|
1730 | 1730 | "contributors": [
|
1731 | 1731 | "Jose Rodriguez @Cyb3rPandaH"
|
1732 | 1732 | ],
|
1733 |
| - "attack": null, |
| 1733 | + "attack": { |
| 1734 | + "data_source": "Firewall", |
| 1735 | + "data_component": "firewall rule modification" |
| 1736 | + }, |
1734 | 1737 | "behavior": {
|
1735 | 1738 | "source": "process",
|
1736 | 1739 | "relationship": "removed",
|
|
1741 | 1744 | "event_id": 2006,
|
1742 | 1745 | "name": "A rule has been deleted in the Windows Defender Firewall exception list",
|
1743 | 1746 | "platform": "windows",
|
1744 |
| - "audit_category": null, |
1745 |
| - "audit_sub_category": null, |
1746 |
| - "log_channel": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall", |
1747 |
| - "log_provider": "Microsoft-Windows-Windows Firewall With Advanced Security" |
| 1747 | + "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security", |
| 1748 | + "event_version": [] |
1748 | 1749 | }
|
1749 | 1750 | ],
|
1750 | 1751 | "references": null,
|
1751 |
| - "notes": [ |
1752 |
| - "Potential contribution for ATT&CK - Firewall / firewall rule modification" |
1753 |
| - ] |
| 1752 | + "notes": null |
1754 | 1753 | },
|
1755 | 1754 | {
|
1756 | 1755 | "relationship_id": "REL-2022-0039",
|
|
3991 | 3990 | "contributors": [
|
3992 | 3991 | "Jose Rodriguez @Cyb3rPandaH"
|
3993 | 3992 | ],
|
3994 |
| - "attack": null, |
| 3993 | + "attack": { |
| 3994 | + "data_source": "Firewall", |
| 3995 | + "data_component": "firewall rule modification" |
| 3996 | + }, |
3995 | 3997 | "behavior": {
|
3996 | 3998 | "source": "process",
|
3997 | 3999 | "relationship": "added",
|
|
4002 | 4004 | "event_id": 2004,
|
4003 | 4005 | "name": "A rule has been added to the Windows Defender Firewall exception list",
|
4004 | 4006 | "platform": "windows",
|
4005 |
| - "audit_category": null, |
4006 |
| - "audit_sub_category": null, |
4007 |
| - "log_channel": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall", |
4008 |
| - "log_provider": "Microsoft-Windows-Windows Firewall With Advanced Security" |
| 4007 | + "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security", |
| 4008 | + "event_version": [] |
4009 | 4009 | }
|
4010 | 4010 | ],
|
4011 | 4011 | "references": null,
|
4012 |
| - "notes": [ |
4013 |
| - "Potential contribution for ATT&CK - Firewall / firewall rule modification" |
4014 |
| - ] |
| 4012 | + "notes": null |
4015 | 4013 | },
|
4016 | 4014 | {
|
4017 | 4015 | "relationship_id": "REL-2022-0089",
|
|
4305 | 4303 | "contributors": [
|
4306 | 4304 | "Jose Rodriguez @Cyb3rPandaH"
|
4307 | 4305 | ],
|
4308 |
| - "attack": null, |
| 4306 | + "attack": { |
| 4307 | + "data_source": "Firewall", |
| 4308 | + "data_component": "firewall rule modification" |
| 4309 | + }, |
4309 | 4310 | "behavior": {
|
4310 | 4311 | "source": "process",
|
4311 | 4312 | "relationship": "modified",
|
|
4316 | 4317 | "event_id": 2005,
|
4317 | 4318 | "name": "A rule has been modified in the Windows Defender Firewall exception list.",
|
4318 | 4319 | "platform": "windows",
|
4319 |
| - "audit_category": null, |
4320 |
| - "audit_sub_category": null, |
4321 |
| - "log_channel": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall", |
4322 |
| - "log_provider": "Microsoft-Windows-Windows Firewall With Advanced Security" |
| 4320 | + "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security", |
| 4321 | + "event_version": [] |
4323 | 4322 | }
|
4324 | 4323 | ],
|
4325 | 4324 | "references": null,
|
4326 |
| - "notes": [ |
4327 |
| - "Potential contribution for ATT&CK - Firewall / firewall rule modification" |
4328 |
| - ] |
| 4325 | + "notes": null |
4329 | 4326 | },
|
4330 | 4327 | {
|
4331 | 4328 | "relationship_id": "REL-2022-0096",
|
|
5359 | 5356 | "event_id": 2006,
|
5360 | 5357 | "name": "A rule has been deleted in the Windows Defender Firewall exception list",
|
5361 | 5358 | "platform": "windows",
|
5362 |
| - "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall" |
| 5359 | + "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security", |
| 5360 | + "event_version": [] |
5363 | 5361 | },
|
5364 | 5362 | {
|
5365 | 5363 | "event_id": "cloudtrail",
|
|
5382 | 5380 | "event_id": 2033,
|
5383 | 5381 | "name": "All rules have been deleted from the Windows Firewall configuration on this computer.",
|
5384 | 5382 | "platform": "windows",
|
5385 |
| - "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall" |
