mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
+1
-1
@@ -3,7 +3,7 @@ id: 21276daa-663d-11eb-ae93-0242ac130002
|
||||
version: 1
|
||||
date: '2021-02-01'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
type: Hunting
|
||||
datamodel: []
|
||||
description: 'Detect a renamed instance of procdump.exe dumping the lsass process.
|
||||
This query looks for both -mm and -ma usage. -mm will produce a mini dump file and
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Account Discovery With Net App
|
||||
id: 339805ce-ac30-11eb-b87d-acde48001122
|
||||
version: 1
|
||||
date: '2021-05-03'
|
||||
version: 3
|
||||
date: '2021-09-16'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
@@ -16,15 +16,15 @@ description: this search is to detect a potential account discovery series of co
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
values(Processes.parent_process) as parent_process values(Processes.process_id)
|
||||
as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.process_name="net.exe" OR Processes.process_name="net1.exe" AND
|
||||
(Processes.process="*user*" OR Processes.process="*config*" OR Processes.process="*view
|
||||
/all*") by Processes.process_name Processes.dest Processes.user Processes.parent_process_name
|
||||
| where count >=5 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `account_discovery_with_net_app_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used.
|
||||
where `process_net` AND (Processes.process="*user*" OR Processes.process="*config*"
|
||||
OR Processes.process="*view /all*") by Processes.process_name Processes.dest Processes.user
|
||||
Processes.parent_process_name | where count >=5 | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `account_discovery_with_net_app_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product..
|
||||
known_false_positives: admin or power user may used this series of command.
|
||||
references:
|
||||
- https://labs.vipre.com/trickbot-and-its-modules/
|
||||
@@ -66,13 +66,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process_id
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.process_guid
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 5
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Allow File And Printing Sharing In Firewall
|
||||
id: ce27646e-d411-11eb-8a00-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-06-23'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
@@ -10,16 +10,17 @@ description: This search is to detect a suspicious modification of firewall to a
|
||||
file and printer sharing. This technique was seen in ransomware to be able to discover
|
||||
more machine connected to the compromised host to encrypt more files
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=netsh.exe
|
||||
Processes.process= "*firewall*" Processes.process= "*group=\"File and Printer Sharing\"*" Processes.process="*enable=Yes*"
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_netsh` Processes.process=
|
||||
"*firewall*" Processes.process= "*group=\"File and Printer Sharing\"*" Processes.process="*enable=Yes*"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `allow_file_and_printing_sharing_in_firewall_filter`'
|
||||
Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `allow_file_and_printing_sharing_in_firewall_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure
|
||||
that this registry was included in your config files ex. sysmon config to be monitored.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: network admin may modify this firewall feature that may cause
|
||||
this rule to be triggered.
|
||||
references:
|
||||
@@ -43,10 +44,13 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
- Processes.parent_process_name
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Allow Network Discovery In Firewall
|
||||
id: ccd6a38c-d40b-11eb-85a5-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-06-23'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
@@ -11,16 +11,17 @@ description: This search is to detect a suspicious modification to the firewall
|
||||
(revil, reddot) to discover other machine connected to the compromised host to encrypt
|
||||
more files.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=netsh.exe
|
||||
Processes.process= "*firewall*" Processes.process= "*group=\"Network Discovery\"*" Processes.process="*enable*"
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_netsh` Processes.process=
|
||||
"*firewall*" Processes.process= "*group=\"Network Discovery\"*" Processes.process="*enable*"
|
||||
Processes.process="*Yes*" by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `allow_network_discovery_in_firewall_filter`'
|
||||
Processes.original_file_name Processes.process_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id Processes.parent_process_name | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `allow_network_discovery_in_firewall_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure
|
||||
that this registry was included in your config files ex. sysmon config to be monitored.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: network admin may modify this firewall feature that may cause
|
||||
this rule to be triggered.
|
||||
references:
|
||||
@@ -45,10 +46,13 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
- Processes.parent_process_name
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Any Powershell DownloadFile
|
||||
id: 1a93b7ea-7af7-11eb-adb5-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-03-01'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -12,15 +12,16 @@ description: The following analytic identifies the use of PowerShell downloading
|
||||
(IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell
|
||||
transaction logs are available, review for further details of the implant.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=powershell.exe
|
||||
OR Processes.process_name=pwsh.exe OR Processes.process_name=PowerShell_ISE.exe)
|
||||
Processes.process=*DownloadFile* by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process=*DownloadFile*
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
|
||||
`any_powershell_downloadfile_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: False positives may be present and filtering will need to occur
|
||||
by parent process or command line argument. It may be required to modify this query
|
||||
to an EDR product for more granular coverage.
|
||||
@@ -69,14 +70,17 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Any Powershell DownloadString
|
||||
id: 4d015ef2-7adf-11eb-95da-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-03-01'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -12,15 +12,15 @@ description: The following analytic identifies the use of PowerShell downloading
|
||||
(IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell
|
||||
transaction logs are available, review for further details of the implant.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe
|
||||
OR Processes.process_name=pwsh.exe OR Processes.process_name=PowerShell_ISE.exe
|
||||
Processes.process=*.DownloadString* by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
|
||||
`any_powershell_downloadstring_filter`'
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process=*.DownloadString* by
|
||||
Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `any_powershell_downloadstring_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: False positives may be present and filtering will need to occur
|
||||
by parent process or command line argument. It may be required to modify this query
|
||||
to an EDR product for more granular coverage.
|
||||
@@ -68,14 +68,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,14 +1,14 @@
|
||||
name: Attempt To Add Certificate To Untrusted Store
|
||||
id: 6bc5243e-ef36-45dc-9b12-f4a6be131159
|
||||
version: 6
|
||||
date: '2020-11-03'
|
||||
version: 7
|
||||
date: '2021-09-16'
|
||||
author: Patrick Bareiss, Rico Valdez, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: Attempt To Add Certificate To Untrusted Store
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime values(Processes.process)
|
||||
as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=*certutil*
|
||||
as process max(_time) as lastTime from datamodel=Endpoint.Processes where `process_certutil`
|
||||
(Processes.process=*-addstore*) by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)`
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Attempt To Stop Security Service
|
||||
id: c8e349c6-b97c-486e-8949-bd7bcd1f3910
|
||||
version: 3
|
||||
version: 4
|
||||
date: '2020-07-21'
|
||||
author: Rico Valdez, Splunk
|
||||
type: TTP
|
||||
@@ -10,22 +10,17 @@ description: This search looks for attempts to stop security-related services on
|
||||
endpoint.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.process_name = net.exe OR Processes.process_name = sc.exe) Processes.process="*
|
||||
stop *" by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |lookup
|
||||
security_services_lookup service as process OUTPUTNEW category, description | search
|
||||
category=security | `attempt_to_stop_security_service_filter`'
|
||||
how_to_implement: You must be ingesting data that records the file-system activity
|
||||
from your hosts to populate the Endpoint file-system data-model node. If you are
|
||||
using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which
|
||||
you want to collect data. The search is shipped with a lookup file, `security_services.csv`,
|
||||
that can be edited to update the list of services to monitor. This lookup file can
|
||||
be edited directly where it lives in `$SPLUNK_HOME/etc/apps/DA-ESS-ContentUpdate/lookups`,
|
||||
or via the Splunk console. You should add the names of services an attacker might
|
||||
use on the command line and surround with asterisks (*****), so that they work properly
|
||||
when searching the command line. The file should be updated with the names of any
|
||||
services you would like to monitor for attempts to stop the service.,
|
||||
where `process_net` OR Processes.process_name = sc.exe Processes.process="* stop
|
||||
*" by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
|lookup security_services_lookup service as process OUTPUTNEW category, description
|
||||
| search category=security | `attempt_to_stop_security_service_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: None identified. Attempts to disable security-related services
|
||||
should be identified and understood.
|
||||
references:
|
||||
@@ -45,7 +40,7 @@ tags:
|
||||
- Source:Endpoint
|
||||
- Stage:Defense Evasion
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon.log
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_defend_service_stop/windows-sysmon.log
|
||||
impact: 40
|
||||
kill_chain_phases:
|
||||
- Installation
|
||||
@@ -84,9 +79,13 @@ tags:
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 20
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Attempted Credential Dump From Registry via Reg exe
|
||||
id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911
|
||||
version: 4
|
||||
date: '2019-12-02'
|
||||
version: 6
|
||||
date: '2021-09-16'
|
||||
author: Patrick Bareiss, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
@@ -9,17 +9,18 @@ datamodel:
|
||||
description: Monitor for execution of reg.exe with parameters specifying an export
|
||||
of keys that contain hashed credentials that attackers may try to crack offline.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=reg.exe
|
||||
OR Processes.process_name=cmd.exe) Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\Security*
|
||||
OR Processes.process=*HKEY_LOCAL_MACHINE\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\System*
|
||||
OR Processes.process=*HKLM\\Security* OR Processes.process=*HKLM\\System* OR Processes.process=*HKLM\\SAM*)
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd`
|
||||
Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\SAM*
|
||||
OR Processes.process=*HKEY_LOCAL_MACHINE\\System* OR Processes.process=*HKLM\\Security*
|
||||
OR Processes.process=*HKLM\\System* OR Processes.process=*HKLM\\SAM*) by Processes.dest
|
||||
Processes.user Processes.parent_process Processes.process_name Processes.original_file_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`'
|
||||
how_to_implement: You must be ingesting endpoint data that tracks process activity,
|
||||
including parent-child relationships from your endpoints, to populate the Endpoint
|
||||
data model in the Processes node. The command-line arguments are mapped to the "process"
|
||||
field in the Endpoint data model.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: None identified.
|
||||
references:
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets
|
||||
@@ -74,9 +75,13 @@ tags:
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 90
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,23 +1,28 @@
|
||||
name: Batch File Write to System32
|
||||
id: 503d17cb-9eab-4cf8-a20e-01d5c6987ae3
|
||||
version: 1
|
||||
date: '2018-12-14'
|
||||
author: Rico Valdez, Splunk
|
||||
version: 2
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Rico Valdez, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The search looks for a batch file (.bat) written to the Windows system
|
||||
directory tree.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime values(Filesystem.dest) as dest values(Filesystem.file_name) as file_name
|
||||
values(Filesystem.user) as user from datamodel=Endpoint.Filesystem by Filesystem.file_path
|
||||
| `drop_dm_object_name(Filesystem)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)`|
|
||||
rex field=file_name "(?<file_extension>\.[^\.]+)$" | search file_path=*system32*
|
||||
AND file_extension=.bat | `batch_file_write_to_system32_filter`'
|
||||
how_to_implement: You must be ingesting data that records the file-system activity
|
||||
from your hosts to populate the Endpoint file-system data-model node. If you are
|
||||
using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which
|
||||
you want to collect data.
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
where Processes.process_name=* by _time span=1h Processes.process_id Processes.process_name
|
||||
Processes.dest | `drop_dm_object_name(Processes)` | join process_guid, _time [|
|
||||
tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\system32\\*",
|
||||
"*\\syswow64\\*") Filesystem.file_name="*.bat" by _time span=1h Filesystem.dest
|
||||
Filesystem.file_create_time Filesystem.file_name Filesystem.file_path | `drop_dm_object_name(Filesystem)`
|
||||
| fields _time dest file_create_time file_name file_path process_name process_path
|
||||
process] | dedup file_create_time | table dest file_create_time, file_name, file_path,
|
||||
process_name | `batch_file_write_to_system32_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: It is possible for this search to generate a notable event
|
||||
for a batch file write to a path that includes the string "system32", but is not
|
||||
the actual Windows system directory. As such, you should confirm the path of the
|
||||
@@ -72,5 +77,8 @@ tags:
|
||||
- Filesystem.file_name
|
||||
- Filesystem.user
|
||||
- Filesystem.file_path
|
||||
- Processes.process_id
|
||||
- Processes.process_name
|
||||
- Processes.dest
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: BITS Job Persistence
|
||||
id: e97a5ffe-90bf-11eb-928a-acde48001122
|
||||
version: 1
|
||||
date: '2021-03-29'
|
||||
version: 2
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
@@ -14,15 +14,17 @@ description: The following query identifies Microsoft Background Intelligent Tra
|
||||
to be used to upload files and this may require further network data analysis to
|
||||
identify. You can use `bitsadmin /list /verbose` to list out the jobs during investigation.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=bitsadmin.exe
|
||||
Processes.process IN (*create*, *addfile*, *setnotifyflags*, *setnotifycmdline*,
|
||||
*setminretrydelay*, *setcustomheaders*, *resume* ) by Processes.dest Processes.user
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_bitsadmin` Processes.process
|
||||
IN (*create*, *addfile*, *setnotifyflags*, *setnotifycmdline*, *setminretrydelay*,
|
||||
*setcustomheaders*, *resume* ) by Processes.dest Processes.user Processes.original_file_name
|
||||
Processes.parent_process Processes.process_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `bits_job_persistence_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Limited false positives will be present. Typically, applications
|
||||
will use `BitsAdmin.exe`. Any filtering should be done based on command-line arguments
|
||||
(legitimate applications) or parent process.
