-
Notifications
You must be signed in to change notification settings - Fork 521
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[UEBA] Discovery Windows DR Performance Analysis #3093
Comments
Looping through our detection rules:
Output:
File: discovery_win_network_connections.toml
Name: "Windows System Network Connections Discovery"
Rule ID: "c4e9ed3e-55a2-4309-a012-bc3c78dad10a"
File: discovery_generic_process_discovery.toml File: discovery_net_share_discovery_winlog.toml File: discovery_generic_account_groups.toml File: discovery_windows_system_information_discovery.toml File: discovery_internet_capabilities.toml File: discovery_posh_password_policy.toml File: discovery_posh_generic.toml File: discovery_generic_registry_query.toml File: discovery_command_system_account.toml File: discovery_group_policy_object_discovery.toml File: discovery_enumerating_domain_trusts_via_dsquery.toml File: discovery_post_exploitation_external_ip_lookup.toml File: discovery_system_service_discovery.toml File: discovery_enumerating_domain_trusts_via_nltest.toml File: discovery_admin_recon.toml File: discovery_system_time_discovery.toml File: discovery_privileged_localgroup_membership.toml File: discovery_posh_invoke_sharefinder.toml File: discovery_peripheral_device.toml File: discovery_net_view.toml File: discovery_adfind_command_activity.toml File: discovery_whoami_command_activity.toml File: discovery_remote_system_discovery_commands_windows.toml File: discovery_security_software_wmic.toml File: discovery_files_dir_systeminfo_via_cmd.toml File: discovery_posh_suspicious_api_functions.toml |
|
This issue is no longer needed, tuning has finished. |
Summary
This issue is used to compile a list of Windows Discovery-related detection rules that can be leveraged as part of the "UEBA - Discovery - Unusual Discovery Activity from User". This list will, if necessary, be tuned/redesigned/converted to new_terms to reduce FPs while maintaining TP detection rate. These rules will then be shipped as a "UEBA Discovery" pack for telemetry gathering / evaluation.
Approach
The text was updated successfully, but these errors were encountered: