modifying existing detections and adding new

This commit is contained in:
mvelazco
2022-09-22 15:00:21 -04:00
parent bff89c6a92
commit 109bf5e707
24 changed files with 807 additions and 82 deletions
@@ -1,28 +1,24 @@
name: Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos
id: 98f22d82-9d62-11eb-9fcf-acde48001122
version: 1
version: 2
date: '2021-04-14'
author: Mauricio Velazco, Splunk
type: Anomaly
type: TTP
datamodel: []
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple disabled domain users using the Kerberos protocol. This behavior could
with 30 unique disabled domain users using the Kerberos protocol within 5 minutes. This behavior could
represent an adversary performing a Password Spraying attack against an Active Directory
environment using Kerberos to obtain initial access or elevate privileges. As attackers
environment using Kerberos to obtain initial access or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
As attackers
progress in a breach, mistakes will be made. In certain scenarios, adversaries may
execute a password spraying attack against disabled users. Event 4768 is generated
every time the Key Distribution Center issues a Kerberos Ticket Granting Ticket
(TGT). Failure code `0x12` stands for `clients credentials have been revoked` (account
disabled, expired or locked out).\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This detection will only trigger on domain controllers, not on member servers or
workstations.\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will only trigger on domain controllers, not on member servers or workstations.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source ip and attempted user accounts.'
@@ -1,26 +1,23 @@
name: Windows Multiple Invalid Users Fail To Authenticate Using Kerberos
id: 001266a6-9d5b-11eb-829b-acde48001122
version: 1
version: 2
date: '2021-04-14'
author: Mauricio Velazco, Splunk
type: Anomaly
type: TTP
datamodel: []
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple invalid domain users using the Kerberos protocol. This behavior could
with 30 unique invalid domain users using the Kerberos protocol. This behavior could
represent an adversary performing a Password Spraying attack against an Active Directory
environment using Kerberos to obtain initial access or elevate privileges. As attackers
environment using Kerberos to obtain initial access or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
As attackers
progress in a breach, mistakes will be made. In certain scenarios, adversaries may
execute a password spraying attack using an invalid list of users. Event 4768 is
generated every time the Key Distribution Center issues a Kerberos Ticket Granting
Ticket (TGT). Failure code 0x6 stands for `client not found in Kerberos database`
(the attempted user is not a valid domain user).\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will only trigger on domain controllers, not on member servers or
workstations.\
@@ -1,14 +1,16 @@
name: Windows Multiple Invalid Users Failed To Authenticate Using NTLM
id: 57ad5a64-9df7-11eb-a290-acde48001122
version: 1
version: 2
date: '2021-04-15'
author: Mauricio Velazco, Splunk
type: Anomaly
type: TTP
datamodel: []
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple invalid users using the NTLM protocol. This behavior could represent
with 30 unique invalid users using the NTLM protocol. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
using NTLM to obtain initial access or elevate privileges. As attackers progress
using NTLM to obtain initial access or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
As attackers progress
in a breach, mistakes will be made. In certain scenarios, adversaries may execute
a password spraying attack using an invalid list of users. Event 4776 is generated
on the computer that is authoritative for the provided credentials. For domain accounts,
@@ -16,12 +18,7 @@ description: 'The following analytic identifies one source endpoint failing to a
authoritative. Error code 0xC0000064 stands for `The username you typed does not
exist` (the attempted user is a legitimate domain user).\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will only trigger on domain controllers, not on member servers or
workstations.\
@@ -1,23 +1,20 @@
name: Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials
id: e61918fa-9ca4-11eb-836c-acde48001122
version: 1
version: 2
date: '2021-04-13'
author: Mauricio Velazco, Splunk
type: Anomaly
type: TTP
datamodel: []
description: 'The following analytic identifies a source user failing to authenticate
with multiple users using explicit credentials on a host. This behavior could represent
with 30 unique users using explicit credentials on a host. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
to obtain initial access or elevate privileges. Event 4648 is generated when a process
to obtain initial access or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
Event 4648 is generated when a process
attempts an account logon by explicitly specifying that accounts credentials. This
event generates on domain controllers, member servers, and workstations.\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will trigger on the potenfially malicious host, perhaps controlled
via a trojan or operated by an insider threat, from where a password spraying attack
is being executed.\
@@ -1,25 +1,22 @@
name: Windows Multiple Users Failed To Authenticate From Host Using NTLM