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: BITSAdmin Download File
|
||||
id: 80630ff4-8e4c-11eb-aab5-acde48001122
|
||||
version: 1
|
||||
date: '2021-03-26'
|
||||
version: 2
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
@@ -19,14 +19,16 @@ description: The following query identifies Microsoft Background Intelligent Tra
|
||||
malicious instances, BITS jobs will be created. You can use `bitsadmin /list /verbose`
|
||||
to list out the jobs during investigation.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=bitsadmin.exe
|
||||
Processes.process=*transfer* by Processes.dest Processes.user Processes.parent_process
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_bitsadmin` Processes.process=*transfer*
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.original_file_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `bitsadmin_download_file_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Limited false positives, however it may be required to filter
|
||||
based on parent process name or network connection.
|
||||
references:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: CertUtil Download With URLCache and Split Arguments
|
||||
id: 415b4306-8bfb-11eb-85c4-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-03-23'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -14,14 +14,16 @@ description: Certutil.exe may download a file from a remote destination using `-
|
||||
During triage, capture any files on disk and review. Review the reputation of the
|
||||
remote IP or domain in question.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe
|
||||
Processes.process=*urlcache* Processes.process=*split* by Processes.dest Processes.user
|
||||
Processes.parent_process Processes.process_name Processes.process Processes.process_id
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_certutil` Processes.process=*urlcache*
|
||||
Processes.process=*split* by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.original_file_name
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `certutil_download_with_urlcache_and_split_arguments_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Limited false positives in most environments, however tune
|
||||
as needed based on parent-child relationship or network connection.
|
||||
references:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: CertUtil Download With VerifyCtl and Split Arguments
|
||||
id: 801ad9e4-8bfb-11eb-8b31-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-03-23'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -14,14 +14,16 @@ description: 'Certutil.exe may download a file from a remote destination using `
|
||||
the remote IP or domain in question. Using `-VerifyCtl`, the file will either be
|
||||
written to the current working directory or `%APPDATA%\..\LocalLow\Microsoft\CryptnetUrlCache\Content\<hash>`. '
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe
|
||||
Processes.process=*verifyctl* Processes.process=*split* by Processes.dest Processes.user
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_certutil` Processes.process=*verifyctl*
|
||||
Processes.process=*split* by Processes.dest Processes.user Processes.original_file_name
|
||||
Processes.parent_process Processes.process_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `certutil_download_with_verifyctl_and_split_arguments_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Limited false positives in most environments, however tune
|
||||
as needed based on parent-child relationship or network connection.
|
||||
references:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: CertUtil With Decode Argument
|
||||
id: bfe94226-8c10-11eb-a4b3-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-03-23'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -15,14 +15,15 @@ description: CertUtil.exe may be used to `encode` and `decode` a file, including
|
||||
further execution. During triage, identify the source of the file being decoded.
|
||||
Review its contents or execution behavior for further analysis.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe
|
||||
Processes.process=*decode* by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `certutil_with_decode_argument_filter`'
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_certutil` Processes.process=*decode*
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `certutil_with_decode_argument_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Typically seen used to `encode` files, but it is possible to
|
||||
see legitimate use of `decode`. Filter based on parent-child relationship, file
|
||||
paths, endpoint or user.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: CMD Echo Pipe - Escalation
|
||||
id: eb277ba0-b96b-11eb-b00e-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-05-20'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -11,14 +11,11 @@ description: This analytic identifies a common behavior by Cobalt Strike and oth
|
||||
Strike PTH) or `getsystem`, using named-pipe impersonation. A suspicious event will
|
||||
look like `cmd.exe /c echo 4sgryt3436 > \\.\Pipe\5erg53`.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=cmd.exe
|
||||
OR Processes.process=*%comspec%*) (Processes.process=*echo* AND Processes.process=*pipe*)
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_cmd` OR Processes.process=*%comspec%* (Processes.process=*echo* AND Processes.process=*pipe*)
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `cmd_echo_pipe___escalation_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Unknown. It is possible filtering may be required to ensure
|
||||
fidelity.
|
||||
references:
|
||||
@@ -69,11 +66,11 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
|
||||
@@ -84,4 +84,4 @@ tags:
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 30
|
||||
security_domain: endpoint
|
||||
security_domain: endpoint
|
||||
@@ -1,24 +1,24 @@
|
||||
name: Create or delete windows shares using net exe
|
||||
id: qw9919ed-fe5f-492c-b139-151bb162140e
|
||||
version: 5
|
||||
date: '2020-07-21'
|
||||
version: 6
|
||||
date: '2020-09-16'
|
||||
author: Bhavin Patel, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This search looks for the creation or deletion of hidden shares using
|
||||
net.exe.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=net.exe
|
||||
OR Processes.process_name=net1.exe) AND (Processes.process="* share *") by Processes.dest
|
||||
Processes.user Processes.parent_process_name Processes.process_name Processes.process
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `create_or_delete_windows_shares_using_net_exe_filter`'
|
||||
how_to_implement: You must be ingesting data that records process activity from your
|
||||
hosts to populate the Endpoint data model in the Processes node. You must also be
|
||||
ingesting logs with both the process name and command line from your endpoints.
|
||||
The command-line arguments are mapped to the "process" field in the Endpoint data
|
||||
model.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.user) as
|
||||
user values(Processes.parent_process) as parent_process min(_time) as firstTime
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` by
|
||||
Processes.process Processes.process_name Processes.original_file_name Processes.dest
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| search process=*share* | `create_or_delete_windows_shares_using_net_exe_filter` '
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Administrators often leverage net.exe to create or delete network
|
||||
shares. You should verify that the activity was intentional and is legitimate.
|
||||
references:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Creation of Shadow Copy with wmic and powershell
|
||||
id: 2ed8b538-d284-449a-be1d-82ad1dbd186b
|
||||
version: 1
|
||||
date: '2019-12-10'
|
||||
version: 3
|
||||
date: '2021-09-16'
|
||||
author: Patrick Bareiss, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
@@ -9,13 +9,15 @@ datamodel:
|
||||
description: This search detects the use of wmic and Powershell to create a shadow
|
||||
copy.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wmic*
|
||||
OR Processes.process_name=powershell* Processes.process=*shadowcopy* Processes.process=*create*
|
||||
by Processes.user Processes.process_name Processes.process Processes.dest | `drop_dm_object_name(Processes)`
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_wmic` OR `process_powershell`
|
||||
Processes.process=*shadowcopy* Processes.process=*create* by Processes.user Processes.process_name
|
||||
Processes.original_file_name Processes.process Processes.dest | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `creation_of_shadow_copy_with_wmic_and_powershell_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Legtimate administrator usage of wmic to create a shadow copy.
|
||||
references:
|
||||
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Credential Dumping via Copy Command from Shadow Copy
|
||||
id: d8c406fe-23d2-45f3-a983-1abe7b83ff3b
|
||||
version: 1
|
||||
date: '2019-12-10'
|
||||
version: 2
|
||||
date: '2021-09-16'
|
||||
author: Patrick Bareiss, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
@@ -9,16 +9,17 @@ datamodel:
|
||||
description: This search detects credential dumping using copy command from a shadow
|
||||
copy.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe
|
||||
(Processes.process=*\\system32\\config\\sam* OR Processes.process=*\\system32\\config\\security*
|
||||
OR Processes.process=*\\system32\\config\\system* OR Processes.process=*\\windows\\ntds\\ntds.dit*)
|
||||
by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_cmd` (Processes.process=*\\system32\\config\\sam*
|
||||
OR Processes.process=*\\system32\\config\\security* OR Processes.process=*\\system32\\config\\system*
|
||||
OR Processes.process=*\\windows\\ntds\\ntds.dit*) by Processes.dest Processes.user
|
||||
Processes.process_name Processes.process Processes.parent_process Processes.original_file_name
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `credential_dumping_via_copy_command_from_shadow_copy_filter` '
|
||||
how_to_implement: You must be ingesting endpoint data that tracks process activity,
|
||||
including parent-child relationships from your endpoints to populate the Endpoint
|
||||
data model in the Processes node. The command-line arguments are mapped to the "process"
|
||||
field in the Endpoint data model.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
|
||||
|
||||
@@ -1,22 +1,23 @@
|
||||
name: Credential Dumping via Symlink to Shadow Copy
|
||||
id: c5eac648-fae0-4263-91a6-773df1f4c903
|
||||
version: 1
|
||||
date: '2019-12-10'
|
||||
version: 2
|
||||
date: '2021-09-16'
|
||||
author: Patrick Bareiss, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This search detects the creation of a symlink to a shadow copy.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe
|
||||
Processes.process=*mklink* Processes.process=*HarddiskVolumeShadowCopy* by Processes.dest
|
||||
Processes.user Processes.process_name Processes.process Processes.parent_process
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `credential_dumping_via_symlink_to_shadow_copy_filter` '
|
||||
how_to_implement: You must be ingesting endpoint data that tracks process activity,
|
||||
including parent-child relationships from your endpoints to populate the Endpoint
|
||||
data model in the Processes node. The command-line arguments are mapped to the "process"
|
||||
field in the Endpoint data model.
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_cmd` Processes.process=*mklink*
|
||||
Processes.process=*HarddiskVolumeShadowCopy* by Processes.dest Processes.user Processes.process_name
|
||||
Processes.process Processes.parent_process Processes.original_file_name Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)` | `credential_dumping_via_symlink_to_shadow_copy_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Deleting Of Net Users
|
||||
id: 1c8c6f66-acce-11eb-aafb-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
@@ -15,14 +15,11 @@ description: This analytic will detect a suspicious net.exe/net1.exe command-lin
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
values(Processes.parent_process) as parent_process values(Processes.process_id)
|
||||
as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.process_name="net.exe" OR Processes.process_name="net1.exe" AND
|
||||
Processes.process="*user*" AND Processes.process="*/delete*" by Processes.process_name
|
||||
where `process_net` AND
|
||||
Processes.process="*user*" AND Processes.process="*/delete*" by Processes.process_name Processes.original_file_name
|
||||
Processes.dest Processes.user Processes.parent_process_name | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `deleting_of_net_users_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed net.exe may be used.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: System administrators or scripts may delete user accounts via
|
||||
this technique. Filter as needed.
|
||||
references:
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
name: Detect HTML Help Renamed
|
||||
id: 62fed254-513b-460e-953d-79771493a9f3
|
||||
version: 1
|
||||
date: '2021-02-11'
|
||||
version: 3
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel: []
|
||||
type: Hunting
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies a renamed instance of hh.exe (HTML
|
||||
Help) executing a Compiled HTML Help (CHM). This particular technique will load
|
||||
Windows script code from a compiled help file. CHM files may contain nearly any
|
||||
@@ -16,14 +17,12 @@ description: The following analytic identifies a renamed instance of hh.exe (HTM
|
||||
or WSH script code. During investigation, identify script content origination. Validate
|
||||
it is the legitimate version of hh.exe by reviewing the PE metadata. hh.exe is natively
|
||||
found in C:\Windows\system32 and C:\Windows\syswow64.
|
||||
search: '`sysmon` EventID=1 OriginalFileName=HH.exe NOT process_name=hh.exe | stats
|
||||
count min(_time) as firstTime max(_time) as lastTime by Computer, User, parent_process_name,
|
||||
process_name, OriginalFileName, process_path, CommandLine | rename Computer as dest
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_html_help_renamed_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed hh.exe may be used.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_hh` by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `detect_html_help_renamed_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Although unlikely a renamed instance of hh.exe will be used
|
||||
legitimately, filter as needed.
|
||||
references:
|
||||
@@ -76,13 +75,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventID
|
||||
- OriginalFileName
|
||||
- process_name
|
||||
- Computer
|
||||
- User
|
||||
- parent_process_name
|
||||
- process_path
|
||||
- CommandLine
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Detect HTML Help URL in Command Line
|
||||
id: 8c5835b9-39d9-438b-817c-95f14c69a31e
|
||||
version: 1
|
||||
date: '2021-02-11'
|
||||
version: 2
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
@@ -18,14 +18,12 @@ description: The following analytic identifies hh.exe (HTML Help) execution of a
|
||||
IP and domain. Some instances, it is worth decompiling the .chm file to review its
|
||||
original contents. hh.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=hh.exe
|
||||
Processes.process=*http* by Processes.dest Processes.user Processes.parent_process
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_hh`
|
||||
Processes.process=*http* by Processes.dest Processes.user Processes.parent_process Processes.original_file_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_html_help_url_in_command_line_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Although unlikely, some legitimate applications may retrieve
|
||||
a CHM remotely, filter as needed.
|
||||
references:
|
||||
@@ -84,11 +82,11 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Detect HTML Help Using InfoTech Storage Handlers
|
||||
id: 0b2eefa5-5508-450d-b970-3dd2fb761aec
|
||||
version: 1
|
||||
date: '2021-02-11'
|
||||
version: 2
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
@@ -20,14 +20,12 @@ description: The following analytic identifies hh.exe (HTML Help) execution of a
|
||||
script content origination. hh.exe is natively found in C:\Windows\system32 and
|
||||
C:\Windows\syswow64.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=hh.exe
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_hh`
|
||||
Processes.process IN ("*its:*", "*mk:@MSITStore:*") by Processes.dest Processes.user
|
||||
Processes.parent_process Processes.process_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `detect_html_help_using_infotech_storage_handlers_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: It is rare to see instances of InfoTech Storage Handlers being
|
||||
used, but it does happen in some legitimate instances. Filter as needed.
|
||||
references:
|
||||
@@ -81,11 +79,11 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Detect mshta inline hta execution
|
||||
id: a0873b32-5b68-11eb-ae93-0242ac130002
|
||||
version: 5
|
||||
date: '2021-01-20'
|
||||
version: 6
|
||||
date: '2021-09-16'
|
||||
author: Bhavin Patel, Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
@@ -13,14 +13,12 @@ description: The following analytic identifies "mshta.exe" execution with inline
|
||||
as well as the target system, the user, process "mshta.exe" and its parent process.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process)
|
||||
as process values(Processes.parent_process) as parent_process min(_time) as firstTime
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=mshta.exe
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where `process_mshta`
|
||||
(Processes.process=*vbscript* OR Processes.process=*javascript* OR Processes.process=*about*)
|
||||
by Processes.user Processes.process_name Processes.parent_process_name Processes.dest |
|
||||
by Processes.user Processes.process_name Processes.original_file_name Processes.parent_process_name Processes.dest |
|
||||
`drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `detect_mshta_inline_hta_execution_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Although unlikely, some legitimate applications may exhibit
|
||||
this behavior, triggering a false positive.
|
||||
references:
|
||||
|
||||
@@ -1,24 +1,23 @@
|
||||
name: Detect mshta renamed
|
||||
id: 8f45fcf0-5b68-11eb-ae93-0242ac130002
|
||||
version: 1
|
||||
date: '2021-01-20'
|
||||
version: 2
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel: []
|
||||
type: Hunting
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies renamed instances of mshta.exe executing.
|
||||
Mshta.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. This
|
||||
analytic utilizes the internal name of the PE to identify if is the legitimate mshta
|
||||
binary. Further analysis should be performed to review the executed content and
|
||||
validation it is the real mshta.
|
||||
search: '`sysmon` EventID=1 (OriginalFileName=mshta.exe AND process_name!=mshta.exe)
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User,
|
||||
parent_process_name, process_name, OriginalFileName, process_path, CommandLine |
|
||||
rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
|
||||
`detect_mshta_renamed_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_mshta` by Processes.dest Processes.user Processes.parent_process_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `detect_mshta_renamed_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use a moved
|
||||
copy of mshta.exe, but never renamed, triggering a false positive.
