From eeddaf1200778a18cd1432a3223a754c034dd268 Mon Sep 17 00:00:00 2001 From: peter-cg <682716+peter-cg@users.noreply.github.com> Date: Tue, 22 Jun 2021 09:23:48 -0500 Subject: [PATCH] Removing old, deprecated version of the parent-child-lolbas detection --- ...are_parent_process_relationship_lolbas.yml | 82 ------------------- 1 file changed, 82 deletions(-) delete mode 100644 detections/deprecated/ssa___rare_parent_process_relationship_lolbas.yml diff --git a/detections/deprecated/ssa___rare_parent_process_relationship_lolbas.yml b/detections/deprecated/ssa___rare_parent_process_relationship_lolbas.yml deleted file mode 100644 index 25c969f69c..0000000000 --- a/detections/deprecated/ssa___rare_parent_process_relationship_lolbas.yml +++ /dev/null @@ -1,82 +0,0 @@ -name: Rare Parent-Child Process Relationship -id: e03aa905-6549-4e34-b304-7a922185b2c4 -version: 1 -date: '2020-08-13' -author: Ignacio Bermudez Corrales, Splunk -type: streaming -datamodel: [] -description: An attacker may use LOLBAS tools spawned from vulnerable applications - not typically used by system administrators. This search leverages the Splunk Streaming - ML DSP plugin to find rare parent/child relationships. The list of application has - been extracted from https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval parent_process=lower(ucast(map_get(input_event, - "parent_process_name"), "string", null)), parent_process_name=mvindex(split(parent_process, - "\\"), -1), process_name=lower(ucast(map_get(input_event, "process_name"), "string", - null)), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), - dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) | where - parent_process_name!=null | select parent_process_name, process_name, timestamp, - dest_device_id, dest_user_id | conditional_anomaly conditional="parent_process_name" - target="process_name" | rename output as input | where input < 1 | adaptive_threshold - algorithm="quantile" entity="parent_process_name" window=604800000L | where label - AND quantile<0.1 AND (process_name="powershell.exe" OR process_name="regsvcs.exe" - OR process_name="ftp.exe" OR process_name="dfsvc.exe" OR process_name="rasautou.exe" - OR process_name="schtasks.exe" OR process_name="xwizard.exe" OR process_name="findstr.exe" - OR process_name="esentutl.exe" OR process_name="cscript.exe" OR process_name="reg.exe" - OR process_name="csc.exe" OR process_name="atbroker.exe" OR process_name="print.exe" - OR process_name="pcwrun.exe" OR process_name="vbc.exe" OR process_name="rpcping.exe" - OR process_name="wsreset.exe" OR process_name="ilasm.exe" OR process_name="certutil.exe" - OR process_name="replace.exe" OR process_name="mshta.exe" OR process_name="bitsadmin.exe" - OR process_name="wscript.exe" OR process_name="ieexec.exe" OR process_name="cmd.exe" - OR process_name="microsoft.workflow.compiler.exe" OR process_name="runscripthelper.exe" - OR process_name="makecab.exe" OR process_name="forfiles.exe" OR process_name="desktopimgdownldr.exe" - OR process_name="control.exe" OR process_name="msbuild.exe" OR process_name="register-cimprovider.exe" - OR process_name="tttracer.exe" OR process_name="ie4uinit.exe" OR process_name="sc.exe" - OR process_name="bash.exe" OR process_name="hh.exe" OR process_name="cmstp.exe" - OR process_name="mmc.exe" OR process_name="jsc.exe" OR process_name="scriptrunner.exe" - OR process_name="odbcconf.exe" OR process_name="extexport.exe" OR process_name="msdt.exe" - OR process_name="diskshadow.exe" OR process_name="extrac32.exe" OR process_name="eventvwr.exe" - OR process_name="mavinject.exe" OR process_name="regasm.exe" OR process_name="gpscript.exe" - OR process_name="rundll32.exe" OR process_name="regsvr32.exe" OR process_name="regedit.exe" - OR process_name="msiexec.exe" OR process_name="gfxdownloadwrapper.exe" OR process_name="presentationhost.exe" - OR process_name="regini.exe" OR process_name="wmic.exe" OR process_name="runonce.exe" - OR process_name="syncappvpublishingserver.exe" OR process_name="verclsid.exe" OR - process_name="psr.exe" OR process_name="infdefaultinstall.exe" OR process_name="explorer.exe" - OR process_name="expand.exe" OR process_name="installutil.exe" OR process_name="netsh.exe" - OR process_name="wab.exe" OR process_name="dnscmd.exe" OR process_name="at.exe" - OR process_name="pcalua.exe" OR process_name="cmdkey.exe" OR process_name="msconfig.exe") - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, - dest_user_id), body = "TBD" | into write_null();' -how_to_implement: Collect endpoint data such as sysmon or 4688 events. -known_false_positives: 'Some custom tools used by admins could be used rarely to launch - remotely applications. This might trigger false positives at the beginning when - it hasn''t collected yet enough data to construct the baseline. - - ' -references: [] -tags: - analytic_story: - - Unusual Processes - cis20: - - CIS 8 - kill_chain_phases: - - Exploitation - mitre_attack_id: - - T1203 - - T1059 - - T1053 - - T1072 - nist: - - PR.PT - - DE.CM - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - parent_process_name - - _time - - dest_device_id - - dest_user_id - risk_severity: low - security_domain: endpoint