +++ b/detections/endpoint/kerberos_user_enumeration.yml @@ -1,8 +1,8 @@ name: Kerberos User Enumeration id: d82d4af4-a0bd-11ec-9445-3e22fbd008af -version: 13 +version: 14 creation_date: '2022-03-11' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: Anomaly @@ -10,9 +10,9 @@ description: The following analytic detects an unusual number of Kerberos Ticket data_source: - Windows Event Log Security 4768 search: |- - `wineventlog_security` EventCode=4768 Status=0x6 TargetUserName!="*$" + `wineventlog_security` EventCode=4768 Status=0x6 Target_User_Name!="*$" | bucket span=2m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts values(dest) as dest + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as tried_accounts values(dest) as dest BY _time, src_ip | eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std BY src_ip diff --git a/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml b/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml index 4fefb3ea75..f83a85c3da 100644 --- a/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml +++ b/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml @@ -1,8 +1,8 @@ name: PetitPotam Suspicious Kerberos TGT Request id: e3ef244e-0a67-11ec-abf2-acde48001122 -version: 11 +version: 12 creation_date: '2021-09-01' -modification_date: '2026-07-04' +modification_date: '2026-09-24' author: Michael Haag, Mauricio Velazco, Splunk status: production type: TTP @@ -13,12 +13,12 @@ search: |- `wineventlog_security` EventCode=4768 src!="::1" - TargetUserName=*$ + Target_User_Name=*$ CertThumbprint!="" PreAuthType=2 | stats count min(_time) as firstTime max(_time) as lastTime - BY dest TargetUserName PreAuthType CertThumbprint src action + BY dest Target_User_Name PreAuthType CertThumbprint src action | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `petitpotam_suspicious_kerberos_tgt_request_filter` diff --git a/detections/endpoint/suspicious_kerberos_service_ticket_request.yml b/detections/endpoint/suspicious_kerberos_service_ticket_request.yml index 36fd9085f7..b710b5a01f 100644 --- a/detections/endpoint/suspicious_kerberos_service_ticket_request.yml +++ b/detections/endpoint/suspicious_kerberos_service_ticket_request.yml @@ -1,8 +1,8 @@ name: Suspicious Kerberos Service Ticket Request id: 8b1297bc-6204-11ec-b7c4-acde48001122 -version: 12 +version: 13 creation_date: '2021-12-20' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: TTP @@ -11,10 +11,10 @@ data_source: - Windows Event Log Security 4769 search: |- `wineventlog_security` EventCode=4769 - | eval isSuspicious = if(lower(ServiceName) = lower(mvindex(split(TargetUserName,"@"),0)),1,0) + | eval isSuspicious = if(lower(ServiceName) = lower(mvindex(split(Target_User_Name,"@"),0)),1,0) | where isSuspicious = 1 | rename Computer as dest - | rename TargetUserName as user + | rename Target_User_Name as user | table _time, dest, src_ip, user, ServiceName, Error_Code, isSuspicious | `suspicious_kerberos_service_ticket_request_filter` how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. diff --git a/detections/endpoint/suspicious_ticket_granting_ticket_request.yml b/detections/endpoint/suspicious_ticket_granting_ticket_request.yml index db6a184f7a..770d1f82e8 100644 --- a/detections/endpoint/suspicious_ticket_granting_ticket_request.yml +++ b/detections/endpoint/suspicious_ticket_granting_ticket_request.yml @@ -1,8 +1,8 @@ name: Suspicious Ticket Granting Ticket Request id: d77d349e-6269-11ec-9cfe-acde48001122 -version: 10 +version: 11 creation_date: '2021-12-21' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -11,12 +11,12 @@ data_source: - Windows Event Log Security 4768 - Windows Event Log Security 4781 search: |- - `wineventlog_security` (EventCode=4781 OldTargetUserName="*$" NewTargetUserName!="*$") OR (EventCode=4768 TargetUserName!="*$") - | eval RenamedComputerAccount = coalesce(NewTargetUserName, TargetUserName) + `wineventlog_security` (EventCode=4781 OldTargetUserName="*$" NewTargetUserName!="*$") OR (EventCode=4768 Target_User_Name!="*$") + | eval RenamedComputerAccount = coalesce(NewTargetUserName, Target_User_Name) | transaction RenamedComputerAccount startswith=(EventCode=4781) endswith=(EventCode=4768) | eval short_lived=case((duration<2),"TRUE") | search short_lived = TRUE - | table _time, Computer, EventCode, TargetUserName, RenamedComputerAccount, short_lived + | table _time, Computer, EventCode, Target_User_Name, RenamedComputerAccount, short_lived | rename Computer as dest | `suspicious_ticket_granting_ticket_request_filter` how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. diff --git a/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml b/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml index cee3e655c7..6521807efa 100644 --- a/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml +++ b/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml @@ -1,15 +1,15 @@ name: Windows Access Token Manipulation SeDebugPrivilege id: 6ece9ed0-5f92-4315-889d-48560472b188 -version: 24 +version: 25 creation_date: '2022-09-05' -modification_date: '2026-08-14' +modification_date: '2026-09-24' author: Teoderick Contreras, Splunk status: production type: Anomaly description: The following analytic detects a process enabling the "SeDebugPrivilege" privilege token. It leverages Windows Security Event Logs with EventCode 4703, filtering out common legitimate processes. This activity is significant