|
||||
references:
|
||||
@@ -70,13 +69,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventID
|
||||
- OriginalFileName
|
||||
- process_name
|
||||
- Computer
|
||||
- User
|
||||
- parent_process_name
|
||||
- process_path
|
||||
- CommandLine
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Detect MSHTA Url in Command Line
|
||||
id: 9b3af1e6-5b68-11eb-ae93-0242ac130002
|
||||
version: 1
|
||||
date: '2021-01-20'
|
||||
version: 2
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
@@ -15,13 +15,11 @@ description: This analytic identifies when Microsoft HTML Application Host (msht
|
||||
as well as the target system, the user, process "rundll32.exe" and its parent process.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process)
|
||||
as process values(Processes.parent_process) as parent_process min(_time) as firstTime
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=mshta.exe
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where `process_mshta`
|
||||
(Processes.process="*http://*" OR Processes.process="*https://*") by Processes.user
|
||||
Processes.process_name Processes.parent_process_name Processes.dest | `drop_dm_object_name(Processes)`
|
||||
Processes.process_name Processes.parent_process_name Processes.original_file_name Processes.dest | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_mshta_url_in_command_line_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: It is possible legitimate applications may perform this behavior
|
||||
and will need to be filtered.
|
||||
references:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Detect Prohibited Applications Spawning cmd exe
|
||||
id: dcfd6b40-42f9-469d-a433-2e53f7486664
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2020-11-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
type: Hunting
|
||||
@@ -10,14 +10,14 @@ description: This search looks for executions of cmd.exe spawned by a process th
|
||||
is often abused by attackers and that does not typically launch cmd.exe.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process)
|
||||
as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.process_name=cmd.exe by Processes.parent_process_name Processes.process_name
|
||||
where `process_cmd` by Processes.parent_process_name Processes.process_name Processes.original_file_name
|
||||
Processes.dest Processes.user| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)` |search [`prohibited_apps_launching_cmd`] | `detect_prohibited_applications_spawning_cmd_exe_filter`'
|
||||
how_to_implement: You must be ingesting data that records process activity from your
|
||||
hosts and populates the Endpoint data model with the resultant dataset. This search
|
||||
includes a lookup file, `prohibited_apps_launching_cmd.csv`, that contains a list
|
||||
of processes that should not be spawning cmd.exe. You can modify this lookup to
|
||||
better suit your environment.
|
||||
better suit your environment. To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: There are circumstances where an application may legitimately
|
||||
execute and interact with the Windows command-line interface. Investigate and modify
|
||||
the lookup file, as appropriate.
|
||||
@@ -73,11 +73,11 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Detect PsExec With accepteula Flag
|
||||
id: b89919ed-fe5f-492c-b139-151xb162040e
|
||||
version: 3
|
||||
date: '2020-11-10'
|
||||
version: 4
|
||||
date: '2021-09-16'
|
||||
author: Bhavin Patel, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
@@ -16,15 +16,15 @@ description: This search looks for events where `PsExec.exe` is run with the `ac
|
||||
within the command line.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.process=*psexec* Processes.process=*accepteula* by Processes.dest
|
||||
Processes.user Processes.parent_process_name Processes.process_name Processes.process
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`|
|
||||
`security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_psexec_with_accepteula_flag_filter`'
|
||||
how_to_implement: You must be ingesting data that records process activity from your
|
||||
hosts to populate the Endpoint data model in the Processes node. You must also be
|
||||
ingesting logs with both the process name and command line from your endpoints.
|
||||
The command-line arguments are mapped to the "process" field in the Endpoint data
|
||||
model.
|
||||
where `process_psexec` Processes.process=*accepteula* by Processes.dest Processes.user
|
||||
Processes.parent_process_name Processes.process_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)`| `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)` | `detect_psexec_with_accepteula_flag_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Administrators can leverage PsExec for accessing remote systems
|
||||
and might pass `accepteula` as an argument if they are running this tool for the
|
||||
first time. However, it is not likely that you'd see multiple occurrences of this
|
||||
|
||||
@@ -1,25 +1,27 @@
|
||||
name: Detect Regasm with no Command Line Arguments
|
||||
id: c3bc1430-04e7-4178-835f-047d8e6e97df
|
||||
version: 1
|
||||
date: '2021-02-12'
|
||||
version: 2
|
||||
date: '2021-09-20'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel: []
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies regasm.exe with no command line arguments.
|
||||
This particular behavior occurs when another process injects into regasm.exe, no
|
||||
command line arguments will be present. During investigation, identify any network
|
||||
connections and parallel processes. Identify any suspicious module loads related
|
||||
to credential dumping or file writes. Regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe
|
||||
and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe.
|
||||
search: '`sysmon` EventID=1 (process_name=regasm.exe OR OriginalFileName=RegAsm.exe)
|
||||
| regex CommandLine="(regasm\.exe.{0,4}$)" | stats count min(_time) as firstTime
|
||||
max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name,
|
||||
OriginalFileName, process_path, CommandLine | rename Computer as dest | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `detect_regasm_with_no_command_line_arguments_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
where `process_regasm` by _time span=1h Processes.process_id Processes.process_name
|
||||
Processes.dest Processes.process_path Processes.process Processes.parent_process_name
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| regex process="(regasm\.exe.{0,4}$)" | `detect_regasm_with_no_command_line_arguments_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Although unlikely, limited instances of regasm.exe or may cause
|
||||
a false positive. Filter based endpoint usage, command line arguments, or process
|
||||
lineage.
|
||||
@@ -43,7 +45,7 @@ tags:
|
||||
impact: 70
|
||||
kill_chain_phases:
|
||||
- Actions on Objectives
|
||||
message: The process $process_name$ was spawned by $parent_image$ without any command-line
|
||||
message: The process $process_name$ was spawned by $parent_process_name$ without any command-line
|
||||
arguments on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1218.009
|
||||
@@ -59,7 +61,7 @@ tags:
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
- name: parent_image
|
||||
- name: parent_process_name
|
||||
type: Parent Process
|
||||
role:
|
||||
- Parent Process
|
||||
@@ -73,15 +75,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventID
|
||||
- process_name
|
||||
- OriginalFileName
|
||||
- CommandLine
|
||||
- dest
|
||||
- User
|
||||
- ParentImage
|
||||
- ParentCommandLine
|
||||
- process_path
|
||||
- Computer
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,25 +1,27 @@
|
||||
name: Detect Regsvcs with No Command Line Arguments
|
||||
id: 6b74d578-a02e-4e94-a0d1-39440d0bf254
|
||||
version: 1
|
||||
date: '2021-02-12'
|
||||
version: 2
|
||||
date: '2021-09-20'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel: []
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies regsvcs.exe with no command line arguments.
|
||||
This particular behavior occurs when another process injects into regsvcs.exe, no
|
||||
command line arguments will be present. During investigation, identify any network
|
||||
connections and parallel processes. Identify any suspicious module loads related
|
||||
to credential dumping or file writes. Regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe
|
||||
and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe.
|
||||
search: '`sysmon` EventID=1 (process_name=regsvcs.exe OR OriginalFileName=RegSvcs.exe)
|
||||
| regex CommandLine="(regsvcs\.exe.{0,4}$)" | stats count min(_time) as firstTime
|
||||
max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name,
|
||||
OriginalFileName, process_path, CommandLine | rename Computer as dest | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `detect_regsvcs_with_no_command_line_arguments_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
where `process_regsvcs` by _time span=1h Processes.process_id Processes.process_name
|
||||
Processes.dest Processes.process_path Processes.process Processes.parent_process_name
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| regex process="(regsvcs\.exe.{0,4}$)"| `detect_regsvcs_with_no_command_line_arguments_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Although unlikely, limited instances of regsvcs.exe may cause
|
||||
a false positive. Filter based endpoint usage, command line arguments, or process
|
||||
lineage.
|
||||
@@ -43,8 +45,8 @@ tags:
|
||||
impact: 70
|
||||
kill_chain_phases:
|
||||
- Actions on Objectives
|
||||
message: The process $process_name$ was spawned by $parent_image$ without any command-line
|
||||
arguments on $dest$ by $user$.
|
||||
message: The process $process_name$ was spawned by $parent_process_name$ without
|
||||
any command-line arguments on $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1218.009
|
||||
nist:
|
||||
@@ -59,7 +61,7 @@ tags:
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
- name: parent_image
|
||||
- name: parent_process_name
|
||||
type: Parent Process
|
||||
role:
|
||||
- Parent Process
|
||||
@@ -73,16 +75,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventID
|
||||
- process_name
|
||||
- OriginalFileName
|
||||
- CommandLine
|
||||
- dest
|
||||
- User
|
||||
- ParentImage
|
||||
- ParentCommandLine
|
||||
- OriginalFileName
|
||||
- process_path
|
||||
- Computer
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Detect Regsvr32 Application Control Bypass
|
||||
id: 070e9b80-6252-11eb-ae93-0242ac130002
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-01-28'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -17,15 +17,11 @@ description: 'Adversaries may abuse Regsvr32.exe to proxy execution of malicious
|
||||
is not required to load scrobj. "scrobj.dll" will be loaded by "regsvr32.exe" upon
|
||||
execution. '
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=regsvr32.exe
|
||||
OR Processes.process_name!=regsvr32.exe) Processes.process=*scrobj* by Processes.dest
|
||||
Processes.user Processes.parent_process Processes.process_name Processes.process
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` Processes.process=*scrobj* by Processes.dest
|
||||
Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_regsvr32_application_control_bypass_filter`'
|
||||
how_to_implement: You must be ingesting endpoint data that tracks process activity,
|
||||
including parent-child relationships from your endpoints, to populate the Endpoint
|
||||
data model in the Processes node. The command-line arguments are mapped to the "process"
|
||||
field in the Endpoint data model. Tune the query by modifying/removing the !=regsv32.exe.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Limited false positives related to third party software registering
|
||||
.DLL's.
|
||||
references:
|
||||
@@ -83,11 +79,11 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
|
||||
@@ -1,23 +1,26 @@
|
||||
name: Detect Renamed 7-Zip
|
||||
id: 4057291a-b8cf-11eb-95fe-acde48001122
|
||||
version: 1
|
||||
date: '2021-05-19'
|
||||
version: 2
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
type: Hunting
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies renamed 7-Zip usage using Sysmon. At
|
||||
this stage of an attack, review parallel processes and file modifications for data
|
||||
that is staged or potentially have been exfiltrated. This analytic utilizes the
|
||||
OriginalFileName to capture the renamed process.
|
||||
search: '`sysmon` EventID=1 (OriginalFileName=7z*.exe AND process_name!=7z*.exe) |
|
||||
stats count min(_time) as firstTime max(_time) as lastTime by Computer, User, parent_process_name,
|
||||
process_name, OriginalFileName, process_path, CommandLine | rename Computer as dest
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_renamed_7_zip_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
OriginalFileName to capture the renamed process. During triage, validate this is
|
||||
the legitimate version of `7zip` by reviewing the PE metadata. In addition, review
|
||||
parallel processes for further suspicious behavior.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.original_file_name=7z*.exe
|
||||
AND Processes.process_name!=7z*.exe) by Processes.dest Processes.user Processes.parent_process_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `detect_renamed_7_zip_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
known_false_positives: Limited false positives, however this analytic will need to
|
||||
be modified for each environment if Sysmon is not used.
|
||||
references:
|
||||
@@ -62,13 +65,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- dest
|
||||
- User
|
||||
- parent_process_name
|
||||
- process_name
|
||||
- OriginalFileName
|
||||
- process_path
|
||||
- CommandLine
|
||||
- Product
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 27
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,26 +1,27 @@
|
||||
name: Detect Renamed PSExec
|
||||
id: 683e6196-b8e8-11eb-9a79-acde48001122
|
||||
version: 1
|
||||
date: '2021-05-19'
|
||||
version: 3
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
type: Hunting
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies renamed instances of `PsExec.exe` being
|
||||
utilized on an endpoint. Most instances, it is highly probable to capture `Psexec.exe`
|
||||
or other SysInternal utility usage with the command-line argument of `-accepteula`.
|
||||
In this instance, we are using `OriginalFileName` from Sysmon to identify `PsExec`
|
||||
usage. During triage, validate this is the legitimate version of `PsExec` by review
|
||||
During triage, validate this is the legitimate version of `PsExec` by reviewing
|
||||
the PE metadata. In addition, review parallel processes for further suspicious behavior.
|
||||
search: '`sysmon` EventID=1 (OriginalFileName=psexec.c process_name!=psexec.exe process_name!=PsExec64.exe)
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User,
|
||||
parent_process_name, process_name, OriginalFileName, process_path, CommandLine Product
|
||||
| rename Computer as dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_psexec` by Processes.dest
|
||||
Processes.user Processes.parent_process_name Processes.process_name Processes.process
|
||||
Processes.process_id Processes.parent_process_id Processes.original_file_name |
|
||||
`drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_renamed_psexec_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Limited false positives should be present. It is possible some
|
||||
third party applications may use older versions of PsExec, filter as needed.
|
||||
references:
|
||||
@@ -72,13 +73,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- dest
|
||||
- User
|
||||
- parent_process_name
|
||||
- process_name
|
||||
- OriginalFileName
|
||||
- process_path
|
||||
- CommandLine
|
||||
- Product
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 27
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,9 +1,9 @@
|
||||
name: Detect Renamed RClone
|
||||
id: 6dca1124-b3ec-11eb-9328-acde48001122
|
||||
version: 1
|
||||
date: '2021-05-13'
|
||||
version: 2
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
type: Hunting
|
||||
datamodel: []
|
||||
description: The following analytic identifies the usage of `rclone.exe`, renamed,
|
||||
being used to exfiltrate data to a remote destination. RClone has been used by multiple
|
||||
@@ -11,15 +11,17 @@ description: The following analytic identifies the usage of `rclone.exe`, rename
|
||||
the legitimate site and executed accordingly. During triage, isolate the endpoint
|
||||
and begin to review parallel processes for additional behavior. At this stage, the
|
||||
adversary may have staged data to be exfiltrated.
