diff --git a/bin/docker_detection_tester/modules/validate_args.py b/bin/docker_detection_tester/modules/validate_args.py index 411f395e52..33742ac5a5 100644 --- a/bin/docker_detection_tester/modules/validate_args.py +++ b/bin/docker_detection_tester/modules/validate_args.py @@ -357,4 +357,4 @@ def validate(configuration: dict, skip_password_accessibility_check: bool = True except Exception as e: print("There was an error validation the configuration: [%s]" % ( str(e)), file=sys.stderr) - return None, setup_schema + return None, setup_schema \ No newline at end of file diff --git a/detections/endpoint/potential_password_in_username.yml b/detections/endpoint/potential_password_in_username.yml new file mode 100644 index 0000000000..ee672b6ca4 --- /dev/null +++ b/detections/endpoint/potential_password_in_username.yml @@ -0,0 +1,95 @@ +name: Potential password in username +id: 5ced34b4-ab32-4bb0-8f22-3b8f186f0a38 +version: 1 +date: '2022-05-11' +author: Mikael Bjerkeland, Splunk +type: Hunting +datamodel: +- Authentication +description: This search identifies users who have entered their passwords in username + fields. This is done by looking for failed authentication attempts using usernames with a length + longer than 7 characters and a high Shannon entropy, and looks for the next successful + authentication attempt from the same source system to the same destination system + as the failed attempt. +search: '| tstats `security_content_summariesonly` earliest(_time) AS starttime + latest(_time) AS endtime latest(sourcetype) AS sourcetype values(Authentication.src) AS src + values(Authentication.dest) AS dest count FROM datamodel=Authentication + WHERE nodename=Authentication.Failed_Authentication BY "Authentication.user" + | `drop_dm_object_name(Authentication)` + | lookup ut_shannon_lookup word AS user + | where ut_shannon>3 AND len(user)>=8 AND mvcount(src) == 1 + | sort count, - ut_shannon + | eval incorrect_password=user + | eval endtime=endtime+1000 + | map maxsearches=70 search="| tstats `security_content_summariesonly` + earliest(_time) AS starttime latest(_time) AS endtime latest(sourcetype) AS sourcetype + values(Authentication.src) AS src values(Authentication.dest) AS dest count + FROM datamodel=Authentication WHERE nodename=Authentication.Successful_Authentication + Authentication.src=\"$src$\" Authentication.dest=\"$dest$\" sourcetype IN (\"$sourcetype$\") + earliest=\"$starttime$\" latest=\"$endtime$\" BY \"Authentication.user\" + | `drop_dm_object_name(\"Authentication\")` + | `potential_password_in_username_false_positive_reduction` + | eval incorrect_password=\"$incorrect_password$\" + | eval ut_shannon=\"$ut_shannon$\" + | sort count" + | where user!=incorrect_password + | outlier action=RM count + | `potential_password_in_username_filter`' +how_to_implement: To successfully implement this search, you need to have relevant + authentication logs mapped to the Authentication data model. You also need to + have the Splunk TA URL Toolbox (https://splunkbase.splunk.com/app/2734/) installed. + The detection must run with a time interval shorter than endtime+1000. +known_false_positives: Valid usernames with high entropy or source/destination system pairs + with multiple authenticating users will make it difficult to identify the real user + authenticating. +references: +- https://medium.com/@markmotig/search-for-passwords-accidentally-typed-into-the-username-field-975f1a389928 +tags: + analytic_story: + - Credential Dumping + - Insider Threat + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Source:AD + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.001/password_in_username/linux_secure.log + impact: 30 + kill_chain_phases: + - Reconnaissance + message: Potential password in username ($user$) with Shannon entropy ($ut_shannon$) + mitre_attack_id: + - T1078.003 + - T1552.001 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: src + type: IP Address + role: + - Attacker + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - Authentication.user + - Authentication.src + - Authentication.dest + - sourcetype + risk_score: 21 + security_domain: access \ No newline at end of file diff --git a/macros/potential_password_in_username_false_positive_reduction.yml b/macros/potential_password_in_username_false_positive_reduction.yml new file mode 100644 index 0000000000..e8555b4f55 --- /dev/null +++ b/macros/potential_password_in_username_false_positive_reduction.yml @@ -0,0 +1,3 @@ +definition: search * +description: Add customer specific known false positives to the map command used in detection - Potential password in username +name: potential_password_in_username_false_positive_reduction \ No newline at end of file diff --git a/tests/endpoint/potential_password_in_username.test.yml b/tests/endpoint/potential_password_in_username.test.yml new file mode 100644 index 0000000000..549a08c3af --- /dev/null +++ b/tests/endpoint/potential_password_in_username.test.yml @@ -0,0 +1,12 @@ +name: Potential password in username Unit Test +tests: +- name: Potential password in username + file: endpoint/potential_password_in_username.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: linux_secure.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552.001/password_in_username/linux_secure.log + source: /var/log/secure + sourcetype: linux_secure \ No newline at end of file