Skip to content

Commit 6d07ef8

Browse files
committedJan 30, 2025·
update: lookups with additional data
1 parent a6c06d0 commit 6d07ef8

8 files changed

+9626
-9497
lines changed
 

‎lookups/asr_rules.csv

+2
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,9 @@ D3E037E1-3EB8-44C8-A917-57927947596D,Block JavaScript or VBScript from launching
1212
26190899-1602-49E8-8B27-EB1D0A1CE869,Block Office communication application from creating child processes
1313
E6DB77E5-3DF2-4CF1-B95A-636979351E5B,Block persistence through WMI event subscription
1414
D1E49AAC-8F56-4280-B9BA-993A6D77406C,Block process creations originating from PSExec and WMI commands
15+
33DDEDF1-C6E0-47CB-833E-DE6133960387,Block rebooting machine in Safe Mode
1516
B2B3F03D-6A65-4F7B-A9C7-1C7EF74A9BA4,Block untrusted and unsigned processes that run from USB
17+
C0033C00-D16D-4114-A5A0-DC9B3A7D2CEB,Block use of copied or impersonated system tools
1618
92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B,Block Win32 API calls from Office macros
1719
C1DB55AB-C21A-4637-BB3F-A12568109D35,Use advanced protection against ransomware
1820
A8F5898E-1DC8-49A9-9878-85004B8A61E6,Block Webshell creation for Servers

‎lookups/asr_rules.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: asr_rules
2-
date: 2024-12-23
3-
version: 2
2+
date: 2025-01-29
3+
version: 3
44
id: 3886d687-ae77-4a61-99eb-e745083e391e
55
author: Splunk Threat Research Team
66
lookup_type: csv

‎lookups/builtin_groups_lookup.csv

+20-9
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
11
builtin_group_string,builtin_group_name
2-
AO,Account operators
3-
RU,Alias to allow previous Windows 2000
2+
AA,Access control assistant operators
43
AN,Anonymous logon
4+
AO,Account operators
5+
AP,Protected users
56
AU,Authenticated users
67
BA,Built-in administrators
78
BG,Built-in guests
@@ -10,30 +11,40 @@ BU,Built-in users
1011
CA,Certificate server administrators
1112
CG,Creator group
1213
CO,Creator owner
14+
CY,Crypto operators
1315
DA,Domain administrators
1416
DC,Domain computers
1517
DD,Domain controllers
1618
DG,Domain guests
1719
DU,Domain users
1820
EA,Enterprise administrators
1921
ED,Enterprise domain controllers
20-
WD,Everyone
21-
PA,Group Policy administrators
22+
ER,Eventlog readers
23+
ES,Endpoint servers
24+
HA,Hyper-V administrators
25+
IS,Anonymous internet users
2226
IU,Interactively logged-on user
27+
KA,Domain key administrators
2328
LA,Local administrator
2429
LG,Local guest
2530
LS,Local service account
26-
SY,Local system
27-
NU,Network sign-in user
31+
LU,Performance log users
32+
MS,Management servers
33+
MU,Performance monitor users
2834
NO,Network configuration operators
2935
NS,Network service account
36+
NU,Network sign-in user
37+
PA,Group Policy administrators
3038
PO,Printer operators
3139
PS,Personal self
3240
PU,Power users
33-
RS,RAS servers group
41+
RC,Restricted code
3442
RD,Terminal server users
3543
RE,Replicator
36-
RC,Restricted code
44+
RS,RAS servers group
45+
RU,Alias to allow previous Windows 2000
3746
SA,Schema administrators
3847
SO,Server operators
39-
SU,Service sign-in user
48+
SU,Service sign-in user
49+
SY,Local system
50+
WD,Everyone

‎lookups/builtin_groups_lookup.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: builtin_groups_lookup
2-
date: 2024-12-23
3-
version: 2
2+
date: 2025-01-29
3+
version: 3
44
id: 7d0a0c1c-2ef0-48a9-87c6-de97a0ad1ccf
55
author: Splunk Threat Research Team
66
lookup_type: csv

‎lookups/dynamic_dns_providers_default.csv

+9,478-9,478
Large diffs are not rendered by default.