|
||||
search: '`sysmon` EventID=1 OriginalFileName=rclone.exe NOT process_name=rclone.exe
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User,
|
||||
parent_process_name, process_name, OriginalFileName, process_path, CommandLine |
|
||||
rename Computer as dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_renamed_rclone_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.original_file_name=rclone.exe
|
||||
AND Processes.process_name!=rclone.exe) by Processes.dest Processes.user Processes.parent_process_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `detect_renamed_rclone_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: False positives should be limited as this analytic identifies
|
||||
renamed instances of `rclone.exe`. Filter as needed if there is a legitimate business
|
||||
use case.
|
||||
@@ -68,10 +70,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- OriginalFileName
|
||||
- process_name
|
||||
- process_path
|
||||
- CommandLine
|
||||
- dest
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 27
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,26 +1,28 @@
|
||||
name: Detect Renamed WinRAR
|
||||
id: 1b7bfb2c-b8e6-11eb-99ac-acde48001122
|
||||
version: 1
|
||||
date: '2021-05-19'
|
||||
version: 3
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
type: Hunting
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analtyic identifies renamed instances of `WinRAR.exe`.
|
||||
In most cases, it is not common for WinRAR to be used renamed, however it is common
|
||||
to be installed by a third party application and executed from a non-standard path.
|
||||
In this instance, we are using `OriginalFileName` from Sysmon to determine if the
|
||||
process is WinRAR. During triage, validate additional metadata from the binary that
|
||||
this is `WinRAR`. Review parallel processes and file modifications.
|
||||
search: '`sysmon` EventID=1 (Product=WinRAR OR OriginalFileName=WinRAR.exe) process_name!=rar.exe
|
||||
process_name!=winrar.exe | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
by Computer, User, parent_process_name, process_name, OriginalFileName, process_path,
|
||||
CommandLine Product | rename Computer as dest | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `detect_renamed_winrar_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Modify query for specific EDR products as needed.
|
||||
During triage, validate additional metadata from the binary that this is `WinRAR`.
|
||||
Review parallel processes and file modifications.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.original_file_name=WinRAR.exe
|
||||
(Processes.process_name!=rar.exe OR Processes.process_name!=winrar.exe) by Processes.dest
|
||||
Processes.user Processes.parent_process_name Processes.process_name Processes.process
|
||||
Processes.process_id Processes.parent_process_id Processes.original_file_name |
|
||||
`drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_renamed_winrar_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Unknown. It is possible third party applications use renamed
|
||||
instances of WinRAR.
|
||||
references:
|
||||
@@ -66,13 +68,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- dest
|
||||
- User
|
||||
- parent_process_name
|
||||
- process_name
|
||||
- OriginalFileName
|
||||
- process_path
|
||||
- CommandLine
|
||||
- Product
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 27
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Detect Rundll32 Application Control Bypass - advpack
|
||||
id: 4aefadfe-9abd-4bf8-b3fd-867e9ef95bf8
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-02-04'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -16,14 +16,12 @@ description: The following analytic identifies rundll32.exe loading advpack.dll
|
||||
investigation, review any network connections and obtain the script content executed.
|
||||
It's possible other files are on disk.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe
|
||||
Processes.process=*advpack* by Processes.dest Processes.user Processes.parent_process_name
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_rundll32`
|
||||
Processes.process=*advpack* by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_rundll32_application_control_bypass___advpack_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use advpack.dll
|
||||
or ieadvpack.dll, triggering a false positive.
|
||||
references:
|
||||
@@ -81,10 +79,14 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Detect Rundll32 Application Control Bypass - setupapi
|
||||
id: 61e7b44a-6088-4f26-b788-9a96ba13b37a
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-02-04'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -16,8 +16,8 @@ description: The following analytic identifies rundll32.exe loading setupapi.dll
|
||||
investigation, review any network connections and obtain the script content executed.
|
||||
It's possible other files are on disk.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe
|
||||
Processes.process=*setupapi* by Processes.dest Processes.user Processes.parent_process_name
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_rundll32`
|
||||
Processes.process=*setupapi* by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_rundll32_application_control_bypass___setupapi_filter`'
|
||||
@@ -81,10 +81,14 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Detect Rundll32 Application Control Bypass - syssetup
|
||||
id: 71b9bf37-cde1-45fb-b899-1b0aa6fa1183
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-02-04'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -16,14 +16,12 @@ description: The following analytic identifies rundll32.exe loading syssetup.dll
|
||||
any network connections and obtain the script content executed. It's possible other
|
||||
files are on disk.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe
|
||||
Processes.process=*syssetup* by Processes.dest Processes.user Processes.parent_process_name
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_rundll32`
|
||||
Processes.process=*syssetup* by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_rundll32_application_control_bypass___syssetup_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use syssetup.dll,
|
||||
triggering a false positive.
|
||||
references:
|
||||
@@ -81,10 +79,14 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Detect Rundll32 Inline HTA Execution
|
||||
id: 91c79f14-5b41-11eb-ae93-0242ac130002
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-01-20'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -15,14 +15,12 @@ description: The following analytic identifies "rundll32.exe" execution with inl
|
||||
"rundll32.exe" and its parent process.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process)
|
||||
as process values(Processes.parent_process) as parent_process min(_time) as firstTime
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32`
|
||||
(Processes.process=*vbscript* OR Processes.process=*javascript* OR Processes.process=*about*)
|
||||
by Processes.user Processes.process_name Processes.parent_process_name Processes.dest |
|
||||
by Processes.user Processes.process_name Processes.parent_process_name Processes.original_file_name Processes.dest |
|
||||
`drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `detect_rundll32_inline_hta_execution_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Although unlikely, some legitimate applications may exhibit
|
||||
this behavior, triggering a false positive.
|
||||
references:
|
||||
@@ -65,11 +63,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process
|
||||
- Processes.process_name
|
||||
- Processes.user
|
||||
- Processes.dest
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,28 +1,30 @@
|
||||
name: Detect SharpHound Usage
|
||||
id: dd04b29a-beed-11eb-87bc-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-05-27'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies SharpHound binary usage by using the
|
||||
`OriginalFileName` from Sysmon. In addition to renaming the PE, other coverage is
|
||||
available to detect command-line arguments. This particular analytic only looks
|
||||
for the OriginalFileName of `SharpHound.exe`. It is possible older instances of
|
||||
SharpHound.exe have different original filenames. Dependent upon the operator, the
|
||||
code may be re-compiled and the attributes removed or changed to anything else.
|
||||
During triage, review the metadata of the binary in question. Review parallel processes
|
||||
for suspicious behavior. Identify the source of this binary.
|
||||
search: '`sysmon` EventID=1 (OriginalFileName=SharpHound.exe process_name!=sharphound.exe)
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User,
|
||||
parent_process_name, process_name, OriginalFileName, process_path, CommandLine Product
|
||||
| rename Computer as dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_sharphound_usage_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
original filena,e. In addition to renaming the PE, other coverage is available
|
||||
to detect command-line arguments. This particular analytic looks for the original_file_name
|
||||
of `SharpHound.exe` and the process name. It is possible older instances of SharpHound.exe
|
||||
have different original filenames. Dependent upon the operator, the code may be
|
||||
re-compiled and the attributes removed or changed to anything else. During triage,
|
||||
review the metadata of the binary in question. Review parallel processes for suspicious
|
||||
behavior. Identify the source of this binary.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=sharphound.exe
|
||||
OR Processes.original_file_name=SharpHound.exe) by Processes.dest Processes.user
|
||||
Processes.parent_process_name Processes.original_file_name Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_sharphound_usage_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: False positives should be limited as this is specific to a
|
||||
file attribute not used by anything else. Filter as needed.
|
||||
references:
|
||||
@@ -63,13 +65,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- dest
|
||||
- User
|
||||
- parent_process_name
|
||||
- process_name
|
||||
- OriginalFileName
|
||||
- process_path
|
||||
- CommandLine
|
||||
- Product
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 24
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Disabling Firewall with Netsh
|
||||
id: 6860a62c-9203-11eb-9e05-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-03-31'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
@@ -10,15 +10,12 @@ description: This search is to identifies suspicious firewall disabling using ne
|
||||
application. this technique is commonly seen in malware that tries to communicate
|
||||
or download its component or other payload to its C2 server.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=netsh.exe
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_netsh`
|
||||
Processes.process= "*firewall*" (Processes.process= "*off*" OR Processes.process=
|
||||
"*disable*") by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
"*disable*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_firewall_with_netsh_filter`'
|
||||
how_to_implement: You must be ingesting data that records the filesystem activity
|
||||
from your hosts to populate the Endpoint file-system data model node. If you are
|
||||
using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which
|
||||
you want to collect data.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: admin may disable firewall during testing or fixing network
|
||||
problem.
|
||||
references:
|
||||
@@ -56,13 +53,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process
|
||||
- Processes.process_name
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 25
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Disabling Net User Account
|
||||
id: c0325326-acd6-11eb-98c2-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
@@ -13,15 +13,11 @@ description: This analytic will identify a suspicious command-line that disables
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
values(Processes.parent_process) as parent_process values(Processes.process_id)
|
||||
as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.process_name="net.exe" OR Processes.process_name="net1.exe" AND
|
||||
Processes.process="*user*" AND Processes.process="*/active:no*" by Processes.process_name
|
||||
where `process_net` AND
|
||||
Processes.process="*user*" AND Processes.process="*/active:no*" by Processes.process_name Processes.original_file_name
|
||||
Processes.dest Processes.user Processes.parent_process_name | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_net_user_account_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed net.exe/net1.exe may be
|
||||
used.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
|
||||
@@ -65,11 +61,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 42
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -9,12 +9,11 @@ datamodel:
|
||||
description: This analytic looks for the execution of `net.exe` or `net1.exe` with command-line arguments utilized to query for domain users.
|
||||
Red Teams and adversaries alike may use net.exe to enumerate domain users for situational awareness and Active Directory Discovery.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="net.exe"
|
||||
OR Processes.process_name="net1.exe") AND Processes.process = "* user*" AND Processes.process
|
||||
= "*/do*" by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `domain_account_discovery_with_net_app_filter`'
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_net` AND Processes.process
|
||||
= "* user*" AND Processes.process = "*/do*" by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `domain_account_discovery_with_net_app_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
|
||||
@@ -16,7 +16,7 @@ search: '`sysmon` EventCode= 11 TargetFilename = "*\\license.dat" AND (TargetFi
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used.
|
||||
Sysmon TA.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://www.cisecurity.org/white-papers/security-primer-icedid/
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Dump LSASS via comsvcs DLL
|
||||
id: 8943b567-f14d-4ee8-a0bb-2121d4ce3184
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2020-02-21'
|
||||
author: Patrick Bareiss, Splunk
|
||||
type: TTP
|
||||
@@ -8,14 +8,11 @@ datamodel:
|
||||
- Endpoint
|
||||
description: Detect the usage of comsvcs.dll for dumping the lsass process.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe
|
||||
Processes.process=*comsvcs.dll* Processes.process=*MiniDump* by Processes.user Processes.process_name
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_rundll32`
|
||||
Processes.process=*comsvcs.dll* Processes.process=*MiniDump* by Processes.user Processes.process_name Processes.original_file_name
|
||||
Processes.process Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `dump_lsass_via_comsvcs_dll_filter`'
|
||||
how_to_implement: You must be ingesting endpoint data that tracks process activity,
|
||||
including parent-child relationships from your endpoints, to populate the Endpoint
|
||||
data model in the Processes node. The command-line arguments are mapped to the "process"
|
||||
field in the Endpoint data model.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: None identified.
|
||||
references:
|
||||
- https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/
|
||||
@@ -71,10 +68,14 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Dump LSASS via procdump
|
||||
id: 3742ebfe-64c2-11eb-ae93-0242ac130002
|
||||
version: 1
|
||||
date: '2021-02-01'
|
||||
version: 2
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
@@ -9,7 +9,7 @@ datamodel:
|
||||
description: 'Detect procdump.exe dumping the lsass process. This query looks for
|
||||
both -mm and -ma usage. -mm will produce a mini dump file and -ma will write a dump
|
||||
file with all process memory. Both are highly suspect and should be reviewed. This
|
||||
query does not monitor for the internal name (OriginalFileName=procdump) of the
|
||||
query does not monitor for the internal name (original_file_name=procdump) of the
|
||||
PE or look for procdump64.exe. Modify the query as needed.\
|
||||
|
||||
During triage, confirm this is procdump.exe executing. If it is the first time a
|
||||
@@ -17,14 +17,15 @@ description: 'Detect procdump.exe dumping the lsass process. This query looks fo
|
||||
the command line. Review other endpoint data sources for cross process (injection)
|
||||
into lsass.exe.'
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=procdump.exe
|
||||
OR Processes.process_name=procdump64.exe (Processes.process=*-ma* OR Processes.process=*-mm*)
|
||||
Processes.process=*lsass* by Processes.user Processes.process_name Processes.process
|
||||
Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `dump_lsass_via_procdump_filter`'
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_procdump` (Processes.process=*-ma*
|
||||
OR Processes.process=*-mm*) Processes.process=*lsass* by Processes.user Processes.process_name
|
||||
Processes.process Processes.original_file_name Processes.dest | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `dump_lsass_via_procdump_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: None identified.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1003/001/
|
||||
|
||||
@@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count values(Registry.registr
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used.
|
||||
Sysmon TA.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://www.mvps.net/docs/how-to-secure-remote-desktop-rdp/
|
||||
|
||||
@@ -15,13 +15,10 @@ description: The following detection identifies Microsoft Excel spawning PowerSh
|
||||
and identify any files that may have been written.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process)
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.parent_process_name="excel.exe" Processes.process_name IN ("powershell.exe",
|
||||
"pwsh.exe") by Processes.parent_process Processes.process_name Processes.user Processes.dest
|
||||
where Processes.parent_process_name="excel.exe" `process_powershell` by Processes.parent_process Processes.process_name Processes.user Processes.dest Processes.original_file_name
|
||||
| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`
|
||||
| `excel_spawning_powershell_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: False positives should be limited, but if any are present,
|
||||
filter as needed.
|
||||
references:
|
||||
@@ -66,12 +63,16 @@ tags:
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- process_name
|
||||
- process_id
|
||||
- parent_process_name
|
||||
- dest
|
||||
- user
|
||||
- parent_process_id
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Excessive Service Stop Attempt
|
||||
id: ae8d3f4a-acd7-11eb-8846-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
@@ -12,16 +12,17 @@ description: This analytic identifies suspicious series of attempt to kill multi
|
||||
there objective and evade detections.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "net.exe"
|
||||
OR Processes.process_name = "sc.exe" OR Processes.process_name = "net1.exe" AND
|
||||
Processes.process="*stop*" OR Processes.process="*delete*" by Processes.process_name
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_net` OR Processes.process_name
|
||||
= "sc.exe" OR Processes.process_name = "net1.exe" AND Processes.process="*stop*"
|
||||
OR Processes.process="*delete*" by Processes.process_name Processes.original_file_name
|
||||
Processes.parent_process_name Processes.dest Processes.user _time span=1m | where
|
||||
count >=5 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `excessive_service_stop_attempt_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed sc.exe may be used.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
|
||||
@@ -58,11 +59,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.process_name
|
||||
- Processes.parent_process_name
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Excessive Usage Of Net App
|
||||
id: 45e52536-ae42-11eb-b5c6-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-05-06'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
@@ -12,14 +12,15 @@ description: This analytic identifies excessive usage of `net.exe` or `net1.exe`
|
||||
malicious behavior.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "net.exe"
|
||||
OR Processes.process_name = "net1.exe" by Processes.process_name Processes.parent_process_name
|
||||
Processes.dest Processes.user _time span=1m | where count >=10 | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `excessive_usage_of_net_app_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed net.exe may be used.