because SeDebugPrivilege allows a process to inspect and modify the memory of other processes, potentially leading to credential dumping or code injection. If confirmed malicious, an attacker could gain extensive control over system processes, enabling them to escalate privileges, persist in the environment, or access sensitive information. data_source: - Windows Event Log Security 4703 -search: '`wineventlog_security` EventCode=4703 EnabledPrivilegeList = "*SeDebugPrivilege*" AND NOT(ProcessName IN ("*\\Program File*", "*\\System32\\lsass.exe*", "*\\SysWOW64\\lsass.exe*", "*\\SysWOW64\\svchost.exe*", "*\\System32\\svchost.exe*")) | stats count min(_time) as firstTime max(_time) as lastTime by Computer ProcessName ProcessId SubjectDomainName SubjectUserName SubjectUserSid TargetUserName TargetLogonId TargetDomainName EnabledPrivilegeList action dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_access_token_manipulation_sedebugprivilege_filter`' +search: '`wineventlog_security` EventCode=4703 EnabledPrivilegeList = "*SeDebugPrivilege*" AND NOT(ProcessName IN ("*\\Program File*", "*\\System32\\lsass.exe*", "*\\SysWOW64\\lsass.exe*", "*\\SysWOW64\\svchost.exe*", "*\\System32\\svchost.exe*")) | stats count min(_time) as firstTime max(_time) as lastTime by Computer ProcessName ProcessId SubjectDomainName SubjectUserName SubjectUserSid Target_User_Name TargetLogonId TargetDomainName EnabledPrivilegeList action dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_access_token_manipulation_sedebugprivilege_filter`' how_to_implement: To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4703 EventCode enabled. The Windows TA is also required. known_false_positives: Some native binaries and browser applications may request SeDebugPrivilege. Filter as needed. references: diff --git a/detections/endpoint/windows_ad_suspicious_attribute_modification.yml b/detections/endpoint/windows_ad_suspicious_attribute_modification.yml index d9f330d17b..177adfe938 100644 --- a/detections/endpoint/windows_ad_suspicious_attribute_modification.yml +++ b/detections/endpoint/windows_ad_suspicious_attribute_modification.yml @@ -1,8 +1,8 @@ name: Windows AD Suspicious Attribute Modification id: 5682052e-ce55-4f9f-8d28-59191420b7e0 -version: 10 +version: 11 creation_date: '2024-07-01' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Dean Luxton status: production type: TTP @@ -15,7 +15,7 @@ search: |- | rename SubjectLogonId as TargetLogonId, src_user as initiator, _time as eventTime | appendpipe [ | map search="search `wineventlog_security` EventCode=4624 TargetLogonId=$TargetLogonId$"] - | stats min(eventTime) as _time values(initiator) as src_user, values(DSName) as targetDomain, values(ObjectDN) as ObjectDN, values(ObjectClass) as ObjectClass, values(src_category) as src_category, values(src_ip) as src_ip values(LogonType) as LogonType values(AttributeValue) as AttributeValue values(AttributeLDAPDisplayName) as AttributeLDAPDisplayName + | stats min(eventTime) as _time values(initiator) as src_user, values(DSName) as targetDomain, values(ObjectDN) as ObjectDN, values(ObjectClass) as ObjectClass, values(src_category) as src_category, values(src_ip) as src_ip values(Logon_Type) as Logon_Type values(AttributeValue) as AttributeValue values(AttributeLDAPDisplayName) as AttributeLDAPDisplayName BY TargetLogonId | rex field=ObjectDN "^CN=(?P.*?),[A-Z]{2}\=" | eval dest=if(ObjectClass="computer",cn,null), user=if(ObjectClass="user",cn,null) diff --git a/detections/endpoint/windows_computer_account_changed_to_domain_controller.yml b/detections/endpoint/windows_computer_account_changed_to_domain_controller.yml index 6a9633f10d..a2fc2497eb 100644 --- a/detections/endpoint/windows_computer_account_changed_to_domain_controller.yml +++ b/detections/endpoint/windows_computer_account_changed_to_domain_controller.yml @@ -1,8 +1,8 @@ name: Windows Computer Account Changed to Domain Controller id: f9df6250-fa45-4f62-bc9a-768c60bf99b2 -version: 2 +version: 3 creation_date: '2026-05-05' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Raven Tait, Splunk status: production type: TTP @@ -19,7 +19,7 @@ search: |- | fillnull | stats count min(_time) as firstTime max(_time) as lastTime - by Computer TargetUserName UserAccountControl EventID + by Computer Target_User_Name UserAccountControl EventID | rename Computer as dest | `security_content_ctime(firstTime)` diff --git a/detections/endpoint/windows_computer_account_requesting_kerberos_ticket.yml b/detections/endpoint/windows_computer_account_requesting_kerberos_ticket.yml index ad73e21f27..4f6ce4a279 100644 --- a/detections/endpoint/windows_computer_account_requesting_kerberos_ticket.yml +++ b/detections/endpoint/windows_computer_account_requesting_kerberos_ticket.yml @@ -1,8 +1,8 @@ name: Windows Computer Account Requesting Kerberos Ticket id: fb3b2bb3-75a4-4279-848a-165b42624770 -version: 10 +version: 11 creation_date: '2022-04-28' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Michael Haag, Splunk status: production type: TTP @@ -10,10 +10,10 @@ description: The following analytic detects a computer account requesting a Kerb data_source: - Windows Event Log Security 4768 search: |- - `wineventlog_security` EventCode=4768 TargetUserName="*$" src_ip!="::1" + `wineventlog_security` EventCode=4768 Target_User_Name="*$" src_ip!="::1" | stats count min(_time) as firstTime max(_time) as lastTime BY dest, subject, action, - user, TargetUserName, src_ip + user, Target_User_Name, src_ip | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_computer_account_requesting_kerberos_ticket_filter` diff --git a/detections/endpoint/windows_dnsadmins_new_member_added.yml b/detections/endpoint/windows_dnsadmins_new_member_added.yml index 4dbb05cc0c..5afae835c5 100644 --- a/detections/endpoint/windows_dnsadmins_new_member_added.yml +++ b/detections/endpoint/windows_dnsadmins_new_member_added.yml @@ -1,8 +1,8 @@ name: Windows DnsAdmins New Member Added id: 27e600aa-77f8-4614-bc80-2662a67e2f48 -version: 12 +version: 13 creation_date: '2023-03-28' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: TTP @@ -10,8 +10,8 @@ description: The following analytic detects the addition of a new member to the data_source: - Windows Event Log Security 4732 search: |- - `wineventlog_security` EventCode=4732 TargetUserName=DnsAdmins - | stats min(_time) as firstTime max(_time) as lastTime values(TargetUserName) as target_users_added values(user) as user + `wineventlog_security` EventCode=4732 Target_User_Name=DnsAdmins + | stats min(_time) as firstTime max(_time) as lastTime values(Target_User_Name) as target_users_added values(user) as user BY dest src_user | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` diff --git a/detections/endpoint/windows_domain_admin_impersonation_indicator.yml b/detections/endpoint/windows_domain_admin_impersonation_indicator.yml index bdd740f73b..be6d8a31f3 100644 --- a/detections/endpoint/windows_domain_admin_impersonation_indicator.yml +++ b/detections/endpoint/windows_domain_admin_impersonation_indicator.yml @@ -1,8 +1,8 @@ name: Windows Domain Admin Impersonation Indicator id: 10381f93-6d38-470a-9c30-d25478e3bd3f -version: 12 +version: 13 creation_date: '2023-10-06' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: TTP @@ -10,13 +10,13 @@ description: The following analytic identifies potential Kerberos ticket forging data_source: - Windows Event Log Security 4627 search: |- - `wineventlog_security` EventCode=4627 LogonType=3 NOT TargetUserName IN ("*$", "SYSTEM", "DWM-*","LOCAL SERVICE","NETWORK SERVICE", "ANONYMOUS LOGON", "UMFD-*") + `wineventlog_security` EventCode=4627 Logon_Type=3 NOT Target_User_Name IN ("*$", "SYSTEM", "DWM-*","LOCAL SERVICE","NETWORK SERVICE", "ANONYMOUS LOGON", "UMFD-*") | where match(GroupMembership, "Domain Admins") | stats count - BY _time TargetUserName GroupMembership + BY _time Target_User_Name GroupMembership action app dest signature_id user vendor_product - | lookup domain_admins username as TargetUserName OUTPUT username + | lookup domain_admins username as Target_User_Name OUTPUT username | fillnull value=NotDA username | search username = "NotDA" | `windows_domain_admin_impersonation_indicator_filter` @@ -28,18 +28,18 @@ references: - https://github.com/GhostPack/Rubeus/pull/136 - https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4627 drilldown_searches: - - name: View the detection results for - "$TargetUserName$" - search: '%original_detection_search% | search TargetUserName = "$TargetUserName$"' + - name: View the detection results for - "$Target_User_Name$" + search: '%original_detection_search% | search Target_User_Name = "$Target_User_Name$"' earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - - name: View risk events for the last 7 days for - "$TargetUserName$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$TargetUserName$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + - name: View risk events for the last 7 days for - "$Target_User_Name$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$Target_User_Name$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset: 7d latest_offset: "0" finding: - title: $TargetUserName$ may be impersonating a Domain Administrator through a forged Kerberos ticket. + title: $Target_User_Name$ may be impersonating a Domain Administrator through a forged Kerberos ticket. entity: - field: TargetUserName + field: Target_User_Name type: user score: 50 analytic_story: diff --git a/detections/endpoint/windows_esx_admins_group_creation_security_event.yml b/detections/endpoint/windows_esx_admins_group_creation_security_event.yml index 184746f29c..2500e30b86 100644 --- a/detections/endpoint/windows_esx_admins_group_creation_security_event.yml +++ b/detections/endpoint/windows_esx_admins_group_creation_security_event.yml @@ -1,8 +1,8 @@ name: Windows ESX Admins Group Creation Security Event id: 53b4c927-5ec4-47cd-8aed-d4b303304f87 -version: 9 +version: 10 creation_date: '2024-07-30' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Michael Haag, Splunk status: production type: TTP @@ -12,9 +12,9 @@ data_source: - Windows Event Log Security 4730 - Windows Event Log Security 4737 search: |- - `wineventlog_security` EventCode IN (4727, 4730, 4737) (TargetUserName="ESX Admins" OR TargetUserName="*ESX Admins*") + `wineventlog_security` EventCode IN (4727, 4730, 4737) (Target_User_Name="ESX Admins" OR Target_User_Name="*ESX Admins*") | stats count min(_time) as firstTime max(_time) as lastTime - BY EventCode TargetUserName TargetDomainName + BY EventCode Target_User_Name TargetDomainName SubjectUserName SubjectDomainName Computer | rename Computer as dest | eval EventCodeDescription=case( EventCode=4727, "Security Enabled Global Group Created", EventCode=4730, "Security Enabled Global Group Deleted", EventCode=4737, "Security Enabled Global Group Modified" ) diff --git a/detections/endpoint/windows_identify_powershell_web_access_iis_pool.yml b/detections/endpoint/windows_identify_powershell_web_access_iis_pool.yml index 8c6585b0de..875b91ee8a 100644 --- a/detections/endpoint/windows_identify_powershell_web_access_iis_pool.yml +++ b/detections/endpoint/windows_identify_powershell_web_access_iis_pool.yml @@ -1,15 +1,15 @@ name: Windows Identify PowerShell Web Access IIS Pool id: d8419343-f0f8-4d8e-91cc-18bb531df87d -version: 5 +version: 6 creation_date: '2024-09-30' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Michael Haag, Splunk status: production type: Hunting description: This analytic detects and analyzes PowerShell Web Access (PSWA) usage in Windows environments. It tracks both connection attempts (EventID 4648) and successful logons (EventID 4624) associated with PSWA, providing a comprehensive view of access patterns. The analytic identifies PSWA's operational status, host servers, processes, and connection metrics. It highlights unique target accounts, domains accessed, and verifies logon types. This information is crucial for detecting potential misuse, such as lateral movement, brute force attempts, or unusual access patterns. By offering insights into PSWA activity, it enables security teams to quickly assess and investigate potential security incidents involving this powerful administrative tool. data_source: - Windows Event Log Security 4648 -search: '`wineventlog_security` (EventCode=4648 OR EventCode=4624 OR EventCode=4625) SubjectUserName="pswa_pool" | fields EventCode, SubjectUserName, TargetUserName, Computer, TargetDomainName, ProcessName, LogonType | rename Computer as dest | stats count(eval(EventCode=4648)) as "Connection Attempts", count(eval(EventCode=4624)) as "Successful Logons", count(eval(EventCode=4625)) as "Unsuccessful Logons", dc(TargetUserName) as "Unique Target Accounts", values(dest) as "PSWA Host", dc(TargetDomainName) as "Unique Target Domains", values(ProcessName) as "PSWA Process", values(TargetUserName) as "Target Users List", values(TargetServerName) as "Target Servers List", values(LogonType) as "Logon Types" | eval PSWA_Running = "Yes", "PSWA Process" = mvindex(split(mvindex("PSWA Process", 0), "\\"), -1) | fields PSWA_Running, "PSWA Host", "PSWA Process", "Connection Attempts", "Successful Logons","Unsuccessful Logons", "Unique Target Accounts", "Unique Target Domains", "Target Users List","Target Servers List", "Logon Types" | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `windows_identify_powershell_web_access_iis_pool_filter`' +search: '`wineventlog_security` (EventCode=4648 OR EventCode=4624 OR EventCode=4625) SubjectUserName="pswa_pool" | fields EventCode, SubjectUserName, Target_User_Name, Computer, TargetDomainName, ProcessName, Logon_Type | rename Computer as dest | stats count(eval(EventCode=4648)) as "Connection Attempts", count(eval(EventCode=4624)) as "Successful Logons", count(eval(EventCode=4625)) as "Unsuccessful Logons", dc(Target_User_Name) as "Unique Target Accounts", values(dest) as "PSWA Host", dc(TargetDomainName) as "Unique Target Domains", values(ProcessName) as "PSWA Process", values(Target_User_Name) as "Target Users List", values(TargetServerName) as "Target Servers List", values(Logon_Type) as "Logon Types" | eval PSWA_Running = "Yes", "PSWA Process" = mvindex(split(mvindex("PSWA Process", 0), "\\"), -1) | fields PSWA_Running, "PSWA Host", "PSWA Process", "Connection Attempts", "Successful Logons","Unsuccessful Logons", "Unique Target Accounts", "Unique Target Domains", "Target Users List","Target Servers List", "Logon Types" | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `windows_identify_powershell_web_access_iis_pool_filter`' how_to_implement: To successfully implement this search, you need to be ingesting Windows Security Event logs, specifically Event ID 4648 (A logon was attempted using explicit credentials). Ensure that your Windows systems are configured to audit logon events and that these logs are being forwarded to your SIEM or log management solution. You may need to enable advanced audit policy settings in Windows to capture these events. Additionally, make sure that your environment is set up to capture the necessary fields such as SubjectUserName, TargetUserName, Computer, TargetServerName, and ProcessName from these events. If you're using Splunk, ensure that you have the appropriate Windows TA installed and configured to collect these security logs. known_false_positives: False positives may occur if legitimate PSWA processes are used for administrative tasks. Careful review of the logs is recommended to distinguish between legitimate and malicious activity. references: diff --git a/detections/endpoint/windows_kerberos_local_successful_logon.yml b/detections/endpoint/windows_kerberos_local_successful_logon.yml index f056478f50..ce38e78671 100644 --- a/detections/endpoint/windows_kerberos_local_successful_logon.yml +++ b/detections/endpoint/windows_kerberos_local_successful_logon.yml @@ -1,8 +1,8 @@ name: Windows Kerberos Local Successful Logon id: 8309c3a8-4d34-48ae-ad66-631658214653 -version: 15 +version: 16 creation_date: '2022-04-28' -modification_date: '2026-07-27' +modification_date: '2026-09-24' author: Michael Haag, Splunk status: production type: TTP @@ -16,7 +16,7 @@ data_source: search: |- `wineventlog_security` EventCode=4624 - LogonType=3 + Logon_Type=3 AuthenticationPackageName=Kerberos action=success src=127.0.0.1 diff --git a/detections/endpoint/windows_large_number_of_computer_service_tickets_requested.yml b/detections/endpoint/windows_large_number_of_computer_service_tickets_requested.yml index a8fed6397c..09263e7eda 100644 --- a/detections/endpoint/windows_large_number_of_computer_service_tickets_requested.yml +++ b/detections/endpoint/windows_large_number_of_computer_service_tickets_requested.yml @@ -1,8 +1,8 @@ name: Windows Large Number of Computer Service Tickets Requested id: 386ad394-c9a7-4b4f-b66f-586252de20f0 -version: 12 +version: 13 creation_date: '2023-03-21' -modification_date: '2026-07-05' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: Anomaly @@ -13,14 +13,14 @@ description: |- data_source: - Windows Event Log Security 4769 search: |- - `wineventlog_security` EventCode=4769 ServiceName="*$" TargetUserName!="*$" - | eval TargetUserName = mvindex(split(TargetUserName, "@"), 0) - | search NOT TargetUserName="*$" + `wineventlog_security` EventCode=4769 ServiceName="*$" Target_User_Name!="*$" + | eval Target_User_Name = mvindex(split(Target_User_Name, "@"), 0) + | search NOT Target_User_Name="*$" | bucket span=5m _time | stats dc(ServiceName) AS unique_targets values(ServiceName) as host_targets values(dest) as dest - by _time, IpAddress, TargetUserName + by _time, IpAddress, Target_User_Name | where unique_targets > 30 | `windows_large_number_of_computer_service_tickets_requested_filter` how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. diff --git a/detections/endpoint/windows_local_administrator_credential_stuffing.yml b/detections/endpoint/windows_local_administrator_credential_stuffing.yml index 0945e07d38..3eca200d52 100644 --- a/detections/endpoint/windows_local_administrator_credential_stuffing.yml +++ b/detections/endpoint/windows_local_administrator_credential_stuffing.yml @@ -1,8 +1,8 @@ name: Windows Local Administrator Credential Stuffing id: 09555511-aca6-484a-b6ab-72cd03d73c34 -version: 13 +version: 14 creation_date: '2023-03-22' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: TTP @@ -11,10 +11,10 @@ data_source: - Windows Event Log Security 4624 - Windows Event Log Security 4625 search: |- - `wineventlog_security` EventCode=4625 OR EventCode=4624 Logon_Type=3 TargetUserName=Administrator + `wineventlog_security` EventCode=4625 OR EventCode=4624 Logon_Type=3 Target_User_Name=Administrator | bucket span=5m _time | stats dc(Computer) AS unique_targets values(Computer) as host_targets values(dest) as dest values(src) as src values(user) as user - BY _time, IpAddress, TargetUserName, + BY _time, IpAddress, Target_User_Name, EventCode, action, app, authentication_method, signature, signature_id | where unique_targets > 30 diff --git a/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml b/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml index b58e5409bc..0407c8438c 100644 --- a/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml +++ b/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml @@ -1,8 +1,8 @@ name: Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos id: 98f22d82-9d62-11eb-9fcf-acde48001122 -version: 12 +version: 13 creation_date: '2021-04-14' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: TTP @@ -10,9 +10,9 @@ description: The following analytic detects a single source endpoint failing to data_source: - Windows Event Log Security 4768 search: |- - `wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x12 + `wineventlog_security` EventCode=4768 Target_User_Name!=*$ Status=0x12 | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as user values(dest) as dest + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as user values(dest) as dest BY _time, IpAddress | where unique_accounts > 30 | `windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos_filter` diff --git a/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml b/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml index feaa99e737..d19ecd5155 100644 --- a/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml +++ b/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml @@ -1,8 +1,8 @@ name: Windows Multiple Invalid Users Fail To Authenticate Using Kerberos id: 001266a6-9d5b-11eb-829b-acde48001122 -version: 12 +version: 13 creation_date: '2021-04-14' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: TTP @@ -10,9 +10,9 @@ description: The following analytic identifies a source endpoint failing to auth data_source: - Windows Event Log Security 4768 search: |- - `wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x6 + `wineventlog_security` EventCode=4768 Target_User_Name!=*$ Status=0x6 | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as user values(dest) as dest + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as user values(dest) as dest BY _time, IpAddress | where unique_accounts > 30 | `windows_multiple_invalid_users_fail_to_authenticate_using_kerberos_filter` diff --git a/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml b/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml index 06f87cfeb2..879f4393a8 100644 --- a/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml +++ b/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml @@ -1,8 +1,8 @@ name: Windows Multiple Invalid Users Failed To Authenticate Using NTLM id: 57ad5a64-9df7-11eb-a290-acde48001122 -version: 13 +version: 14 creation_date: '2021-04-14' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: TTP @@ -10,9 +10,9 @@ description: The following analytic detects a single source endpoint failing to data_source: - Windows Event Log Security 4776 search: |- - `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xc0000064 + `wineventlog_security` EventCode=4776 Target_User_Name!