Skip to content

Commit 5c4abbc

Browse files
committed
auditd_detection_updates
1 parent 6869ca9 commit 5c4abbc

5 files changed

+15
-15
lines changed

detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Linux Auditd File Permission Modification Via Chmod
22
id: 5f1d2ea7-eec0-4790-8b24-6875312ad492
3-
version: 8
4-
date: '2025-02-20'
3+
version: 9
4+
date: '2025-02-24'
55
author: Teoderick Contreras, Splunk, Ivar Nygård
66
status: production
77
type: Anomaly
@@ -63,7 +63,7 @@ tags:
6363
- Compromised Linux Host
6464
- Linux Persistence Techniques
6565
- XorDDos
66-
- Nexus APT Threat Activity
66+
- China-Nexus Threat Activity
6767
- Earth Estries
6868
asset_type: Endpoint
6969
mitre_attack_id:

detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Linux Auditd Nopasswd Entry In Sudoers File
22
id: 651df959-ad17-4b73-a323-90cb96d5fa1b
3-
version: 5
4-
date: '2025-02-20'
3+
version: 6
4+
date: '2025-02-24'
55
author: Teoderick Contreras, Splunk
66
status: production
77
type: Anomaly
@@ -60,7 +60,7 @@ tags:
6060
- Linux Privilege Escalation
6161
- Compromised Linux Host
6262
- Linux Persistence Techniques
63-
- Nexus APT Threat Activity
63+
- China-Nexus Threat Activity
6464
- Earth Estries
6565
asset_type: Endpoint
6666
mitre_attack_id:

detections/endpoint/linux_auditd_possible_access_to_credential_files.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Linux Auditd Possible Access To Credential Files
22
id: 0419cb7a-57ea-467b-974f-77c303dfe2a3
3-
version: 6
4-
date: '2025-02-20'
3+
version: 7
4+
date: '2025-02-24'
55
author: Teoderick Contreras, Splunk
66
status: production
77
type: Anomaly
@@ -60,7 +60,7 @@ tags:
6060
- Linux Privilege Escalation
6161
- Compromised Linux Host
6262
- Linux Persistence Techniques
63-
- Nexus APT Threat Activity
63+
- China-Nexus Threat Activity
6464
- Earth Estries
6565
asset_type: Endpoint
6666
mitre_attack_id:

detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Linux Auditd Possible Access To Sudoers File
22
id: 8be88f46-f7e8-4ae6-b15e-cf1b13392834
3-
version: 6
4-
date: '2025-02-20'
3+
version: 7
4+
date: '2025-02-24'
55
author: Teoderick Contreras, Splunk
66
status: production
77
type: Anomaly
@@ -59,7 +59,7 @@ tags:
5959
- Linux Privilege Escalation
6060
- Compromised Linux Host
6161
- Linux Persistence Techniques
62-
- Nexus APT Threat Activity
62+
- China-Nexus Threat Activity
6363
- Earth Estries
6464
asset_type: Endpoint
6565
mitre_attack_id:

detections/endpoint/linux_auditd_preload_hijack_library_calls.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Linux Auditd Preload Hijack Library Calls
22
id: 35c50572-a70b-452f-afa9-bebdf3c3ce36
3-
version: 6
4-
date: '2025-02-20'
3+
version: 7
4+
date: '2025-02-24'
55
author: Teoderick Contreras, Splunk
66
status: production
77
type: TTP
@@ -62,7 +62,7 @@ tags:
6262
- Linux Privilege Escalation
6363
- Compromised Linux Host
6464
- Linux Persistence Techniques
65-
- Nexus APT Threat Activity
65+
- China-Nexus Threat Activity
6666
- Earth Estries
6767
asset_type: Endpoint
6868
mitre_attack_id:

0 commit comments

Comments
 (0)