‎lookups/dynamic_dns_providers_default.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: dynamic_dns_providers_default
2-
date: 2024-12-23
3-
version: 2
2+
date: 2025-01-29
3+
version: 3
44
id: 37046407-ef07-48a5-b63d-384fd15b8c4b
55
author: Splunk Threat Research Team
66
lookup_type: csv

‎lookups/security_services_lookup.csv

+117-1
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,126 @@
11
service,description,category
22
*mpssvc*,Windows Firewall Service,security
33
*wscsvc*,Windows Security Center Service,security
4-
*windefend*,Windows Defender Service,security
54
*sysmon*,Sysmon Driver,security
65
*csc_iseagent*,Cisco Secure Client - ISE Posture Agent,security
76
*csc_nvmagent*,Cisco Secure Client - Network Visibility Agent,security
87
*csc_umbrellaagent*,Cisco Secure Client - Umbrella Agent,security
98
*csc_swgagent*,Cisco Secure Client - Umbrella SWG Agent,security
109
*CiscoAMP*,Cisco Secure Endpoint,security
10+
*CiscoOrbital*,Cisco AMP Orbital,security
11+
*CiscoSCMS*,Cisco Security Connector Monitoring,security
12+
*avast! Antivirus*,Avast,security
13+
*aswBcc*,Avast,security
14+
*Avast Business Console Client Antivirus Service*,Avast,security
15+
*epag*,Bitdefender Endpoint Agent,security
16+
*CylanceSvc*,Cylance,security
17+
*CynetLauncher*,Cynet Launcher Service,security
18+
*xagt*,FireEye Endpoint Agent,security
19+
*fgprocsvc*,ForeScout Remote Inspection Service,security
20+
*SecureConnector*, ForeScout SecureConnector Service,security
21+
*fsdevcon*,F-Secure,security
22+
*FSDFWD*,F-Secure,security
23+
*F-Secure Network Request Broker*,F-Secure,security
24+
*FSMA*,F-Secure,security
25+
*FSORSPClient*,F-Secure,security
26+
*klif*,Kasperksky,security
27+
*klim*,Kasperksky,security
28+
*kltdi*,Kasperksky,security
29+
*enterceptagent*,MacAfee,security
30+
*McAfeeFramework*,MacAfee Agent Backwards Compatiblity Service,security
31+
*McAfeeEngineService*,MacAfee,security
32+
*mfevtp*,MacAfee Validation Trust Protection Service,security
33+
*cyverak*,PaloAlto Traps KernelDriver,security
34+
*cyvrmtgn*,PaloAlto Traps KernelDriver,security
35+
*cyvrfsfd*,PaloAlto Traps FileSystemDriver,security
36+
*CyveraService*,PaloAlto Traps,security
37+
*tlaservice*,PaloAlto Traps Local Analysis Service,security
38+
*twdservice*,PaloAlto Traps Watchdog Service,security
39+
*SentinelHelperService*,SentinelOne,security
40+
*sophosssp*,Sophos,security
41+
*Sophos Agent*,Sophos,security
42+
*Sophos AutoUpdate Service*,Sophos,security
43+
*Sophos Clean Service*,Sophos,security
44+
*Sophos Device Control Service*,Sophos,security
45+
*Sophos Message Router*,Sophos,security
46+
*Sophos Safestore Service*,Sophos,security
47+
*Sophos Web Control Service*,Sophos,security
48+
*sophossps*,Sophos,security
49+
*Symantec System Recovery*, Symantec System Recovery,security
50+
*Smcinst*,Symantec Connect,security
51+
*SmcService*,Symantec Connect,security
52+
*AMSP*,Trend,security
53+
*tmcomm*,Trend,security
54+
*tmactmon*,Trend,security
55+
*tmevtmgr*,Trend,security
56+
*ntrtscan*,Trend Micro Worry Free Business,security
57+
*WRSVC*,Webroot,security
58+
*AcronisActiveProtectionService*,Acronis Active Protection Service,security
59+
*bdredline_agent*,Bitdefender Agent RedLine Service,security
60+
*BDAuxSrv*,Bitdefender Auxiliary Service,security
61+
*UPDATESRV*,Bitdefender Desktop Update Service,security
62+
*VSSERV*,Bitdefender Virus Shield,security
63+
*bdredline*,Bitdefender RedLine Service,security
64+
*EPRedline*,Bitdefender Endpoint Redline Service,security
65+
*EPUpdateService*,Bitdefender Endpoint Update Service,security
66+
*EPSecurityService*,Bitdefender Endpoint Security Service,security
67+
*EPProtectedService*,Bitdefender Endpoint Protected Service,security
68+
*EPIntegrationService*,Bitdefender Endpoint Integration Service,security
69+
*Parity*,Carbon Black App Control Agent,security
70+
*CSFalconService*,CrowdStrike Falcon Sensor Service,security
71+
*xdrhealth*,Cortex XDR Health Helper,security