=*$ Status=0xc0000064 | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts values(dest) as dest + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as tried_accounts values(dest) as dest BY _time, Workstation | where unique_accounts > 30 | `windows_multiple_invalid_users_failed_to_authenticate_using_ntlm_filter` diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml index 2776bccf2e..d42179b249 100644 --- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml +++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml @@ -1,8 +1,8 @@ name: Windows Multiple Users Failed To Authenticate From Host Using NTLM id: 7ed272a4-9c77-11eb-af22-acde48001122 -version: 13 +version: 14 creation_date: '2021-04-14' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: TTP @@ -10,9 +10,9 @@ description: The following analytic identifies a single source endpoint failing data_source: - Windows Event Log Security 4776 search: |- - `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xC000006A + `wineventlog_security` EventCode=4776 Target_User_Name!=*$ Status=0xC000006A | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts values(dest) as dest + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as tried_accounts values(dest) as dest BY _time, Workstation | where unique_accounts > 30 | `windows_multiple_users_failed_to_authenticate_from_host_using_ntlm_filter` diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml index e2eaf4743a..61d22a029e 100644 --- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml +++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml @@ -1,8 +1,8 @@ name: Windows Multiple Users Failed To Authenticate From Process id: 9015385a-9c84-11eb-bef2-acde48001122 -version: 13 +version: 14 creation_date: '2021-04-14' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: TTP @@ -12,7 +12,7 @@ data_source: search: |- `wineventlog_security` EventCode=4625 Logon_Type=2 ProcessName!="-" | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts values(dest) as dest values(src) as src values(user) as user + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as tried_accounts values(dest) as dest values(src) as src values(user) as user BY _time, ProcessName, SubjectUserName, Computer, action, app, authentication_method, signature, signature_id diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml index df8f9277ab..cc7f61e777 100644 --- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml +++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml @@ -1,8 +1,8 @@ name: Windows Multiple Users Failed To Authenticate Using Kerberos id: 3a91a212-98a9-11eb-b86a-acde48001122 -version: 12 +version: 13 creation_date: '2021-04-14' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: TTP @@ -10,9 +10,9 @@ description: The following analytic identifies a single source endpoint failing data_source: - Windows Event Log Security 4771 search: |- - `wineventlog_security` EventCode=4771 TargetUserName!="*$" Status=0x18 + `wineventlog_security` EventCode=4771 Target_User_Name!="*$" Status=0x18 | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as user values(dest) as dest + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as user values(dest) as dest BY _time, IpAddress | where unique_accounts > 30 | `windows_multiple_users_failed_to_authenticate_using_kerberos_filter` diff --git a/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml b/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml index 0e0b3f6932..6389a1e78d 100644 --- a/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml +++ b/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml @@ -1,8 +1,8 @@ name: Windows Multiple Users Remotely Failed To Authenticate From Host id: 80f9d53e-9ca1-11eb-b0d6-acde48001122 -version: 13 +version: 14 creation_date: '2021-04-14' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: TTP @@ -12,7 +12,7 @@ data_source: search: |- `wineventlog_security` EventCode=4625 Logon_Type=3 IpAddress!="-" | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts values(dest) as dest values(src) as src values(user) as user + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as tried_accounts values(dest) as dest values(src) as src values(user) as user BY _time, IpAddress, Computer, action, app, authentication_method, signature, signature_id diff --git a/detections/endpoint/windows_privileged_group_modification.yml b/detections/endpoint/windows_privileged_group_modification.yml index 9ad62213ae..c92486a291 100644 --- a/detections/endpoint/windows_privileged_group_modification.yml +++ b/detections/endpoint/windows_privileged_group_modification.yml @@ -1,8 +1,8 @@ name: Windows Privileged Group Modification id: b8cbef2c-2cc3-4550-b0fc-9715b7852df9 -version: 12 +version: 13 creation_date: '2024-07-30' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Brandon Sternfield, Optiv + ClearShark status: production type: TTP @@ -33,7 +33,7 @@ search: |- 4783, 4790 ) - TargetUserName IN ( + Target_User_Name IN ( "Account Operators", "Administrators", "Admins