Files

Different lists to work with the Elastic Stack without using sigma rules by https://github.com/ekitji

Guide for detection in Windows logs

  1. Download the th_keywords_elk.txt to your client where you have kibana access.

  2. Go to Alerts (documentation) https://www.elastic.co/guide/en/security/7.17/detections-ui-exceptions.html image

  3. Click on Upload Value lists image

  4. Upload your th_keywords_elk.txt (as a keyword list, which should be default selection by kibana)

  5. Go to Create Rules (Rules → Detection rules (SIEM) → Create new rule. The Create new rule )

  6. Select "Indicator Match" image

  7. NOTICE! Provided screenshot is only a example (documentation) https://www.elastic.co/guide/en/security/7.17/rules-ui-create.html#indicator-value-lists change values as shown below (number 9-14) image

  8. Source: Choose your index for where you have your windows logs

  9. Custom query: event.code (1 OR 4688)

  10. Indicator index patterns: .items-{YOUR SPACE name}

  11. Indicator index query: list_id: "th_keywords_elk.txt"

  12. Indicator mapping field: process.command_line.text

  13. Indicator index field: keyword

  14. Go on and finish your rule creating according to your routines.

You can do the same with th_keywords_processnames_elk.txt and the other files as long as the field type is text Upload it and follow the same steps, at number 12 change the list_id to th_keywords_processnames_elk.txt Then change the indicator mapping field to process.name instead (field type must be text).

Reference list rmm_domain_names_elk.txt is a custom list from https://github.com/jischell-msft/RemoteManagementMonitoringTools/blob/main/Network%20Indicators/RMM_SummaryNetworkURI.csv and from https://github.com/0x706972686f/RMM-Catalogue/blob/main/rmm.csv

Files

Observere that the field types you want to match words on must be a text field type.

creds_catcher.txt, use on process.command_line AND powershell scriptblock to catch bad password usage

rmm_domain_names_elk.txt, use on events where you have domain names to catch suspicious activity to RMM domains

suspicious_named_pipe_elk.txt, use on events with named pipes.

suspicious_windows_services_names_elk.txt, use on events with service names.

th_keywords_elk.txt, use on process.command_line AND powershell scriptblock to catch malicious activity

th_keywords_processnames_elk.txt, use on events where you have process.names OR parent.process.names

user_agent_elk.txt, use on events where you have user_agent fields to catch malicious activity