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_net` by Processes.process_name
|
||||
Processes.parent_process_name Processes.original_file_name Processes.dest Processes.user
|
||||
_time span=1m | where count >=10 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `excessive_usage_of_net_app_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: unknown. Filter as needed. Modify the time span as needed.
|
||||
references:
|
||||
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
|
||||
@@ -62,11 +63,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.process_name
|
||||
- Processes.parent_process_name
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 28
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -11,12 +11,12 @@ description: The following analytic identifies the use of `reg.exe` exporting Wi
|
||||
registry hives for offline credential access attacks. Typically found executed from
|
||||
a untrusted process or script. Upon execution, a file will be written to disk.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=reg.exe
|
||||
(Processes.process=*save* OR Processes.process=*export*) AND (Processes.process="*\sam
|
||||
*" OR Processes.process="*\system *" OR Processes.process="*\security *") by Processes.dest
|
||||
Processes.user Processes.parent_process Processes.process_name Processes.process
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `extraction_of_registry_hives_filter`'
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_reg` (Processes.process=*save*
|
||||
OR Processes.process=*export*) AND (Processes.process="*\sam *" OR Processes.process="*\system
|
||||
*" OR Processes.process="*\security *") by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `extraction_of_registry_hives_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
@@ -66,10 +66,14 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Local Account Discovery with Net
|
||||
id: 5d0d4830-0133-11ec-bae3-acde48001122
|
||||
version: 1
|
||||
date: '2021-08-19'
|
||||
version: 2
|
||||
date: '2021-09-16'
|
||||
author: Mauricio Velazco, Splunk
|
||||
type: Hunting
|
||||
datamodel:
|
||||
@@ -11,8 +11,7 @@ description: This analytic looks for the execution of `net.exe` or `net1.exe` wi
|
||||
and 'users', return a list of all local users. Red Teams and adversaries alike use
|
||||
net.exe to enumerate users for situational awareness and Active Directory Discovery.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="net.exe"
|
||||
OR Processes.process_name="net1.exe") (Processes.process=*user OR Processes.process=*users)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_net` (Processes.process=*user OR Processes.process=*users)
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `local_account_discovery_with_net_filter`'
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Local Account Discovery With Wmic
|
||||
id: 4902d7aa-0134-11ec-9d65-acde48001122
|
||||
version: 1
|
||||
date: '2021-08-19'
|
||||
version: 2
|
||||
date: '2021-09-16'
|
||||
author: Mauricio Velazco, Splunk
|
||||
type: Hunting
|
||||
datamodel:
|
||||
@@ -11,11 +11,10 @@ description: This analytic looks for the execution of `wmic.exe` with command-li
|
||||
to leverage WMI to return a list of all local users. Red Teams and adversaries alike
|
||||
use net.exe to enumerate users for situational awareness and Active Directory Discovery.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="wmic.exe")
|
||||
(Processes.process=*useraccount*) by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `local_account_discovery_with_wmic_filter`'
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_wmic` (Processes.process=*useraccount*)
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `local_account_discovery_with_wmic_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
|
||||
+18
-12
@@ -1,6 +1,6 @@
|
||||
name: Malicious PowerShell Process - Connect To Internet With Hidden Window
|
||||
id: ee18ed37-0802-4268-9435-b3b91aaa18db
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2020-11-20'
|
||||
author: David Dorsey, Splunk
|
||||
type: TTP
|
||||
@@ -14,16 +14,16 @@ description: This search looks for PowerShell processes started with parameters
|
||||
download file with System.Net.WebClient.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process)
|
||||
as process values(Processes.parent_process) as parent_process min(_time) as firstTime
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell`
|
||||
Processes.process=*-WindowStyle* Processes.process=*hidden* Processes.process="*New-Object*"
|
||||
by Processes.user Processes.process_name Processes.parent_process_name Processes.process
|
||||
Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
|
||||
by Processes.user Processes.process_name Processes.original_file_name Processes.parent_process_name
|
||||
Processes.process Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)` | `malicious_powershell_process___connect_to_internet_with_hidden_window_filter`'
|
||||
how_to_implement: You must be ingesting data that records process activity from your
|
||||
hosts to populate the Endpoint data model in the Processes node. You must also be
|
||||
ingesting logs with both the process name and command line from your endpoints.
|
||||
The command-line arguments are mapped to the "process" field in the Endpoint data
|
||||
model.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Legitimate process can have this combination of command-line
|
||||
options, but it's not common.
|
||||
references: []
|
||||
@@ -77,10 +77,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process
|
||||
- Processes.process_name
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.dest
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 81
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Malicious PowerShell Process - Encoded Command
|
||||
id: c4db14d9-7909-48b4-a054-aa14d89dbb19
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2020-07-21'
|
||||
author: David Dorsey, Splunk
|
||||
type: Hunting
|
||||
@@ -10,16 +10,16 @@ description: This search looks for PowerShell processes that have encoded the sc
|
||||
within the command-line. Malware has been seen using this parameter, as it obfuscates
|
||||
the code and makes it relatively easy to pass a script on the command-line.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = powershell.exe
|
||||
(Processes.process=*-EncodedCommand* OR Processes.process=*-enc*) by Processes.user
|
||||
Processes.process_name Processes.process Processes.parent_process_name Processes.dest
|
||||
Processes.process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)` | `malicious_powershell_process___encoded_command_filter`'
|
||||
how_to_implement: You must be ingesting data that records process activity from your
|
||||
hosts to populate the Endpoint data model in the Processes node. You must also be
|
||||
ingesting logs with both the process name and command line from your endpoints.
|
||||
The command-line arguments are mapped to the "process" field in the Endpoint data
|
||||
model.
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_powershell` (Processes.process=*-EncodedCommand*
|
||||
OR Processes.process=*-enc*) by Processes.user Processes.process_name Processes.process
|
||||
Processes.parent_process_name Processes.original_file_name Processes.dest Processes.process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `malicious_powershell_process___encoded_command_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: System administrators may use this option, but it's not common.
|
||||
references: []
|
||||
tags:
|
||||
@@ -62,11 +62,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.dest
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Malicious PowerShell Process - Execution Policy Bypass
|
||||
id: 9be56c82-b1cc-4318-87eb-d138afaaca39
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2020-07-21'
|
||||
author: Rico Valdez, Mauricio Velazco, Splunk
|
||||
type: TTP
|
||||
@@ -13,14 +13,14 @@ description: This search looks for PowerShell processes started with parameters
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process_id) as
|
||||
process_id, values(Processes.parent_process_id) as parent_process_id values(Processes.process)
|
||||
as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.process_name=powershell.exe (Processes.process="* -ex*" OR Processes.process="*
|
||||
bypass *") by Processes.process_id, Processes.user, Processes.dest | `drop_dm_object_name(Processes)`
|
||||
where `process_powershell` (Processes.process="* -ex*" OR Processes.process="* bypass
|
||||
*") by Processes.process_id, Processes.user, Processes.dest | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `malicious_powershell_process___execution_policy_bypass_filter`'
|
||||
how_to_implement: You must be ingesting data that records process activity from your
|
||||
hosts to populate the Endpoint data model in the Processes node. You must also be
|
||||
ingesting logs with both the process name and command line from your endpoints.
|
||||
The command-line arguments are mapped to the "process" field in the Endpoint data
|
||||
model.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: There may be legitimate reasons to bypass the PowerShell execution
|
||||
policy. The PowerShell script being run with this parameter should be validated
|
||||
to ensure that it is legitimate.
|
||||
@@ -65,11 +65,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_id
|
||||
- Processes.process
|
||||
- Processes.process_name
|
||||
- Processes.user
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 42
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Malicious PowerShell Process With Obfuscation Techniques
|
||||
id: cde75cf6-3c7a-4dd6-af01-27cdb4511fd4
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2021-01-19'
|
||||
author: David Dorsey, Splunk
|
||||
type: TTP
|
||||
@@ -10,17 +10,17 @@ description: This search looks for PowerShell processes launched with arguments
|
||||
have characters indicative of obfuscation on the command-line.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process)
|
||||
as process values(Processes.parent_process) as parent_process min(_time) as firstTime
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe
|
||||
by Processes.user Processes.process_name Processes.parent_process_name Processes.dest
|
||||
Processes.process | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell`
|
||||
by Processes.user Processes.process_name Processes.original_file_name Processes.parent_process_name
|
||||
Processes.dest Processes.process | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)`| eval num_obfuscation = (mvcount(split(process,"`"))-1)
|
||||
+ (mvcount(split(process, "^"))-1) + (mvcount(split(process, "''"))-1) | `malicious_powershell_process_with_obfuscation_techniques_filter`
|
||||
| search num_obfuscation > 10 '
|
||||
how_to_implement: You must be ingesting data that records process activity from your
|
||||
hosts to populate the Endpoint data model in the Processes node. You must also be
|
||||
ingesting logs with both the process name and command line from your endpoints.
|
||||
The command-line arguments are mapped to the "process" field in the Endpoint data
|
||||
model.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: These characters might be legitimately on the command-line,
|
||||
but it is not common.
|
||||
references: []
|
||||
@@ -63,11 +63,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process
|
||||
- Processes.parent_process
|
||||
- Processes.process_name
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.dest
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 42
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Mshta spawning Rundll32 OR Regsvr32 Process
|
||||
id: 4aa5d062-e893-11eb-9eb2-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-07-19'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
@@ -12,14 +12,15 @@ description: This search is to detect a suspicious mshta.exe process that spawn
|
||||
trickbot payload.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name
|
||||
= "mshta.exe" (Processes.process_name=rundll32.exe OR Processes.process_name=regsvr32.exe)
|
||||
by Processes.parent_process Processes.process_name Processes.process Processes.process_id
|
||||
Processes.process_guid Processes.user Processes.dest | `drop_dm_object_name("Processes")`
|
||||
| `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `mshta_spawning_rundll32_or_regsvr32_process_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed mshta.exe may be used.
|
||||
= "mshta.exe" `process_rundll32` OR `process_regsvr32` by Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.process_guid
|
||||
Processes.user Processes.dest | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`
|
||||
|`security_content_ctime(lastTime)` | `mshta_spawning_rundll32_or_regsvr32_process_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: limitted. this anomaly behavior is not commonly seen in clean
|
||||
host.
|
||||
references:
|
||||
@@ -56,10 +57,17 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- parent_process
|
||||
- process_name
|
||||
- process
|
||||
- process_id
|
||||
- process_guid
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Nishang PowershellTCPOneLine
|
||||
id: 1a382c6c-7c2e-11eb-ac69-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-03-03'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -13,15 +13,16 @@ description: This query detects the Nishang Invoke-PowerShellTCPOneLine utility
|
||||
suspicious. Review the reputation of the remote IP or domain contacted by the powershell
|
||||
process.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe
|
||||
OR Processes.process_name=pwsh.exe OR Processes.process_name=PowerShell_ISE.exe
|
||||
(Processes.process=*Net.Sockets.TCPClient* AND Processes.process=*System.Text.ASCIIEncoding*)
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_powershell` (Processes.process=*Net.Sockets.TCPClient*
|
||||
AND Processes.process=*System.Text.ASCIIEncoding*) by Processes.dest Processes.user
|
||||
Processes.parent_process Processes.original_file_name Processes.process_name Processes.process
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `nishang_powershelltcponeline_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Limited false positives may be present. Filter as needed based
|
||||
on initial analysis.
|
||||
references:
|
||||
@@ -57,13 +58,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 42
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Office Application Spawn Regsvr32 process
|
||||
id: 2d9fc90c-f11f-11eb-9300-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-07-30'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
@@ -13,15 +13,16 @@ description: this detection was designed to identifies suspicious spawned proces
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name
|
||||
= "winword.exe" OR Processes.parent_process_name = "excel.exe" OR Processes.parent_process_name
|
||||
= "powerpnt.exe" OR Processes.parent_process_name = "outlook.exe") Processes.process_name=regsvr32.exe
|
||||
= "powerpnt.exe" OR Processes.parent_process_name = "outlook.exe") `process_regsvr32`
|
||||
by Processes.parent_process_name Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.process_guid Processes.user Processes.dest
|
||||
| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)`
|
||||
| `office_application_spawn_regsvr32_process_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.process_guid
|
||||
Processes.user Processes.dest | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`
|
||||
|`security_content_ctime(lastTime)` | `office_application_spawn_regsvr32_process_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://www.joesandbox.com/analysis/380662/0/html
|
||||
@@ -52,13 +53,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.process_guid
|
||||
- Processes.user
|
||||
- Processes.dest
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Office Application Spawn rundll32 process
|
||||
id: 958751e4-9c5f-11eb-b103-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-04-13'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
@@ -13,14 +13,15 @@ description: this detection was designed to identifies suspicious spawned proces
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process)
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.parent_process_name = "winword.exe" OR Processes.parent_process_name
|
||||
= "excel.exe" OR Processes.parent_process_name = "powerpnt.exe") Processes.process_name=rundll32.exe by
|
||||
= "excel.exe" OR Processes.parent_process_name = "powerpnt.exe") `process_rundll32` by
|
||||
Processes.parent_process Processes.process_name Processes.process_id Processes.process_guid
|
||||
Processes.user Processes.dest | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`
|
||||
| `office_application_spawn_rundll32_process_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://any.run/malware-trends/trickbot
|
||||
@@ -53,12 +54,16 @@ tags:
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- Processes.process
|
||||
- Processes.parent_process_name
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,27 +1,29 @@
|
||||
name: Office Document Spawned Child Process To Download
|
||||
id: 6fed27d2-9ec7-11eb-8fe4-aa665a019aa3
|
||||
version: 2
|
||||
date: '2021-06-23'
|
||||
version: 3
|
||||
date: '2021-09-20'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: this search is to detect potential malicious office document executing
|
||||
description: This search is to detect potential malicious office document executing
|
||||
lolbin child process to download payload or other malware. Since most of the attacker
|
||||
abused the capability of office document to execute living on land application to
|
||||
blend it to the normal noise in the infected machine to cover its track.
