|
133 | 133 | "Baseline Of Kubernetes Process Resource", |
134 | 134 | "Baseline Of Kubernetes Process Resource Ratio", |
135 | 135 | "Baseline Of Open S3 Bucket Decommissioning", |
| 136 | + "Baseline of Network ACL Activity by ARN", |
136 | 137 | "Baseline of S3 Bucket deletion activity by ARN", |
| 138 | + "Baseline of Security Group Activity by ARN", |
137 | 139 | "Baseline of blocked outbound traffic from AWS", |
138 | 140 | "BishopFox Sliver Adversary Emulation Framework", |
139 | 141 | "Black Basta Ransomware", |
|
216 | 218 | "ConnectWise ScreenConnect Vulnerabilities", |
217 | 219 | "Count of Unique IPs Connecting to Ports", |
218 | 220 | "Count of assets by category", |
| 221 | + "Create a list of approved AWS service accounts", |
219 | 222 | "Credential Dumping", |
220 | 223 | "Critical Alerts", |
221 | 224 | "CrowdStrike Falcon Stream Alert", |
|
227 | 230 | "DHS Report TA18-074A", |
228 | 231 | "DNS Amplification Attacks", |
229 | 232 | "DNS Hijacking", |
| 233 | + "DNSTwist Domain Names", |
230 | 234 | "DarkCrystal RAT", |
231 | 235 | "DarkGate Malware", |
232 | 236 | "DarkSide Ransomware", |
|
241 | 245 | "Detect Zerologon Attack", |
242 | 246 | "Dev Sec Ops", |
243 | 247 | "Disabling Security Tools", |
| 248 | + "Discover DNS records", |
244 | 249 | "Disk Wiper", |
245 | 250 | "Domain Trust Discovery", |
246 | 251 | "Double Zero Destructor", |
|
439 | 444 | "Previously Seen Zoom Child Processes - Initial", |
440 | 445 | "Previously Seen Zoom Child Processes - Update", |
441 | 446 | "Previously seen S3 bucket access by remote IP", |
| 447 | + "Previously seen command line arguments", |
442 | 448 | "PrintNightmare CVE-2021-34527", |
443 | 449 | "Prohibited Traffic Allowed or Protocol Mismatch", |
444 | 450 | "PromptFlux", |
|
2892 | 2898 | "Baseline Of Kubernetes Process Resource", |
2893 | 2899 | "Baseline Of Kubernetes Process Resource Ratio", |
2894 | 2900 | "Baseline Of Open S3 Bucket Decommissioning", |
| 2901 | + "Baseline of Network ACL Activity by ARN", |
2895 | 2902 | "Baseline of S3 Bucket deletion activity by ARN", |
| 2903 | + "Baseline of Security Group Activity by ARN", |
2896 | 2904 | "Baseline of blocked outbound traffic from AWS", |
2897 | 2905 | "Count of Unique IPs Connecting to Ports", |
2898 | 2906 | "Count of assets by category", |
| 2907 | + "Create a list of approved AWS service accounts", |
| 2908 | + "DNSTwist Domain Names", |
| 2909 | + "Discover DNS records", |
2899 | 2910 | "Identify Systems Creating Remote Desktop Traffic", |
2900 | 2911 | "Identify Systems Receiving Remote Desktop Traffic", |
2901 | 2912 | "Identify Systems Using Remote Desktop", |
|
2920 | 2931 | "Previously Seen Zoom Child Processes - Initial", |
2921 | 2932 | "Previously Seen Zoom Child Processes - Update", |
2922 | 2933 | "Previously seen S3 bucket access by remote IP", |
| 2934 | + "Previously seen command line arguments", |
2923 | 2935 | "Windows Updates Install Failures", |
2924 | 2936 | "Windows Updates Install Successes" |
2925 | 2937 | ], |
|
0 commit comments