id: 7ed272a4-9c77-11eb-af22-acde48001122
version: 1
version: 2
date: '2021-04-13'
author: Mauricio Velazco, Splunk
type: Anomaly
type: TTP
datamodel: []
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple valid users using the NTLM protocol. This behavior could represent
with 30 unique valid users using the NTLM protocol. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
using NTLM to obtain initial access or elevate privileges. Event 4776 is generated
using NTLM to obtain initial access or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
Event 4776 is generated
on the computer that is authoritative for the provided credentials. For domain accounts,
the domain controller is authoritative. For local accounts, the local computer is
authoritative. Error code 0xC000006A means: misspelled or bad password (the attempted
user is a legitimate domain user).\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will only trigger on domain controllers, not on member servers or
workstations.\
@@ -1,23 +1,20 @@
name: Windows Multiple Users Failed To Authenticate From Process
id: 9015385a-9c84-11eb-bef2-acde48001122
version: 1
version: 2
date: '2021-04-13'
author: Mauricio Velazco, Splunk
type: Anomaly
type: TTP
datamodel: []
description: 'The following analytic identifies a source process name failing to authenticate
with multiple users. This behavior could represent an adversary performing a Password
with 30 uniquer users. This behavior could represent an adversary performing a Password
Spraying attack against an Active Directory environment to obtain initial access
or elevate privileges. Event 4625 generates on domain controllers, member servers,
or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
Event 4625 generates on domain controllers, member servers,
and workstations when an account fails to logon. Logon Type 2 describes an iteractive
logon attempt.\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will trigger on the potenfially malicious host, perhaps controlled
via a trojan or operated by an insider threat, from where a password spraying attack
is being executed. This could be a domain controller as well as a member server
@@ -1,24 +1,21 @@
name: Windows Multiple Users Failed To Authenticate Using Kerberos
id: 3a91a212-98a9-11eb-b86a-acde48001122
version: 1
version: 2
date: '2021-04-08'
author: Mauricio Velazco, Splunk
type: Anomaly
type: TTP
datamodel: []
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple valid users using the Kerberos protocol. This behavior could represent
with 30 unique users using the Kerberos protocol. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
using Kerberos to obtain initial access or elevate privileges. Event 4771 is generated
using Kerberos to obtain initial access or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
Event 4771 is generated
when the Key Distribution Center fails to issue a Kerberos Ticket Granting Ticket
(TGT). Failure code 0x18 stands for `wrong password provided` (the attempted user
is a legitimate domain user).\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will only trigger on domain controllers, not on member servers or
workstations.\
@@ -1,24 +1,21 @@
name: Windows Multiple Users Remotely Failed To Authenticate From Host
id: 80f9d53e-9ca1-11eb-b0d6-acde48001122
version: 1
version: 2
date: '2021-04-13'
author: Mauricio Velazco, Splunk
type: Anomaly
type: TTP
datamodel: []
description: 'The following analytic identifies a source host failing to authenticate
against a remote host with multiple users. This behavior could represent an adversary
against a remote host with 30 unique users. This behavior could represent an adversary
performing a Password Spraying attack against an Active Directory environment to
obtain initial access or elevate privileges. Event 4625 documents each and every
obtain initial access or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
Event 4625 documents each and every
failed attempt to logon to the local computer. This event generates on domain controllers,
member servers, and workstations. Logon Type 3 describes an remote authentication
attempt.\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will trigger on the host that is the target of the password spraying
attack. This could be a domain controller as well as a member server or workstation.\
@@ -0,0 +1,80 @@
name: Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos
id: f65aa026-b811-42ab-b4b9-d9088137648f
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
type: Anomaly
datamodel: []
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple disabled domain users using the Kerberos protocol. This behavior could
represent an adversary performing a Password Spraying attack against an Active Directory
environment using Kerberos to obtain initial access or elevate privileges. As attackers
progress in a breach, mistakes will be made. In certain scenarios, adversaries may
execute a password spraying attack against disabled users. Event 4768 is generated
every time the Key Distribution Center issues a Kerberos Ticket Granting Ticket
(TGT). Failure code `0x12` stands for `clients credentials have been revoked` (account
disabled, expired or locked out).\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This detection will only trigger on domain controllers, not on member servers or
workstations.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source ip and attempted user accounts.'