72+
*cyserver*, Cortex XDR,security
73+
*CybereasonActiveProbe*,Cybereason Active Probe,security
74+
*CybereasonCRS*,Cybereason Anti-Ransomware,security
75+
*CybereasonBlocki*,Cybereason Execution Prevention,security
76+
*ekm*,ESET,security
77+
*epfw*,ESET,security
78+
*epfwlwf*,ESET,security
79+
*epfwwfp*,ESET,security
80+
*EraAgentSvc*,ESET Management Agent service,security
81+
*ERAAgent*,ESET Management Agent service,security
82+
*efwd*,ESET Communication Forwarding Service,security
83+
*ehttpsrv*,ESET HTTP Server,security
84+
*AVKWCtl*,Anti-virus Kit Window Control,security
85+
*AVKProxy*,G Data AntiVirus Proxy Service,security
86+
*GDScan*,GDSG Data AntiVirus Scan Service,security
87+
*kavfsslp*,Kaspersky Security Exploit Prevention Service,security
88+
*KAVFS*,Kaspersky Security Service,security
89+
*KAVFSGT*,Kaspersky Security Management Service,security
90+
*klnagent*,Kaspersky Security Center,security
91+
*PandaAetherAgent*,Panda Endpoint Agent,security
92+
*PSUAService*,Panda Product Service,security
93+
*NanoServiceMain*,Panda Cloud Antivirus Service,security
94+
*SentinelAgent*,SentinelOne Endpoint Protection Agent,security
95+
*SentinelStaticEngine*,Manage static engines for SentinelOne Endpoint Protection,security
96+
*LogProcessorService*,Manage logs for SentinelOne Endpoint Protection,security
97+
*SepMasterService*,Symantec Endpoint Protection,security
98+
*SepScanService*,Symantec Endpoint Protection Scan Services,security
99+
*SNAC*,Symantec Network Access Control,security
100+
*SntpService*,Sophos Network Threat Protection,security
101+
*Sophos Endpoint Defense Service*,Sophos Endpoint Defense Service,security
102+
*Sophos File Scanner Service*,Sophos File Scanner Service,security
103+
*Sophos Health Service*,Sophos Health Service,security
104+
*Sophos Live Query*,Sophos Live Query,security
105+
*Sophos Managed Threat Response*,Sophos Managed Threat Response,security
106+
*Sophos MCS Agent*,Sophos MCS Agent,security
107+
*Sophos MCS Client*,Sophos MCS Client,security
108+
*Sophos System Protection Service*,Sophos System Protection Service,security
109+
*McAfee Endpoint Security Platform Service*,Trellix Core Service,security
110+
*mfemactl*,Trellix Management Service,security
111+
*mfemms*,McAfee Management Service,security
112+
*mfefire*,Trellix Firewall Core Service,security
113+
*masvc*,Trellix Agent Service,security
114+
*macmnsvc*,Trellix Agent Common Service,security
115+
*mfetp*,Trellix Endpoint Threat Prevention Service,security
116+
*mfewc*,Trellix Endpoint Security Web Control Service*,security
117+
*mfeaack*,Trellix Anti-Malware Core Service,security
118+
*Trend Micro Endpoint Basecamp*,Trend Micro Endpoint Basecamp,security
119+
*TMBMServer*,Trend Micro Unauthorized Change Prevention Service,security
120+
*Trend Micro Web Service Communicator*,Trend Micro Web Service Communicator,security
121+
*TMiACAgentSvc*,Trend Micro Application Control Service (Agent),security
122+
*CETASvc*,Trend Micro Cloud Endpoint Telemetry Service,security
123+
*iVPAgent*,Trend Micro Vulnerability Protection Service (Agent),security
124+
*WinDefend*,Windows Defender Antivirus Service,security
125+
*Sense*,Windows Defender Advanced Threat Protection Service,security
126+
*WdNisSvc*,Windows Defender Antivirus Network Inspection Service,security

‎lookups/security_services_lookup.yml

+3-3
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
11
name: security_services_lookup
2-
date: 2024-12-23
3-
version: 2
2+
date: 2025-01-29
3+
version: 4
44
id: c9038bad-c77b-4caa-9df2-09dc4454ac77
55
author: Splunk Threat Research Team
66
lookup_type: csv
77
default_match: false
8-
description: A list of services that deal with security
8+
description: A list of services that deal with security, such as Antivirus, Endpoint Detection and Response, etc.
99
match_type:
1010
- WILDCARD(service)
1111
min_matches: 1

0 commit comments

Comments
 (0)
Please sign in to comment.