DNS", @@ -68,7 +68,7 @@ search: |- | rename Computer as dest result as change_type - TargetUserName as object + Target_User_Name as object TargetSid as object_path | stats count min(_time) as firstTime diff --git a/detections/endpoint/windows_rapid_authentication_on_multiple_hosts.yml b/detections/endpoint/windows_rapid_authentication_on_multiple_hosts.yml index 6fbd01af6f..4d0c2ebbd5 100644 --- a/detections/endpoint/windows_rapid_authentication_on_multiple_hosts.yml +++ b/detections/endpoint/windows_rapid_authentication_on_multiple_hosts.yml @@ -1,8 +1,8 @@ name: Windows Rapid Authentication On Multiple Hosts id: 62606c77-d53d-4182-9371-b02cdbbbcef7 -version: 11 +version: 12 creation_date: '2023-03-23' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: TTP @@ -10,10 +10,10 @@ description: The following analytic detects a source computer authenticating to data_source: - Windows Event Log Security 4624 search: |- - `wineventlog_security` EventCode=4624 LogonType=3 TargetUserName!="ANONYMOUS LOGON" TargetUserName!="*$" + `wineventlog_security` EventCode=4624 Logon_Type=3 Target_User_Name!="ANONYMOUS LOGON" Target_User_Name!="*$" | bucket span=5m _time | stats dc(Computer) AS unique_targets values(Computer) as host_targets values(dest) as dest values(src) as src values(user) as user - BY _time, IpAddress, TargetUserName, + BY _time, IpAddress, Target_User_Name, action, app, authentication_method, signature, signature_id | where unique_targets > 30 diff --git a/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml b/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml index 8686a907b3..177268e914 100644 --- a/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml +++ b/detections/endpoint/windows_steal_authentication_certificates___esc1_authentication.yml @@ -1,8 +1,8 @@ name: Windows Steal Authentication Certificates - ESC1 Authentication id: f0306acf-a6ab-437a-bbc6-8628f8d5c97e -version: 10 +version: 11 creation_date: '2023-07-28' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Steven Dick status: production type: TTP @@ -41,7 +41,7 @@ search: |- EventCode=4768 CertThumbprint=* | rename - TargetUserName as user + Target_User_Name as user Computer as auth_dest IpAddress as auth_src | fields auth_src, auth_dest, user diff --git a/detections/endpoint/windows_suspicious_burst_of_password_changes.yml b/detections/endpoint/windows_suspicious_burst_of_password_changes.yml index d8d495550e..2d10cf98e3 100644 --- a/detections/endpoint/windows_suspicious_burst_of_password_changes.yml +++ b/detections/endpoint/windows_suspicious_burst_of_password_changes.yml @@ -1,8 +1,8 @@ name: Windows Suspicious Burst of Password Changes id: 0dcfcab9-e936-43bc-8203-005e17dc0744 -version: 1 +version: 2 creation_date: '2026-04-29' -modification_date: '2026-04-29' +modification_date: '2026-09-24' author: Raven Tait, Splunk status: production type: TTP @@ -27,14 +27,14 @@ search: |- | stats count AS EventsForAccount min(log_time) AS firstTime max(log_time) AS lastTime - by Computer TargetUserName SubjectUserName time_bucket + by Computer Target_User_Name SubjectUserName time_bucket | where EventsForAccount >= 4 | eval DurationSecs = round(lastTime - firstTime, 3), DurationSecs = if(DurationSecs = 0, 0.001, DurationSecs), ChangeRatePerSec = round(EventsForAccount / DurationSecs, 2) | rename Computer as dest - | stats dc(TargetUserName) AS AffectedAccounts - values(TargetUserName) AS Accounts + | stats dc(Target_User_Name) AS AffectedAccounts + values(Target_User_Name) AS Accounts values(SubjectUserName) AS InitiatingAccounts sum(EventsForAccount) AS TotalEvents max(ChangeRatePerSec) AS PeakChangeRatePerSec diff --git a/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml index 928ca65c33..3978dc0542 100644 --- a/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml +++ b/detections/endpoint/windows_unusual_count_of_disabled_users_failed_auth_using_kerberos.yml @@ -1,8 +1,8 @@ name: Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos id: f65aa026-b811-42ab-b4b9-d9088137648f -version: 11 +version: 12 creation_date: '2021-04-14' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: Anomaly @@ -10,9 +10,9 @@ description: The following analytic identifies a source endpoint failing to auth data_source: - Windows Event Log Security 4768 search: |- - `wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x12 + `wineventlog_security` EventCode=4768 Target_User_Name!=*$ Status=0x12 | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as user values(dest) as dest + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as user values(dest) as dest BY _time, IpAddress | eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std BY IpAddress diff --git a/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml index 39803843db..78282353fe 100644 --- a/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml +++ b/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml @@ -1,8 +1,8 @@ name: Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos id: f122cb2e-d773-4f11-8399-62a3572d8dd7 -version: 11 +version: 12 creation_date: '2021-04-14' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: Anomaly @@ -10,9 +10,9 @@ description: The following analytic identifies a source endpoint failing to auth data_source: - Windows Event Log Security 4768 search: |- - `wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x6 + `wineventlog_security` EventCode=4768 Target_User_Name!