|
||||
search: '`sysmon` EventCode=1 parent_process_name IN ("powerpnt.exe", "winword.exe",
|
||||
"excel.exe", "visio.exe") process_name = "*.exe" cmdline IN ("*http:*","*https:*") NOT(OriginalFileName
|
||||
IN("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe")) | stats min(_time)
|
||||
as firstTime max(_time) as lastTime count by parent_process_name process_name parent_process
|
||||
cmdline process_id OriginalFileName ProcessGuid Computer EventCode | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `office_document_spawned_child_process_to_download_filter`'
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name
|
||||
IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") Processes.process
|
||||
IN ("*http:*","*https:*") NOT (Processes.original_file_name IN("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe")) by
|
||||
Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `office_document_spawned_child_process_to_download_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances office application and browser may be
|
||||
used.
|
||||
known_false_positives: default browser not in the filter list
|
||||
known_false_positives: Default browser not in the filter list.
|
||||
references:
|
||||
- https://app.any.run/tasks/92d7ef61-bfd7-4c92-bc15-322172b4ebec/#
|
||||
tags:
|
||||
@@ -51,14 +53,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- parent_process_name
|
||||
- process_name
|
||||
- parent_process
|
||||
- cmdline
|
||||
- process_id
|
||||
- OriginalFileName
|
||||
- ProcessGuid
|
||||
- Computer
|
||||
- EventCode
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Office Product Spawn CMD Process
|
||||
id: b8b19420-e892-11eb-9244-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-07-19'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
@@ -14,14 +14,15 @@ description: this search is to detect a suspicious office product process that s
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name
|
||||
= "winword.exe" OR Processes.parent_process_name= "excel.exe" OR Processes.parent_process_name
|
||||
= "powerpnt.exe") Processes.process_name=cmd.exe by Processes.parent_process Processes.process_name
|
||||
= "powerpnt.exe") `process_cmd` by Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.process_guid Processes.user Processes.dest
|
||||
| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)`
|
||||
| `office_product_spawn_cmd_process_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
Processes.original_file_name | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`
|
||||
|`security_content_ctime(lastTime)` | `office_product_spawn_cmd_process_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: IT or network admin may create an document automation that
|
||||
will run shell script.
|
||||
references:
|
||||
@@ -57,10 +58,17 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- parent_process
|
||||
- process_name
|
||||
- process
|
||||
- process_id
|
||||
- process_guid
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Office Product Spawning BITSAdmin
|
||||
id: e8c591f4-a6d7-11eb-8cf7-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-04-26'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -19,13 +19,16 @@ description: The following detection identifies the latest behavior utilized by
|
||||
for further activity.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name
|
||||
IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") Processes.process_name=bitsadmin.exe
|
||||
IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_bitsadmin`
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `office_product_spawning_bitsadmin_filter`'
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `office_product_spawning_bitsadmin_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: No false positives known. Filter as needed.
|
||||
references:
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1197/T1197.md
|
||||
@@ -61,11 +64,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- process_name
|
||||
- process_id
|
||||
- parent_process_name
|
||||
- dest
|
||||
- user
|
||||
- parent_process_id
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Office Product Spawning CertUtil
|
||||
id: 6925fe72-a6d5-11eb-9e17-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-04-26'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -18,13 +18,16 @@ description: The following detection identifies the latest behavior utilized by
|
||||
for further activity.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name
|
||||
IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") Processes.process_name=certutil.exe
|
||||
IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_certutil`
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `office_product_spawning_certutil_filter`'
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `office_product_spawning_certutil_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: No false positives known. Filter as needed.
|
||||
references:
|
||||
- https://redcanary.com/threat-detection-report/threats/TA551/
|
||||
@@ -61,11 +64,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- process_name
|
||||
- process_id
|
||||
- parent_process_name
|
||||
- dest
|
||||
- user
|
||||
- parent_process_id
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Office Product Spawning MSHTA
|
||||
id: 6078fa20-a6d2-11eb-b662-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-04-26'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -18,13 +18,16 @@ description: The following detection identifies the latest behavior utilized by
|
||||
parallel processes for further activity.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name
|
||||
IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") Processes.process_name=mshta.exe
|
||||
IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_mshta`
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `office_product_spawning_mshta_filter`'
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `office_product_spawning_mshta_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: No false positives known. Filter as needed.
|
||||
references:
|
||||
- https://redcanary.com/threat-detection-report/threats/TA551/
|
||||
@@ -61,11 +64,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- process_name
|
||||
- process_id
|
||||
- parent_process_name
|
||||
- dest
|
||||
- user
|
||||
- parent_process_id
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Office Product Spawning Rundll32 with no DLL
|
||||
id: c661f6be-a38c-11eb-be57-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-04-22'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -18,14 +18,16 @@ description: The following detection identifies the latest behavior utilized by
|
||||
additional parallel processes for further activity.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name
|
||||
IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") Processes.process_name=rundll32.exe
|
||||
IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_rundll32`
|
||||
(Processes.process!=*.dll*) by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `office_product_spawning_rundll32_with_no_dll_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: False positives should be limited, but if any are present,
|
||||
filter as needed.
|
||||
references:
|
||||
@@ -65,11 +67,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- process_name
|
||||
- process_id
|
||||
- parent_process_name
|
||||
- dest
|
||||
- user
|
||||
- parent_process_id
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Office Product Spawning Wmic
|
||||
id: ffc236d6-a6c9-11eb-95f1-acde48001122
|
||||
version: 1
|
||||
date: '2021-04-26'
|
||||
version: 3
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
@@ -18,13 +18,16 @@ description: The following detection identifies the latest behavior utilized by
|
||||
activity.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name
|
||||
IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") Processes.process_name=wmic.exe
|
||||
IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe") `process_wmic`
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `office_product_spawning_wmic_filter`'
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `office_product_spawning_wmic_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: No false positives known. Filter as needed.
|
||||
references:
|
||||
- https://app.any.run/tasks/fb894ab8-a966-4b72-920b-935f41756afd/
|
||||
@@ -33,6 +36,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Spearphishing Attachments
|
||||
- FIN7
|
||||
automated_detection_testing: passed
|
||||
confidence: 90
|
||||
context:
|
||||
@@ -62,11 +66,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- process_name
|
||||
- process_id
|
||||
- parent_process_name
|
||||
- dest
|
||||
- user
|
||||
- parent_process_id
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Powershell Disable Security Monitoring
|
||||
id: c148a894-dd93-11eb-bf2a-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-07-05'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -10,15 +10,17 @@ description: This search is to identifies a modification in registry to disable
|
||||
windows denfender real time behavior monitoring. This event or technique is commonly
|
||||
seen in RAT, bot, or Trojan to disable AV to evade detections.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("powershell.exe",
|
||||
"pwsh.exe", "sqlps.exe", "sqltoolsps.exe") Processes.process="*set-mppreference*"
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process="*set-mppreference*"
|
||||
AND Processes.process IN ("*disablerealtimemonitoring*","*disableioavprotection*","*disableintrusionpreventionsystem*","*disablescriptscanning*","*disableblockatfirstseen*")
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `powershell_disable_security_monitoring_filter`'
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.original_file_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `powershell_disable_security_monitoring_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Limited false positives. However, tune based on scripts that
|
||||
may perform this action.
|
||||
references:
|
||||
@@ -42,9 +44,13 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: PowerShell Start-BitsTransfer
|
||||
id: 39e2605a-90d8-11eb-899e-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-03-29'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -14,14 +14,16 @@ description: Start-BitsTransfer is the PowerShell "version" of BitsAdmin.exe. Si
|
||||
processes and process lineage. Capture any files on disk and review. For the remote
|
||||
domain or IP, what is the reputation?
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe
|
||||
Processes.process=*start-bitstransfer* by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process=*start-bitstransfer*
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.original_file_name Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `powershell_start_bitstransfer_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Limited false positives. It is possible administrators will
|
||||
utilize Start-BitsTransfer for administrative tasks, otherwise filter based parent
|
||||
process or command-line arguments.
|
||||
@@ -61,10 +63,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process
|
||||
- Processes.parent_process
|
||||
- Processes.process_name
|
||||
- Processes.user
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Process Kill Base On File Path
|
||||
id: 5ffaa42c-acdb-11eb-9ad3-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-05-04'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
@@ -11,15 +11,16 @@ description: The following analytic identifies the use of `wmic.exe` using `dele
|
||||
stages of an adversary setting up for mining on an endpoint.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name =
|
||||
"wmic.exe" AND Processes.process="*process*" AND Processes.process="*executablepath*"
|
||||
AND Processes.process="*delete*" by Processes.parent_process_name Processes.process_name
|
||||
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `process_kill_base_on_file_path_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed wmic.exe may be used.
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_wmic` AND Processes.process="*process*"
|
||||
AND Processes.process="*executablepath*" AND Processes.process="*delete*" by Processes.parent_process_name
|
||||
Processes.process_name Processes.original_file_name Processes.dest Processes.user
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `process_kill_base_on_file_path_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Unknown.
|
||||
references:
|
||||
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
|
||||
@@ -55,11 +56,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.parent_process_name
|
||||
- Processes.process_name
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
name: Processes launching netsh
|
||||
id: b89919ed-fe5f-492c-b139-95dbb162040e
|
||||
version: 3
|
||||
date: '2020-07-10'
|
||||
author: Josef Kuepker, Splunk
|
||||
version: 4
|
||||
date: '2021-09-16'
|
||||
author: Michael Haag, Josef Kuepker, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
@@ -14,11 +14,15 @@ description: This search looks for processes launching netsh.exe. Netsh is a com
|
||||
executing commands via the command line.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process)
|
||||
AS Processes.process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.process=*netsh* by Processes.parent_process_name Processes.parent_process
|
||||
Processes.process_name Processes.user Processes.dest |`drop_dm_object_name("Processes")`
|
||||
|`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` |`processes_launching_netsh_filter`'
|
||||
how_to_implement: To successfully implement this search, you must be ingesting data
|
||||
that records process activity from your hosts to populate the endpoint data model
|
||||
where `process_netsh` by Processes.parent_process_name Processes.parent_process
|
||||
Processes.original_file_name Processes.process_name Processes.user Processes.dest
|
||||
|`drop_dm_object_name("Processes")` |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)`
|
||||
|`processes_launching_netsh_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Some VPN applications are known to launch netsh.exe. Outside
|
||||
of these instances, it is unusual for an executable to launch netsh.exe and run
|
||||
commands.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Recursive Delete of Directory In Batch CMD
|
||||
id: ba570b3a-d356-11eb-8358-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-06-22'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
@@ -11,15 +11,16 @@ description: This search is to detect a suspicious commandline designed to delet
|
||||
(reddot) where it it tries to delete the files in recycle bin to impaire user from
|
||||
recovering deleted files.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe
|
||||
Processes.process=*/c* Processes.process=* rd * Processes.process="*/s*" Processes.process="*/q*"
|
||||
by Processes.user Processes.process_name Processes.parent_process_name Processes.parent_process
|
||||
Processes.process Processes.process_id Processes.dest |`drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `recursive_delete_of_directory_in_batch_cmd_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_cmd` Processes.process=*/c* Processes.process=*
|
||||
rd * Processes.process="*/s*" Processes.process="*/q*" by Processes.user Processes.process_name
|
||||
Processes.parent_process_name Processes.parent_process Processes.process Processes.process_id
|
||||
Processes.dest |`drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `recursive_delete_of_directory_in_batch_cmd_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: network operator may use this batch command to delete recursively
|
||||
a directory or files within directory
|
||||
references:
|
||||
@@ -40,11 +41,15 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.parent_process_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.parent_process
|
||||
- Processes.process_id
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,24 +1,24 @@
|
||||
name: Remote Process Instantiation via WMI
|
||||
id: d25d2c3d-d9d8-40ec-8fdf-e86fe155a3da
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2020-11-30'
|
||||
author: Rico Valdez, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This search looks for wmic.exe being launched with parameters to spawn
|
||||
description: This analytic identifies wmic.exe being launched with parameters to spawn
|
||||
a process on a remote system.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.process_name = wmic.exe Processes.process="*/node*" Processes.process="*process*"
|
||||
Processes.process="*call*" Processes.process="*create*" by Processes.process_name
|
||||
where `process_wmic` Processes.process="*/node*" Processes.process="*process*" Processes.process="*call*"
|
||||
Processes.process="*create*" by Processes.process_name Processes.original_file_name
|
||||
Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `remote_process_instantiation_via_wmi_filter`'
|
||||
how_to_implement: You must be ingesting data that records process activity from your
|
||||
hosts to populate the Endpoint data model in the Processes node. You must also be
|
||||
ingesting logs with both the process name and command line from your endpoints.
|
||||
The command-line arguments are mapped to the "process" field in the Endpoint data
|
||||
model.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: The wmic.exe utility is a benign Windows application. It may
|
||||
be used legitimately by Administrators with these parameters for remote system administration,
|
||||
but it's relatively uncommon.
|
||||
@@ -65,10 +65,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.parent_process_name
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Remote WMI Command Attempt
|
||||
id: 272df6de-61f1-4784-877c-1fbc3e2d0838
|
||||
version: 3
|
||||
version: 4
|
||||
date: '2018-12-03'
|
||||
author: Rico Valdez, Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -12,16 +12,16 @@ description: The following analytic identifies usage of `wmic.exe` spawning a lo
|
||||
and after `wmic.exe` execution. In addition, identify the remote endpoint and confirm
|
||||
execution or file modifications. Contain and isolate the endpoint as needed.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wmic.exe
|
||||
Processes.process=*node* by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `remote_wmi_command_attempt_filter`'
|
||||
how_to_implement: You must be ingesting data that records process activity from your
|
||||
hosts to populate the Endpoint data model in the Processes node. You must also be
|
||||
ingesting logs with both the process name and command line from your endpoints.
|
||||
The command-line arguments are mapped to the "process" field in the Endpoint data
|
||||
model. Deprecated because duplicate of Remote Process Instantiation via WMI.