search: '`wineventlog_security` EventCode=4768 Account_Name!="*$" Result_Code=0x12
| bucket span=2m _time | stats dc(Account_Name) AS unique_accounts values(Account_Name)
as tried_accounts by _time, Client_Address | eventstats avg(unique_accounts) as
comp_avg , stdev(unique_accounts) as comp_std by Client_Address | eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1 | `windows_disabled_users_failing_to_authenticate_kerberos_filter` '
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
known_false_positives: A host failing to authenticate with multiple disabled domain
users is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners, multi-user systems missconfigured
systems.
references:
- https://attack.mitre.org/techniques/T1110/003/
tags:
analytic_story:
- Active Directory Password Spraying
- Active Directory Kerberos Attacks
automated_detection_testing: passed
confidence: 70
context:
- Source:Endpoint
- Stage:Initial Access
- Stage:Privilege Escalation
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_disabled_users_kerberos_xml/windows-security.log
impact: 70
kill_chain_phases:
- Exploitation
message: Potential Kerberos based password spraying attack from $Client_Address$
mitre_attack_id:
- T1110.003
- T1110
observable:
- name: Client_Address
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- Result_Code
- Account_Name
- Client_Address
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
@@ -0,0 +1,80 @@
name: Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos
id: f122cb2e-d773-4f11-8399-62a3572d8dd7
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
type: Anomaly
datamodel: []
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple invalid domain users using the Kerberos protocol. This behavior could
represent an adversary performing a Password Spraying attack against an Active Directory
environment using Kerberos to obtain initial access or elevate privileges. As attackers
progress in a breach, mistakes will be made. In certain scenarios, adversaries may
execute a password spraying attack using an invalid list of users. Event 4768 is
generated every time the Key Distribution Center issues a Kerberos Ticket Granting
Ticket (TGT). Failure code 0x6 stands for `client not found in Kerberos database`
(the attempted user is not a valid domain user).\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This detection will only trigger on domain controllers, not on member servers or
workstations.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source ip and attempted user accounts.'
search: '`wineventlog_security` EventCode=4768 Result_Code=0x6 Account_Name!="*$"
| bucket span=2m _time | stats dc(Account_Name) AS unique_accounts values(Account_Name)
as tried_accounts by _time, Client_Address | eventstats avg(unique_accounts) as
comp_avg , stdev(unique_accounts) as comp_std by Client_Address | eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1 | `windows_invalid_users_failed_authentication_via_kerberos_filter` '
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
known_false_positives: A host failing to authenticate with multiple invalid domain
users is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners, multi-user systems and missconfigured
systems.
references:
- https://attack.mitre.org/techniques/T1110/003/
tags:
analytic_story:
- Active Directory Password Spraying
- Active Directory Kerberos Attacks
automated_detection_testing: passed
confidence: 70
context:
- Source:Endpoint
- Stage:Initial Access
- Stage:Privilege Escalation
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos_xml/windows-security.log
impact: 70
kill_chain_phases:
- Exploitation
message: Potential Kerberos based password spraying attack from $Client_Address$
mitre_attack_id:
- T1110.003
- T1110
observable:
- name: Client_Address
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- Result_Code
- Account_Name
- Client_Address
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
@@ -0,0 +1,82 @@
name: Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM
id: 15603165-147d-4a6e-9778-bd0ff39e668f
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
type: Anomaly
datamodel: []
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple invalid users using the NTLM protocol. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
using NTLM to obtain initial access or elevate privileges. As attackers progress
in a breach, mistakes will be made. In certain scenarios, adversaries may execute
a password spraying attack using an invalid list of users. Event 4776 is generated
on the computer that is authoritative for the provided credentials. For domain accounts,
the domain controller is authoritative. For local accounts, the local computer is
authoritative. Error code 0xC0000064 stands for `The username you typed does not
exist` (the attempted user is a legitimate domain user).\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This detection will only trigger on domain controllers, not on member servers or
workstations.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source workstation name and attempted user accounts.'
search: ' `wineventlog_security` EventCode=4776 Logon_Account!="*$" 0xC0000064 action=failure
| bucket span=2m _time | stats dc(Logon_Account) AS unique_accounts values(Logon_Account)
as tried_accounts by _time, Source_Workstation | eventstats avg(unique_accounts)
as comp_avg , stdev(unique_accounts) as comp_std by Source_Workstation | eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1 | `windows_multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller events. The Advanced Security Audit policy setting `Audit Credential
Validation' within `Account Logon` needs to be enabled.
known_false_positives: A host failing to authenticate with multiple invalid domain
users is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners and missconfigured systems.