| 5383 | + "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security", |
| 5384 | + "event_version": [] |
5386 | 5385 | }
|
5387 | 5386 | ],
|
5388 | 5387 | "references": null,
|
|
5802 | 5801 | "event_id": 2009,
|
5803 | 5802 | "name": "The Windows Firewall service failed to load Group Policy.",
|
5804 | 5803 | "platform": "windows",
|
5805 |
| - "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall" |
| 5804 | + "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security", |
| 5805 | + "event_version": [] |
5806 | 5806 | }
|
5807 | 5807 | ],
|
5808 | 5808 | "references": null,
|
|
7039 | 7039 | "contributors": [
|
7040 | 7040 | "Jose Rodriguez @Cyb3rPandaH"
|
7041 | 7041 | ],
|
7042 |
| - "attack": null, |
| 7042 | + "attack": { |
| 7043 | + "data_source": "Firewall", |
| 7044 | + "data_component": "firewall metadata" |
| 7045 | + }, |
7043 | 7046 | "behavior": {
|
7044 | 7047 | "source": "user",
|
7045 | 7048 | "relationship": "modified",
|
|
7050 | 7053 | "event_id": 2002,
|
7051 | 7054 | "name": "A Windows Defender Firewall setting has changed.",
|
7052 | 7055 | "platform": "windows",
|
7053 |
| - "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall" |
| 7056 | + "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security", |
| 7057 | + "event_version": [] |
7054 | 7058 | },
|
7055 | 7059 | {
|
7056 | 7060 | "event_id": 2003,
|
7057 | 7061 | "name": "A Windows Defender Firewall setting in the Private profile has changed.",
|
7058 | 7062 | "platform": "windows",
|
7059 |
| - "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall" |
| 7063 | + "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security", |
| 7064 | + "event_version": [] |
7060 | 7065 | }
|
7061 | 7066 | ],
|
7062 | 7067 | "references": null,
|
|
7876 | 7881 | "platform": "windows",
|
7877 | 7882 | "audit_category": null,
|
7878 | 7883 | "audit_sub_category": null,
|
7879 |
| - "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall" |
| 7884 | + "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security", |
| 7885 | + "event_version": [] |
7880 | 7886 | },
|
7881 | 7887 | {
|
7882 | 7888 | "event_id": "cloudtrail",
|
|
8450 | 8456 | "event_id": 2005,
|
8451 | 8457 | "name": "A rule has been modified in the Windows Defender Firewall exception list.",
|
8452 | 8458 | "platform": "windows",
|
8453 |
| - "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall" |
| 8459 | + "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security", |
| 8460 | + "event_version": [] |
8454 | 8461 | },
|
8455 | 8462 | {
|
8456 | 8463 | "event_id": "cloudtrail",
|
|
8479 | 8486 | "contributors": [
|
8480 | 8487 | "Jose Rodriguez @Cyb3rPandaH"
|
8481 | 8488 | ],
|
8482 |
| - "attack": null, |
| 8489 | + "attack": { |
| 8490 | + "data_source": "Firewall", |
| 8491 | + "data_component": "firewall metadata" |
| 8492 | + }, |
8483 | 8493 | "behavior": {
|
8484 | 8494 | "source": "process",
|
8485 | 8495 | "relationship": "modified",
|
|
8490 | 8500 | "event_id": 2002,
|
8491 | 8501 | "name": "A Windows Defender Firewall setting has changed.",
|
8492 | 8502 | "platform": "windows",
|
8493 |
| - "audit_category": null, |
8494 |
| - "audit_sub_category": null, |
8495 |
| - "log_channel": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall", |
8496 |
| - "log_provider": "Microsoft-Windows-Windows Firewall With Advanced Security" |
| 8503 | + "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security", |
| 8504 | + "event_version": [] |
8497 | 8505 | },
|
8498 | 8506 | {
|
8499 | 8507 | "event_id": 2003,
|
8500 | 8508 | "name": "A Windows Defender Firewall setting in the Private profile has changed.",
|
8501 | 8509 | "platform": "windows",
|
8502 |
| - "audit_category": null, |
8503 |
| - "audit_sub_category": null, |
8504 |
| - "log_channel": "Microsoft-Windows-Windows Firewall With Advanced Security/Firewall", |
8505 |
| - "log_provider": "Microsoft-Windows-Windows Firewall With Advanced Security" |
| 8510 | + "log_source": "Microsoft-Windows-Windows Firewall With Advanced Security", |
| 8511 | + "event_version": [] |
8506 | 8512 | }
|
8507 | 8513 | ],
|
8508 | 8514 | "references": null,
|
8509 |
| - "notes": [ |
8510 |
| - "Potential contribution for ATT&CK - Firewall / firewall modification (New data component and relationship)" |
8511 |
| - ] |
| 8515 | + "notes": null |
8512 | 8516 | },
|
8513 | 8517 | {
|
8514 | 8518 | "relationship_id": "REL-2022-0181",
|
|
0 commit comments