Skip to content

Commit

Permalink
Merge pull request #713 from CrossRealms/remove-app-dependancy
Browse files Browse the repository at this point in the history
removed content update app dependancy
  • Loading branch information
hardikhdholariya authored Feb 10, 2025
2 parents be0f4d6 + 310d27f commit 87e6cb9
Show file tree
Hide file tree
Showing 7 changed files with 402 additions and 11 deletions.

Large diffs are not rendered by default.

6 changes: 5 additions & 1 deletion cyences_app_for_splunk/default/macros.conf
Original file line number Diff line number Diff line change
Expand Up @@ -851,7 +851,11 @@ iseval = 0

# Ransomware
[cs_ransomware_extensions]
definition = lookup update=true ransomware_extensions_lookup Extensions AS file_extension OUTPUT Name AS Ransomware_Name | search Ransomware_Name!=False
definition = lookup update=true cs_ransomware_extensions Extensions AS file_extension OUTPUT Name AS Ransomware_Name | search Ransomware_Name!=False
iseval = 0

[cs_ransomware_notes]
definition = lookup cs_ransomware_notes ransomware_notes as file_name OUTPUT status as "Known Ransomware Notes" | search "Known Ransomware Notes"=True
iseval = 0

[cs_spike_in_file_writes_filter]
Expand Down
8 changes: 4 additions & 4 deletions cyences_app_for_splunk/default/savedsearches.conf
Original file line number Diff line number Diff line change
Expand Up @@ -5116,7 +5116,7 @@ counttype = number of events
quantity = 0
relation = greater than
cron_schedule = 4,14,24,34,44,54 * * * *
description = This alert is based on a lookup from the ES Content Update app. It will inspect for common ransomware file extensions.
description = This alert will inspect for common ransomware file extensions.
dispatch.earliest_time = -12m@m
dispatch.latest_time = -2m@m
display.general.type = statistics
Expand Down Expand Up @@ -5195,7 +5195,7 @@ counttype = number of events
quantity = 0
relation = greater than
cron_schedule = 8,18,28,38,48,58 * * * *
description = This alert is based on a lookup from the ES Content Update app. It will inspect for common ransomware notes.
description = This alert will inspect for common ransomware notes.
dispatch.earliest_time = -12m@m
dispatch.latest_time = -2m@m
display.general.type = statistics
Expand All @@ -5205,12 +5205,12 @@ request.ui_dispatch_app = cyences_app_for_splunk
request.ui_dispatch_view = search
search = | tstats `cs_summariesonly_endpoint` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name \
| `cs_drop_dm_object_name(Filesystem)` | `cs_human_readable_time_format(lastTime)` | `cs_human_readable_time_format(firstTime)` \
| rex field=file_name "(?<file_extension>\.[^\.]+)$" | `ransomware_notes` \
| rex field=file_name "(?<file_extension>\.[^\.]+)$" | `cs_ransomware_notes` \
| eval cyences_severity = "critical" \
| `cs_common_ransomware_notes_filter`
action.cyences_notable_event_action = 1
action.cyences_notable_event_action.param.filter_macro_name = cs_common_ransomware_notes_filter
action.cyences_notable_event_action.contributing_events = | datamodel Endpoint Filesystem search strict_fields=false | `cs_drop_dm_object_name(Filesystem)` | rex field=file_name "(?<file_extension>\.[^\.]+)$" | `ransomware_notes`
action.cyences_notable_event_action.contributing_events = | datamodel Endpoint Filesystem search strict_fields=false | `cs_drop_dm_object_name(Filesystem)` | rex field=file_name "(?<file_extension>\.[^\.]+)$" | `cs_ransomware_notes`
action.cyences_notable_event_action.system_compromised_search = | stats sum(count) as count by dest
action.cyences_notable_event_action.system_compromised_drilldown = | datamodel Endpoint Filesystem search strict_fields=false | search Filesystem.dest=$row.dest$ | `cs_drop_dm_object_name(Filesystem)`
action.cyences_notable_event_action.attacker_search = | stats sum(count) as count by file_name
Expand Down
15 changes: 15 additions & 0 deletions cyences_app_for_splunk/default/transforms.conf
Original file line number Diff line number Diff line change
Expand Up @@ -272,3 +272,18 @@ case_sensitive_match = false
[tenable_sc_last_scan_time_extract]
REGEX = Scan\sStart\sDate\s*:\s*(?<last_scan_time>[^\n\r]+)
SOURCE_KEY = pluginText

# Ransomware lookups (from DA-ESS-ContentUpdate app)
[cs_ransomware_extensions]
filename = cs_ransomware_extensions.csv
default_match = false
case_sensitive_match = false
match_type = WILDCARD(Extensions)
min_matches = 1

[cs_ransomware_notes]
filename = cs_ransomware_notes.csv
default_match = false
case_sensitive_match = false
match_type = WILDCARD(ransomware_notes)
min_matches = 1
302 changes: 302 additions & 0 deletions cyences_app_for_splunk/lookups/cs_ransomware_extensions.csv
Original file line number Diff line number Diff line change
@@ -0,0 +1,302 @@
Extensions,Name
.enc,.CryptoHasYou.
.777,777
.R4A,7ev3n
.R5A,7ev3n
.7h9r,7h9r
.8lock8,8lock8
.encrypt,Alpha Ransomware
.amba,AMBA
.adk,Angry Duck
.encrypted,Apocalypse
.SecureCrypted,Apocalypse
.FuckYourData,Apocalypse
.unavailable,Apocalypse
.bleepYourFiles,Apocalypse
.Where_my_files.txt,Apocalypse
.encrypted,ApocalypseVM
.locked,ApocalypseVM
.locky,AutoLocky
.adr,BaksoCrypt
.avos,AvosLocker
.avos2,AvosLocker
.avoslinux,AvosLocker
.bart.zip,Bart
.bart,Bart
.perl,Bart
.clf,BitCryptor
.bitstak,BitStak
.Silent,BlackShades Crypter
.blocatto,Blocatto
.cry,Central Security Treatment Organization
.cerber,Cerber
.cerber2,Cerber
.cerber3,Cerber
.clf,CoinVault
.coverton,Coverton
.enigma,Coverton
.czvxce,Coverton
.criptiko,CryFile
.criptoko,CryFile
.criptokod,CryFile
.cripttt,CryFile
.aga,CryFile
.cry,CryLocker
.ENCRYPTED,Crypren
.crypt38,Crypt38
.scl,CryptFIle2
.crinf,CryptInfinite
.frtrss,CryptoFortress
.clf,CryptoGraphic Locker
.crjoker,CryptoJoker
.encrypted ,CryptoLocker
.ENC,CryptoLocker
.code,CryptoMix
.scl,CryptoMix
.crptrgr,CryptoRoger
.locked,CryptoShocker
.CryptoTorLocker2015!,CryptoTorLocker2015
.crypt,CryptXXX
.crypt,CryptXXX 2.0
.crypt,CryptXXX 3.0
.cryp1,CryptXXX 3.0
.crypz,CryptXXX 3.0
.cryptz,CryptXXX 3.0
.cryp1,CryptXXX 3.1
.ctbl,CTB-Locker
.encrypted,CuteRansomware
.ded,DEDCryptor
.domino,Domino
.locked,EDA2 / HiddenTear
.isis,EduCrypt
.locked,EduCrypt
.ha3,El-Polocker
.enigma,Enigma
.1txt,Enigma
.exotic,Exotic
.locked,Fakben
.fantom,Fantom
.Z81928819,GhostCrypt
.purge,Globe v1
.globe,Globe v3
.locked,GNL Locker
.crypt,Gomasom
.herbst,Herbst
.cry,Hi Buddy!
.locky,Hucky
.crime,iLock
.crime,iLockLight
.btc,Jigsaw
.kkk,Jigsaw
.fun,Jigsaw
.gws,Jigsaw
.porno,Jigsaw
.payransom,Jigsaw
.payms,Jigsaw
.paymst,Jigsaw
.AFD,Jigsaw
.paybtcs,Jigsaw
.epic,Jigsaw
.xyz,Jigsaw
.locked,Job Crypter
.encrypted,KeRanger
.keybtc@inbox_com,KeyBTC
.rip,Killer Locker
.kimcilware,KimcilWare
.locked,KimcilWare
.kostya,Kostya
.kratos,KratosCrypt
.LeChiffre,LeChiffre
.locky,Locky
.zepto,Locky
.odin,Locky
.shit,Locky
.thor,Locky
.asier,Locky
.zzzzz,Locky
.osiris,Locky
.lock93,Lock93
.crime,Lortok
.oor,LowLevel04
.magic,Magic
.Lock,MIRCOP
.fucked,MireWare
.fuck,MireWare
.locked,MM Locker
.KEYZ,Mobef
.KEYH0LES,Mobef
.crypted,Nemucod
.odcodc,ODCODC
.cbf,Offline ransomware
.LOL!,OMG! Ransomware
.OMG!,OMG! Ransomware
.padcrypt,PadCrypt
.locked,Philadelphia
.locked,PokemonGO
.filock,Popcorn Time
.locky,PowerWare
.crypt,R980
.locked,RAA encryptor
.RDM,Radamant
.RRK,Radamant
.RAD,Radamant
.RADAMANT,Radamant
.locked,Rakhni
.kraken,Rakhni
.darkness,Rakhni
.nochance,Rakhni
.oshit,Rakhni
.oplata@qq_com,Rakhni
.relock@qq_com,Rakhni
.crypto,Rakhni
[email protected],Rakhni
.pizda@qq_com,Rakhni
.dyatel@qq_com,Rakhni
._ryp,Rakhni
.nalog@qq_com,Rakhni
.chifrator@qq_com,Rakhni
.gruzin@qq_com,Rakhni
.troyancoder@qq_com,Rakhni
.encrypted,Rakhni
.cry,Rakhni
.AES256,Rakhni
.enc,Rakhni
.hb15,Rakhni
.vscrypt,Rector
.infected,Rector
.bloc,Rector
.korrektor,Rector
.rekt,RektLocker
.remind,RemindMe
.crashed,RemindMe
.rokku,Rokku
.encryptedAES,Samas-Samsam
.encryptedRSA,Samas-Samsam
.encedRSA,Samas-Samsam
.justbtcwillhelpyou,Samas-Samsam
.btcbtcbtc,Samas-Samsam
.btc-help-you,Samas-Samsam
.only-we_can-help_you,Samas-Samsam
.iwanthelpuuu,Samas-Samsam
.notfoundrans,Samas-Samsam
.encmywork,Samas-Samsam
.weapologize,Samas-Samsam
.stubbin,Samas-Samsam
.areyoulovemyrans,Samas-Samsam
.loveransisgood,Samas-Samsam
.myransext2017,Samas-Samsam
.disposed2017,Samas-Samsam
.prosperous666,Samas-Samsam
.supported2017,Samas-Samsam
.country82000,Samas-Samsam
.moments2900,Samas-Samsam
.breeding123,Samas-Samsam
.mention9823,Samas-Samsam
.suppose666,Samas-Samsam
.skjdthghh,Samas-Samsam
.cifgksaffsfyghd,Samas-Samsam
.iaufkakfhsaraf,Samas-Samsam
.filegofprencrp,Samas-Samsam
.weencedufiles,Samas-Samsam
.encryptedyourfiles,Samas-Samsam
.letmetrydecfiles,Samas-Samsam
.otherinformation,Samas-Samsam
.weareyourfriends,Samas-Samsam
.noproblemwedecfiles,Samas-Samsam
.powerfulldecrypt,Samas-Samsam
.wowreadfordecryp,Samas-Samsam
.wowwhereismyfiles,Samas-Samsam
.helpmeencedfiles,Samas-Samsam
.theworldisyours,Samas-Samsam
.vekanhelpu,Samas-Samsam
.howcanihelpusir,Samas-Samsam
.VforVendetta,Samas-Samsam
.checkdiskenced,Samas-Samsam
.goforhelp,Samas-Samsam
.iloveworld,Samas-Samsam
.canihelpyou,Samas-Samsam
.AreYouLoveMyRansFile,Samas-Samsam
.fucku,Samas-Samsam
.happenencedfiles,Samas-Samsam
.iwishiyou,Samas-Samsam
.powerfulldecryp,Samas-Samsam
.suppose665,Samas-Samsam
.Whereisyourfiles,Samas-Samsam
.sanction,Sanction
.locked,Shark
.shino,ShinoLocker
.locked,SkidLocker / Pompous
.encrypted,Smrss32
.RSNSlocked,SNSLocker
.RSplited,SNSLocker
.sport,Sport
.locked,Stampado
.locked,Strictor
.surprise,Surprise
.tzu,Surprise
.szf,SZFLocker
.xcri,TeleCrypt
.vvv,TeslaCrypt 0.x - 2.2.0
.ecc,TeslaCrypt 0.x - 2.2.0
.exx,TeslaCrypt 0.x - 2.2.0
.ezz,TeslaCrypt 0.x - 2.2.0
.abc,TeslaCrypt 0.x - 2.2.0
.aaa,TeslaCrypt 0.x - 2.2.0
.zzz,TeslaCrypt 0.x - 2.2.0
.xyz,TeslaCrypt 0.x - 2.2.0
.micro,TeslaCrypt 3.0+
.xxx,TeslaCrypt 3.0+
.ttt,TeslaCrypt 3.0+
.mp3,TeslaCrypt 3.0+
.Encrypted,TorrentLocker
.enc,TorrentLocker
.toxcrypt,Toxcrypt
.better_call_saul,Troldesh
.xtbl,Troldesh
.da_vinci_code,Troldesh
.windows10,Troldesh
.enc,TrueCrypter
.locked,Turkish Ransom
.H3LL,Ungluk
.0x0,Ungluk
.1999,Ungluk
.CRRRT,Unlock92
.CCCRRRPPP,Unlock92
.vault,VaultCrypt
.xort,VaultCrypt
.trun,VaultCrypt
.Venusf,VenusLocker
.Venusp,VenusLocker
.CrySiS,Virus-Encoder
.xtbl,Virus-Encoder
.wflx,WildFire Locker
.EnCiPhErEd,Xorist
.73i87A,Xorist
.p5tkjw,Xorist
.PoAr2w,Xorist
.fileiscryptedhard,Xorist
.encoderpass,Xorist
.zc3791,Xorist
.xrtn,XRTN
.zcrypt,Zcrypt
.crypto,Zimbra
.vault,Zlader / Russian
.zyklon,Zyklon
.wncry,WannaCry
.wcry,WannaCry
.wnry,WannaCry
.wncryt,WannaCry
.WNCRYT,WannaCry
.RYK,Ryuk
.Clop,Clop
.Cllp,Clop
.JSWORM,JSWorm
.NEMTY_*,Nemty
.NEFILIM,Nefilim
.OFFWHITE,Offwhite
.TELEGRAM,Telegram
.FUSION,Fusion
.MILIHPEN,Milihpen
.GANGBANG,Gangbang
.reddot,RedDot
.MEDUSA,Medusa
Loading

0 comments on commit 87e6cb9

Please sign in to comment.