=*$ Status=0x6 | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as user values(dest) as dest + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as user values(dest) as dest BY _time, IpAddress | eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std BY IpAddress diff --git a/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml b/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml index 82358f447d..37584ec874 100644 --- a/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml +++ b/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml @@ -1,8 +1,8 @@ name: Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM id: 15603165-147d-4a6e-9778-bd0ff39e668f -version: 12 +version: 13 creation_date: '2021-04-14' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: Anomaly @@ -10,9 +10,9 @@ description: The following analytic identifies a source endpoint failing to auth data_source: - Windows Event Log Security 4776 search: |- - `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xc0000064 + `wineventlog_security` EventCode=4776 Target_User_Name!=*$ Status=0xc0000064 | bucket span=2m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as user values(dest) as dest + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as user values(dest) as dest BY _time, Workstation | eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std BY Workstation diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml index 3b197ab1d4..c0fd601207 100644 --- a/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml +++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml @@ -1,8 +1,8 @@ name: Windows Unusual Count Of Users Failed To Auth Using Kerberos id: bc9cb715-08ba-40c3-9758-6e2b26e455cb -version: 11 +version: 12 creation_date: '2021-04-14' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: Anomaly @@ -10,9 +10,9 @@ description: The following analytic identifies a source endpoint failing to auth data_source: - Windows Event Log Security 4771 search: |- - `wineventlog_security` EventCode=4771 TargetUserName!="*$" Status=0x18 + `wineventlog_security` EventCode=4771 Target_User_Name!="*$" Status=0x18 | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as user values(dest) as dest + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as user values(dest) as dest BY _time, IpAddress | eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std BY IpAddress diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml index 9b65d729cb..55be1e5707 100644 --- a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml +++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml @@ -1,8 +1,8 @@ name: Windows Unusual Count Of Users Failed To Authenticate From Process id: 25bdb6cb-2e49-4d34-a93c-d6c567c122fe -version: 12 +version: 13 creation_date: '2021-04-14' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: Anomaly @@ -12,7 +12,7 @@ data_source: search: |- `wineventlog_security` EventCode=4625 Logon_Type=2 ProcessName!="-" | bucket span=2m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as user values(dest) as dest values(src) as src + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as user values(dest) as dest values(src) as src BY _time, ProcessName, SubjectUserName, Computer, action, app, authentication_method, signature, signature_id diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml index c0dc3ac251..571808008e 100644 --- a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml +++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml @@ -1,8 +1,8 @@ name: Windows Unusual Count Of Users Failed To Authenticate Using NTLM id: 6f6c8fd7-6a6b-4af9-a0e9-57cfc47a58b4 -version: 12 +version: 13 creation_date: '2021-04-14' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: Anomaly @@ -10,9 +10,9 @@ description: The following analytic identifies a source endpoint failing to auth data_source: - Windows Event Log Security 4776 search: |- - `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xC000006A + `wineventlog_security` EventCode=4776 Target_User_Name!=*$ Status=0xC000006A | bucket span=2m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts values(dest) as dest + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as tried_accounts values(dest) as dest BY _time, Workstation | eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std BY Workstation diff --git a/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml b/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml index 617bf0f815..a4a64ad9df 100644 --- a/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml +++ b/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml @@ -1,8 +1,8 @@ name: Windows Unusual Count Of Users Remotely Failed To Auth From Host id: cf06a0ee-ffa9-4ed3-be77-0670ed9bab52 -version: 12 +version: 13 creation_date: '2021-04-14' -modification_date: '2026-05-13' +modification_date: '2026-09-24' author: Mauricio Velazco, Splunk status: production type: Anomaly @@ -12,7 +12,7 @@ data_source: search: |- `wineventlog_security` EventCode=4625 Logon_Type=3 IpAddress!="-" | bucket span=2m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts values(dest) as dest values(src) as src values(user) as user + | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as tried_accounts values(dest) as dest values(src) as src values(user) as user BY _time, IpAddress, Computer, action, app, authentication_method, signature, signature_id