If this detection triggers on a host other than a Domain Controller, the behavior
could represent a password spraying attack against the host's local accounts.
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776
tags:
analytic_story:
- Active Directory Password Spraying
confidence: 70
context:
- Source:Endpoint
- Stage:Initial Access
- Stage:Privilege Escalation
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_ntlm_xml/windows-security.log
impact: 70
kill_chain_phases:
- Exploitation
message: Potential NTLM based password spraying attack from $Source_Workstation$
mitre_attack_id:
- T1110.003
- T1110
observable:
- name: Source_Workstation
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- action
- Logon_Account
- Source_Workstation
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
@@ -0,0 +1,84 @@
name: Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials
id: 14f414cf-3080-4b9b-aaf6-55a4ce947b93
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
type: Anomaly
datamodel: []
description: 'The following analytic identifies a source user failing to authenticate
with multiple users using explicit credentials on a host. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
to obtain initial access or elevate privileges. Event 4648 is generated when a process
attempts an account logon by explicitly specifying that accounts credentials. This
event generates on domain controllers, member servers, and workstations.\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This detection will trigger on the potenfially malicious host, perhaps controlled
via a trojan or operated by an insider threat, from where a password spraying attack
is being executed.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source account, attempted user accounts and the endpoint were
the behavior was identified.'
search: ' `wineventlog_security` EventCode=4648 | bucket span=2m _time | eval Source_Account
= mvindex(Account_Name, 0) | eval Destination_Account = mvindex(Account_Name, 1)
| search Source_Account != "*$" Source_Account !="-" Destination_Account !="*$"
| stats dc(Destination_Account) AS unique_accounts values(Destination_Account) as
tried_account by _time, ComputerName, Source_Account | eventstats avg(unique_accounts)
as comp_avg , stdev(unique_accounts) as comp_std by ComputerName | eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1 | `windows_users_authenticate_using_explicit_credentials_filter` '
how_to_implement: To successfully implement this search, you need to be ingesting
Windows Event Logs from domain controllers as well as member servers and workstations.
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
to be enabled.
known_false_positives: A source user failing attempting to authenticate multiple users
on a host is not a common behavior for regular systems. Some applications, however,
may exhibit this behavior in which case sets of users hosts can be added to an allow
list. Possible false positive scenarios include systems where several users connect
to like Mail servers, identity providers, remote desktop services, Citrix, etc.
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
tags:
analytic_story:
- Active Directory Password Spraying
- Insider Threat
confidence: 70
context:
- Source:Endpoint
- Stage:Initial Access
- Stage:Privilege Escalation
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_explicit_credential_spray_xml/windows-security.log
impact: 70
kill_chain_phases:
- Exploitation
message: Potential password spraying attack from $ComputerName$
mitre_attack_id:
- T1110.003
- T1110
observable:
- name: ComputerName
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- Security_ID
- Account_Name
- ComputerName
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
@@ -0,0 +1,80 @@
name: Windows Unusual Count Of Users Failed To Auth Using Kerberos
id: bc9cb715-08ba-40c3-9758-6e2b26e455cb
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
type: Anomaly
datamodel: []
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple valid users using the Kerberos protocol. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
using Kerberos to obtain initial access or elevate privileges. Event 4771 is generated
when the Key Distribution Center fails to issue a Kerberos Ticket Granting Ticket
(TGT). Failure code 0x18 stands for `wrong password provided` (the attempted user
is a legitimate domain user).\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This detection will only trigger on domain controllers, not on member servers or
workstations.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source ip and attempted user accounts.'
search: '`wineventlog_security` EventCode=4771 Failure_Code=0x18 Account_Name!="*$"
| bucket span=2m _time | stats dc(Account_Name) AS unique_accounts values(Account_Name)
as tried_accounts by _time, Client_Address | eventstats avg(unique_accounts) as
comp_avg , stdev(unique_accounts) as comp_std by Client_Address | eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1 | `multiple_users_failing_to_authenticate_from_host_using_kerberos_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
known_false_positives: A host failing to authenticate with multiple valid domain users
is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners, missconfigured systems and
multi-user systems like Citrix farms.
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn319109(v=ws.11)
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4771
tags:
analytic_story:
- Active Directory Password Spraying
- Active Directory Kerberos Attacks
automated_detection_testing: passed
confidence: 70
context:
- Source:Endpoint
- Stage:Initial Access
- Stage:Privilege Escalation
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_kerberos_xml/windows-security.log
impact: 70
kill_chain_phases:
- Exploitation
message: Potential Kerberos based password spraying attack from $Client_Address$
mitre_attack_id:
- T1110.003
- T1110
observable:
- name: Client_Address
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- Result_Code
- Account_Name
- Client_Address
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
@@ -0,0 +1,85 @@
name: Windows Unusual Count Of Users Failed To Authenticate From Process
id: 25bdb6cb-2e49-4d34-a93c-d6c567c122fe
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
type: Anomaly
datamodel: []
description: 'The following analytic identifies a source process name failing to authenticate
with multiple users. This behavior could represent an adversary performing a Password
Spraying attack against an Active Directory environment to obtain initial access
or elevate privileges. Event 4625 generates on domain controllers, member servers,
and workstations when an account fails to logon. Logon Type 2 describes an iteractive
logon attempt.\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This detection will trigger on the potenfially malicious host, perhaps controlled
via a trojan or operated by an insider threat, from where a password spraying attack
is being executed. This could be a domain controller as well as a member server
or workstation.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source process name, source account and attempted user accounts.'
search: ' `wineventlog_security` EventCode=4625 Logon_Type=2 Caller_Process_Name!="-"
| bucket span=2m _time | eval Source_Account = mvindex(Account_Name, 0) | eval Destination_Account
= mvindex(Account_Name, 1) | stats dc(Destination_Account) AS unique_accounts values(Account_Name)
as tried_accounts by _time, Caller_Process_Name, Source_Account, ComputerName |
eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std
by Caller_Process_Name, Source_Account, ComputerName | eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1 | `multiple_users_failing_to_authenticate_from_process_filter` '
how_to_implement: To successfully implement this search, you need to be ingesting
Windows Event Logs from domain controllers aas well as member servers and workstations.
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
to be enabled.
known_false_positives: A process failing to authenticate with multiple users is not
a common behavior for legitimate user sessions. Possible false positive scenarios
include but are not limited to vulnerability scanners and missconfigured systems.
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
tags:
analytic_story:
- Active Directory Password Spraying
- Insider Threat
confidence: 70
context:
- Source:Endpoint
- Stage:Initial Access
- Stage:Privilege Escalation
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_multiple_users_from_process_xml/windows-security.log
impact: 70
kill_chain_phases:
- Exploitation
message: Potential password spraying attack from $ComputerName$
mitre_attack_id:
- T1110.003
- T1110
observable:
- name: ComputerName
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- Logon_Type
- Caller_Process_Name
- Security_ID
- Account_Name
- ComputerName
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
@@ -0,0 +1,80 @@
name: Windows Unusual Count Of Users Failed To Authenticate Using NTLM
id: 6f6c8fd7-6a6b-4af9-a0e9-57cfc47a58b4
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
type: Anomaly
datamodel: []
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple valid users using the NTLM protocol. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
using NTLM to obtain initial access or elevate privileges. Event 4776 is generated
on the computer that is authoritative for the provided credentials. For domain accounts,
the domain controller is authoritative. For local accounts, the local computer is
authoritative. Error code 0xC000006A means: misspelled or bad password (the attempted
user is a legitimate domain user).\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This detection will only trigger on domain controllers, not on member servers or
workstations.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source workstation name and attempted user accounts.'
search: ' `wineventlog_security` EventCode=4776 Logon_Account!="*$" 0xC000006A action=failure
| bucket span=2m _time | stats dc(Logon_Account) AS unique_accounts values(Logon_Account)
as tried_accounts by _time, Source_Workstation | eventstats avg(unique_accounts)
as comp_avg , stdev(unique_accounts) as comp_std by Source_Workstation | eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1 | `multiple_users_failing_to_authenticate_from_host_using_ntlm_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller events. The Advanced Security Audit policy setting `Audit Credential
Validation` within `Account Logon` needs to be enabled.
known_false_positives: A host failing to authenticate with multiple valid domain users
is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners and missconfigured systems.
If this detection triggers on a host other than a Domain Controller, the behavior
could represent a password spraying attack against the host's local accounts.