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_wmic` Processes.process=*node*
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `remote_wmi_command_attempt_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product. Deprecated because duplicate of Remote Process Instantiation via
|
||||
WMI.
|
||||
known_false_positives: Administrators may use this legitimately to gather info from
|
||||
remote systems. Filter as needed.
|
||||
references:
|
||||
|
||||
@@ -7,7 +7,7 @@ type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This analytic identifies the suspicious Remote Thread execution of rundll32.exe
|
||||
process to cmd.exe process . This technique was seen in IcedID malware to execute
|
||||
process to cmd.exe process. This technique was seen in IcedID malware to execute
|
||||
its malicious code in normal process for defense evasion and to steal sensitive
|
||||
information the the compromised host. browser process.
|
||||
search: '`sysmon` EventCode=8 SourceImage = "*\\rundll32.exe" TargetImage = "*.exe"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Rundll32 with no Command Line Arguments with Network
|
||||
id: 35307032-a12d-11eb-835f-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-04-19'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -14,8 +14,8 @@ description: The following analytic identifies rundll32.exe with no command line
|
||||
dumping or file writes. Rundll32.exe is natively found in C:\Windows\system32 and
|
||||
C:\Windows\syswow64.
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
where Processes.process_name=rundll32.exe by _time span=1h Processes.process_id
|
||||
Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name
|
||||
where `process_rundll32` by _time span=1h Processes.process_id
|
||||
Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name Processes.original_file_name
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| regex process="(rundll32\.exe.{0,4}$)" | join process_id [| tstats `security_content_summariesonly`
|
||||
count FROM datamodel=Endpoint.Ports where Ports.dest_port !="0" by Ports.process_id
|
||||
@@ -24,7 +24,7 @@ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint
|
||||
connection_to_CNC dest_port | `rundll32_with_no_command_line_arguments_with_network_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` and `port` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` and `port` node. To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use a moved
|
||||
copy of rundll32, triggering a false positive.
|
||||
references:
|
||||
@@ -66,12 +66,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventID
|
||||
- process_name
|
||||
- process_id
|
||||
- parent_process_name
|
||||
- dest_port
|
||||
- process_path
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 70
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: RunDLL Loading DLL By Ordinal
|
||||
id: 6c135f8d-5e60-454e-80b7-c56eed739833
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2020-11-30'
|
||||
author: David Dorsey, Splunk
|
||||
type: TTP
|
||||
@@ -13,14 +13,14 @@ description: This search looks for executing scripts with rundll32. Adversaries
|
||||
operations.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.process_name = rundll32.exe by Processes.process_name Processes.parent_process_name
|
||||
Processes.process Processes.dest Processes.user | `drop_dm_object_name(Processes)`
|
||||
where `process_rundll32` by Processes.process_name Processes.parent_process_name
|
||||
Processes.original_file_name Processes.process Processes.dest Processes.user | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `rundll_loading_dll_by_ordinal_filter`'
|
||||
how_to_implement: You must be ingesting data that records process activity from your
|
||||
hosts to populate the Endpoint data model in the Processes node. You must also be
|
||||
ingesting logs with both the process name and command line from your endpoints.
|
||||
The command-line arguments are mapped to the "process" field in the Endpoint data
|
||||
model.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: While not common, loading a DLL under %AppData% and calling
|
||||
a function by ordinal is possible by a legitimate process
|
||||
references: []
|
||||
@@ -62,10 +62,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.parent_process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 70
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -14,9 +14,7 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as
|
||||
*" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `schtasks_used_for_forcing_a_reboot_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting logs
|
||||
with both the process name and command-line from your endpoints. If you are using
|
||||
Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Administrators may create jobs on systems forcing reboots to
|
||||
perform updates, maintenance, etc.
|
||||
references: []
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Spoolsv Spawning Rundll32
|
||||
id: 15d905f6-da6b-11eb-ab82-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-07-01'
|
||||
author: Mauricio Velazco, Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -14,13 +14,11 @@ description: The following analytic identifies a suspicious child process, `rund
|
||||
additional file modification events.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=spoolsv.exe
|
||||
Processes.process_name=rundll32.exe by Processes.dest Processes.user Processes.parent_process
|
||||
`process_rundll32` by Processes.dest Processes.user Processes.parent_process Processes.original_file_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `spoolsv_spawning_rundll32_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Limited false positives have been identified. There are limited
|
||||
instances where `rundll32.exe` may be spawned by a legitimate print driver.
|
||||
references:
|
||||
@@ -68,10 +66,14 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 72
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,25 +1,27 @@
|
||||
name: Suspicious DLLHost no Command Line Arguments
|
||||
id: ff61e98c-0337-4593-a78f-72a676c56f26
|
||||
version: 1
|
||||
date: '2021-02-23'
|
||||
version: 2
|
||||
date: '2021-09-20'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel: []
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies DLLHost.exe with no command line arguments.
|
||||
It is unusual for DLLHost.exe to execute with no command line arguments present.
|
||||
This particular behavior is common with malicious software, including Cobalt Strike.
|
||||
During investigation, identify any network connections and parallel processes. Identify
|
||||
any suspicious module loads related to credential dumping or file writes. DLLHost.exe
|
||||
is natively found in C:\Windows\system32 and C:\Windows\syswow64.
|
||||
search: '`sysmon` EventID=1 (process_name=dllhost.exe OR OriginalFileName=dllhost.exe)
|
||||
| regex CommandLine="(dllhost\.exe.{0,4}$)" | stats count min(_time) as firstTime
|
||||
max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name,
|
||||
OriginalFileName, process_path, CommandLine | rename Computer as dest | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `suspicious_dllhost_no_command_line_arguments_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
where `process_dllhost` by _time span=1h Processes.process_id Processes.process_name
|
||||
Processes.dest Processes.process_path Processes.process Processes.parent_process_name
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| regex process="(dllhost\.exe.{0,4}$)" | `suspicious_dllhost_no_command_line_arguments_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Limited false positives may be present in small environments.
|
||||
Tuning may be required based on parent process.
|
||||
references:
|
||||
@@ -59,14 +61,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventID
|
||||
- process_name
|
||||
- OriginalFileName
|
||||
- CommandLine
|
||||
- dest
|
||||
- User
|
||||
- ParentImage
|
||||
- ParentCommandLine
|
||||
- process_path
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,21 +1,22 @@
|
||||
name: Suspicious GPUpdate no Command Line Arguments
|
||||
id: f308490a-473a-40ef-ae64-dd7a6eba284a
|
||||
version: 1
|
||||
date: '2021-02-23'
|
||||
version: 2
|
||||
date: '2021-09-20'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel: []
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies gpupdate.exe with no command line arguments.
|
||||
It is unusual for gpupdate.exe to execute with no command line arguments present.
|
||||
This particular behavior is common with malicious software, including Cobalt Strike.
|
||||
During investigation, identify any network connections and parallel processes. Identify
|
||||
any suspicious module loads related to credential dumping or file writes. gpupdate.exe
|
||||
is natively found in C:\Windows\system32 and C:\Windows\syswow64.
|
||||
search: '`sysmon` EventID=1 (process_name=gpupdate.exe OR OriginalFileName=GPUpdate.exe)
|
||||
| regex CommandLine="(gpupdate\.exe.{0,4}$)" | stats count min(_time) as firstTime
|
||||
max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name,
|
||||
OriginalFileName, process_path, CommandLine | rename Computer as dest | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `suspicious_gpupdate_no_command_line_arguments_filter`'
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
where `process_gpupdate` by _time span=1h Processes.process_id Processes.process_name
|
||||
Processes.dest Processes.process_path Processes.process Processes.parent_process_name
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| regex process="(gpupdate\.exe.{0,4}$)" | `suspicious_gpupdate_no_command_line_arguments_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
@@ -59,14 +60,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventID
|
||||
- process_name
|
||||
- OriginalFileName
|
||||
- CommandLine
|
||||
- dest
|
||||
- User
|
||||
- ParentImage
|
||||
- ParentCommandLine
|
||||
- process_path
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
name: Suspicious IcedID Regsvr32 Cmdline
|
||||
id: c9ef7dc4-eeaf-11eb-b2b6-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-07-27'
|
||||
author: Teoderick Contreras,
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
@@ -11,15 +11,12 @@ description: this search is to detect a suspicious regsvr32 commandline "-s" to
|
||||
dll that will download the 2nd stage loader that will download and decrypt the config
|
||||
payload.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=regsvr32.exe
|
||||
Processes.process=*-s* by Processes.process_name Processes.process Processes.parent_process_name
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_regsvr32`
|
||||
Processes.process=*-s* by Processes.process_name Processes.process Processes.parent_process_name Processes.original_file_name
|
||||
Processes.parent_process Processes.process_id Processes.parent_process_id Processes.dest
|
||||
Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `suspicious_icedid_regsvr32_cmdline_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed regsvr32.exe may be used.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: minimal. but network operator can use this application to load
|
||||
dll.
|
||||
references:
|
||||
@@ -55,13 +52,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- process_name
|
||||
- process
|
||||
- parent_process_name
|
||||
- parent_process
|
||||
- process_id
|
||||
- parent_process_id
|
||||
- dest
|
||||
- user
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Suspicious IcedID Rundll32 Cmdline
|
||||
id: bed761f8-ee29-11eb-8bf3-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-07-26'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
@@ -10,15 +10,12 @@ description: This search is to detect a suspicious rundll32.exe commandline to e
|
||||
dll file. This technique was seen in IcedID malware to load its payload dll with
|
||||
the following parameter to load encrypted dll payload which is the license.dat.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_rundll32`
|
||||
Processes.process=*/i:* by Processes.process_name Processes.process Processes.parent_process_name
|
||||
Processes.parent_process Processes.process_id Processes.parent_process_id Processes.dest
|
||||
Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `suspicious_icedid_rundll32_cmdline_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: limitted. this parameter is not commonly used by windows application
|
||||
but can be used by the network operator.
|
||||
references:
|
||||
@@ -54,13 +51,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- process_name
|
||||
- process
|
||||
- parent_process_name
|
||||
- parent_process
|
||||
- process_id
|
||||
- parent_process_id
|
||||
- dest
|
||||
- user
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,25 +1,23 @@
|
||||
name: Suspicious microsoft workflow compiler rename
|
||||
id: f0db4464-55d9-11eb-ae93-0242ac130002
|
||||
version: 1
|
||||
date: '2021-01-12'
|
||||
version: 3
|
||||
date: '2021-09-20'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel: []
|
||||
type: Hunting
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies a renamed instance of microsoft.workflow.compiler.exe.
|
||||
Microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319
|
||||
and is rarely utilized. When investigating, identify the executed code on disk and
|
||||
review. A spawned child process from microsoft.workflow.compiler.exe is uncommon.
|
||||
In any instance, microsoft.workflow.compiler.exe spawning from an Office product
|
||||
or any living off the land binary is highly suspect.
|
||||
search: '`sysmon` EventID=1 (OriginalFileName=microsoft.workflow.compiler.exe OR process_name=microsoft.workflow.compiler.exe)
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User,
|
||||
parent_process_name, process_name, OriginalFileName, process_path, CommandLine |
|
||||
rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
|
||||
`suspicious_microsoft_workflow_compiler_rename_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_microsoftworkflowcompiler` by Processes.dest Processes.user
|
||||
Processes.parent_process_name Processes.process_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id Processes.original_file_name | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_microsoft_workflow_compiler_rename_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use a moved
|
||||
copy of microsoft.workflow.compiler.exe, triggering a false positive.
|
||||
references:
|
||||
@@ -68,13 +66,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventID
|
||||
- OriginalFileName
|
||||
- process_name
|
||||
- Computer
|
||||
- User
|
||||
- parent_process_name
|
||||
- process_path
|
||||
- CommandLine
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Suspicious microsoft workflow compiler usage
|
||||
id: 9bbc62e8-55d8-11eb-ae93-0242ac130002
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-01-12'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -10,14 +10,12 @@ description: The following analytic identifies microsoft.workflow.compiler.exe u
|
||||
microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319
|
||||
and is rarely utilized. When investigating, identify the executed code on disk and
|
||||
review. It is not a commonly used process by many applications.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process_name)
|
||||
as process_name values(Processes.process) as process min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=microsoft.workflow.compiler.exe
|
||||
by Processes.dest Processes.parent_process Processes.user | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_microsoft_workflow_compiler_usage_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_microsoftworkflowcompiler` by Processes.dest Processes.parent_process
|
||||
Processes.process_name Processes.original_file_name Processes.process Processes.user
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `suspicious_microsoft_workflow_compiler_usage_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Although unlikely, limited instances have been identified coming
|
||||
from native Microsoft utilities similar to SCCM.
|
||||
references:
|
||||
@@ -34,8 +32,6 @@ tags:
|
||||
context:
|
||||
- Source:Endpoint
|
||||
- Stage:Defense Evasion
|
||||
- Stage:Execution
|
||||
- Stage:Defense Evasion
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log
|
||||
impact: 70
|
||||
@@ -62,10 +58,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.parent_process
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Suspicious msbuild path
|
||||
id: f5198224-551c-11eb-ae93-0242ac130002
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-01-12'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -13,13 +13,11 @@ description: The following analytic identifies msbuild.exe executing from a non-
|
||||
there are instances of build applications that will move or use a copy of MSBuild.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process_name)
|
||||
as process_name values(Processes.process) as process min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=msbuild.exe
|
||||
AND (Processes.process_path!=c:\\windows\\microsoft.net\\framework*\\v*\\*) by Processes.dest
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_msbuild`
|
||||
AND (Processes.process_path!=c:\\windows\\microsoft.net\\framework*\\v*\\*) by Processes.dest Processes.original_file_name
|
||||
Processes.parent_process Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`| `suspicious_msbuild_path_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Some legitimate applications may use a moved copy of msbuild.exe,
|
||||
triggering a false positive. Baselining of MSBuild.exe usage is recommended to better
|
||||
understand it's path usage. Visual Studio runs an instance out of a path that will
|
||||
@@ -69,11 +67,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_path
|
||||
- Processes.dest
|
||||
- Processes.parent_process
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,23 +1,24 @@
|
||||
name: Suspicious MSBuild Rename
|
||||
id: 4006adac-5937-11eb-ae93-0242ac130002
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-01-12'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel: []
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies renamed instances of msbuild.exe executing.
|
||||
Msbuild.exe is natively found in C:\Windows\Microsoft.NET\Framework\v4.0.30319 and
|
||||
C:\Windows\Microsoft.NET\Framework64\v4.0.30319. During investigation, identify
|
||||
the code executed and what is executing a renamed instance of MSBuild.
|
||||
search: '`sysmon` EventID=1 (OriginalFileName=msbuild.exe process_name!=msbuild.exe)
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User,
|
||||
parent_process_name, process_name, OriginalFileName, process_path, CommandLine |
|
||||
rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
|
||||
`suspicious_msbuild_rename_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_msbuild`
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `suspicious_msbuild_rename_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use a moved
|
||||
copy of msbuild, triggering a false positive.
|
||||
references:
|
||||
@@ -66,13 +67,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventID
|
||||
- OriginalFileName
|
||||
- process_name
|
||||
- Computer
|
||||
- User
|
||||
- parent_process_name
|
||||
- process_path
|
||||
- CommandLine
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Suspicious MSBuild Spawn
|
||||
id: a115fba6-5514-11eb-ae93-0242ac130002
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-01-12'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -16,12 +16,10 @@ description: The following analytic identifies wmiprvse.exe spawning msbuild.exe
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process_name)
|
||||
as process_name values(Processes.process) as process min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=wmiprvse.exe
|
||||
AND Processes.process_name=msbuild.exe by Processes.dest Processes.parent_process
|
||||
AND `process_msbuild` by Processes.dest Processes.parent_process Processes.original_file_name
|
||||
Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `suspicious_msbuild_spawn_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Although unlikely, some legitimate applications may exhibit
|
||||
this behavior, triggering a false positive.
|
||||
references:
|
||||
@@ -65,11 +63,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.parent_process_name
|
||||
- Processes.dest
|
||||
- Processes.parent_process
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 42
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Suspicious mshta spawn
|
||||
id: 4d33a488-5b5f-11eb-ae93-0242ac130002
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-01-20'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -13,12 +13,10 @@ description: The following analytic identifies wmiprvse.exe spawning mshta.exe.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process_name)
|
||||
as process_name values(Processes.process) as process min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=svchost.exe
|
||||
OR Processes.parent_process_name=wmiprvse.exe) AND Processes.process_name=mshta.exe
|
||||
by Processes.dest Processes.parent_process Processes.user | `drop_dm_object_name(Processes)`
|
||||
OR Processes.parent_process_name=wmiprvse.exe) AND `process_mshta`
|
||||
by Processes.dest Processes.parent_process Processes.user Processes.original_file_name| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_mshta_spawn_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Although unlikely, some legitimate applications may exhibit
|
||||
this behavior, triggering a false positive.
|
||||
references:
|
||||
@@ -59,11 +57,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.parent_process_name
|
||||
- Processes.dest
|
||||
- Processes.parent_process
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 42
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Suspicious Regsvr32 Register Suspicious Path
|
||||
id: 62732736-6250-11eb-ae93-0242ac130002
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-01-28'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -11,17 +11,21 @@ description: Adversaries may abuse Regsvr32.exe to proxy execution of malicious
|
||||
look for network connections to remote destinations (internal or external). Review
|
||||
additional parrallel processes and child processes for additional activity.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=regsvr32.exe
|
||||
(Processes.process=*appdata* OR Processes.process=*programdata* OR Processes.process=*windows\temp*)
|
||||
(Processes.process!=*.dll Processes.process!=*.ax Processes.process!=*.ocx) by Processes.dest
|
||||
Processes.user Processes.parent_process Processes.process_name Processes.process
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` (Processes.process=*appdata*
|
||||
OR Processes.process=*programdata* OR Processes.process=*windows\temp*) (Processes.process!=*.dll
|
||||
Processes.process!=*.ax Processes.process!=*.ocx) by Processes.dest Processes.user
|
||||
Processes.parent_process Processes.process_name Processes.process Processes.original_file_name
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `suspicious_regsvr32_register_suspicious_path_filter`'
|
||||
how_to_implement: You must be ingesting endpoint data that tracks process activity,
|
||||
including parent-child relationships from your endpoints, to populate the Endpoint
|
||||
data model in the Processes node. The command-line arguments are mapped to the "process"
|
||||
field in the Endpoint data model. Tune the query by filtering additional extensions
|
||||
found to be used by legitimate processes.
|
||||
found to be used by legitimate processes. To successfully implement this search
|
||||
you need to be ingesting information on process that include the name of the process
|
||||
responsible for the changes from your endpoints into the `Endpoint` datamodel in
|
||||
the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is
|
||||
installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Limited false positives with the query restricted to specified
|
||||
paths. Add more world writeable paths as tuning continues.
|
||||
references:
|
||||
@@ -70,13 +74,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Suspicious Rundll32 dllregisterserver
|
||||
id: 8c00a385-9b86-4ac0-8932-c9ec3713b159
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-02-09'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -14,14 +14,16 @@ description: The following analytic identifies rundll32.exe using dllregisterser
|
||||
parrellel processes executing. Capture the DLL being loaded and inspect further.
|
||||
Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe
|
||||
Processes.process=*dllregisterserver* by Processes.dest Processes.user Processes.parent_process
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*dllregisterserver*
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.original_file_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `suspicious_rundll32_dllregisterserver_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: This is likely to produce false positives and will require
|
||||
some filtering. Tune the query by adding command line paths to known good DLLs,
|
||||
or filtering based on parent process names.
|
||||
@@ -72,12 +74,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Suspicious Rundll32 PluginInit
|
||||
id: 92d51712-ee29-11eb-b1ae-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-07-26'
|
||||
author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
@@ -10,15 +10,16 @@ description: This search is to detect a suspicious rundll32.exe process with plu
|
||||
parameter. This technique is commonly seen in IceID malware to execute its initial
|
||||
dll stager to download another payload to the compromised machine.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe
|
||||
Processes.process=*PluginInit* by Processes.process_name Processes.process Processes.parent_process_name
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*PluginInit*
|
||||
by Processes.process_name Processes.process Processes.parent_process_name Processes.original_file_name
|
||||
Processes.parent_process Processes.process_id Processes.parent_process_id Processes.dest
|
||||
Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `suspicious_rundll32_plugininit_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: third party application may used this dll export name to execute
|
||||
function.
|
||||
references:
|
||||
@@ -54,13 +55,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- process_name
|
||||
- process
|
||||
- parent_process_name
|
||||
- parent_process
|
||||
- process_id
|
||||
- parent_process_id
|
||||
- dest
|
||||
- user
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 42
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,25 +1,28 @@
|
||||
name: Suspicious Rundll32 Rename
|
||||
id: 7360137f-abad-473e-8189-acbdaa34d114
|
||||
version: 1
|
||||
version: 3
|
||||
date: '2021-02-04'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel: []
|
||||
type: Hunting
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies renamed instances of rundll32.exe executing.
|
||||
rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During
|
||||
investigation, validate it is the legitimate rundll32.exe executing and what script
|
||||
content it is loading. This query relies on the OriginalFileName from Sysmon, or
|
||||
internal name from the PE meta data. Expand the query as needed by looking for specific
|
||||
command line arguments outlined in other analytics.
|
||||
search: '`sysmon` EventID=1 OriginalFileName=RUNDLL32.EXE NOT process_name=rundll32.exe
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User,
|
||||
parent_process_name, process_name, OriginalFileName, process_path, CommandLine |
|
||||
rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
|
||||
`suspicious_rundll32_rename_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used.
|
||||
content it is loading. This query relies on the original filename or internal name
|
||||
from the PE meta data. Expand the query as needed by looking for specific command
|
||||
line arguments outlined in other analytics.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_rundll32` by Processes.dest
|
||||
Processes.user Processes.parent_process_name Processes.process_name Processes.process
|
||||
Processes.process_id Processes.parent_process_id Processes.original_file_name |
|
||||
`drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `suspicious_rundll32_rename_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use a moved
|
||||
copy of rundll32, triggering a false positive.
|
||||
references:
|
||||
@@ -67,13 +70,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventID
|
||||
- OriginalFileName
|
||||
- process_name
|
||||
- Computer
|
||||
- User
|
||||
- parent_process_name
|
||||
- process_path
|
||||
- CommandLine
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Suspicious Rundll32 StartW
|
||||
id: 9319dda5-73f2-4d43-a85a-67ce961bddb7
|
||||
version: 1
|
||||
version: 3
|
||||
date: '2021-02-04'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -16,14 +16,11 @@ description: The following analytic identifies rundll32.exe executing a DLL func
|
||||
rundll32.exe is the default process it opens and injects shellcode into. This default
|
||||
process can be changed, but typically is not.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe
|
||||
Processes.process=*start* by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `suspicious_rundll32_startw_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*start* by Processes.dest
|
||||
Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_rundll32_startw_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use Start
|
||||
as a function and call it via the command line. Filter as needed.
|
||||
references:
|
||||
@@ -73,12 +70,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,25 +1,27 @@
|
||||
name: Suspicious Rundll32 no Command Line Arguments
|
||||
id: e451bd16-e4c5-4109-8eb1-c4c6ecf048b4
|
||||
version: 1
|
||||
date: '2021-02-09'
|
||||
version: 2
|
||||
date: '2021-09-20'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel: []
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies rundll32.exe with no command line arguments.
|
||||
It is unusual for rundll32.exe to execute with no command line arguments present.
|
||||
This particular behavior is common with malicious software, including Cobalt Strike.
|
||||
During investigation, identify any network connections and parallel processes. Identify
|
||||
any suspicious module loads related to credential dumping or file writes. Rundll32.exe
|
||||
is natively found in C:\Windows\system32 and C:\Windows\syswow64.
|
||||
search: '`sysmon` EventID=1 (process_name=rundll32.exe OR OriginalFileName=RUNDLL32.EXE)
|
||||
| regex CommandLine="(rundll32\.exe.{0,4}$)" | stats count min(_time) as firstTime
|
||||
max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name,
|
||||
OriginalFileName, process_path, CommandLine | rename Computer as dest | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `suspicious_rundll32_no_command_line_arguments_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
where `process_rundll32` by _time span=1h Processes.process_id Processes.process_name
|
||||
Processes.dest Processes.process_path Processes.process Processes.parent_process_name
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| regex process="(rundll32\.exe.{0,4}$)" | `suspicious_rundll32_no_command_line_arguments_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use a moved
|
||||
copy of rundll32, triggering a false positive.
|
||||
references:
|
||||
@@ -69,14 +71,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventID
|
||||
- process_name
|
||||
- OriginalFileName
|
||||
- CommandLine
|
||||
- dest
|
||||
- User
|
||||
- ParentImage
|
||||
- ParentCommandLine
|
||||
- process_path
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
name: Suspicious SearchProtocolHost no Command Line Arguments
|
||||
id: f52d2db8-31f9-4aa7-a176-25779effe55c
|
||||
version: 1
|
||||
date: '2021-02-23'
|
||||
version: 2
|
||||
date: '2021-09-20'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel: []
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies searchprotocolhost.exe with no command
|
||||
line arguments. It is unusual for searchprotocolhost.exe to execute with no command
|
||||
line arguments present. This particular behavior is common with malicious software,
|
||||
@@ -12,15 +13,16 @@ description: The following analytic identifies searchprotocolhost.exe with no co
|
||||
and parallel processes. Identify any suspicious module loads related to credential
|
||||
dumping or file writes. searchprotocolhost.exe is natively found in C:\Windows\system32
|
||||
and C:\Windows\syswow64.
|
||||
search: '`sysmon` EventID=1 (process_name=searchprotocolhost.exe OR OriginalFileName=SearchProtocolHost.exe)
|
||||
| regex CommandLine="(searchprotocolhost\.exe.{0,4}$)" | stats count min(_time)
|
||||
as firstTime max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine,
|
||||
process_name, OriginalFileName, process_path, CommandLine | rename Computer as dest
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_searchprotocolhost_no_command_line_arguments_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
where Processes.process_name=searchprotocolhost.exe by _time span=1h Processes.process_id
|
||||
Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| regex process="(searchprotocolhost\.exe.{0,4}$)" | `suspicious_searchprotocolhost_no_command_line_arguments_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Limited false positives may be present in small environments.
|
||||
Tuning may be required based on parent process.
|
||||
references:
|
||||
@@ -59,14 +61,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- EventID
|
||||
- process_name
|
||||
- OriginalFileName
|
||||
- CommandLine
|
||||
- dest
|
||||
- User
|
||||
- ParentImage
|
||||
- ParentCommandLine
|
||||
- process_path
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: W3WP Spawning Shell
|
||||
id: 0f03423c-7c6a-11eb-bc47-acde48001122
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2021-03-03'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
@@ -17,12 +17,14 @@ description: This query identifies a shell, PowerShell.exe or Cmd.exe, spawning
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process_name)
|
||||
as process_name values(Processes.process) as process min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=w3wp.exe
|
||||
AND Processes.process_name=cmd.exe OR Processes.process_name=powershell.exe by Processes.dest
|
||||
Processes.parent_process Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`| `w3wp_spawning_shell_filter`'
|
||||
AND `process_cmd` OR `process_powershell` by Processes.dest Processes.parent_process
|
||||
Processes.original_file_name Processes.user | `drop_dm_object_name(Processes)` |
|
||||
`security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `w3wp_spawning_shell_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Baseline your environment before production. It is possible
|
||||
build systems using IIS will spawn cmd.exe to perform a software build. Filter as
|
||||
needed.
|
||||
@@ -60,10 +62,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user