Skip to content

Commit b6b0b47

Browse files
MHaggisnasbenchpatel-bhavin
authored
Storm-0501 Ransomware Analytic Story and Tagging (#3871)
--------- Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com> Co-authored-by: Bhavin Patel <bpatel@splunk.com>
1 parent d08d829 commit b6b0b47

15 files changed

Lines changed: 117 additions & 56 deletions

detections/cloud/azure_ad_new_federated_domain_added.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Azure AD New Federated Domain Added
22
id: a87cd633-076d-4ab2-9047-977751a3c1a0
3-
version: 10
4-
date: '2025-10-14'
3+
version: 11
4+
date: '2026-01-20'
55
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
66
status: production
77
type: TTP
@@ -62,6 +62,7 @@ tags:
6262
- Azure Active Directory Persistence
6363
- Scattered Lapsus$ Hunters
6464
- Hellcat Ransomware
65+
- Storm-0501 Ransomware
6566
asset_type: Azure Active Directory
6667
mitre_attack_id:
6768
- T1484.002

detections/cloud/azure_ad_privileged_role_assigned.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Azure AD Privileged Role Assigned
22
id: a28f0bc3-3400-4a6e-a2da-89b9e95f0d2a
3-
version: 11
4-
date: '2025-10-14'
3+
version: 12
4+
date: '2026-01-20'
55
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
66
status: production
77
type: TTP
@@ -69,6 +69,7 @@ tags:
6969
- Azure Active Directory Persistence
7070
- NOBELIUM Group
7171
- Scattered Lapsus$ Hunters
72+
- Storm-0501 Ransomware
7273
asset_type: Azure Active Directory
7374
mitre_attack_id:
7475
- T1098.003

detections/endpoint/common_ransomware_notes.yml

Lines changed: 14 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -52,19 +52,20 @@ known_false_positives: |
5252
references: []
5353
tags:
5454
analytic_story:
55-
- Chaos Ransomware
56-
- Rhysida Ransomware
57-
- Ransomware
58-
- LockBit Ransomware
59-
- Medusa Ransomware
60-
- SamSam Ransomware
61-
- Clop Ransomware
62-
- Ryuk Ransomware
63-
- Black Basta Ransomware
64-
- Termite Ransomware
65-
- Interlock Ransomware
66-
- NailaoLocker Ransomware
67-
- Hellcat Ransomware
55+
- Chaos Ransomware
56+
- Rhysida Ransomware
57+
- Ransomware
58+
- LockBit Ransomware
59+
- Medusa Ransomware
60+
- SamSam Ransomware
61+
- Clop Ransomware
62+
- Ryuk Ransomware
63+
- Black Basta Ransomware
64+
- Termite Ransomware
65+
- Interlock Ransomware
66+
- NailaoLocker Ransomware
67+
- Hellcat Ransomware
68+
- Storm-0501 Ransomware
6869
asset_type: Endpoint
6970
mitre_attack_id:
7071
- T1485

detections/endpoint/detect_psexec_with_accepteula_flag.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Detect PsExec With accepteula Flag
22
id: 27c3a83d-cada-47c6-9042-67baf19d2574
3-
version: 14
4-
date: '2025-12-15'
3+
version: 15
4+
date: '2026-01-22'
55
author: Bhavin Patel, Splunk
66
status: production
77
type: TTP
@@ -95,6 +95,7 @@ tags:
9595
- Volt Typhoon
9696
- Seashell Blizzard
9797
- VanHelsing Ransomware
98+
- Storm-0501 Ransomware
9899
asset_type: Endpoint
99100
mitre_attack_id:
100101
- T1021.002

detections/endpoint/detect_rclone_command_line_usage.yml

Lines changed: 9 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Detect RClone Command-Line Usage
22
id: 32e0baea-b3f1-11eb-a2ce-acde48001122
3-
version: 15
4-
date: '2025-12-15'
3+
version: 16
4+
date: '2026-01-20'
55
author: Michael Haag, Splunk
66
status: production
77
type: TTP
@@ -89,12 +89,13 @@ rba:
8989
type: process_name
9090
tags:
9191
analytic_story:
92-
- Hellcat Ransomware
93-
- DarkSide Ransomware
94-
- Ransomware
95-
- Black Basta Ransomware
96-
- Cactus Ransomware
97-
- Cisco Network Visibility Module Analytics
92+
- Storm-0501 Ransomware
93+
- Hellcat Ransomware
94+
- DarkSide Ransomware
95+
- Ransomware
96+
- Black Basta Ransomware
97+
- Cactus Ransomware
98+
- Cisco Network Visibility Module Analytics
9899
asset_type: Endpoint
99100
mitre_attack_id:
100101
- T1020

detections/endpoint/detect_remote_access_software_usage_process.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Detect Remote Access Software Usage Process
22
id: ffd5e001-2e34-48f4-97a2-26dc4bb08178
3-
version: 12
4-
date: '2025-10-14'
3+
version: 13
4+
date: '2026-01-20'
55
author: Steven Dick, Sebastian Wurl, Splunk Community
66
status: production
77
type: Anomaly
@@ -106,6 +106,7 @@ tags:
106106
- Interlock Ransomware
107107
- GhostRedirector IIS Module and Rungan Backdoor
108108
- Scattered Lapsus$ Hunters
109+
- Storm-0501 Ransomware
109110
asset_type: Endpoint
110111
mitre_attack_id:
111112
- T1219

detections/endpoint/disable_windows_behavior_monitoring.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Disable Windows Behavior Monitoring
22
id: 79439cae-9200-11eb-a4d3-acde48001122
3-
version: 17
4-
date: '2025-11-20'
3+
version: 18
4+
date: '2026-01-20'
55
author: Teoderick Contreras, Splunk, Steven Dick
66
status: production
77
type: TTP
@@ -70,6 +70,7 @@ tags:
7070
- Cactus Ransomware
7171
- Scattered Lapsus$ Hunters
7272
- NetSupport RMM Tool Abuse
73+
- Storm-0501 Ransomware
7374
asset_type: Endpoint
7475
mitre_attack_id:
7576
- T1562.001

detections/endpoint/impacket_lateral_movement_commandline_parameters.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Impacket Lateral Movement Commandline Parameters
22
id: 8ce07472-496f-11ec-ab3b-3e22fbd008af
3-
version: 10
4-
date: '2025-05-02'
3+
version: 11
4+
date: '2026-01-20'
55
author: Mauricio Velazco, Splunk
66
status: production
77
type: TTP
@@ -84,6 +84,7 @@ tags:
8484
- Graceful Wipe Out Attack
8585
- Compromised Windows Host
8686
- CISA AA22-277A
87+
- Storm-0501 Ransomware
8788
asset_type: Endpoint
8889
mitre_attack_id:
8990
- T1021.002

detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Impacket Lateral Movement WMIExec Commandline Parameters
22
id: d6e464e4-5c6a-474e-82d2-aed616a3a492
3-
version: 8
4-
date: '2025-05-02'
3+
version: 9
4+
date: '2026-01-20'
55
author: Michael Haag, Splunk
66
status: production
77
type: TTP
@@ -83,6 +83,7 @@ tags:
8383
- Graceful Wipe Out Attack
8484
- Compromised Windows Host
8585
- CISA AA22-277A
86+
- Storm-0501 Ransomware
8687
asset_type: Endpoint
8788
atomic_guid: []
8889
mitre_attack_id:

detections/endpoint/nltest_domain_trust_discovery.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: NLTest Domain Trust Discovery
22
id: c3e05466-5f22-11eb-ae93-0242ac130002
3-
version: 9
4-
date: '2025-12-18'
3+
version: 10
4+
date: '2026-01-20'
55
author: Michael Haag, Splunk
66
status: production
77
type: TTP
@@ -78,6 +78,7 @@ tags:
7878
- Rhysida Ransomware
7979
- IcedID
8080
- Ryuk Ransomware
81+
- Storm-0501 Ransomware
8182
asset_type: Endpoint
8283
mitre_attack_id:
8384
- T1482

0 commit comments

Comments
 (0)