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776
tags:
analytic_story:
- Active Directory Password Spraying
confidence: 70
context:
- Source:Endpoint
- Stage:Initial Access
- Stage:Privilege Escalation
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_ntlm_xml/windows-security.log
impact: 70
kill_chain_phases:
- Exploitation
message: Potential NTLM based password spraying attack from $Source_Workstation$
mitre_attack_id:
- T1110.003
- T1110
observable:
- name: Source_Workstation
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- action
- Logon_Account
- Source_Workstation
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
@@ -0,0 +1,83 @@
name: Windows Unusual Count Of Users Remotely Failed To Auth From Host
id: cf06a0ee-ffa9-4ed3-be77-0670ed9bab52
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
type: Anomaly
datamodel: []
description: 'The following analytic identifies a source host failing to authenticate
against a remote host with multiple users. This behavior could represent an adversary
performing a Password Spraying attack against an Active Directory environment to
obtain initial access or elevate privileges. Event 4625 documents each and every
failed attempt to logon to the local computer. This event generates on domain controllers,
member servers, and workstations. Logon Type 3 describes an remote authentication
attempt.\
The detection calculates the standard deviation for each host and leverages the
3-sigma statistical rule to identify an unusual number of users. To customize this
analytic, users can try different combinations of the `bucket` span time and the
calculation of the `upperBound` field. This logic can be used for real time security
monitoring as well as threat hunting exercises.\
This detection will trigger on the host that is the target of the password spraying
attack. This could be a domain controller as well as a member server or workstation.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source process name, source account and attempted user accounts.'
search: ' `wineventlog_security` EventCode=4625 Logon_Type=3 Source_Network_Address!="-"
| bucket span=2m _time | eval Destination_Account = mvindex(Account_Name, 1) | stats
dc(Destination_Account) AS unique_accounts values(Destination_Account) as tried_accounts
by _time, Source_Network_Address, ComputerName | eventstats avg(unique_accounts)
as comp_avg , stdev(unique_accounts) as comp_std by Source_Network_Address, ComputerName
| eval upperBound=(comp_avg+comp_std*3) | eval isOutlier=if(unique_accounts > 10
and unique_accounts >= upperBound, 1, 0) | search isOutlier=1 | `multiple_users_remotely_failing_to_authenticate_from_host_filter` '
how_to_implement: To successfully implement this search, you need to be ingesting
Windows Event Logs from domain controllers as as well as member servers and workstations.
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
to be enabled.
known_false_positives: A host failing to authenticate with multiple valid users against
a remote host is not a common behavior for legitimate systems. Possible false positive
scenarios include but are not limited to vulnerability scanners, remote administration
tools, missconfigyred systems, etc.
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
tags:
analytic_story:
- Active Directory Password Spraying
confidence: 70
context:
- Source:Endpoint
- Stage:Initial Access
- Stage:Privilege Escalation
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_remote_spray_xml/windows-security.log
impact: 70
kill_chain_phases:
- Exploitation
message: Potential password spraying attack on $ComputerName$
mitre_attack_id:
- T1110.003
- T1110
observable:
- name: ComputerName
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- Logon_Type
- Security_ID
- Account_Name
- ComputerName
- Source_Network_Address
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
@@ -0,0 +1,12 @@
name: Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos Unit Test
tests:
- name: Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos
file: endpoint/windows_unusual_count_of_disabled_users_failed_to_auth_using_kerberos.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_disabled_users_kerberos_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
@@ -0,0 +1,12 @@
name: Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos Unit Test
tests:
- name: Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos
file: endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
@@ -0,0 +1,12 @@
name: Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM Unit Test
tests:
- name: Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM
file: endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_ntlm_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
@@ -0,0 +1,12 @@
name: Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials Unit Test
tests:
- name: Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials
file: endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_explicit_credential_spray_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
@@ -0,0 +1,12 @@
name: Windows Unusual Count Of Users Failed To Auth Using Kerberos Unit Test
tests:
- name: Windows Unusual Count Of Users Failed To Auth Using Kerberos
file: endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_kerberos_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
@@ -0,0 +1,12 @@
name: Windows Unusual Count Of Users Failed To Authenticate From Process Unit Test
tests:
- name: Windows Unusual Count Of Users Failed To Authenticate From Process
file: endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_multiple_users_from_process_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
@@ -0,0 +1,12 @@
name: Windows Unusual Count Of Users Failed To Authenticate Using NTLM Unit Test
tests:
- name: Windows Unusual Count Of Users Failed To Authenticate Using NTLM
file: endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_ntlm_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
@@ -0,0 +1,12 @@
name: Windows Unusual Count Of Users Remotely Failed To Auth From Host Unit Test
tests:
- name: Windows Unusual Count Of Users Remotely Failed To Auth From Host
file: endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_remote_spray_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog