{"id":"547dfc53-ebf6-4afe-8d2e-793d9574975d","title":"OpenCanary - REDIS Action Command Attempt","description":"Detects instances where a REDIS service on an OpenCanary node has had an action command attempted.","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":"","tags":["attack.credential-access","attack.collection","attack.t1003","attack.t1213"],"technique_ids":["T1003","T1213"],"logsource":{"category":"application","product":"opencanary"},"falsepositives":["Unlikely"],"references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"source_path":"rules/application/opencanary/opencanary_redis_command.yml","source_sha256":"1785801f8142f9d42c46b6720a33491fcead0a4f100fef1ee8f5c988079f247d","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/application/opencanary/opencanary_redis_command.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: OpenCanary - REDIS Action Command Attempt\nid: 547dfc53-ebf6-4afe-8d2e-793d9574975d\nstatus: test\ndescription: Detects instances where a REDIS service on an OpenCanary node has had an action command attempted.\nreferences:\n    - https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration\n    - https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52\nauthor: Security Onion Solutions\ndate: 2024-03-08\ntags:\n    - attack.credential-access\n    - attack.collection\n    - attack.t1003\n    - attack.t1213\nlogsource:\n    category: application\n    product: opencanary\ndetection:\n    selection:\n        logtype: 17001\n    condition: selection\nfalsepositives:\n    - Unlikely\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1003","id":"T1003","name":"OS Credential Dumping","page":"techniques/enterprise/T1003/"},{"key":"enterprise/T1213","id":"T1213","name":"Data from Information Repositories","page":"techniques/enterprise/T1213/"}],"data_path":"data/detection-rules/547dfc53-ebf6-4afe-8d2e-793d9574975d.json","kind":"sigma"}
