mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -11,7 +11,7 @@ azure-identity==1.6.0
|
||||
azure-mgmt-compute==20.0.0
|
||||
azure-mgmt-core==1.2.1
|
||||
azure-mgmt-network==16.0.0
|
||||
azure-mgmt-resource==16.1.0
|
||||
azure-mgmt-resource==17.0.0
|
||||
bcrypt==3.2.0
|
||||
boto3==1.17.74
|
||||
botocore==1.20.30
|
||||
|
||||
@@ -28,6 +28,9 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Prohibited Traffic Allowed or Protocol Mismatch
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
@@ -44,6 +47,3 @@ tags:
|
||||
- Registry.dest
|
||||
- Registry.user
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log
|
||||
|
||||
@@ -24,6 +24,9 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Prohibited Traffic Allowed or Protocol Mismatch
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
@@ -39,6 +42,3 @@ tags:
|
||||
- ComputerName
|
||||
- User
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log
|
||||
|
||||
@@ -27,6 +27,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cobalt Strike
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
@@ -49,4 +50,3 @@ tags:
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_id
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
|
||||
@@ -20,12 +20,14 @@ how_to_implement: To successfully implement this search, you need to be ingestin
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
known_false_positives: 3rd party tool may have commandline parameter that can trigger this detection.
|
||||
known_false_positives: 3rd party tool may have commandline parameter that can trigger
|
||||
this detection.
|
||||
references:
|
||||
- https://malpedia.caad.fkie.fraunhofer.de/details/win.conti
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ransomware
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/conti/inf1/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
@@ -46,4 +48,3 @@ tags:
|
||||
- Processes.process_id
|
||||
- Processes.process_guid
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
|
||||
@@ -27,6 +27,9 @@ tags:
|
||||
- DarkSide Ransomware
|
||||
- Ransomware
|
||||
- Revil Ransomware
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-powershell.log
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
@@ -42,6 +45,3 @@ tags:
|
||||
- ComputerName
|
||||
- User
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-powershell.log
|
||||
|
||||
@@ -28,6 +28,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Discovery Techniques
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
@@ -52,4 +53,3 @@ tags:
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_id
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
|
||||
@@ -31,6 +31,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Discovery Techniques
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
@@ -53,4 +54,3 @@ tags:
|
||||
- process_id
|
||||
- file_create_time
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
|
||||
@@ -25,6 +25,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Collection and Staging
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
@@ -46,4 +47,3 @@ tags:
|
||||
- CommandLine
|
||||
- Product
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
|
||||
@@ -33,6 +33,7 @@ tags:
|
||||
- HAFNIUM Group
|
||||
- DarkSide Ransomware
|
||||
- Lateral Movement
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
@@ -56,4 +57,3 @@ tags:
|
||||
- CommandLine
|
||||
- Product
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
|
||||
@@ -28,6 +28,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Collection and Staging
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
@@ -50,4 +51,3 @@ tags:
|
||||
- CommandLine
|
||||
- Product
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
|
||||
@@ -32,6 +32,7 @@ tags:
|
||||
analytic_story:
|
||||
- Discovery Techniques
|
||||
- Ransomware
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
@@ -56,4 +57,3 @@ tags:
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_id
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
analytic_story:
|
||||
- Discovery Techniques
|
||||
- Ransomware
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
@@ -64,4 +65,3 @@ tags:
|
||||
- process_id
|
||||
- file_create_time
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
|
||||
@@ -35,6 +35,7 @@ tags:
|
||||
analytic_story:
|
||||
- Discovery Techniques
|
||||
- Ransomware
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
@@ -60,4 +61,3 @@ tags:
|
||||
- CommandLine
|
||||
- Product
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
|
||||
@@ -26,6 +26,9 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Prohibited Traffic Allowed or Protocol Mismatch
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
@@ -41,6 +44,3 @@ tags:
|
||||
- Registry.user
|
||||
- Registry.registry_value_name
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log
|
||||
|
||||
@@ -0,0 +1,52 @@
|
||||
name: Excessive number of taskhost processes
|
||||
id: f443dac2-c7cf-11eb-ab51-acde48001122
|
||||
version: 1
|
||||
date: '2021-06-07'
|
||||
author: Michael Hart
|
||||
type: batch
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This detection targets behaviors observed in post exploit kits like Meterpreter
|
||||
and Koadic that are run in memory. We have observed that these tools must invoke
|
||||
an excessive number of taskhost.exe and taskhostex.exe processes to complete various
|
||||
actions (discovery, lateral movement, etc.). It is extremely uncommon in the course
|
||||
of normal operations to see so many distinct taskhost and taskhostex processes running
|
||||
concurrently in a short time frame.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process_id) as
|
||||
process_ids min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes
|
||||
WHERE Processes.process_name = "taskhost.exe" OR Processes.process_name = "taskhostex.exe"
|
||||
BY Processes.dest Processes.process_name _time span=1h | `drop_dm_object_name(Processes)`
|
||||
| eval pid_count=mvcount(process_ids) | eval taskhost_count_=if(process_name ==
|
||||
"taskhost.exe", pid_count, 0) | eval taskhostex_count_=if(process_name == "taskhostex.exe",
|
||||
pid_count, 0) | stats sum(taskhost_count_) as taskhost_count, sum(taskhostex_count_)
|
||||
as taskhostex_count by _time, dest, firstTime, lastTime | where taskhost_count >
|
||||
10 and taskhostex_count > 10 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `excessive_number_of_taskhost_processes_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting events
|
||||
related to processes on the endpoints that include the name of the process and process
|
||||
id into the `Endpoint` datamodel in the `Processes` node.
|
||||
known_false_positives: Administrators, administrative actions or certain applications
|
||||
may run many instances of taskhost and taskhostex concurrently. Filter as needed.
|
||||
references:
|
||||
- https://attack.mitre.org/software/S0250/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Meterpreter
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/meterpreter/taskhost_processes/logExcessiveTaskHost.log
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1033
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.process_id
|
||||
- Processes.process_name
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
security_domain: endpoint
|
||||
@@ -18,14 +18,17 @@ search: '`wineventlog_system` EventCode=7036 Message IN ("*Volume Shadow Copy*",
|
||||
| `known_services_killed_by_ransomware_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the 7036 EventCode ScManager in System audit Logs from your endpoints.
|
||||
known_false_positives: Admin activities or installing related updates may do a sudden stop to
|
||||
list of services we monitor.
|
||||
known_false_positives: Admin activities or installing related updates may do a sudden
|
||||
stop to list of services we monitor.
|
||||
references:
|
||||
- https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/
|
||||
- https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ransomware
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf3/windows-system.log
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
@@ -41,6 +44,3 @@ tags:
|
||||
- dest
|
||||
- Type
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf3/windows-system.log
|
||||
|
||||
@@ -25,6 +25,9 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Exfiltration
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
@@ -40,6 +43,3 @@ tags:
|
||||
- ComputerName
|
||||
- User
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log
|
||||
|
||||
@@ -27,6 +27,9 @@ tags:
|
||||
analytic_story:
|
||||
- Ransomware
|
||||
- Revil Ransomware
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
@@ -46,6 +49,3 @@ tags:
|
||||
- process_id
|
||||
- user_id
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log
|
||||
|
||||
@@ -9,7 +9,8 @@ datamodel:
|
||||
description: The following analytics identifies a big number of instance of ransomware
|
||||
notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This
|
||||
behavior is a good sensor if the ransomware note filename is quite new for security
|
||||
industry or the ransomware note filename is not in your ransomware lookup table list for monitoring.
|
||||
industry or the ransomware note filename is not in your ransomware lookup table
|
||||
list for monitoring.
|
||||
search: '`sysmon` EventCode=11 file_name IN ("*\.txt","*\.html","*\.hta") |bin _time
|
||||
span=10s | stats min(_time) as firstTime max(_time) as lastTime dc(TargetFilename)
|
||||
as unique_readme_path_count values(TargetFilename) as list_of_readme_path by Computer
|
||||
|
||||
@@ -28,6 +28,9 @@ tags:
|
||||
analytic_story:
|
||||
- Ransomware
|
||||
- Revil Ransomware
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
@@ -47,6 +50,3 @@ tags:
|
||||
- Processes.process_id
|
||||
- Processes.process_guid
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log
|
||||
|
||||
@@ -28,6 +28,9 @@ tags:
|
||||
analytic_story:
|
||||
- Ransomware
|
||||
- Revil Ransomware
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
@@ -44,6 +47,3 @@ tags:
|
||||
- Registry.registry_path
|
||||
- Registry.registry_key_name
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-sysmon.log
|
||||
|
||||
@@ -28,6 +28,9 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
@@ -46,6 +49,3 @@ tags:
|
||||
- Processes.process_id
|
||||
- Processes.process_guid
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log
|
||||
|
||||
@@ -26,6 +26,9 @@ tags:
|
||||
analytic_story:
|
||||
- Ransomware
|
||||
- Revil Ransomware
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf2/windows-sysmon.log
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
@@ -46,6 +49,3 @@ tags:
|
||||
- Hashes
|
||||
- IMPHASH
|
||||
security_domain: endpoint
|
||||
automated_detection_testing: passed
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf2/windows-sysmon.log
|
||||
|
||||
Vendored
+1
-1
@@ -5,7 +5,7 @@
|
||||
"id": {
|
||||
"group": null,
|
||||
"name": "DA-ESS-ContentUpdate",
|
||||
"version": "3.22.0"
|
||||
"version": "3.23.0"
|
||||
},
|
||||
"author": [
|
||||
{
|
||||
|
||||
+59
-23
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2021-05-24T20:38:43 UTC
|
||||
# On Date: 2021-06-10T18:24:24 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
@@ -316,8 +316,8 @@ modification_date = 2021-02-16
|
||||
id = bcfd17e8-5461-400a-80a2-3b7d1459220c
|
||||
version = 1
|
||||
reference = ["https://www.cobaltstrike.com/", "https://www.infocyte.com/blog/2020/09/02/cobalt-strike-the-new-favorite-among-thieves/", "https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/", "https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html", "https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html", "https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence", "https://github.com/zer0yu/Awesome-CobaltStrike"]
|
||||
detection_searches = ["ESCU - Anomalous usage of 7zip - Rule", "ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - DLLHost with no Command Line Arguments with Network - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - GPUpdate with no Command Line Arguments with Network - Rule", "ESCU - Rundll32 with no Command Line Arguments with Network - Rule", "ESCU - SearchProtocolHost with no Command Line with Network - Rule", "ESCU - Services Escalate Exe - Rule", "ESCU - Suspicious DLLHost no Command Line Arguments - Rule", "ESCU - Suspicious GPUpdate no Command Line Arguments - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious SearchProtocolHost no Command Line Arguments - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious msbuild path - Rule"]
|
||||
mappings = {"cis20": ["CIS 16", "CIS 8"], "kill_chain_phases": ["Actions on Objective", "Actions on Objectives", "Exploitation", "Privilege Escalation"], "mitre_attack": ["T1036.003", "T1055", "T1127", "T1127.001", "T1218.010", "T1218.011", "T1548", "T1560.001"], "nist": ["DE.CM", "PR.PT"]}
|
||||
detection_searches = ["ESCU - Anomalous usage of 7zip - Rule", "ESCU - CMD Echo Pipe - Escalation - Rule", "ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - DLLHost with no Command Line Arguments with Network - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - GPUpdate with no Command Line Arguments with Network - Rule", "ESCU - Rundll32 with no Command Line Arguments with Network - Rule", "ESCU - SearchProtocolHost with no Command Line with Network - Rule", "ESCU - Services Escalate Exe - Rule", "ESCU - Suspicious DLLHost no Command Line Arguments - Rule", "ESCU - Suspicious GPUpdate no Command Line Arguments - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious SearchProtocolHost no Command Line Arguments - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious msbuild path - Rule"]
|
||||
mappings = {"cis20": ["CIS 16", "CIS 8"], "kill_chain_phases": ["Actions on Objective", "Actions on Objectives", "Exploitation", "Privilege Escalation"], "mitre_attack": ["T1036.003", "T1055", "T1059.003", "T1127", "T1127.001", "T1218.010", "T1218.011", "T1543.003", "T1548", "T1560.001"], "nist": ["DE.CM", "PR.PT"]}
|
||||
investigative_searches = []
|
||||
support_searches = []
|
||||
data_models = ["Endpoint"]
|
||||
@@ -361,8 +361,8 @@ modification_date = 2020-02-03
|
||||
id = 8e03c61e-13c4-4dcd-bfbe-5ce5a8dc031a
|
||||
version = 1
|
||||
reference = ["https://attack.mitre.org/wiki/Collection", "https://attack.mitre.org/wiki/Technique/T1074"]
|
||||
detection_searches = ["ESCU - Email files written outside of the Outlook directory - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Hosts receiving high volume of network traffic from email server - Rule", "ESCU - Suspicious writes to System Volume Information - Rule", "ESCU - Suspicious writes to windows Recycle Bin - Rule"]
|
||||
mappings = {"cis20": ["CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1036", "T1114.001", "T1114.002"], "nist": ["DE.AE", "DE.CM", "PR.PT"]}
|
||||
detection_searches = ["ESCU - Detect Renamed 7-Zip - Rule", "ESCU - Detect Renamed WinRAR - Rule", "ESCU - Email files written outside of the Outlook directory - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Hosts receiving high volume of network traffic from email server - Rule", "ESCU - Suspicious writes to System Volume Information - Rule", "ESCU - Suspicious writes to windows Recycle Bin - Rule"]
|
||||
mappings = {"cis20": ["CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exfiltration", "Exploitation"], "mitre_attack": ["T1036", "T1114.001", "T1114.002", "T1560.001"], "nist": ["DE.AE", "DE.CM", "PR.PT"]}
|
||||
investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task"]
|
||||
support_searches = []
|
||||
data_models = ["Endpoint", "Network_Traffic"]
|
||||
@@ -433,7 +433,7 @@ modification_date = 2020-02-04
|
||||
id = 854d78bf-d0e2-4f4e-b05c-640905f86d7a
|
||||
version = 3
|
||||
reference = ["https://attack.mitre.org/wiki/Technique/T1003", "https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html"]
|
||||
detection_searches = ["ESCU - Access LSASS Memory for Dump Creation - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Create Remote Thread into LSASS - Rule", "ESCU - Creation of Shadow Copy - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Creation of lsass Dump with Taskmgr - Rule", "ESCU - Credential Dumping via Copy Command from Shadow Copy - Rule", "ESCU - Credential Dumping via Symlink to Shadow Copy - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Extract SAM from Registry - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Unsigned Image Loaded by LSASS - Rule"]
|
||||
detection_searches = ["ESCU - Access LSASS Memory for Dump Creation - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Create Remote Thread into LSASS - Rule", "ESCU - Creation of Shadow Copy - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Creation of lsass Dump with Taskmgr - Rule", "ESCU - Credential Dumping via Copy Command from Shadow Copy - Rule", "ESCU - Credential Dumping via Symlink to Shadow Copy - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Extract SAM from Registry - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - SecretDumps Offline NTDS Dumping Tool - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Unsigned Image Loaded by LSASS - Rule"]
|
||||
mappings = {"cis20": ["CIS 16", "CIS 3", "CIS 5", "CIS 6", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exploitation", "Installation"], "mitre_attack": ["T1003.001", "T1003.002", "T1003.003", "T1059.001"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.IP"]}
|
||||
investigative_searches = ["ESCU - Investigate Failed Logins for Multiple Destinations - Response Task", "ESCU - Investigate Pass the Hash Attempts - Response Task", "ESCU - Investigate Pass the Ticket Attempts - Response Task", "ESCU - Investigate Previous Unseen User - Response Task"]
|
||||
support_searches = []
|
||||
@@ -452,8 +452,8 @@ modification_date = 2020-01-22
|
||||
id = 0c016e5c-88be-4e2c-8c6c-c2b55b4fb4ef
|
||||
version = 2
|
||||
reference = ["https://www.us-cert.gov/ncas/alerts/TA18-074A"]
|
||||
detection_searches = ["ESCU - Create local admin accounts using net exe - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Single Letter Process On Endpoint - Rule", "ESCU - Suspicious Reg exe Process - Rule"]
|
||||
mappings = {"cis20": ["CIS 12", "CIS 16", "CIS 2", "CIS 3", "CIS 5", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Installation"], "mitre_attack": ["T1021.002", "T1053.005", "T1059.001", "T1059.003", "T1071.002", "T1112", "T1136.001", "T1204.002", "T1543.003", "T1547.001", "T1562.004"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.AC", "PR.AT", "PR.DS", "PR.IP", "PR.PT"]}
|
||||
detection_searches = ["ESCU - Create local admin accounts using net exe - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Single Letter Process On Endpoint - Rule", "ESCU - Suspicious Reg exe Process - Rule"]
|
||||
mappings = {"cis20": ["CIS 12", "CIS 16", "CIS 2", "CIS 3", "CIS 5", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Execution", "Exploitation", "Installation", "Lateral Movement"], "mitre_attack": ["T1021.002", "T1053.005", "T1059.001", "T1059.003", "T1071.002", "T1112", "T1136.001", "T1204.002", "T1543.003", "T1547.001", "T1562.004", "T1569.002"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.AC", "PR.AT", "PR.DS", "PR.IP", "PR.PT"]}
|
||||
investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process File Activity - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task"]
|
||||
support_searches = ["ESCU - Baseline of SMB Traffic - MLTK", "ESCU - Previously seen command line arguments"]
|
||||
data_models = ["Endpoint", "Network_Traffic"]
|
||||
@@ -515,8 +515,8 @@ modification_date = 2021-05-12
|
||||
id = 507edc74-13d5-4339-878e-b9114ded1f35
|
||||
version = 1
|
||||
reference = ["https://www.splunk.com/en_us/blog/security/the-darkside-of-the-ransomware-pipeline.htmlbig-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/", "https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html"]
|
||||
detection_searches = ["ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - BITSAdmin Download File - Rule", "ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule", "ESCU - CertUtil Download With URLCache and Split Arguments - Rule", "ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule", "ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - Delete ShadowCopy With PowerShell - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect RClone Command-Line Usage - Rule", "ESCU - Detect Renamed RClone - Rule", "ESCU - Extract SAM from Registry - Rule", "ESCU - Ransomware Notes bulk creation - Rule", "ESCU - SLUI RunAs Elevated - Rule", "ESCU - SLUI Spawning a Process - Rule"]
|
||||
mappings = {"cis20": ["CIS 16", "CIS 3", "CIS 5", "CIS 6", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exfiltration", "Exploitation", "Obfuscation"], "mitre_attack": ["T1003.001", "T1003.002", "T1020", "T1021.002", "T1055", "T1105", "T1197", "T1218.003", "T1486", "T1490", "T1548.002"], "nist": ["DE.AE", "DE.CM", "PR.PT"]}
|
||||
detection_searches = ["ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - BITSAdmin Download File - Rule", "ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule", "ESCU - CertUtil Download With URLCache and Split Arguments - Rule", "ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule", "ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - Delete ShadowCopy With PowerShell - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect RClone Command-Line Usage - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - Detect Renamed RClone - Rule", "ESCU - Extract SAM from Registry - Rule", "ESCU - Ransomware Notes bulk creation - Rule", "ESCU - SLUI RunAs Elevated - Rule", "ESCU - SLUI Spawning a Process - Rule"]
|
||||
mappings = {"cis20": ["CIS 16", "CIS 3", "CIS 5", "CIS 6", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Execution", "Exfiltration", "Exploitation", "Lateral Movement", "Obfuscation"], "mitre_attack": ["T1003.001", "T1003.002", "T1020", "T1021.002", "T1055", "T1105", "T1197", "T1218.003", "T1486", "T1490", "T1548.002", "T1569.002"], "nist": ["DE.AE", "DE.CM", "PR.PT"]}
|
||||
investigative_searches = []
|
||||
support_searches = []
|
||||
data_models = ["Endpoint"]
|
||||
@@ -532,8 +532,8 @@ modification_date = 2020-10-21
|
||||
id = 66b0fe0c-1351-11eb-adc1-0242ac120002
|
||||
version = 1
|
||||
reference = ["https://attack.mitre.org/tactics/TA0010/"]
|
||||
detection_searches = ["ESCU - Detect SNICat SNI Exfiltration - Rule", "ESCU - O365 PST export alert - Rule", "ESCU - O365 Suspicious Admin Email Forwarding - Rule", "ESCU - O365 Suspicious User Email Forwarding - Rule"]
|
||||
mappings = {"cis20": ["CIS 13", "CIS 16"], "kill_chain_phases": ["Actions on Objective", "Actions on Objectives"], "mitre_attack": ["T1041", "T1114", "T1114.003"], "nist": ["DE.AE", "DE.CM", "DE.DP", "PR.DS"]}
|
||||
detection_searches = ["ESCU - Detect SNICat SNI Exfiltration - Rule", "ESCU - Mailsniper Invoke functions - Rule", "ESCU - O365 PST export alert - Rule", "ESCU - O365 Suspicious Admin Email Forwarding - Rule", "ESCU - O365 Suspicious User Email Forwarding - Rule"]
|
||||
mappings = {"cis20": ["CIS 13", "CIS 16"], "kill_chain_phases": ["Actions on Objective", "Actions on Objectives", "Exploitation"], "mitre_attack": ["T1041", "T1114", "T1114.001", "T1114.003"], "nist": ["DE.AE", "DE.CM", "DE.DP", "PR.DS"]}
|
||||
investigative_searches = ["ESCU - Get Notable History - Response Task"]
|
||||
support_searches = []
|
||||
data_models = []
|
||||
@@ -706,8 +706,8 @@ modification_date = 2021-03-03
|
||||
id = beae2ab0-7c3f-11eb-8b63-acde48001122
|
||||
version = 1
|
||||
reference = ["https://www.splunk.com/en_us/blog/security/detecting-hafnium-exchange-server-zero-day-activity-in-splunk.html", "https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/", "https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/", "https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/"]
|
||||
detection_searches = ["ESCU - Any Powershell DownloadString - Rule", "ESCU - Detect Exchange Web Shell - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Nishang PowershellTCPOneLine - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Unified Messaging Service Spawning a Process - Rule", "ESCU - W3WP Spawning Shell - Rule"]
|
||||
mappings = {"cis20": ["CIS 16", "CIS 3", "CIS 5", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Exploitation", "Installation"], "mitre_attack": ["T1003.001", "T1003.003", "T1021.002", "T1059.001", "T1114.002", "T1136.001", "T1190", "T1505.003"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.IP", "PR.PT"]}
|
||||
detection_searches = ["ESCU - Any Powershell DownloadString - Rule", "ESCU - Detect Exchange Web Shell - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Nishang PowershellTCPOneLine - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Unified Messaging Service Spawning a Process - Rule", "ESCU - W3WP Spawning Shell - Rule"]
|
||||
mappings = {"cis20": ["CIS 16", "CIS 3", "CIS 5", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Execution", "Exploitation", "Installation", "Lateral Movement"], "mitre_attack": ["T1003.001", "T1003.003", "T1021.002", "T1059.001", "T1114.002", "T1136.001", "T1190", "T1505.003", "T1569.002"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.IP", "PR.PT"]}
|
||||
investigative_searches = []
|
||||
support_searches = []
|
||||
data_models = ["Endpoint", "Network_Traffic"]
|
||||
@@ -861,8 +861,8 @@ modification_date = 2020-02-04
|
||||
id = 399d65dc-1f08-499b-a259-aad9051f38ad
|
||||
version = 2
|
||||
reference = ["https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html"]
|
||||
detection_searches = ["ESCU - Detect Activity Related to Pass the Hash Attacks - Rule", "ESCU - Kerberoasting spn request with RC4 encryption - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - Schtasks scheduling job on remote system - Rule"]
|
||||
mappings = {"cis20": ["CIS 16", "CIS 3", "CIS 5", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1021.001", "T1053.005", "T1550.002", "T1558.003"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.AT", "PR.IP", "PR.PT"]}
|
||||
detection_searches = ["ESCU - Detect Activity Related to Pass the Hash Attacks - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - Kerberoasting spn request with RC4 encryption - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - Schtasks scheduling job on remote system - Rule"]
|
||||
mappings = {"cis20": ["CIS 16", "CIS 3", "CIS 5", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Execution", "Exploitation", "Lateral Movement"], "mitre_attack": ["T1021.001", "T1021.002", "T1053.005", "T1550.002", "T1558.003", "T1569.002"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.AT", "PR.IP", "PR.PT"]}
|
||||
investigative_searches = ["ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task"]
|
||||
support_searches = []
|
||||
data_models = ["Endpoint", "Network_Traffic"]
|
||||
@@ -920,6 +920,25 @@ The following content is here to assist with binaries within `system32` or `sysw
|
||||
There will be false positives as some native Windows processes are moved or ran by third party applications from different paths. If file names are mismatched between the file name on disk and that of the binarys PE metadata, this is a likely indicator that a binary was renamed after it was compiled. Collecting and comparing disk and resource filenames for binaries by looking to see if the InternalName, OriginalFilename, and or ProductName match what is expected could provide useful leads, but may not always be indicative of malicious activity. Do not focus on the possible names a file could have, but instead on the command-line arguments that are known to be used and are distinct because it will have a better rate of detection.
|
||||
product = ['Splunk Enterprise', 'Splunk Enterprise Security', 'Splunk Cloud']
|
||||
|
||||
[Meterpreter]
|
||||
category = Adversary Tactics
|
||||
creation_date = 2021-06-08
|
||||
modification_date = 2021-06-08
|
||||
id = d5f8e298-c85a-11eb-9fea-acde48001122
|
||||
version = 1
|
||||
reference = ["https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/", "https://doubleoctopus.com/security-wiki/threats-and-tools/meterpreter/", "https://www.rapid7.com/products/metasploit/"]
|
||||
detection_searches = ["ESCU - Excessive number of taskhost processes - Rule"]
|
||||
mappings = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1033"]}
|
||||
investigative_searches = []
|
||||
support_searches = []
|
||||
data_models = []
|
||||
providing_technologies = none
|
||||
description = Meterpreter provides red teams, pen testers and threat actors interactive access to a compromised host to run commands, upload payloads, download files, and other actions.
|
||||
narrative = This Analytic Story supports you to detect Tactics, Techniques and Procedures (TTPs) from Meterpreter. Meterpreter is a Metasploit payload for remote execution that leverages DLL injection to make it extremely difficult to detect. Since the software runs in memory, no new processes are created upon injection. It also leverages encrypted communication channels.\
|
||||
Meterpreter enables the operator to remotely run commands on the target machine, upload payloads, download files, dump password hashes, and much more. It is difficult to determine from the forensic evidence what actions the operator performed. Splunk Research, however, has observed anomalous behaviors on the compromised hosts that seem to only appear when Meterpreter is executing various commands. With that, we have written new detections targeted to these detections.\
|
||||
While investigating a detection related to this analytic story, please bear in mind that the detections look for anomalies in system behavior. It will be imperative to look for other signs in the endpoint and network logs for lateral movement, discovery and other actions to confirm that the host was compromised and a remote actor used it to progress on their objectives.
|
||||
product = ['Splunk Enterprise', 'Splunk Enterprise Security', 'Splunk Cloud']
|
||||
|
||||
[Monitor Backup Solution]
|
||||
category = Best Practices
|
||||
creation_date = 2017-09-12
|
||||
@@ -1097,11 +1116,11 @@ modification_date = 2017-09-11
|
||||
id = 6d13121c-90f3-446d-8ac3-27efbbc65218
|
||||
version = 1
|
||||
reference = ["http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/"]
|
||||
detection_searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - TOR Traffic - Rule"]
|
||||
mappings = {"cis20": ["CIS 12", "CIS 13", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery"], "mitre_attack": ["T1048", "T1048.003", "T1071.001", "T1189"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.DS", "PR.PT"]}
|
||||
detection_searches = ["ESCU - Allow Inbound Traffic By Firewall Rule Registry - Rule", "ESCU - Allow Inbound Traffic In Firewall Rule - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Enable RDP In Other Port Number - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - TOR Traffic - Rule"]
|
||||
mappings = {"cis20": ["CIS 12", "CIS 13", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery", "Exploitation"], "mitre_attack": ["T1021", "T1021.001", "T1048", "T1048.003", "T1071.001", "T1189"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.DS", "PR.PT"]}
|
||||
investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task"]
|
||||
support_searches = []
|
||||
data_models = ["Network_Resolution", "Network_Traffic"]
|
||||
data_models = ["Endpoint", "Network_Resolution", "Network_Traffic"]
|
||||
providing_technologies = none
|
||||
description = Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers.
|
||||
narrative = A traditional security best practice is to control the ports, protocols, and services allowed within your environment. By limiting the services and protocols to those explicitly approved by policy, administrators can minimize the attack surface. The combined effect allows both network defenders and security controls to focus and not be mired in superfluous traffic or data types. Looking for deviations to policy can identify attacker activity that abuses services and protocols to run on alternate or non-standard ports in the attempt to avoid detection or frustrate forensic analysts.
|
||||
@@ -1114,8 +1133,8 @@ modification_date = 2020-02-04
|
||||
id = cf309d0d-d4aa-4fbb-963d-1e79febd3756
|
||||
version = 1
|
||||
reference = ["https://www.carbonblack.com/2017/06/28/carbon-black-threat-research-technical-analysis-petya-notpetya-ransomware/", "https://www.splunk.com/blog/2017/06/27/closing-the-detection-to-mitigation-gap-or-to-petya-or-notpetya-whocares-.html"]
|
||||
detection_searches = ["ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect RClone Command-Line Usage - Rule", "ESCU - Detect Renamed RClone - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - TOR Traffic - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - WinEvent Scheduled Task Created Within Public Path - Rule", "ESCU - WinEvent Scheduled Task Created to Spawn Shell - Rule", "ESCU - Windows Event Log Cleared - Rule"]
|
||||
mappings = {"cis20": ["CIS 10", "CIS 12", "CIS 3", "CIS 5", "CIS 6", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery", "Exfiltration", "Exploitation", "Privilege Escalation"], "mitre_attack": ["T1020", "T1021.002", "T1036.003", "T1047", "T1048", "T1053.005", "T1070", "T1070.001", "T1071.001", "T1218.003", "T1485", "T1490", "T1547.001"], "nist": ["DE.AE", "DE.CM", "DE.DP", "PR.AC", "PR.AT", "PR.IP", "PR.PT"]}
|
||||
detection_searches = ["ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Conti Common Exec parameter - Rule", "ESCU - Delete ShadowCopy With PowerShell - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect RClone Command-Line Usage - Rule", "ESCU - Detect Renamed RClone - Rule", "ESCU - Detect SharpHound Command-Line Arguments - Rule", "ESCU - Detect SharpHound File Modifications - Rule", "ESCU - Detect SharpHound Usage - Rule", "ESCU - Known Services Killed by Ransomware - Rule", "ESCU - Modification Of Wallpaper - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - Revil Common Exec Parameter - Rule", "ESCU - Revil Registry Entry - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - TOR Traffic - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - Wbemprox COM Object Execution - Rule", "ESCU - WinEvent Scheduled Task Created Within Public Path - Rule", "ESCU - WinEvent Scheduled Task Created to Spawn Shell - Rule", "ESCU - Windows Event Log Cleared - Rule"]
|
||||
mappings = {"cis20": ["CIS 10", "CIS 12", "CIS 3", "CIS 5", "CIS 6", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery", "Exfiltration", "Exploitation", "Privilege Escalation", "Reconnaissance"], "mitre_attack": ["T1020", "T1021.002", "T1036.003", "T1047", "T1048", "T1053.005", "T1069.001", "T1069.002", "T1070", "T1070.001", "T1071.001", "T1087.001", "T1087.002", "T1112", "T1204", "T1218.003", "T1482", "T1485", "T1490", "T1491", "T1547.001"], "nist": ["DE.AE", "DE.CM", "DE.DP", "PR.AC", "PR.AT", "PR.IP", "PR.PT"]}
|
||||
investigative_searches = ["ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task"]
|
||||
support_searches = ["ESCU - Baseline of Command Line Length - MLTK", "ESCU - Baseline of SMB Traffic - MLTK"]
|
||||
data_models = ["Endpoint", "Network_Traffic"]
|
||||
@@ -1141,6 +1160,23 @@ description = Leverage searches that allow you to detect and investigate unusual
|
||||
narrative = Ransomware is an ever-present risk to the enterprise, wherein an infected host encrypts business-critical data, holding it hostage until the victim pays the attacker a ransom. There are many types and varieties of ransomware that can affect an enterprise.Cloud ransomware can be deployed by obtaining high privilege credentials from targeted users or resources.
|
||||
product = ['Splunk Security Analytics for AWS', 'Splunk Enterprise', 'Splunk Enterprise Security', 'Splunk Cloud']
|
||||
|
||||
[Revil Ransomware]
|
||||
category = Malware
|
||||
creation_date = 2021-06-04
|
||||
modification_date = 2021-06-04
|
||||
id = 817cae42-f54b-457a-8a36-fbf45521e29e
|
||||
version = 1
|
||||
reference = ["https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/", "https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/"]
|
||||
detection_searches = ["ESCU - Delete ShadowCopy With PowerShell - Rule", "ESCU - Modification Of Wallpaper - Rule", "ESCU - Revil Common Exec Parameter - Rule", "ESCU - Revil Registry Entry - Rule", "ESCU - Wbemprox COM Object Execution - Rule"]
|
||||
mappings = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1112", "T1204", "T1218.003", "T1490", "T1491"]}
|
||||
investigative_searches = []
|
||||
support_searches = []
|
||||
data_models = ["Endpoint"]
|
||||
providing_technologies = none
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the Revil ransomware, including looking for file writes associated with Revil, encrypting network shares, deleting shadow volume storage, registry key modification, deleting of security logs, and more.
|
||||
narrative = Revil ransomware is a RaaS,that a single group may operates and manges the development of this ransomware. It involve the use of ransomware payloads along with exfiltration of data. Malicious actors demand payment for ransome of data and threaten deletion and exposure of exfiltrated data.
|
||||
product = ['Splunk Enterprise', 'Splunk Enterprise Security', 'Splunk Cloud']
|
||||
|
||||
[Router and Infrastructure Security]
|
||||
category = Best Practices
|
||||
creation_date = 2017-09-12
|
||||
@@ -1201,8 +1237,8 @@ modification_date = 2018-12-13
|
||||
id = c4b89506-fbcf-4cb7-bfd6-527e54789604
|
||||
version = 1
|
||||
reference = ["https://www.crowdstrike.com/blog/an-in-depth-analysis-of-samsam-ransomware-and-boss-spider/", "https://nakedsecurity.sophos.com/2018/07/31/samsam-the-almost-6-million-ransomware/", "https://thehackernews.com/2018/07/samsam-ransomware-attacks.html"]
|
||||
detection_searches = ["ESCU - Batch File Write to System32 - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect attackers scanning for vulnerable JBoss servers - Rule", "ESCU - Detect malicious requests to exploit JBoss servers - Rule", "ESCU - File with Samsam Extension - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Samsam Test File Write - Rule", "ESCU - Spike in File Writes - Rule"]
|
||||
mappings = {"cis20": ["CIS 10", "CIS 12", "CIS 16", "CIS 18", "CIS 2", "CIS 3", "CIS 4", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery", "Installation", "Reconnaissance"], "mitre_attack": ["T1021.001", "T1021.002", "T1082", "T1204.002", "T1485", "T1486", "T1490"], "nist": ["DE.AE", "DE.CM", "ID.AM", "ID.RA", "PR.AC", "PR.DS", "PR.IP", "PR.MA", "PR.PT"]}
|
||||
detection_searches = ["ESCU - Batch File Write to System32 - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - Detect attackers scanning for vulnerable JBoss servers - Rule", "ESCU - Detect malicious requests to exploit JBoss servers - Rule", "ESCU - File with Samsam Extension - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Samsam Test File Write - Rule", "ESCU - Spike in File Writes - Rule"]
|
||||
mappings = {"cis20": ["CIS 10", "CIS 12", "CIS 16", "CIS 18", "CIS 2", "CIS 3", "CIS 4", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery", "Execution", "Exploitation", "Installation", "Lateral Movement", "Reconnaissance"], "mitre_attack": ["T1021.001", "T1021.002", "T1082", "T1204.002", "T1485", "T1486", "T1490", "T1569.002"], "nist": ["DE.AE", "DE.CM", "ID.AM", "ID.RA", "PR.AC", "PR.DS", "PR.IP", "PR.MA", "PR.PT"]}
|
||||
investigative_searches = ["ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task"]
|
||||
support_searches = []
|
||||
data_models = ["Endpoint", "Network_Traffic", "Web"]
|
||||
|
||||
+247
-13
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2021-05-24T20:38:43 UTC
|
||||
# On Date: 2021-06-10T18:24:24 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
@@ -220,7 +220,7 @@ version = 1
|
||||
references = ["https://www.cobaltstrike.com/", "https://www.infocyte.com/blog/2020/09/02/cobalt-strike-the-new-favorite-among-thieves/", "https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/", "https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html", "https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html", "https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence", "https://github.com/zer0yu/Awesome-CobaltStrike"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Anomalous usage of 7zip - Rule", "ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - DLLHost with no Command Line Arguments with Network - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - GPUpdate with no Command Line Arguments with Network - Rule", "ESCU - Rundll32 with no Command Line Arguments with Network - Rule", "ESCU - SearchProtocolHost with no Command Line with Network - Rule", "ESCU - Services Escalate Exe - Rule", "ESCU - Suspicious DLLHost no Command Line Arguments - Rule", "ESCU - Suspicious GPUpdate no Command Line Arguments - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious SearchProtocolHost no Command Line Arguments - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious msbuild path - Rule"]
|
||||
searches = ["ESCU - Anomalous usage of 7zip - Rule", "ESCU - CMD Echo Pipe - Escalation - Rule", "ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - DLLHost with no Command Line Arguments with Network - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - GPUpdate with no Command Line Arguments with Network - Rule", "ESCU - Rundll32 with no Command Line Arguments with Network - Rule", "ESCU - SearchProtocolHost with no Command Line with Network - Rule", "ESCU - Services Escalate Exe - Rule", "ESCU - Suspicious DLLHost no Command Line Arguments - Rule", "ESCU - Suspicious GPUpdate no Command Line Arguments - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious SearchProtocolHost no Command Line Arguments - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious msbuild path - Rule"]
|
||||
description = Cobalt Strike is threat emulation software. Red teams and penetration testers use Cobalt Strike to demonstrate the risk of a breach and evaluate mature security programs. Most recently, Cobalt Strike has become the choice tool by threat groups due to its ease of use and extensibility.
|
||||
narrative = This Analytic Story supports you to detect Tactics, Techniques and Procedures (TTPs) from Cobalt Strike. Cobalt Strike has many ways to be enhanced by using aggressor scripts, malleable C2 profiles, default attack packages, and much more. For endpoint behavior, Cobalt Strike is most commonly identified via named pipes, spawn to processes, and DLL function names. Many additional variables are provided for in memory operation of the beacon implant. On the network, depending on the malleable C2 profile used, it is near infinite in the amount of ways to conceal the C2 traffic with Cobalt Strike. Not every query may be specific to Cobalt Strike the tool, but the methodologies and techniques used by it.\
|
||||
Splunk Threat Research reviewed all publicly available instances of Malleabe C2 Profiles and generated a list of the most commonly used spawnto and pipenames.\
|
||||
@@ -253,7 +253,7 @@ version = 1
|
||||
references = ["https://attack.mitre.org/wiki/Collection", "https://attack.mitre.org/wiki/Technique/T1074"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Email files written outside of the Outlook directory - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Hosts receiving high volume of network traffic from email server - Rule", "ESCU - Suspicious writes to System Volume Information - Rule", "ESCU - Suspicious writes to windows Recycle Bin - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task"]
|
||||
searches = ["ESCU - Detect Renamed 7-Zip - Rule", "ESCU - Detect Renamed WinRAR - Rule", "ESCU - Email files written outside of the Outlook directory - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Hosts receiving high volume of network traffic from email server - Rule", "ESCU - Suspicious writes to System Volume Information - Rule", "ESCU - Suspicious writes to windows Recycle Bin - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task"]
|
||||
description = Monitor for and investigate activities--such as suspicious writes to the Windows Recycling Bin or email servers sending high amounts of traffic to specific hosts, for example--that may indicate that an adversary is harvesting and exfiltrating sensitive data.
|
||||
narrative = A common adversary goal is to identify and exfiltrate data of value from a target organization. This data may include email conversations and addresses, confidential company information, links to network design/infrastructure, important dates, and so on.\
|
||||
Attacks are composed of three activities: identification, collection, and staging data for exfiltration. Identification typically involves scanning systems and observing user activity. Collection can involve the transfer of large amounts of data from various repositories. Staging/preparation includes moving data to a central location and compressing (and optionally encoding and/or encrypting) it. All of these activities provide opportunities for defenders to identify their presence. \
|
||||
@@ -301,7 +301,7 @@ version = 3
|
||||
references = ["https://attack.mitre.org/wiki/Technique/T1003", "https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Access LSASS Memory for Dump Creation - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Create Remote Thread into LSASS - Rule", "ESCU - Creation of Shadow Copy - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Creation of lsass Dump with Taskmgr - Rule", "ESCU - Credential Dumping via Copy Command from Shadow Copy - Rule", "ESCU - Credential Dumping via Symlink to Shadow Copy - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Extract SAM from Registry - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Unsigned Image Loaded by LSASS - Rule", "ESCU - Investigate Failed Logins for Multiple Destinations - Response Task", "ESCU - Investigate Pass the Hash Attempts - Response Task", "ESCU - Investigate Pass the Ticket Attempts - Response Task", "ESCU - Investigate Previous Unseen User - Response Task"]
|
||||
searches = ["ESCU - Access LSASS Memory for Dump Creation - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Create Remote Thread into LSASS - Rule", "ESCU - Creation of Shadow Copy - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Creation of lsass Dump with Taskmgr - Rule", "ESCU - Credential Dumping via Copy Command from Shadow Copy - Rule", "ESCU - Credential Dumping via Symlink to Shadow Copy - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Extract SAM from Registry - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - SecretDumps Offline NTDS Dumping Tool - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Unsigned Image Loaded by LSASS - Rule", "ESCU - Investigate Failed Logins for Multiple Destinations - Response Task", "ESCU - Investigate Pass the Hash Attempts - Response Task", "ESCU - Investigate Pass the Ticket Attempts - Response Task", "ESCU - Investigate Previous Unseen User - Response Task"]
|
||||
description = Uncover activity consistent with credential dumping, a technique wherein attackers compromise systems and attempt to obtain and exfiltrate passwords. The threat actors use these pilfered credentials to further escalate privileges and spread throughout a target environment. The included searches in this Analytic Story are designed to identify attempts to credential dumping.
|
||||
narrative = Credential dumping—gathering credentials from a target system, often hashed or encrypted—is a common attack technique. Even though the credentials may not be in plain text, an attacker can still exfiltrate the data and set to cracking it offline, on their own systems. The threat actors target a variety of sources to extract them, including the Security Accounts Manager (SAM), Local Security Authority (LSA), NTDS from Domain Controllers, or the Group Policy Preference (GPP) files.\
|
||||
Once attackers obtain valid credentials, they use them to move throughout a target network with ease, discovering new systems and identifying assets of interest. Credentials obtained in this manner typically include those of privileged users, which may provide access to more sensitive information and system operations.\
|
||||
@@ -314,7 +314,7 @@ version = 2
|
||||
references = ["https://www.us-cert.gov/ncas/alerts/TA18-074A"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Create local admin accounts using net exe - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Single Letter Process On Endpoint - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process File Activity - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task"]
|
||||
searches = ["ESCU - Create local admin accounts using net exe - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Single Letter Process On Endpoint - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process File Activity - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task"]
|
||||
description = Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA18-074A. Some of the activities that adversaries used in these compromises included spearfishing attacks, malware, watering-hole domains, many and more.
|
||||
narrative = The frequency of nation-state cyber attacks has increased significantly over the last decade. Employing numerous tactics and techniques, these attacks continue to escalate in complexity. \
|
||||
There is a wide range of motivations for these state-sponsored hacks, including stealing valuable corporate, military, or diplomatic dataѿall of which could confer advantages in various arenas. They may also target critical infrastructure. \
|
||||
@@ -359,7 +359,7 @@ version = 1
|
||||
references = ["https://www.splunk.com/en_us/blog/security/the-darkside-of-the-ransomware-pipeline.htmlbig-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/", "https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - BITSAdmin Download File - Rule", "ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule", "ESCU - CertUtil Download With URLCache and Split Arguments - Rule", "ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule", "ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - Delete ShadowCopy With PowerShell - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect RClone Command-Line Usage - Rule", "ESCU - Detect Renamed RClone - Rule", "ESCU - Extract SAM from Registry - Rule", "ESCU - Ransomware Notes bulk creation - Rule", "ESCU - SLUI RunAs Elevated - Rule", "ESCU - SLUI Spawning a Process - Rule"]
|
||||
searches = ["ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - BITSAdmin Download File - Rule", "ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule", "ESCU - CertUtil Download With URLCache and Split Arguments - Rule", "ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule", "ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - Delete ShadowCopy With PowerShell - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect RClone Command-Line Usage - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - Detect Renamed RClone - Rule", "ESCU - Extract SAM from Registry - Rule", "ESCU - Ransomware Notes bulk creation - Rule", "ESCU - SLUI RunAs Elevated - Rule", "ESCU - SLUI Spawning a Process - Rule"]
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the DarkSide Ransomware
|
||||
narrative = This story addresses Darkside ransomware. This ransomware payload has many similarities to common ransomware however there are certain items particular to it. The creation of a .TXT log that shows every item being encrypted as well as the creation of ransomware notes and files adding a machine ID created based on CRC32 checksum algorithm. This ransomware payload leaves machines in minimal operation level,enough to browse the attackers websites. A customized URI with leaked information is presented to each victim.This is the ransomware payload that shut down the Colonial pipeline. The story is composed of several detection searches covering similar items to other ransomware payloads and those particular to Darkside payload.
|
||||
|
||||
@@ -370,7 +370,7 @@ version = 1
|
||||
references = ["https://attack.mitre.org/tactics/TA0010/"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Shannon Davis"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Detect SNICat SNI Exfiltration - Rule", "ESCU - O365 PST export alert - Rule", "ESCU - O365 Suspicious Admin Email Forwarding - Rule", "ESCU - O365 Suspicious User Email Forwarding - Rule", "ESCU - Get Notable History - Response Task"]
|
||||
searches = ["ESCU - Detect SNICat SNI Exfiltration - Rule", "ESCU - Mailsniper Invoke functions - Rule", "ESCU - O365 PST export alert - Rule", "ESCU - O365 Suspicious Admin Email Forwarding - Rule", "ESCU - O365 Suspicious User Email Forwarding - Rule", "ESCU - Get Notable History - Response Task"]
|
||||
description = The stealing of data by an adversary.
|
||||
narrative = Exfiltration comes in many flavors. Adversaries can collect data over encrypted or non-encrypted channels. They can utilise Command and Control channels that are already in place to exfiltrate data. They can use both standard data transfer protocols such as FTP, SCP, etc to exfiltrate data. Or they can use non-standard protocols such as DNS, ICMP, etc with specially crafted fields to try and circumvent security technologies in place.
|
||||
|
||||
@@ -484,7 +484,7 @@ version = 1
|
||||
references = ["https://www.splunk.com/en_us/blog/security/detecting-hafnium-exchange-server-zero-day-activity-in-splunk.html", "https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/", "https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/", "https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Any Powershell DownloadString - Rule", "ESCU - Detect Exchange Web Shell - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Nishang PowershellTCPOneLine - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Unified Messaging Service Spawning a Process - Rule", "ESCU - W3WP Spawning Shell - Rule"]
|
||||
searches = ["ESCU - Any Powershell DownloadString - Rule", "ESCU - Detect Exchange Web Shell - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Nishang PowershellTCPOneLine - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Unified Messaging Service Spawning a Process - Rule", "ESCU - W3WP Spawning Shell - Rule"]
|
||||
description = HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVEs in the wild - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
|
||||
narrative = On Tuesday, March 2, 2021, Microsoft released a set of security patches for its mail server, Microsoft Exchange. These patches respond to a group of vulnerabilities known to impact Exchange 2013, 2016, and 2019. It is important to note that an Exchange 2010 security update has also been issued, though the CVEs do not reference that version as being vulnerable.\
|
||||
While the CVEs do not shed much light on the specifics of the vulnerabilities or exploits, the first vulnerability (CVE-2021-26855) has a remote network attack vector that allows the attacker, a group Microsoft named HAFNIUM, to authenticate as the Exchange server. Three additional vulnerabilities (CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) were also identified as part of this activity. When chained together along with CVE-2021-26855 for initial access, the attacker would have complete control over the Exchange server. This includes the ability to run code as SYSTEM and write to any path on the server.\
|
||||
@@ -591,7 +591,7 @@ version = 2
|
||||
references = ["https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Detect Activity Related to Pass the Hash Attacks - Rule", "ESCU - Kerberoasting spn request with RC4 encryption - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - Schtasks scheduling job on remote system - Rule", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task"]
|
||||
searches = ["ESCU - Detect Activity Related to Pass the Hash Attacks - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - Kerberoasting spn request with RC4 encryption - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - Schtasks scheduling job on remote system - Rule", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task"]
|
||||
description = Detect and investigate tactics, techniques, and procedures around how attackers move laterally within the enterprise. Because lateral movement can expose the adversary to detection, it should be an important focus for security analysts.
|
||||
narrative = Once attackers gain a foothold within an enterprise, they will seek to expand their accesses and leverage techniques that facilitate lateral movement. Attackers will often spend quite a bit of time and effort moving laterally. Because lateral movement renders an attacker the most vulnerable to detection, it's an excellent focus for detection and investigation.\
|
||||
Indications of lateral movement can include the abuse of system utilities (such as `psexec.exe`), unauthorized use of remote desktop services, `file/admin$` shares, WMI, PowerShell, pass-the-hash, or the abuse of scheduled tasks. Organizations must be extra vigilant in detecting lateral movement techniques and look for suspicious activity in and around high-value strategic network assets, such as Active Directory, which are often considered the primary target or "crown jewels" to a persistent threat actor.\
|
||||
@@ -632,6 +632,19 @@ narrative = Security monitoring and control mechanisms may be in place for syste
|
||||
The following content is here to assist with binaries within `system32` or `syswow64` being moved to a new location or an adversary bringing a the binary in to execute.\
|
||||
There will be false positives as some native Windows processes are moved or ran by third party applications from different paths. If file names are mismatched between the file name on disk and that of the binarys PE metadata, this is a likely indicator that a binary was renamed after it was compiled. Collecting and comparing disk and resource filenames for binaries by looking to see if the InternalName, OriginalFilename, and or ProductName match what is expected could provide useful leads, but may not always be indicative of malicious activity. Do not focus on the possible names a file could have, but instead on the command-line arguments that are known to be used and are distinct because it will have a better rate of detection.
|
||||
|
||||
[analytic_story://Meterpreter]
|
||||
category = Adversary Tactics
|
||||
last_updated = 2021-06-08
|
||||
version = 1
|
||||
references = ["https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/", "https://doubleoctopus.com/security-wiki/threats-and-tools/meterpreter/", "https://www.rapid7.com/products/metasploit/"]
|
||||
maintainers = [{"company": "no", "email": "-", "name": "Michael Hart"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Excessive number of taskhost processes - Rule"]
|
||||
description = Meterpreter provides red teams, pen testers and threat actors interactive access to a compromised host to run commands, upload payloads, download files, and other actions.
|
||||
narrative = This Analytic Story supports you to detect Tactics, Techniques and Procedures (TTPs) from Meterpreter. Meterpreter is a Metasploit payload for remote execution that leverages DLL injection to make it extremely difficult to detect. Since the software runs in memory, no new processes are created upon injection. It also leverages encrypted communication channels.\
|
||||
Meterpreter enables the operator to remotely run commands on the target machine, upload payloads, download files, dump password hashes, and much more. It is difficult to determine from the forensic evidence what actions the operator performed. Splunk Research, however, has observed anomalous behaviors on the compromised hosts that seem to only appear when Meterpreter is executing various commands. With that, we have written new detections targeted to these detections.\
|
||||
While investigating a detection related to this analytic story, please bear in mind that the detections look for anomalies in system behavior. It will be imperative to look for other signs in the endpoint and network logs for lateral movement, discovery and other actions to confirm that the host was compromised and a remote actor used it to progress on their objectives.
|
||||
|
||||
[analytic_story://Monitor Backup Solution]
|
||||
category = Best Practices
|
||||
last_updated = 2017-09-12
|
||||
@@ -761,7 +774,7 @@ version = 1
|
||||
references = ["http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task"]
|
||||
searches = ["ESCU - Allow Inbound Traffic By Firewall Rule Registry - Rule", "ESCU - Allow Inbound Traffic In Firewall Rule - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Enable RDP In Other Port Number - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task"]
|
||||
description = Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers.
|
||||
narrative = A traditional security best practice is to control the ports, protocols, and services allowed within your environment. By limiting the services and protocols to those explicitly approved by policy, administrators can minimize the attack surface. The combined effect allows both network defenders and security controls to focus and not be mired in superfluous traffic or data types. Looking for deviations to policy can identify attacker activity that abuses services and protocols to run on alternate or non-standard ports in the attempt to avoid detection or frustrate forensic analysts.
|
||||
|
||||
@@ -772,7 +785,7 @@ version = 1
|
||||
references = ["https://www.carbonblack.com/2017/06/28/carbon-black-threat-research-technical-analysis-petya-notpetya-ransomware/", "https://www.splunk.com/blog/2017/06/27/closing-the-detection-to-mitigation-gap-or-to-petya-or-notpetya-whocares-.html"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect RClone Command-Line Usage - Rule", "ESCU - Detect Renamed RClone - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - TOR Traffic - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - WinEvent Scheduled Task Created Within Public Path - Rule", "ESCU - WinEvent Scheduled Task Created to Spawn Shell - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task"]
|
||||
searches = ["ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Conti Common Exec parameter - Rule", "ESCU - Delete ShadowCopy With PowerShell - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect RClone Command-Line Usage - Rule", "ESCU - Detect Renamed RClone - Rule", "ESCU - Detect SharpHound Command-Line Arguments - Rule", "ESCU - Detect SharpHound File Modifications - Rule", "ESCU - Detect SharpHound Usage - Rule", "ESCU - Known Services Killed by Ransomware - Rule", "ESCU - Modification Of Wallpaper - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - Revil Common Exec Parameter - Rule", "ESCU - Revil Registry Entry - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - TOR Traffic - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - Wbemprox COM Object Execution - Rule", "ESCU - WinEvent Scheduled Task Created Within Public Path - Rule", "ESCU - WinEvent Scheduled Task Created to Spawn Shell - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task"]
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware--spikes in SMB traffic, suspicious wevtutil usage, the presence of common ransomware extensions, and system processes run from unexpected locations, and many others.
|
||||
narrative = Ransomware is an ever-present risk to the enterprise, wherein an infected host encrypts business-critical data, holding it hostage until the victim pays the attacker a ransom. There are many types and varieties of ransomware that can affect an enterprise. Attackers can deploy ransomware to enterprises through spearphishing campaigns and driveby downloads, as well as through traditional remote service-based exploitation. In the case of the WannaCry campaign, there was self-propagating wormable functionality that was used to maximize infection. Fortunately, organizations can apply several techniques--such as those in this Analytic Story--to detect and or mitigate the effects of ransomware.
|
||||
|
||||
@@ -787,6 +800,17 @@ searches = ["ESCU - AWS Detect Users creating keys with encrypt policy without M
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware. These searches include cloud related objects that may be targeted by malicious actors via cloud providers own encryption features.
|
||||
narrative = Ransomware is an ever-present risk to the enterprise, wherein an infected host encrypts business-critical data, holding it hostage until the victim pays the attacker a ransom. There are many types and varieties of ransomware that can affect an enterprise.Cloud ransomware can be deployed by obtaining high privilege credentials from targeted users or resources.
|
||||
|
||||
[analytic_story://Revil Ransomware]
|
||||
category = Malware
|
||||
last_updated = 2021-06-04
|
||||
version = 1
|
||||
references = ["https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/", "https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Teoderick Contreras"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Delete ShadowCopy With PowerShell - Rule", "ESCU - Modification Of Wallpaper - Rule", "ESCU - Revil Common Exec Parameter - Rule", "ESCU - Revil Registry Entry - Rule", "ESCU - Wbemprox COM Object Execution - Rule"]
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the Revil ransomware, including looking for file writes associated with Revil, encrypting network shares, deleting shadow volume storage, registry key modification, deleting of security logs, and more.
|
||||
narrative = Revil ransomware is a RaaS,that a single group may operates and manges the development of this ransomware. It involve the use of ransomware payloads along with exfiltration of data. Malicious actors demand payment for ransome of data and threaten deletion and exposure of exfiltrated data.
|
||||
|
||||
[analytic_story://Router and Infrastructure Security]
|
||||
category = Best Practices
|
||||
last_updated = 2017-09-12
|
||||
@@ -829,7 +853,7 @@ version = 1
|
||||
references = ["https://www.crowdstrike.com/blog/an-in-depth-analysis-of-samsam-ransomware-and-boss-spider/", "https://nakedsecurity.sophos.com/2018/07/31/samsam-the-almost-6-million-ransomware/", "https://thehackernews.com/2018/07/samsam-ransomware-attacks.html"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Batch File Write to System32 - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect attackers scanning for vulnerable JBoss servers - Rule", "ESCU - Detect malicious requests to exploit JBoss servers - Rule", "ESCU - File with Samsam Extension - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Samsam Test File Write - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task"]
|
||||
searches = ["ESCU - Batch File Write to System32 - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - Detect attackers scanning for vulnerable JBoss servers - Rule", "ESCU - Detect malicious requests to exploit JBoss servers - Rule", "ESCU - File with Samsam Extension - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Samsam Test File Write - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task"]
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the SamSam ransomware, including looking for file writes associated with SamSam, RDP brute force attacks, the presence of files with SamSam ransomware extensions, suspicious psexec use, and more.
|
||||
narrative = The first version of the SamSam ransomware (a.k.a. Samas or SamsamCrypt) was launched in 2015 by a group of Iranian threat actors. The malicious software has affected and continues to affect thousands of victims and has raised almost $6M in ransom.\
|
||||
Although categorized under the heading of ransomware, SamSam campaigns have some importance distinguishing characteristics. Most notable is the fact that conventional ransomware is a numbers game. Perpetrators use a "spray-and-pray" approach with phishing campaigns or other mechanisms, charging a small ransom (typically under $1,000). The goal is to find a large number of victims willing to pay these mini-ransoms, adding up to a lucrative payday. They use relatively simple methods for infecting systems.\
|
||||
@@ -1682,6 +1706,26 @@ annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1087.00
|
||||
known_false_positives = admin or power user may used this series of command.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Allow Inbound Traffic By Firewall Rule Registry - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This analytic detects a potential suspicious modification of firewall rule registry allowing inbound traffic in specific port with public profile. This technique was seen in some attacker want to have a remote access to a machine by allowing the traffic in firewall rule.
|
||||
how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1021.001"]}
|
||||
known_false_positives = network admin may add/remove/modify public inbound firewall rule that may cause this rule to be triggered.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Allow Inbound Traffic In Firewall Rule - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This search is to detect suspicious powershell command to allow inbound traffic in specific local port with public profile. This technique was seen in some attacker want to have a remote access to a machine by allowing the traffic in firewall rule.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1021.001"]}
|
||||
known_false_positives = administrator may allow inbound traffic in certain network or machine.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Amazon EKS Kubernetes Pod scan detection - Rule]
|
||||
type = detection
|
||||
asset_type = Amazon EKS Kubernetes cluster Pod
|
||||
@@ -1802,6 +1846,16 @@ annotations = {"cis20": ["CIS 8"], "kill_chain_phases": ["Delivery"], "mitre_att
|
||||
known_false_positives = It is possible for this search to generate a notable event for a batch file write to a path that includes the string "system32", but is not the actual Windows system directory. As such, you should confirm the path of the batch file identified by the search. In addition, a false positive may be generated by an administrator copying a legitimate batch file in this directory tree. You should confirm that the activity is legitimate and modify the search to add exclusions, as necessary.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - CMD Echo Pipe - Escalation - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This analytic identifies a common behavior by Cobalt Strike and other frameworks where the adversary will escalate privileges, either via `jump` (Cobalt Strike PTH) or `getsystem`, using named-pipe impersonation. A suspicious event will look like `cmd.exe /c echo 4sgryt3436 > \\.\Pipe\5erg53`.
|
||||
how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
annotations = {"kill_chain_phases": ["Exploitation", "Privilege Escalation"], "mitre_attack": ["T1059.003", "T1543.003"]}
|
||||
known_false_positives = Unknown. It is possible filtering may be required to ensure fidelity.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
@@ -2043,6 +2097,16 @@ annotations = {"cis20": ["CIS 8"], "kill_chain_phases": ["Actions on Objectives"
|
||||
known_false_positives = It's possible that a legitimate file could be created with the same name used by ransomware note files.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Conti Common Exec parameter - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This search detects the suspicious commandline argument of revil ransomware to encrypt specific or all local drive and network shares of the compromised machine or host.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1204"]}
|
||||
known_false_positives = 3rd party tool may have commandline parameter that can trigger this detection.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Create Remote Thread into LSASS - Rule]
|
||||
type = detection
|
||||
asset_type = Windows
|
||||
@@ -2340,6 +2404,26 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Act
|
||||
known_false_positives = Legitimate logon activity by authorized NTLM systems may be detected by this search. Please investigate as appropriate.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect AzureHound Command-Line Arguments - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analytic identifies the common command-line argument used by AzureHound `Invoke-AzureHound`. Being the script is FOSS, function names may be modified, but these changes are dependent upon the operator. In most instances the defaults are used. This analytic works to identify the common command-line attributes used. It does not cover the entirety of every argument in order to avoid false positives.
|
||||
how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
annotations = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1087.002", "T1087.001", "T1482", "T1069.002", "T1069.001"]}
|
||||
known_false_positives = Unknown.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect AzureHound File Modifications - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analytic is similar to SharpHound file modifications, but this instance covers the use of Invoke-AzureHound. AzureHound is the SharpHound equivilent but for Azure. It's possible this may never be seen in an environment as most attackers may execute this tool remotely. Once execution is complete, a zip file with a similar name will drop `20210601090751-azurecollection.zip`. In addition to the zip, multiple .json files will be written to disk, which are in the zip.
|
||||
how_to_implement = To successfully implement this search you need to be ingesting information on file modifications that include the name of the process, and file, responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node.
|
||||
annotations = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1087.002", "T1087.001", "T1482", "T1069.002", "T1069.001"]}
|
||||
known_false_positives = False positives should be limited as the analytic is specific to a filename with extension .zip. Filter as needed.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect Baron Samedit CVE-2021-3156 - Rule]
|
||||
type = detection
|
||||
asset_type = Endpoint
|
||||
@@ -2759,6 +2843,26 @@ annotations = {"cis20": ["CIS 8", "CIS 16"], "kill_chain_phases": ["Actions on O
|
||||
known_false_positives = Limited false positives related to third party software registering .DLL's.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect Renamed 7-Zip - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analytic identifies renamed 7-Zip usage using Sysmon. At this stage of an attack, review parallel processes and file modifications for data that is staged or potentially have been exfiltrated. This analytic utilizes the OriginalFileName to capture the renamed process.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Exfiltration"], "mitre_attack": ["T1560.001"]}
|
||||
known_false_positives = Limited false positives, however this analytic will need to be modified for each environment if Sysmon is not used.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect Renamed PSExec - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analytic identifies renamed instances of `PsExec.exe` being utilized on an endpoint. Most instances, it is highly probable to capture `Psexec.exe` or other SysInternal utility usage with the command-line argument of `-accepteula`. In this instance, we are using `OriginalFileName` from Sysmon to identify `PsExec` usage. During triage, validate this is the legitimate version of `PsExec` by review the PE metadata. In addition, review parallel processes for further suspicious behavior.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used.
|
||||
annotations = {"kill_chain_phases": ["Exploitation", "Lateral Movement", "Execution"], "mitre_attack": ["T1569.002"]}
|
||||
known_false_positives = Limited false positives should be present. It is possible some third party applications may use older versions of PsExec, filter as needed.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect Renamed RClone - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
@@ -2769,6 +2873,16 @@ annotations = {"kill_chain_phases": ["Exfiltration"], "mitre_attack": ["T1020"]}
|
||||
known_false_positives = False positives should be limited as this analytic identifies renamed instances of `rclone.exe`. Filter as needed if there is a legitimate business use case.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect Renamed WinRAR - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analtyic identifies renamed instances of `WinRAR.exe`. In most cases, it is not common for WinRAR to be used renamed, however it is common to be installed by a third party application and executed from a non-standard path. In this instance, we are using `OriginalFileName` from Sysmon to determine if the process is WinRAR. During triage, validate additional metadata from the binary that this is `WinRAR`. Review parallel processes and file modifications.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Modify query for specific EDR products as needed.
|
||||
annotations = {"kill_chain_phases": ["Exploitation", "Exfiltration"], "mitre_attack": ["T1560.001"]}
|
||||
known_false_positives = Unknown. It is possible third party applications use renamed instances of WinRAR.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect Rogue DHCP Server - Rule]
|
||||
type = detection
|
||||
asset_type = Infrastructure
|
||||
@@ -2839,6 +2953,36 @@ annotations = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives
|
||||
known_false_positives = Unknown
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect SharpHound Command-Line Arguments - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analytic identifies common command-line arguments used by SharpHound `-collectionMethod` and `invoke-bloodhound`. Being the script is FOSS, function names may be modified, but these changes are dependent upon the operator. In most instances the defaults are used. This analytic works to identify the common command-line attributes used. It does not cover the entirety of every argument in order to avoid false positives.
|
||||
how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
annotations = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1087.002", "T1087.001", "T1482", "T1069.002", "T1069.001"]}
|
||||
known_false_positives = False positives should be limited as the arguments used are specific to SharpHound. Filter as needed or add more command-line arguments as needed.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect SharpHound File Modifications - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = SharpHound is used as a reconnaissance collector, ingestor, for BloodHound. SharpHound will query the domain controller and begin gathering all the data related to the domain and trusts. For output, it will drop a .zip file upon completion following a typical pattern that is often not changed. This analytic focuses on the default file name scheme. Note that this may be evaded with different parameters within SharpHound, but that depends on the operator. `-randomizefilenames` and `-encryptzip` are two examples. In addition, executing SharpHound via .exe or .ps1 without any command-line arguments will still perform activity and dump output to the default filename. Example default filename `20210601181553_BloodHound.zip`. SharpHound creates multiple temp files following the same pattern `20210601182121_computers.json`, `domains.json`, `gpos.json`, `ous.json` and `users.json`. Tuning may be required, or remove these json's entirely if it is too noisy. During traige, review parallel processes for further suspicious behavior. Typically, the process executing the `.ps1` ingestor will be PowerShell.
|
||||
how_to_implement = To successfully implement this search you need to be ingesting information on file modifications that include the name of the process, and file, responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node.
|
||||
annotations = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1087.002", "T1087.001", "T1482", "T1069.002", "T1069.001"]}
|
||||
known_false_positives = False positives should be limited as the analytic is specific to a filename with extension .zip. Filter as needed.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect SharpHound Usage - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analytic identifies SharpHound binary usage by using the `OriginalFileName` from Sysmon. In addition to renaming the PE, other coverage is available to detect command-line arguments. This particular analytic only looks for the OriginalFileName of `SharpHound.exe`. It is possible older instances of SharpHound.exe have different original filenames. Dependent upon the operator, the code may be re-compiled and the attributes removed or changed to anything else. During triage, review the metadata of the binary in question. Review parallel processes for suspicious behavior. Identify the source of this binary.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1087.002", "T1087.001", "T1482", "T1069.002", "T1069.001"]}
|
||||
known_false_positives = False positives should be limited as this is specific to a file attribute not used by anything else. Filter as needed.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect Software Download To Network Device - Rule]
|
||||
type = detection
|
||||
asset_type = Infrastructure
|
||||
@@ -3377,6 +3521,16 @@ annotations = {"cis20": ["CIS 7"], "kill_chain_phases": ["Actions on Objectives"
|
||||
known_false_positives = The false-positive rate will vary based on how you set the deviation_threshold and data_samples values. Our recommendation is to adjust these values based on your network traffic to and from your email servers.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Enable RDP In Other Port Number - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This search is to detect a modification to registry to enable rdp to a machine with different port number. This technique was seen in some atttacker tries to do lateral movement and remote access to a compromised machine to gain control of it.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1021"]}
|
||||
known_false_positives = unknown
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Enumerate Users Local Group Using Telegram - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
@@ -3487,6 +3641,16 @@ annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1048"]}
|
||||
known_false_positives = unknown
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Excessive number of taskhost processes - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This detection targets behaviors observed in post exploit kits like Meterpreter and Koadic that are run in memory. We have observed that these tools must invoke an excessive number of taskhost.exe and taskhostex.exe processes to complete various actions (discovery, lateral movement, etc.). It is extremely uncommon in the course of normal operations to see so many distinct taskhost and taskhostex processes running concurrently in a short time frame.
|
||||
how_to_implement = To successfully implement this search you need to be ingesting events related to processes on the endpoints that include the name of the process and process id into the `Endpoint` datamodel in the `Processes` node.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1033"]}
|
||||
known_false_positives = Administrators, administrative actions or certain applications may run many instances of taskhost and taskhostex concurrently. Filter as needed.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Executables Or Script Creation In Suspicious Path - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
@@ -3761,6 +3925,16 @@ annotations = {"cis20": ["CIS 8", "CIS 16"], "kill_chain_phases": ["Actions on O
|
||||
known_false_positives = Older systems that support kerberos RC4 by default NetApp may generate false positives
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Known Services Killed by Ransomware - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This search detects a suspicioous termination of known services killed by ransomware before encrypting files in a compromised machine. This technique is commonly seen in most of ransomware now a days to avoid exception error while accessing the targetted files it wants to encrypts because of the open handle of those services to the targetted file.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the 7036 EventCode ScManager in System audit Logs from your endpoints.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1490"]}
|
||||
known_false_positives = Admin activities or installing related updates may do a sudden stop to list of services we monitor.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Kubernetes AWS detect RBAC authorization by account - Rule]
|
||||
type = detection
|
||||
asset_type = AWS EKS Kubernetes cluster
|
||||
@@ -3971,6 +4145,16 @@ annotations = {"cis20": ["CIS 8"], "kill_chain_phases": ["Installation", "Comman
|
||||
known_false_positives = At this stage, there are no known false positives. During testing, no process events refering the com.apple.loginwindow.plist files were observed during normal operation of re-opening applications on reboot. Therefore, it can be asumed that any occurences of this in the process events would be worth investigating. In the event that the legitimate modification by the system of these files is in fact logged to the process log, then the process_name of that process can be added to an allow list.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Mailsniper Invoke functions - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This search is to detect known mailsniper.ps1 functions executed in a machine. This technique was seen in some attacker to harvest some sensitive e-mail in a compromised exchange server.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1114.001"]}
|
||||
known_false_positives = unknown
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule]
|
||||
type = detection
|
||||
asset_type = Endpoint
|
||||
@@ -4031,6 +4215,16 @@ annotations = {"kill_chain_phases": ["Privilege Escalation"], "mitre_attack": ["
|
||||
known_false_positives = Creating a hidden powershell service is rare and could key off of those instances.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Modification Of Wallpaper - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This analytic identifies suspicious modification of registry to deface or change the wallpaper of a compromised machines as part of its payload. This technique was commonly seen in ransomware like REVIL where it create a bitmap file contain a note that the machine was compromised and make it as a wallpaper.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the Image, TargetObject registry key, registry Details from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1491"]}
|
||||
known_false_positives = 3rd party tool may used to changed the wallpaper of the machine
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Modify ACL permission To Files Or Folder - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
@@ -4661,7 +4855,7 @@ providing_technologies = []
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analytics identifies a big number of instance of ransomware notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This behavior is a good sensor if the ransomware note filename is quite new for security industry or the ransomware note filename is not in your lookup table list for monitoring.
|
||||
explanation = The following analytics identifies a big number of instance of ransomware notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This behavior is a good sensor if the ransomware note filename is quite new for security industry or the ransomware note filename is not in your ransomware lookup table list for monitoring.
|
||||
how_to_implement = You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data.
|
||||
annotations = {"kill_chain_phases": ["Obfuscation"], "mitre_attack": ["T1486"]}
|
||||
known_false_positives = unknown
|
||||
@@ -4787,6 +4981,26 @@ annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1490"]}
|
||||
known_false_positives = network admin can resize the shadowstorage for valid purposes.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Revil Common Exec Parameter - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This analytic identifies suspicious commandline parameter that are commonly used by REVIL ransomware to encrypts the compromise machine.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1204"]}
|
||||
known_false_positives = third party tool may have same command line parameters as revil ransomware.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Revil Registry Entry - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This analytic identifies suspicious modification in registry entry to keep some malware data during its infection. This technique seen in several apt implant, malware and ransomware like REVIL where it keep some information like the random generated file extension it uses for all the encrypted files and ransomware notes file name in the compromised host.
|
||||
how_to_implement = to successfully implement this search, you need to be ingesting logs with the Image, TargetObject registry key, registry Details from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1112"]}
|
||||
known_false_positives = unknown
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - RunDLL Loading DLL By Ordinal - Rule]
|
||||
type = detection
|
||||
asset_type = Endpoint
|
||||
@@ -4990,6 +5204,16 @@ annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1055"]}
|
||||
known_false_positives = Limited false positives may be present in small environments. Tuning may be required based on parent process.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - SecretDumps Offline NTDS Dumping Tool - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This analytic detects a potential usage of secretsdump.py tool for dumping credentials (ntlm hash) from a copy of ntds.dit and SAM.Security,SYSTEM registrry hive. This technique was seen in some attacker that dump ntlm hashes offline after having a copy of ntds.dit and SAM/SYSTEM/SECURITY registry hive.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1003.003"]}
|
||||
known_false_positives = unknown
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Services Escalate Exe - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
@@ -5608,6 +5832,16 @@ annotations = {"cis20": ["CIS 3", "CIS 5"], "kill_chain_phases": ["Actions on Ob
|
||||
known_false_positives = Some software may create WMI temporary event subscriptions for various purposes. The included search contains an exception for two of these that occur by default on Windows 10 systems. You may need to modify the search to create exceptions for other legitimate events.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Wbemprox COM Object Execution - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = this search is designed to detect potential malicious process loading COM object to wbemprox.dll,
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name and imageloaded executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1218.003"]}
|
||||
known_false_positives = legitimate process that are not in the exception list may trigger this event.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Web Fraud - Account Harvesting - Rule]
|
||||
type = detection
|
||||
asset_type = Account
|
||||
|
||||
Vendored
+2
-2
@@ -4,7 +4,7 @@
|
||||
is_configured = false
|
||||
state = enabled
|
||||
state_change_requires_restart = false
|
||||
build = 29832
|
||||
build = 30583
|
||||
|
||||
[triggers]
|
||||
reload.analytic_stories = simple
|
||||
@@ -19,7 +19,7 @@ reload.content-version = simple
|
||||
|
||||
[launcher]
|
||||
author = Splunk
|
||||
version = 3.22.0
|
||||
version = 3.23.0
|
||||
description = Explore the Analytic Stories included with ES Content Updates.
|
||||
|
||||
[ui]
|
||||
|
||||
Vendored
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2021-05-24T20:38:43 UTC
|
||||
# On Date: 2021-06-10T18:24:24 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+1
-1
@@ -1,2 +1,2 @@
|
||||
[content-version]
|
||||
version = 3.22.0
|
||||
version = 3.23.0
|
||||
|
||||
+14
@@ -335,6 +335,13 @@ disabled = 0
|
||||
|
||||
panels = ["panel://workbench_panel_get_notable_history___response_task"]
|
||||
|
||||
[panel_group://workbench_panel_group_meterpreter]
|
||||
label = Meterpreter
|
||||
description = Meterpreter provides red teams, pen testers and threat actors interactive access to a compromised host to run commands, upload payloads, download files, and other actions.
|
||||
disabled = 0
|
||||
|
||||
panels = ["panel://workbench_panel_get_notable_history___response_task"]
|
||||
|
||||
[panel_group://workbench_panel_group_monitor_backup_solution]
|
||||
label = Monitor Backup Solution
|
||||
description = Address common concerns when monitoring your backup processes. These searches can help you reduce risks from ransomware, device theft, or denial of physical access to a host by backing up data on endpoints.
|
||||
@@ -412,6 +419,13 @@ disabled = 0
|
||||
|
||||
panels = ["panel://workbench_panel_get_notable_history___response_task"]
|
||||
|
||||
[panel_group://workbench_panel_group_revil_ransomware]
|
||||
label = Revil Ransomware
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the Revil ransomware, including looking for file writes associated with Revil, encrypting network shares, deleting shadow volume storage, registry key modification, deleting of security logs, and more.
|
||||
disabled = 0
|
||||
|
||||
panels = ["panel://workbench_panel_get_notable_history___response_task"]
|
||||
|
||||
[panel_group://workbench_panel_group_router_and_infrastructure_security]
|
||||
label = Router and Infrastructure Security
|
||||
description = Validate the security configuration of network infrastructure and verify that only authorized users and systems are accessing critical assets. Core routing and switching infrastructure are common strategic targets for attackers.
|
||||
|
||||
Vendored
+85
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2021-05-24T20:38:43 UTC
|
||||
# On Date: 2021-06-10T18:24:25 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
@@ -427,6 +427,14 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[allow_inbound_traffic_by_firewall_rule_registry_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[allow_inbound_traffic_in_firewall_rule_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[amazon_eks_kubernetes_pod_scan_detection_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -475,6 +483,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[cmd_echo_pipe___escalation_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[cmlua_or_cmstplua_uac_bypass_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -567,6 +579,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[conti_common_exec_parameter_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[create_remote_thread_into_lsass_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -675,6 +691,14 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[detect_azurehound_command_line_arguments_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[detect_azurehound_file_modifications_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[detect_baron_samedit_cve_2021_3156_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -839,10 +863,22 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[detect_renamed_7_zip_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[detect_renamed_psexec_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[detect_renamed_rclone_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[detect_renamed_winrar_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[detect_rogue_dhcp_server_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -871,6 +907,18 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[detect_sharphound_command_line_arguments_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[detect_sharphound_file_modifications_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[detect_sharphound_usage_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[detect_software_download_to_network_device_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -1079,6 +1127,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[enable_rdp_in_other_port_number_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[enumerate_users_local_group_using_telegram_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -1123,6 +1175,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[excessive_number_of_taskhost_processes_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[executables_or_script_creation_in_suspicious_path_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -1231,6 +1287,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[known_services_killed_by_ransomware_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[kubernetes_aws_detect_rbac_authorization_by_account_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -1315,6 +1375,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[mailsniper_invoke_functions_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[malicious_powershell_process___connect_to_internet_with_hidden_window_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -1339,6 +1403,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[modification_of_wallpaper_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[modify_acl_permission_to_files_or_folder_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -1631,6 +1699,14 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[revil_common_exec_parameter_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[revil_registry_entry_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[rundll_loading_dll_by_ordinal_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -1711,6 +1787,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[secretdumps_offline_ntds_dumping_tool_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[services_escalate_exe_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -1951,6 +2031,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[wbemprox_com_object_execution_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[web_fraud___account_harvesting_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
Vendored
+1431
-28
File diff suppressed because it is too large
Load Diff
Vendored
+2
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2021-05-24T20:38:43 UTC
|
||||
# On Date: 2021-06-10T18:24:24 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
@@ -210,6 +210,7 @@ filename = ransomware_extensions.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of file extensions that are associated with ransomware
|
||||
match_type = WILDCARD(Extensions)
|
||||
min_matches = 1
|
||||
|
||||
[ransomware_notes_lookup]
|
||||
|
||||
+247
-13
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2021-05-24T20:38:43 UTC
|
||||
# On Date: 2021-06-10T18:24:24 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
@@ -220,7 +220,7 @@ version = 1
|
||||
references = ["https://www.cobaltstrike.com/", "https://www.infocyte.com/blog/2020/09/02/cobalt-strike-the-new-favorite-among-thieves/", "https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/", "https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html", "https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html", "https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence", "https://github.com/zer0yu/Awesome-CobaltStrike"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Anomalous usage of 7zip - Rule", "ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - DLLHost with no Command Line Arguments with Network - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - GPUpdate with no Command Line Arguments with Network - Rule", "ESCU - Rundll32 with no Command Line Arguments with Network - Rule", "ESCU - SearchProtocolHost with no Command Line with Network - Rule", "ESCU - Services Escalate Exe - Rule", "ESCU - Suspicious DLLHost no Command Line Arguments - Rule", "ESCU - Suspicious GPUpdate no Command Line Arguments - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious SearchProtocolHost no Command Line Arguments - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious msbuild path - Rule"]
|
||||
searches = ["ESCU - Anomalous usage of 7zip - Rule", "ESCU - CMD Echo Pipe - Escalation - Rule", "ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - DLLHost with no Command Line Arguments with Network - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - GPUpdate with no Command Line Arguments with Network - Rule", "ESCU - Rundll32 with no Command Line Arguments with Network - Rule", "ESCU - SearchProtocolHost with no Command Line with Network - Rule", "ESCU - Services Escalate Exe - Rule", "ESCU - Suspicious DLLHost no Command Line Arguments - Rule", "ESCU - Suspicious GPUpdate no Command Line Arguments - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious SearchProtocolHost no Command Line Arguments - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious msbuild path - Rule"]
|
||||
description = Cobalt Strike is threat emulation software. Red teams and penetration testers use Cobalt Strike to demonstrate the risk of a breach and evaluate mature security programs. Most recently, Cobalt Strike has become the choice tool by threat groups due to its ease of use and extensibility.
|
||||
narrative = This Analytic Story supports you to detect Tactics, Techniques and Procedures (TTPs) from Cobalt Strike. Cobalt Strike has many ways to be enhanced by using aggressor scripts, malleable C2 profiles, default attack packages, and much more. For endpoint behavior, Cobalt Strike is most commonly identified via named pipes, spawn to processes, and DLL function names. Many additional variables are provided for in memory operation of the beacon implant. On the network, depending on the malleable C2 profile used, it is near infinite in the amount of ways to conceal the C2 traffic with Cobalt Strike. Not every query may be specific to Cobalt Strike the tool, but the methodologies and techniques used by it.\
|
||||
Splunk Threat Research reviewed all publicly available instances of Malleabe C2 Profiles and generated a list of the most commonly used spawnto and pipenames.\
|
||||
@@ -253,7 +253,7 @@ version = 1
|
||||
references = ["https://attack.mitre.org/wiki/Collection", "https://attack.mitre.org/wiki/Technique/T1074"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Email files written outside of the Outlook directory - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Hosts receiving high volume of network traffic from email server - Rule", "ESCU - Suspicious writes to System Volume Information - Rule", "ESCU - Suspicious writes to windows Recycle Bin - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task"]
|
||||
searches = ["ESCU - Detect Renamed 7-Zip - Rule", "ESCU - Detect Renamed WinRAR - Rule", "ESCU - Email files written outside of the Outlook directory - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Hosts receiving high volume of network traffic from email server - Rule", "ESCU - Suspicious writes to System Volume Information - Rule", "ESCU - Suspicious writes to windows Recycle Bin - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task"]
|
||||
description = Monitor for and investigate activities--such as suspicious writes to the Windows Recycling Bin or email servers sending high amounts of traffic to specific hosts, for example--that may indicate that an adversary is harvesting and exfiltrating sensitive data.
|
||||
narrative = A common adversary goal is to identify and exfiltrate data of value from a target organization. This data may include email conversations and addresses, confidential company information, links to network design/infrastructure, important dates, and so on.\
|
||||
Attacks are composed of three activities: identification, collection, and staging data for exfiltration. Identification typically involves scanning systems and observing user activity. Collection can involve the transfer of large amounts of data from various repositories. Staging/preparation includes moving data to a central location and compressing (and optionally encoding and/or encrypting) it. All of these activities provide opportunities for defenders to identify their presence. \
|
||||
@@ -301,7 +301,7 @@ version = 3
|
||||
references = ["https://attack.mitre.org/wiki/Technique/T1003", "https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Access LSASS Memory for Dump Creation - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Create Remote Thread into LSASS - Rule", "ESCU - Creation of Shadow Copy - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Creation of lsass Dump with Taskmgr - Rule", "ESCU - Credential Dumping via Copy Command from Shadow Copy - Rule", "ESCU - Credential Dumping via Symlink to Shadow Copy - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Extract SAM from Registry - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Unsigned Image Loaded by LSASS - Rule", "ESCU - Investigate Failed Logins for Multiple Destinations - Response Task", "ESCU - Investigate Pass the Hash Attempts - Response Task", "ESCU - Investigate Pass the Ticket Attempts - Response Task", "ESCU - Investigate Previous Unseen User - Response Task"]
|
||||
searches = ["ESCU - Access LSASS Memory for Dump Creation - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Create Remote Thread into LSASS - Rule", "ESCU - Creation of Shadow Copy - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Creation of lsass Dump with Taskmgr - Rule", "ESCU - Credential Dumping via Copy Command from Shadow Copy - Rule", "ESCU - Credential Dumping via Symlink to Shadow Copy - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Extract SAM from Registry - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - SecretDumps Offline NTDS Dumping Tool - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Unsigned Image Loaded by LSASS - Rule", "ESCU - Investigate Failed Logins for Multiple Destinations - Response Task", "ESCU - Investigate Pass the Hash Attempts - Response Task", "ESCU - Investigate Pass the Ticket Attempts - Response Task", "ESCU - Investigate Previous Unseen User - Response Task"]
|
||||
description = Uncover activity consistent with credential dumping, a technique wherein attackers compromise systems and attempt to obtain and exfiltrate passwords. The threat actors use these pilfered credentials to further escalate privileges and spread throughout a target environment. The included searches in this Analytic Story are designed to identify attempts to credential dumping.
|
||||
narrative = Credential dumping—gathering credentials from a target system, often hashed or encrypted—is a common attack technique. Even though the credentials may not be in plain text, an attacker can still exfiltrate the data and set to cracking it offline, on their own systems. The threat actors target a variety of sources to extract them, including the Security Accounts Manager (SAM), Local Security Authority (LSA), NTDS from Domain Controllers, or the Group Policy Preference (GPP) files.\
|
||||
Once attackers obtain valid credentials, they use them to move throughout a target network with ease, discovering new systems and identifying assets of interest. Credentials obtained in this manner typically include those of privileged users, which may provide access to more sensitive information and system operations.\
|
||||
@@ -314,7 +314,7 @@ version = 2
|
||||
references = ["https://www.us-cert.gov/ncas/alerts/TA18-074A"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Create local admin accounts using net exe - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Single Letter Process On Endpoint - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process File Activity - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task"]
|
||||
searches = ["ESCU - Create local admin accounts using net exe - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Single Letter Process On Endpoint - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process File Activity - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task"]
|
||||
description = Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA18-074A. Some of the activities that adversaries used in these compromises included spearfishing attacks, malware, watering-hole domains, many and more.
|
||||
narrative = The frequency of nation-state cyber attacks has increased significantly over the last decade. Employing numerous tactics and techniques, these attacks continue to escalate in complexity. \
|
||||
There is a wide range of motivations for these state-sponsored hacks, including stealing valuable corporate, military, or diplomatic dataѿall of which could confer advantages in various arenas. They may also target critical infrastructure. \
|
||||
@@ -359,7 +359,7 @@ version = 1
|
||||
references = ["https://www.splunk.com/en_us/blog/security/the-darkside-of-the-ransomware-pipeline.htmlbig-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/", "https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - BITSAdmin Download File - Rule", "ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule", "ESCU - CertUtil Download With URLCache and Split Arguments - Rule", "ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule", "ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - Delete ShadowCopy With PowerShell - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect RClone Command-Line Usage - Rule", "ESCU - Detect Renamed RClone - Rule", "ESCU - Extract SAM from Registry - Rule", "ESCU - Ransomware Notes bulk creation - Rule", "ESCU - SLUI RunAs Elevated - Rule", "ESCU - SLUI Spawning a Process - Rule"]
|
||||
searches = ["ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - BITSAdmin Download File - Rule", "ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule", "ESCU - CertUtil Download With URLCache and Split Arguments - Rule", "ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule", "ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - Delete ShadowCopy With PowerShell - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect RClone Command-Line Usage - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - Detect Renamed RClone - Rule", "ESCU - Extract SAM from Registry - Rule", "ESCU - Ransomware Notes bulk creation - Rule", "ESCU - SLUI RunAs Elevated - Rule", "ESCU - SLUI Spawning a Process - Rule"]
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the DarkSide Ransomware
|
||||
narrative = This story addresses Darkside ransomware. This ransomware payload has many similarities to common ransomware however there are certain items particular to it. The creation of a .TXT log that shows every item being encrypted as well as the creation of ransomware notes and files adding a machine ID created based on CRC32 checksum algorithm. This ransomware payload leaves machines in minimal operation level,enough to browse the attackers websites. A customized URI with leaked information is presented to each victim.This is the ransomware payload that shut down the Colonial pipeline. The story is composed of several detection searches covering similar items to other ransomware payloads and those particular to Darkside payload.
|
||||
|
||||
@@ -370,7 +370,7 @@ version = 1
|
||||
references = ["https://attack.mitre.org/tactics/TA0010/"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Shannon Davis"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Detect SNICat SNI Exfiltration - Rule", "ESCU - O365 PST export alert - Rule", "ESCU - O365 Suspicious Admin Email Forwarding - Rule", "ESCU - O365 Suspicious User Email Forwarding - Rule", "ESCU - Get Notable History - Response Task"]
|
||||
searches = ["ESCU - Detect SNICat SNI Exfiltration - Rule", "ESCU - Mailsniper Invoke functions - Rule", "ESCU - O365 PST export alert - Rule", "ESCU - O365 Suspicious Admin Email Forwarding - Rule", "ESCU - O365 Suspicious User Email Forwarding - Rule", "ESCU - Get Notable History - Response Task"]
|
||||
description = The stealing of data by an adversary.
|
||||
narrative = Exfiltration comes in many flavors. Adversaries can collect data over encrypted or non-encrypted channels. They can utilise Command and Control channels that are already in place to exfiltrate data. They can use both standard data transfer protocols such as FTP, SCP, etc to exfiltrate data. Or they can use non-standard protocols such as DNS, ICMP, etc with specially crafted fields to try and circumvent security technologies in place.
|
||||
|
||||
@@ -484,7 +484,7 @@ version = 1
|
||||
references = ["https://www.splunk.com/en_us/blog/security/detecting-hafnium-exchange-server-zero-day-activity-in-splunk.html", "https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/", "https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/", "https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Any Powershell DownloadString - Rule", "ESCU - Detect Exchange Web Shell - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Nishang PowershellTCPOneLine - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Unified Messaging Service Spawning a Process - Rule", "ESCU - W3WP Spawning Shell - Rule"]
|
||||
searches = ["ESCU - Any Powershell DownloadString - Rule", "ESCU - Detect Exchange Web Shell - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Nishang PowershellTCPOneLine - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Unified Messaging Service Spawning a Process - Rule", "ESCU - W3WP Spawning Shell - Rule"]
|
||||
description = HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVEs in the wild - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
|
||||
narrative = On Tuesday, March 2, 2021, Microsoft released a set of security patches for its mail server, Microsoft Exchange. These patches respond to a group of vulnerabilities known to impact Exchange 2013, 2016, and 2019. It is important to note that an Exchange 2010 security update has also been issued, though the CVEs do not reference that version as being vulnerable.\
|
||||
While the CVEs do not shed much light on the specifics of the vulnerabilities or exploits, the first vulnerability (CVE-2021-26855) has a remote network attack vector that allows the attacker, a group Microsoft named HAFNIUM, to authenticate as the Exchange server. Three additional vulnerabilities (CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) were also identified as part of this activity. When chained together along with CVE-2021-26855 for initial access, the attacker would have complete control over the Exchange server. This includes the ability to run code as SYSTEM and write to any path on the server.\
|
||||
@@ -591,7 +591,7 @@ version = 2
|
||||
references = ["https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Detect Activity Related to Pass the Hash Attacks - Rule", "ESCU - Kerberoasting spn request with RC4 encryption - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - Schtasks scheduling job on remote system - Rule", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task"]
|
||||
searches = ["ESCU - Detect Activity Related to Pass the Hash Attacks - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - Kerberoasting spn request with RC4 encryption - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - Schtasks scheduling job on remote system - Rule", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task"]
|
||||
description = Detect and investigate tactics, techniques, and procedures around how attackers move laterally within the enterprise. Because lateral movement can expose the adversary to detection, it should be an important focus for security analysts.
|
||||
narrative = Once attackers gain a foothold within an enterprise, they will seek to expand their accesses and leverage techniques that facilitate lateral movement. Attackers will often spend quite a bit of time and effort moving laterally. Because lateral movement renders an attacker the most vulnerable to detection, it's an excellent focus for detection and investigation.\
|
||||
Indications of lateral movement can include the abuse of system utilities (such as `psexec.exe`), unauthorized use of remote desktop services, `file/admin$` shares, WMI, PowerShell, pass-the-hash, or the abuse of scheduled tasks. Organizations must be extra vigilant in detecting lateral movement techniques and look for suspicious activity in and around high-value strategic network assets, such as Active Directory, which are often considered the primary target or "crown jewels" to a persistent threat actor.\
|
||||
@@ -632,6 +632,19 @@ narrative = Security monitoring and control mechanisms may be in place for syste
|
||||
The following content is here to assist with binaries within `system32` or `syswow64` being moved to a new location or an adversary bringing a the binary in to execute.\
|
||||
There will be false positives as some native Windows processes are moved or ran by third party applications from different paths. If file names are mismatched between the file name on disk and that of the binarys PE metadata, this is a likely indicator that a binary was renamed after it was compiled. Collecting and comparing disk and resource filenames for binaries by looking to see if the InternalName, OriginalFilename, and or ProductName match what is expected could provide useful leads, but may not always be indicative of malicious activity. Do not focus on the possible names a file could have, but instead on the command-line arguments that are known to be used and are distinct because it will have a better rate of detection.
|
||||
|
||||
[analytic_story://Meterpreter]
|
||||
category = Adversary Tactics
|
||||
last_updated = 2021-06-08
|
||||
version = 1
|
||||
references = ["https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/", "https://doubleoctopus.com/security-wiki/threats-and-tools/meterpreter/", "https://www.rapid7.com/products/metasploit/"]
|
||||
maintainers = [{"company": "no", "email": "-", "name": "Michael Hart"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Excessive number of taskhost processes - Rule"]
|
||||
description = Meterpreter provides red teams, pen testers and threat actors interactive access to a compromised host to run commands, upload payloads, download files, and other actions.
|
||||
narrative = This Analytic Story supports you to detect Tactics, Techniques and Procedures (TTPs) from Meterpreter. Meterpreter is a Metasploit payload for remote execution that leverages DLL injection to make it extremely difficult to detect. Since the software runs in memory, no new processes are created upon injection. It also leverages encrypted communication channels.\
|
||||
Meterpreter enables the operator to remotely run commands on the target machine, upload payloads, download files, dump password hashes, and much more. It is difficult to determine from the forensic evidence what actions the operator performed. Splunk Research, however, has observed anomalous behaviors on the compromised hosts that seem to only appear when Meterpreter is executing various commands. With that, we have written new detections targeted to these detections.\
|
||||
While investigating a detection related to this analytic story, please bear in mind that the detections look for anomalies in system behavior. It will be imperative to look for other signs in the endpoint and network logs for lateral movement, discovery and other actions to confirm that the host was compromised and a remote actor used it to progress on their objectives.
|
||||
|
||||
[analytic_story://Monitor Backup Solution]
|
||||
category = Best Practices
|
||||
last_updated = 2017-09-12
|
||||
@@ -761,7 +774,7 @@ version = 1
|
||||
references = ["http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task"]
|
||||
searches = ["ESCU - Allow Inbound Traffic By Firewall Rule Registry - Rule", "ESCU - Allow Inbound Traffic In Firewall Rule - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Enable RDP In Other Port Number - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task"]
|
||||
description = Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers.
|
||||
narrative = A traditional security best practice is to control the ports, protocols, and services allowed within your environment. By limiting the services and protocols to those explicitly approved by policy, administrators can minimize the attack surface. The combined effect allows both network defenders and security controls to focus and not be mired in superfluous traffic or data types. Looking for deviations to policy can identify attacker activity that abuses services and protocols to run on alternate or non-standard ports in the attempt to avoid detection or frustrate forensic analysts.
|
||||
|
||||
@@ -772,7 +785,7 @@ version = 1
|
||||
references = ["https://www.carbonblack.com/2017/06/28/carbon-black-threat-research-technical-analysis-petya-notpetya-ransomware/", "https://www.splunk.com/blog/2017/06/27/closing-the-detection-to-mitigation-gap-or-to-petya-or-notpetya-whocares-.html"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect RClone Command-Line Usage - Rule", "ESCU - Detect Renamed RClone - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - TOR Traffic - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - WinEvent Scheduled Task Created Within Public Path - Rule", "ESCU - WinEvent Scheduled Task Created to Spawn Shell - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task"]
|
||||
searches = ["ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Conti Common Exec parameter - Rule", "ESCU - Delete ShadowCopy With PowerShell - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect RClone Command-Line Usage - Rule", "ESCU - Detect Renamed RClone - Rule", "ESCU - Detect SharpHound Command-Line Arguments - Rule", "ESCU - Detect SharpHound File Modifications - Rule", "ESCU - Detect SharpHound Usage - Rule", "ESCU - Known Services Killed by Ransomware - Rule", "ESCU - Modification Of Wallpaper - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - Revil Common Exec Parameter - Rule", "ESCU - Revil Registry Entry - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - TOR Traffic - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - Wbemprox COM Object Execution - Rule", "ESCU - WinEvent Scheduled Task Created Within Public Path - Rule", "ESCU - WinEvent Scheduled Task Created to Spawn Shell - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task"]
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware--spikes in SMB traffic, suspicious wevtutil usage, the presence of common ransomware extensions, and system processes run from unexpected locations, and many others.
|
||||
narrative = Ransomware is an ever-present risk to the enterprise, wherein an infected host encrypts business-critical data, holding it hostage until the victim pays the attacker a ransom. There are many types and varieties of ransomware that can affect an enterprise. Attackers can deploy ransomware to enterprises through spearphishing campaigns and driveby downloads, as well as through traditional remote service-based exploitation. In the case of the WannaCry campaign, there was self-propagating wormable functionality that was used to maximize infection. Fortunately, organizations can apply several techniques--such as those in this Analytic Story--to detect and or mitigate the effects of ransomware.
|
||||
|
||||
@@ -787,6 +800,17 @@ searches = ["ESCU - AWS Detect Users creating keys with encrypt policy without M
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware. These searches include cloud related objects that may be targeted by malicious actors via cloud providers own encryption features.
|
||||
narrative = Ransomware is an ever-present risk to the enterprise, wherein an infected host encrypts business-critical data, holding it hostage until the victim pays the attacker a ransom. There are many types and varieties of ransomware that can affect an enterprise.Cloud ransomware can be deployed by obtaining high privilege credentials from targeted users or resources.
|
||||
|
||||
[analytic_story://Revil Ransomware]
|
||||
category = Malware
|
||||
last_updated = 2021-06-04
|
||||
version = 1
|
||||
references = ["https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/", "https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Teoderick Contreras"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Delete ShadowCopy With PowerShell - Rule", "ESCU - Modification Of Wallpaper - Rule", "ESCU - Revil Common Exec Parameter - Rule", "ESCU - Revil Registry Entry - Rule", "ESCU - Wbemprox COM Object Execution - Rule"]
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the Revil ransomware, including looking for file writes associated with Revil, encrypting network shares, deleting shadow volume storage, registry key modification, deleting of security logs, and more.
|
||||
narrative = Revil ransomware is a RaaS,that a single group may operates and manges the development of this ransomware. It involve the use of ransomware payloads along with exfiltration of data. Malicious actors demand payment for ransome of data and threaten deletion and exposure of exfiltrated data.
|
||||
|
||||
[analytic_story://Router and Infrastructure Security]
|
||||
category = Best Practices
|
||||
last_updated = 2017-09-12
|
||||
@@ -829,7 +853,7 @@ version = 1
|
||||
references = ["https://www.crowdstrike.com/blog/an-in-depth-analysis-of-samsam-ransomware-and-boss-spider/", "https://nakedsecurity.sophos.com/2018/07/31/samsam-the-almost-6-million-ransomware/", "https://thehackernews.com/2018/07/samsam-ransomware-attacks.html"]
|
||||
maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}]
|
||||
spec_version = 3
|
||||
searches = ["ESCU - Batch File Write to System32 - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect attackers scanning for vulnerable JBoss servers - Rule", "ESCU - Detect malicious requests to exploit JBoss servers - Rule", "ESCU - File with Samsam Extension - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Samsam Test File Write - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task"]
|
||||
searches = ["ESCU - Batch File Write to System32 - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect Renamed PSExec - Rule", "ESCU - Detect attackers scanning for vulnerable JBoss servers - Rule", "ESCU - Detect malicious requests to exploit JBoss servers - Rule", "ESCU - File with Samsam Extension - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Samsam Test File Write - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task"]
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the SamSam ransomware, including looking for file writes associated with SamSam, RDP brute force attacks, the presence of files with SamSam ransomware extensions, suspicious psexec use, and more.
|
||||
narrative = The first version of the SamSam ransomware (a.k.a. Samas or SamsamCrypt) was launched in 2015 by a group of Iranian threat actors. The malicious software has affected and continues to affect thousands of victims and has raised almost $6M in ransom.\
|
||||
Although categorized under the heading of ransomware, SamSam campaigns have some importance distinguishing characteristics. Most notable is the fact that conventional ransomware is a numbers game. Perpetrators use a "spray-and-pray" approach with phishing campaigns or other mechanisms, charging a small ransom (typically under $1,000). The goal is to find a large number of victims willing to pay these mini-ransoms, adding up to a lucrative payday. They use relatively simple methods for infecting systems.\
|
||||
@@ -1682,6 +1706,26 @@ annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1087.00
|
||||
known_false_positives = admin or power user may used this series of command.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Allow Inbound Traffic By Firewall Rule Registry - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This analytic detects a potential suspicious modification of firewall rule registry allowing inbound traffic in specific port with public profile. This technique was seen in some attacker want to have a remote access to a machine by allowing the traffic in firewall rule.
|
||||
how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1021.001"]}
|
||||
known_false_positives = network admin may add/remove/modify public inbound firewall rule that may cause this rule to be triggered.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Allow Inbound Traffic In Firewall Rule - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This search is to detect suspicious powershell command to allow inbound traffic in specific local port with public profile. This technique was seen in some attacker want to have a remote access to a machine by allowing the traffic in firewall rule.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1021.001"]}
|
||||
known_false_positives = administrator may allow inbound traffic in certain network or machine.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Amazon EKS Kubernetes Pod scan detection - Rule]
|
||||
type = detection
|
||||
asset_type = Amazon EKS Kubernetes cluster Pod
|
||||
@@ -1802,6 +1846,16 @@ annotations = {"cis20": ["CIS 8"], "kill_chain_phases": ["Delivery"], "mitre_att
|
||||
known_false_positives = It is possible for this search to generate a notable event for a batch file write to a path that includes the string "system32", but is not the actual Windows system directory. As such, you should confirm the path of the batch file identified by the search. In addition, a false positive may be generated by an administrator copying a legitimate batch file in this directory tree. You should confirm that the activity is legitimate and modify the search to add exclusions, as necessary.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - CMD Echo Pipe - Escalation - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This analytic identifies a common behavior by Cobalt Strike and other frameworks where the adversary will escalate privileges, either via `jump` (Cobalt Strike PTH) or `getsystem`, using named-pipe impersonation. A suspicious event will look like `cmd.exe /c echo 4sgryt3436 > \\.\Pipe\5erg53`.
|
||||
how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
annotations = {"kill_chain_phases": ["Exploitation", "Privilege Escalation"], "mitre_attack": ["T1059.003", "T1543.003"]}
|
||||
known_false_positives = Unknown. It is possible filtering may be required to ensure fidelity.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - CMLUA Or CMSTPLUA UAC Bypass - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
@@ -2043,6 +2097,16 @@ annotations = {"cis20": ["CIS 8"], "kill_chain_phases": ["Actions on Objectives"
|
||||
known_false_positives = It's possible that a legitimate file could be created with the same name used by ransomware note files.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Conti Common Exec parameter - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This search detects the suspicious commandline argument of revil ransomware to encrypt specific or all local drive and network shares of the compromised machine or host.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1204"]}
|
||||
known_false_positives = 3rd party tool may have commandline parameter that can trigger this detection.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Create Remote Thread into LSASS - Rule]
|
||||
type = detection
|
||||
asset_type = Windows
|
||||
@@ -2340,6 +2404,26 @@ annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 16"], "kill_chain_phases": ["Act
|
||||
known_false_positives = Legitimate logon activity by authorized NTLM systems may be detected by this search. Please investigate as appropriate.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect AzureHound Command-Line Arguments - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analytic identifies the common command-line argument used by AzureHound `Invoke-AzureHound`. Being the script is FOSS, function names may be modified, but these changes are dependent upon the operator. In most instances the defaults are used. This analytic works to identify the common command-line attributes used. It does not cover the entirety of every argument in order to avoid false positives.
|
||||
how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
annotations = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1087.002", "T1087.001", "T1482", "T1069.002", "T1069.001"]}
|
||||
known_false_positives = Unknown.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect AzureHound File Modifications - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analytic is similar to SharpHound file modifications, but this instance covers the use of Invoke-AzureHound. AzureHound is the SharpHound equivilent but for Azure. It's possible this may never be seen in an environment as most attackers may execute this tool remotely. Once execution is complete, a zip file with a similar name will drop `20210601090751-azurecollection.zip`. In addition to the zip, multiple .json files will be written to disk, which are in the zip.
|
||||
how_to_implement = To successfully implement this search you need to be ingesting information on file modifications that include the name of the process, and file, responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node.
|
||||
annotations = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1087.002", "T1087.001", "T1482", "T1069.002", "T1069.001"]}
|
||||
known_false_positives = False positives should be limited as the analytic is specific to a filename with extension .zip. Filter as needed.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect Baron Samedit CVE-2021-3156 - Rule]
|
||||
type = detection
|
||||
asset_type = Endpoint
|
||||
@@ -2759,6 +2843,26 @@ annotations = {"cis20": ["CIS 8", "CIS 16"], "kill_chain_phases": ["Actions on O
|
||||
known_false_positives = Limited false positives related to third party software registering .DLL's.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect Renamed 7-Zip - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analytic identifies renamed 7-Zip usage using Sysmon. At this stage of an attack, review parallel processes and file modifications for data that is staged or potentially have been exfiltrated. This analytic utilizes the OriginalFileName to capture the renamed process.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Exfiltration"], "mitre_attack": ["T1560.001"]}
|
||||
known_false_positives = Limited false positives, however this analytic will need to be modified for each environment if Sysmon is not used.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect Renamed PSExec - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analytic identifies renamed instances of `PsExec.exe` being utilized on an endpoint. Most instances, it is highly probable to capture `Psexec.exe` or other SysInternal utility usage with the command-line argument of `-accepteula`. In this instance, we are using `OriginalFileName` from Sysmon to identify `PsExec` usage. During triage, validate this is the legitimate version of `PsExec` by review the PE metadata. In addition, review parallel processes for further suspicious behavior.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used.
|
||||
annotations = {"kill_chain_phases": ["Exploitation", "Lateral Movement", "Execution"], "mitre_attack": ["T1569.002"]}
|
||||
known_false_positives = Limited false positives should be present. It is possible some third party applications may use older versions of PsExec, filter as needed.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect Renamed RClone - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
@@ -2769,6 +2873,16 @@ annotations = {"kill_chain_phases": ["Exfiltration"], "mitre_attack": ["T1020"]}
|
||||
known_false_positives = False positives should be limited as this analytic identifies renamed instances of `rclone.exe`. Filter as needed if there is a legitimate business use case.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect Renamed WinRAR - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analtyic identifies renamed instances of `WinRAR.exe`. In most cases, it is not common for WinRAR to be used renamed, however it is common to be installed by a third party application and executed from a non-standard path. In this instance, we are using `OriginalFileName` from Sysmon to determine if the process is WinRAR. During triage, validate additional metadata from the binary that this is `WinRAR`. Review parallel processes and file modifications.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Modify query for specific EDR products as needed.
|
||||
annotations = {"kill_chain_phases": ["Exploitation", "Exfiltration"], "mitre_attack": ["T1560.001"]}
|
||||
known_false_positives = Unknown. It is possible third party applications use renamed instances of WinRAR.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect Rogue DHCP Server - Rule]
|
||||
type = detection
|
||||
asset_type = Infrastructure
|
||||
@@ -2839,6 +2953,36 @@ annotations = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives
|
||||
known_false_positives = Unknown
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect SharpHound Command-Line Arguments - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analytic identifies common command-line arguments used by SharpHound `-collectionMethod` and `invoke-bloodhound`. Being the script is FOSS, function names may be modified, but these changes are dependent upon the operator. In most instances the defaults are used. This analytic works to identify the common command-line attributes used. It does not cover the entirety of every argument in order to avoid false positives.
|
||||
how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
annotations = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1087.002", "T1087.001", "T1482", "T1069.002", "T1069.001"]}
|
||||
known_false_positives = False positives should be limited as the arguments used are specific to SharpHound. Filter as needed or add more command-line arguments as needed.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect SharpHound File Modifications - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = SharpHound is used as a reconnaissance collector, ingestor, for BloodHound. SharpHound will query the domain controller and begin gathering all the data related to the domain and trusts. For output, it will drop a .zip file upon completion following a typical pattern that is often not changed. This analytic focuses on the default file name scheme. Note that this may be evaded with different parameters within SharpHound, but that depends on the operator. `-randomizefilenames` and `-encryptzip` are two examples. In addition, executing SharpHound via .exe or .ps1 without any command-line arguments will still perform activity and dump output to the default filename. Example default filename `20210601181553_BloodHound.zip`. SharpHound creates multiple temp files following the same pattern `20210601182121_computers.json`, `domains.json`, `gpos.json`, `ous.json` and `users.json`. Tuning may be required, or remove these json's entirely if it is too noisy. During traige, review parallel processes for further suspicious behavior. Typically, the process executing the `.ps1` ingestor will be PowerShell.
|
||||
how_to_implement = To successfully implement this search you need to be ingesting information on file modifications that include the name of the process, and file, responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node.
|
||||
annotations = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1087.002", "T1087.001", "T1482", "T1069.002", "T1069.001"]}
|
||||
known_false_positives = False positives should be limited as the analytic is specific to a filename with extension .zip. Filter as needed.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect SharpHound Usage - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analytic identifies SharpHound binary usage by using the `OriginalFileName` from Sysmon. In addition to renaming the PE, other coverage is available to detect command-line arguments. This particular analytic only looks for the OriginalFileName of `SharpHound.exe`. It is possible older instances of SharpHound.exe have different original filenames. Dependent upon the operator, the code may be re-compiled and the attributes removed or changed to anything else. During triage, review the metadata of the binary in question. Review parallel processes for suspicious behavior. Identify the source of this binary.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1087.002", "T1087.001", "T1482", "T1069.002", "T1069.001"]}
|
||||
known_false_positives = False positives should be limited as this is specific to a file attribute not used by anything else. Filter as needed.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Detect Software Download To Network Device - Rule]
|
||||
type = detection
|
||||
asset_type = Infrastructure
|
||||
@@ -3377,6 +3521,16 @@ annotations = {"cis20": ["CIS 7"], "kill_chain_phases": ["Actions on Objectives"
|
||||
known_false_positives = The false-positive rate will vary based on how you set the deviation_threshold and data_samples values. Our recommendation is to adjust these values based on your network traffic to and from your email servers.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Enable RDP In Other Port Number - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This search is to detect a modification to registry to enable rdp to a machine with different port number. This technique was seen in some atttacker tries to do lateral movement and remote access to a compromised machine to gain control of it.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1021"]}
|
||||
known_false_positives = unknown
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Enumerate Users Local Group Using Telegram - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
@@ -3487,6 +3641,16 @@ annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1048"]}
|
||||
known_false_positives = unknown
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Excessive number of taskhost processes - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This detection targets behaviors observed in post exploit kits like Meterpreter and Koadic that are run in memory. We have observed that these tools must invoke an excessive number of taskhost.exe and taskhostex.exe processes to complete various actions (discovery, lateral movement, etc.). It is extremely uncommon in the course of normal operations to see so many distinct taskhost and taskhostex processes running concurrently in a short time frame.
|
||||
how_to_implement = To successfully implement this search you need to be ingesting events related to processes on the endpoints that include the name of the process and process id into the `Endpoint` datamodel in the `Processes` node.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1033"]}
|
||||
known_false_positives = Administrators, administrative actions or certain applications may run many instances of taskhost and taskhostex concurrently. Filter as needed.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Executables Or Script Creation In Suspicious Path - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
@@ -3761,6 +3925,16 @@ annotations = {"cis20": ["CIS 8", "CIS 16"], "kill_chain_phases": ["Actions on O
|
||||
known_false_positives = Older systems that support kerberos RC4 by default NetApp may generate false positives
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Known Services Killed by Ransomware - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This search detects a suspicioous termination of known services killed by ransomware before encrypting files in a compromised machine. This technique is commonly seen in most of ransomware now a days to avoid exception error while accessing the targetted files it wants to encrypts because of the open handle of those services to the targetted file.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the 7036 EventCode ScManager in System audit Logs from your endpoints.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1490"]}
|
||||
known_false_positives = Admin activities or installing related updates may do a sudden stop to list of services we monitor.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Kubernetes AWS detect RBAC authorization by account - Rule]
|
||||
type = detection
|
||||
asset_type = AWS EKS Kubernetes cluster
|
||||
@@ -3971,6 +4145,16 @@ annotations = {"cis20": ["CIS 8"], "kill_chain_phases": ["Installation", "Comman
|
||||
known_false_positives = At this stage, there are no known false positives. During testing, no process events refering the com.apple.loginwindow.plist files were observed during normal operation of re-opening applications on reboot. Therefore, it can be asumed that any occurences of this in the process events would be worth investigating. In the event that the legitimate modification by the system of these files is in fact logged to the process log, then the process_name of that process can be added to an allow list.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Mailsniper Invoke functions - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This search is to detect known mailsniper.ps1 functions executed in a machine. This technique was seen in some attacker to harvest some sensitive e-mail in a compromised exchange server.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1114.001"]}
|
||||
known_false_positives = unknown
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule]
|
||||
type = detection
|
||||
asset_type = Endpoint
|
||||
@@ -4031,6 +4215,16 @@ annotations = {"kill_chain_phases": ["Privilege Escalation"], "mitre_attack": ["
|
||||
known_false_positives = Creating a hidden powershell service is rare and could key off of those instances.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Modification Of Wallpaper - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This analytic identifies suspicious modification of registry to deface or change the wallpaper of a compromised machines as part of its payload. This technique was commonly seen in ransomware like REVIL where it create a bitmap file contain a note that the machine was compromised and make it as a wallpaper.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the Image, TargetObject registry key, registry Details from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1491"]}
|
||||
known_false_positives = 3rd party tool may used to changed the wallpaper of the machine
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Modify ACL permission To Files Or Folder - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
@@ -4661,7 +4855,7 @@ providing_technologies = []
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = The following analytics identifies a big number of instance of ransomware notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This behavior is a good sensor if the ransomware note filename is quite new for security industry or the ransomware note filename is not in your lookup table list for monitoring.
|
||||
explanation = The following analytics identifies a big number of instance of ransomware notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This behavior is a good sensor if the ransomware note filename is quite new for security industry or the ransomware note filename is not in your ransomware lookup table list for monitoring.
|
||||
how_to_implement = You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data.
|
||||
annotations = {"kill_chain_phases": ["Obfuscation"], "mitre_attack": ["T1486"]}
|
||||
known_false_positives = unknown
|
||||
@@ -4787,6 +4981,26 @@ annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1490"]}
|
||||
known_false_positives = network admin can resize the shadowstorage for valid purposes.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Revil Common Exec Parameter - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This analytic identifies suspicious commandline parameter that are commonly used by REVIL ransomware to encrypts the compromise machine.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1204"]}
|
||||
known_false_positives = third party tool may have same command line parameters as revil ransomware.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Revil Registry Entry - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This analytic identifies suspicious modification in registry entry to keep some malware data during its infection. This technique seen in several apt implant, malware and ransomware like REVIL where it keep some information like the random generated file extension it uses for all the encrypted files and ransomware notes file name in the compromised host.
|
||||
how_to_implement = to successfully implement this search, you need to be ingesting logs with the Image, TargetObject registry key, registry Details from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1112"]}
|
||||
known_false_positives = unknown
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - RunDLL Loading DLL By Ordinal - Rule]
|
||||
type = detection
|
||||
asset_type = Endpoint
|
||||
@@ -4990,6 +5204,16 @@ annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1055"]}
|
||||
known_false_positives = Limited false positives may be present in small environments. Tuning may be required based on parent process.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - SecretDumps Offline NTDS Dumping Tool - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = This analytic detects a potential usage of secretsdump.py tool for dumping credentials (ntlm hash) from a copy of ntds.dit and SAM.Security,SYSTEM registrry hive. This technique was seen in some attacker that dump ntlm hashes offline after having a copy of ntds.dit and SAM/SYSTEM/SECURITY registry hive.
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1003.003"]}
|
||||
known_false_positives = unknown
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Services Escalate Exe - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
@@ -5608,6 +5832,16 @@ annotations = {"cis20": ["CIS 3", "CIS 5"], "kill_chain_phases": ["Actions on Ob
|
||||
known_false_positives = Some software may create WMI temporary event subscriptions for various purposes. The included search contains an exception for two of these that occur by default on Windows 10 systems. You may need to modify the search to create exceptions for other legitimate events.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Wbemprox COM Object Execution - Rule]
|
||||
type = detection
|
||||
asset_type =
|
||||
confidence = medium
|
||||
explanation = this search is designed to detect potential malicious process loading COM object to wbemprox.dll,
|
||||
how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name and imageloaded executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1218.003"]}
|
||||
known_false_positives = legitimate process that are not in the exception list may trigger this event.
|
||||
providing_technologies = []
|
||||
|
||||
[savedsearch://ESCU - Web Fraud - Account Harvesting - Rule]
|
||||
type = detection
|
||||
asset_type = Account
|
||||
|
||||
+9
-1
@@ -287,4 +287,12 @@ Extensions,Name
|
||||
.WNCRYT,WannaCry
|
||||
.RYK,Ryuk
|
||||
.Clop,Clop
|
||||
.Cllp,Clop
|
||||
.Cllp,Clop
|
||||
.JSWORM,JSWorm
|
||||
.NEMTY_*,Nemty
|
||||
.NEFILIM,Nefilim
|
||||
.OFFWHITE,Offwhite
|
||||
.TELEGRAM,Telegram
|
||||
.FUSION,Fusion
|
||||
.MILIHPEN,Milihpen
|
||||
.GANGBANG,Gangbang
|
||||
|
+9
-1
@@ -58,4 +58,12 @@ HELP_DECRYPT_YOUR_FILES.HTML,True
|
||||
*-READ-FOR-HELLPP.html,True
|
||||
RyukReadMe.html,True
|
||||
ClopReadMe.txt,True
|
||||
README_README.txt,True
|
||||
README_README.txt,True
|
||||
JSWORM-DECRYPT.html,True
|
||||
NEMTY_*-DECRYPT.txt,True
|
||||
NEFILIM-DECRYPT.txt,True
|
||||
OFFWHITE-MANUAL.txt,True
|
||||
TELEGRAM-RECOVER.txt,True
|
||||
FUSION-README.txt,True
|
||||
MILIHPEN-INSTRUCT.txt,True
|
||||
GANGBANG-NOTE.txt,True
|
||||
|
Vendored
+3
-3
@@ -1,7 +1,7 @@
|
||||
# Splunk ES Content Update
|
||||
# Splunk Security Analytics for AWS Content Update
|
||||
|
||||
This subscription service delivers pre-packaged Security Content for use with Splunk Enterprise Security. Subscribers get regular updates to help security practitioners more quickly address ongoing and time-sensitive customer problems and threats.
|
||||
This subscription service delivers pre-packaged Security Content for use with Splunk Security Analytics for AWS Content. Subscribers get regular updates to help security practitioners more quickly address ongoing and time-sensitive customer problems and threats.
|
||||
|
||||
Requires Splunk Enterprise Security version 4.5 or greater.
|
||||
|
||||
For more information please visit the [Splunk ES Content Update user documentation](https://docs.splunk.com/Documentation/ESSOC).
|
||||
For more information please visit the [Splunk ES Content Update user documentation](https://docs.splunk.com/Documentation/ESSOC).
|
||||
|
||||
Vendored
+1
-1
@@ -5,7 +5,7 @@
|
||||
"id": {
|
||||
"group": null,
|
||||
"name": "DA-ESS_AmazonWebServices_Content",
|
||||
"version": "3.22.0"
|
||||
"version": "3.23.0"
|
||||
},
|
||||
"author": [
|
||||
{
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2021-05-24T20:39:00 UTC
|
||||
# On Date: 2021-06-10T18:24:49 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2021-05-24T20:39:00 UTC
|
||||
# On Date: 2021-06-10T18:24:49 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
Vendored
+2
-2
@@ -4,7 +4,7 @@
|
||||
is_configured = false
|
||||
state = enabled
|
||||
state_change_requires_restart = false
|
||||
build = 29832
|
||||
build = 30583
|
||||
|
||||
[triggers]
|
||||
reload.analytic_stories = simple
|
||||
@@ -18,7 +18,7 @@ reload.content-version = simple
|
||||
|
||||
[launcher]
|
||||
author = Splunk
|
||||
version = 3.22.0
|
||||
version = 3.23.0
|
||||
description = Explore the Analytic Stories included with Splunk Security Analytics for AWS Content
|
||||
|
||||
[ui]
|
||||
|
||||
Vendored
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2021-05-24T20:39:00 UTC
|
||||
# On Date: 2021-06-10T18:24:49 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+1
-1
@@ -1,2 +1,2 @@
|
||||
[content-version]
|
||||
version = 3.22.0
|
||||
version = 3.23.0
|
||||
|
||||
Vendored
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2021-05-24T20:39:00 UTC
|
||||
# On Date: 2021-06-10T18:24:49 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+51
-51
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2021-05-24T20:39:00 UTC
|
||||
# On Date: 2021-06-10T18:24:49 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
@@ -38,8 +38,8 @@ action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Es
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -78,8 +78,8 @@ action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Es
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -118,8 +118,8 @@ action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Es
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -158,8 +158,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud Aut
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -198,8 +198,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Ransomware Cloud"],
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -238,8 +238,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Ransomware Cloud"],
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -278,8 +278,8 @@ action.correlationsearch.annotations = {"analytic_story": ["AWS User Monitoring"
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -318,8 +318,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud Use
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -358,8 +358,8 @@ action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Es
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -398,8 +398,8 @@ action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Es
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -438,8 +438,8 @@ action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Es
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -478,8 +478,8 @@ action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Es
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -518,8 +518,8 @@ action.correlationsearch.annotations = {"analytic_story": ["AWS Network ACL Acti
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -558,8 +558,8 @@ action.correlationsearch.annotations = {"analytic_story": ["AWS Network ACL Acti
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -598,8 +598,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Cloud Federated Cred
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -638,8 +638,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Cloud Federated Cred
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -678,8 +678,8 @@ action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Es
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -718,8 +718,8 @@ action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Es
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -758,8 +758,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud Use
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -798,8 +798,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud Ins
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -838,8 +838,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Cloud Cryptomining",
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -878,8 +878,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud Use
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -918,8 +918,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud Use
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -958,8 +958,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Cloud Cryptomining"]
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -998,8 +998,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Cloud Cryptomining"]
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1038,8 +1038,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Cloud Cryptomining"]
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1078,8 +1078,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Cloud Cryptomining"]
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1118,8 +1118,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud Ins
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1159,8 +1159,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud Pro
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1200,8 +1200,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud Pro
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1241,8 +1241,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud Pro
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1282,8 +1282,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud Pro
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1322,8 +1322,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud Aut
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1362,8 +1362,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious AWS Login
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1402,8 +1402,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious AWS Login
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1442,8 +1442,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious AWS Login
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1482,8 +1482,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious AWS S3 Ac
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1522,8 +1522,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Suspicious AWS S3 Ac
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1562,8 +1562,8 @@ action.correlationsearch.annotations = {"analytic_story": ["AWS Security Hub Ale
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1602,8 +1602,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Office 365 Detection
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1642,8 +1642,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Office 365 Detection
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1682,8 +1682,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Office 365 Detection
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1722,8 +1722,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Office 365 Detection
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1762,8 +1762,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Office 365 Detection
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1802,8 +1802,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Office 365 Detection
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1842,8 +1842,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Office 365 Detection
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1882,8 +1882,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Office 365 Detection
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1922,8 +1922,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Office 365 Detection
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -1962,8 +1962,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Office 365 Detection
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
@@ -2002,8 +2002,8 @@ action.correlationsearch.annotations = {"analytic_story": ["Office 365 Detection
|
||||
schedule_window = auto
|
||||
alert.digest_mode = 1
|
||||
disabled = false
|
||||
allow_skew = 100%
|
||||
enableSched = 1
|
||||
allow_skew = 100%
|
||||
counttype = number of events
|
||||
relation = greater than
|
||||
quantity = 0
|
||||
|
||||
Vendored
+2
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2021-05-24T20:39:00 UTC
|
||||
# On Date: 2021-06-10T18:24:49 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
@@ -210,6 +210,7 @@ filename = ransomware_extensions.csv
|
||||
default_match = false
|
||||
case_sensitive_match = false
|
||||
# description = A list of file extensions that are associated with ransomware
|
||||
match_type = WILDCARD(Extensions)
|
||||
min_matches = 1
|
||||
|
||||
[ransomware_notes_lookup]
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2021-05-24T20:39:00 UTC
|
||||
# On Date: 2021-06-10T18:24:49 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+9
-1
@@ -287,4 +287,12 @@ Extensions,Name
|
||||
.WNCRYT,WannaCry
|
||||
.RYK,Ryuk
|
||||
.Clop,Clop
|
||||
.Cllp,Clop
|
||||
.Cllp,Clop
|
||||
.JSWORM,JSWorm
|
||||
.NEMTY_*,Nemty
|
||||
.NEFILIM,Nefilim
|
||||
.OFFWHITE,Offwhite
|
||||
.TELEGRAM,Telegram
|
||||
.FUSION,Fusion
|
||||
.MILIHPEN,Milihpen
|
||||
.GANGBANG,Gangbang
|
||||
|
+9
-1
@@ -58,4 +58,12 @@ HELP_DECRYPT_YOUR_FILES.HTML,True
|
||||
*-READ-FOR-HELLPP.html,True
|
||||
RyukReadMe.html,True
|
||||
ClopReadMe.txt,True
|
||||
README_README.txt,True
|
||||
README_README.txt,True
|
||||
JSWORM-DECRYPT.html,True
|
||||
NEMTY_*-DECRYPT.txt,True
|
||||
NEFILIM-DECRYPT.txt,True
|
||||
OFFWHITE-MANUAL.txt,True
|
||||
TELEGRAM-RECOVER.txt,True
|
||||
FUSION-README.txt,True
|
||||
MILIHPEN-INSTRUCT.txt,True
|
||||
GANGBANG-NOTE.txt,True
|
||||
|
+2026
-7
File diff suppressed because it is too large
Load Diff
+2019
-91
File diff suppressed because it is too large
Load Diff
+38902
-26057
File diff suppressed because it is too large
Load Diff
+23855
-13579
File diff suppressed because it is too large
Load Diff
+22387
-11010
File diff suppressed because it is too large
Load Diff
+22906
-20704
File diff suppressed because it is too large
Load Diff
+220
-20
@@ -119,8 +119,6 @@ Fortify your data-protection arsenal--while continuing to ensure data confidenti
|
||||
| ----------- | ----------- |--------------|
|
||||
| T1189 | Drive-by Compromise | Initial Access |
|
||||
| T1048.003 | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration |
|
||||
| T1048 | Exfiltration Over Alternative Protocol | Exfiltration |
|
||||
| T1071.001 | Web Protocols | Command and Control |
|
||||
|
||||
#### Kill Chain Phase
|
||||
|
||||
@@ -429,7 +427,7 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
|
||||
|
||||
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
- **Datamodel**: Endpoint
|
||||
- **ATT&CK**: [T1036.003](https://attack.mitre.org/techniques/T1036.003/), [T1055](https://attack.mitre.org/techniques/T1055/), [T1127](https://attack.mitre.org/techniques/T1127/), [T1127.001](https://attack.mitre.org/techniques/T1127.001/), [T1218.010](https://attack.mitre.org/techniques/T1218.010/), [T1218.011](https://attack.mitre.org/techniques/T1218.011/), [T1548](https://attack.mitre.org/techniques/T1548/), [T1560.001](https://attack.mitre.org/techniques/T1560.001/)
|
||||
- **ATT&CK**: [T1036.003](https://attack.mitre.org/techniques/T1036.003/), [T1055](https://attack.mitre.org/techniques/T1055/), [T1059.003](https://attack.mitre.org/techniques/T1059.003/), [T1127](https://attack.mitre.org/techniques/T1127/), [T1127.001](https://attack.mitre.org/techniques/T1127.001/), [T1218.010](https://attack.mitre.org/techniques/T1218.010/), [T1218.011](https://attack.mitre.org/techniques/T1218.011/), [T1543.003](https://attack.mitre.org/techniques/T1543.003/), [T1548](https://attack.mitre.org/techniques/T1548/), [T1560.001](https://attack.mitre.org/techniques/T1560.001/)
|
||||
- **Last Updated**: 2021-02-16
|
||||
|
||||
<details>
|
||||
@@ -439,6 +437,8 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
|
||||
|
||||
* [Anomalous usage of 7zip](detections.md#anomalous-usage-of-7zip)
|
||||
|
||||
* [CMD Echo Pipe - Escalation](detections.md#cmd-echo-pipe---escalation)
|
||||
|
||||
* [Cobalt Strike Named Pipes](detections.md#cobalt-strike-named-pipes)
|
||||
|
||||
* [DLLHost with no Command Line Arguments with Network](detections.md#dllhost-with-no-command-line-arguments-with-network)
|
||||
@@ -475,15 +475,15 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
|
||||
| ID | Technique | Tactic |
|
||||
| ----------- | ----------- |--------------|
|
||||
| T1560.001 | Archive via Utility | Collection |
|
||||
| T1059.003 | Windows Command Shell | Execution |
|
||||
| T1543.003 | Windows Service | Persistence, Privilege Escalation |
|
||||
| T1055 | Process Injection | Defense Evasion, Privilege Escalation |
|
||||
| T1071.002 | File Transfer Protocols | Command and Control |
|
||||
| T1059.003 | Windows Command Shell | Execution |
|
||||
| T1218.010 | Regsvr32 | Defense Evasion |
|
||||
| T1218.005 | Mshta | Defense Evasion |
|
||||
| T1569.002 | Service Execution | Execution |
|
||||
| T1027 | Obfuscated Files or Information | Defense Evasion |
|
||||
| T1218.011 | Rundll32 | Defense Evasion |
|
||||
| T1543.003 | Windows Service | Persistence, Privilege Escalation |
|
||||
| T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation |
|
||||
| T1548 | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation |
|
||||
| T1203 | Exploitation for Client Execution | Execution |
|
||||
@@ -532,7 +532,7 @@ Monitor for and investigate activities--such as suspicious writes to the Windows
|
||||
|
||||
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
- **Datamodel**: Endpoint, Network_Traffic
|
||||
- **ATT&CK**: [T1036](https://attack.mitre.org/techniques/T1036/), [T1114.001](https://attack.mitre.org/techniques/T1114.001/), [T1114.002](https://attack.mitre.org/techniques/T1114.002/)
|
||||
- **ATT&CK**: [T1036](https://attack.mitre.org/techniques/T1036/), [T1114.001](https://attack.mitre.org/techniques/T1114.001/), [T1114.002](https://attack.mitre.org/techniques/T1114.002/), [T1560.001](https://attack.mitre.org/techniques/T1560.001/)
|
||||
- **Last Updated**: 2020-02-03
|
||||
|
||||
<details>
|
||||
@@ -540,6 +540,10 @@ Monitor for and investigate activities--such as suspicious writes to the Windows
|
||||
|
||||
#### Detection Profile
|
||||
|
||||
* [Detect Renamed 7-Zip](detections.md#detect-renamed-7-zip)
|
||||
|
||||
* [Detect Renamed WinRAR](detections.md#detect-renamed-winrar)
|
||||
|
||||
* [Email files written outside of the Outlook directory](detections.md#email-files-written-outside-of-the-outlook-directory)
|
||||
|
||||
* [Email servers sending high volume traffic to hosts](detections.md#email-servers-sending-high-volume-traffic-to-hosts)
|
||||
@@ -555,6 +559,7 @@ Monitor for and investigate activities--such as suspicious writes to the Windows
|
||||
|
||||
| ID | Technique | Tactic |
|
||||
| ----------- | ----------- |--------------|
|
||||
| T1560.001 | Archive via Utility | Collection |
|
||||
| T1114.001 | Local Email Collection | Collection |
|
||||
| T1114.002 | Remote Email Collection | Collection |
|
||||
| T1036 | Masquerading | Defense Evasion |
|
||||
@@ -563,6 +568,10 @@ Monitor for and investigate activities--such as suspicious writes to the Windows
|
||||
|
||||
* Actions on Objectives
|
||||
|
||||
* Exfiltration
|
||||
|
||||
* Exploitation
|
||||
|
||||
|
||||
#### Reference
|
||||
|
||||
@@ -776,6 +785,8 @@ Uncover activity consistent with credential dumping, a technique wherein attacke
|
||||
|
||||
* [Ntdsutil Export NTDS](detections.md#ntdsutil-export-ntds)
|
||||
|
||||
* [SecretDumps Offline NTDS Dumping Tool](detections.md#secretdumps-offline-ntds-dumping-tool)
|
||||
|
||||
* [Set Default PowerShell Execution Policy To Unrestricted or Bypass](detections.md#set-default-powershell-execution-policy-to-unrestricted-or-bypass)
|
||||
|
||||
* [Unsigned Image Loaded by LSASS](detections.md#unsigned-image-loaded-by-lsass)
|
||||
@@ -888,8 +899,8 @@ _version_: 1
|
||||
The stealing of data by an adversary.
|
||||
|
||||
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
- **Datamodel**:
|
||||
- **ATT&CK**: [T1041](https://attack.mitre.org/techniques/T1041/), [T1114](https://attack.mitre.org/techniques/T1114/), [T1114.003](https://attack.mitre.org/techniques/T1114.003/)
|
||||
- **Datamodel**: Endpoint
|
||||
- **ATT&CK**: [T1041](https://attack.mitre.org/techniques/T1041/), [T1114](https://attack.mitre.org/techniques/T1114/), [T1114.001](https://attack.mitre.org/techniques/T1114.001/), [T1114.003](https://attack.mitre.org/techniques/T1114.003/)
|
||||
- **Last Updated**: 2020-10-21
|
||||
|
||||
<details>
|
||||
@@ -899,6 +910,8 @@ The stealing of data by an adversary.
|
||||
|
||||
* [Detect SNICat SNI Exfiltration](detections.md#detect-snicat-sni-exfiltration)
|
||||
|
||||
* [Mailsniper Invoke functions](detections.md#mailsniper-invoke-functions)
|
||||
|
||||
* [O365 PST export alert](detections.md#o365-pst-export-alert)
|
||||
|
||||
* [O365 Suspicious Admin Email Forwarding](detections.md#o365-suspicious-admin-email-forwarding)
|
||||
@@ -911,6 +924,7 @@ The stealing of data by an adversary.
|
||||
| ID | Technique | Tactic |
|
||||
| ----------- | ----------- |--------------|
|
||||
| T1041 | Exfiltration Over C2 Channel | Exfiltration |
|
||||
| T1114.001 | Local Email Collection | Collection |
|
||||
| T1114 | Email Collection | Collection |
|
||||
| T1114.003 | Email Forwarding Rule | Collection |
|
||||
|
||||
@@ -920,6 +934,8 @@ The stealing of data by an adversary.
|
||||
|
||||
* Actions on Objectives
|
||||
|
||||
* Exploitation
|
||||
|
||||
|
||||
#### Reference
|
||||
|
||||
@@ -1166,7 +1182,7 @@ HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVE
|
||||
|
||||
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
- **Datamodel**: Endpoint, Network_Traffic
|
||||
- **ATT&CK**: [T1003.001](https://attack.mitre.org/techniques/T1003.001/), [T1003.003](https://attack.mitre.org/techniques/T1003.003/), [T1021.002](https://attack.mitre.org/techniques/T1021.002/), [T1059.001](https://attack.mitre.org/techniques/T1059.001/), [T1114.002](https://attack.mitre.org/techniques/T1114.002/), [T1136.001](https://attack.mitre.org/techniques/T1136.001/), [T1190](https://attack.mitre.org/techniques/T1190/), [T1505.003](https://attack.mitre.org/techniques/T1505.003/)
|
||||
- **ATT&CK**: [T1003.001](https://attack.mitre.org/techniques/T1003.001/), [T1003.003](https://attack.mitre.org/techniques/T1003.003/), [T1021.002](https://attack.mitre.org/techniques/T1021.002/), [T1059.001](https://attack.mitre.org/techniques/T1059.001/), [T1114.002](https://attack.mitre.org/techniques/T1114.002/), [T1136.001](https://attack.mitre.org/techniques/T1136.001/), [T1190](https://attack.mitre.org/techniques/T1190/), [T1505.003](https://attack.mitre.org/techniques/T1505.003/), [T1569.002](https://attack.mitre.org/techniques/T1569.002/)
|
||||
- **Last Updated**: 2021-03-03
|
||||
|
||||
<details>
|
||||
@@ -1182,6 +1198,8 @@ HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVE
|
||||
|
||||
* [Detect PsExec With accepteula Flag](detections.md#detect-psexec-with-accepteula-flag)
|
||||
|
||||
* [Detect Renamed PSExec](detections.md#detect-renamed-psexec)
|
||||
|
||||
* [Dump LSASS via comsvcs DLL](detections.md#dump-lsass-via-comsvcs-dll)
|
||||
|
||||
* [Dump LSASS via procdump](detections.md#dump-lsass-via-procdump)
|
||||
@@ -1213,6 +1231,7 @@ HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVE
|
||||
| T1505.003 | Web Shell | Persistence |
|
||||
| T1136.001 | Local Account | Persistence |
|
||||
| T1021.002 | SMB/Windows Admin Shares | Lateral Movement |
|
||||
| T1569.002 | Service Execution | Execution |
|
||||
| T1003.001 | LSASS Memory | Credential Access |
|
||||
| T1114.002 | Remote Email Collection | Collection |
|
||||
| T1003.003 | NTDS | Credential Access |
|
||||
@@ -1224,10 +1243,14 @@ HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVE
|
||||
|
||||
* Command and Control
|
||||
|
||||
* Execution
|
||||
|
||||
* Exploitation
|
||||
|
||||
* Installation
|
||||
|
||||
* Lateral Movement
|
||||
|
||||
|
||||
#### Reference
|
||||
|
||||
@@ -1313,7 +1336,7 @@ Detect and investigate tactics, techniques, and procedures around how attackers
|
||||
|
||||
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
- **Datamodel**: Endpoint, Network_Traffic
|
||||
- **ATT&CK**: [T1021.001](https://attack.mitre.org/techniques/T1021.001/), [T1053.005](https://attack.mitre.org/techniques/T1053.005/), [T1550.002](https://attack.mitre.org/techniques/T1550.002/), [T1558.003](https://attack.mitre.org/techniques/T1558.003/)
|
||||
- **ATT&CK**: [T1021.001](https://attack.mitre.org/techniques/T1021.001/), [T1021.002](https://attack.mitre.org/techniques/T1021.002/), [T1053.005](https://attack.mitre.org/techniques/T1053.005/), [T1550.002](https://attack.mitre.org/techniques/T1550.002/), [T1558.003](https://attack.mitre.org/techniques/T1558.003/), [T1569.002](https://attack.mitre.org/techniques/T1569.002/)
|
||||
- **Last Updated**: 2020-02-04
|
||||
|
||||
<details>
|
||||
@@ -1325,6 +1348,10 @@ Detect and investigate tactics, techniques, and procedures around how attackers
|
||||
|
||||
* [Detect Pass the Hash](detections.md#detect-pass-the-hash)
|
||||
|
||||
* [Detect PsExec With accepteula Flag](detections.md#detect-psexec-with-accepteula-flag)
|
||||
|
||||
* [Detect Renamed PSExec](detections.md#detect-renamed-psexec)
|
||||
|
||||
* [Kerberoasting spn request with RC4 encryption](detections.md#kerberoasting-spn-request-with-rc4-encryption)
|
||||
|
||||
* [Remote Desktop Network Traffic](detections.md#remote-desktop-network-traffic)
|
||||
@@ -1339,6 +1366,8 @@ Detect and investigate tactics, techniques, and procedures around how attackers
|
||||
| ID | Technique | Tactic |
|
||||
| ----------- | ----------- |--------------|
|
||||
| T1550.002 | Pass the Hash | Defense Evasion, Lateral Movement |
|
||||
| T1021.002 | SMB/Windows Admin Shares | Lateral Movement |
|
||||
| T1569.002 | Service Execution | Execution |
|
||||
| T1558.003 | Kerberoasting | Credential Access |
|
||||
| T1021.001 | Remote Desktop Protocol | Lateral Movement |
|
||||
| T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation |
|
||||
@@ -1347,6 +1376,12 @@ Detect and investigate tactics, techniques, and procedures around how attackers
|
||||
|
||||
* Actions on Objectives
|
||||
|
||||
* Execution
|
||||
|
||||
* Exploitation
|
||||
|
||||
* Lateral Movement
|
||||
|
||||
|
||||
#### Reference
|
||||
|
||||
@@ -1496,6 +1531,47 @@ Adversaries may rename legitimate system utilities to try to evade security mech
|
||||
* https://attack.mitre.org/techniques/T1036/003/
|
||||
|
||||
|
||||
_version_: 1
|
||||
</details>
|
||||
|
||||
---
|
||||
|
||||
### Meterpreter
|
||||
Meterpreter provides red teams, pen testers and threat actors interactive access to a compromised host to run commands, upload payloads, download files, and other actions.
|
||||
|
||||
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
- **Datamodel**: Endpoint
|
||||
- **ATT&CK**: [T1033](https://attack.mitre.org/techniques/T1033/)
|
||||
- **Last Updated**: 2021-06-08
|
||||
|
||||
<details>
|
||||
<summary>details</summary>
|
||||
|
||||
#### Detection Profile
|
||||
|
||||
* [Excessive number of taskhost processes](detections.md#excessive-number-of-taskhost-processes)
|
||||
|
||||
|
||||
#### ATT&CK
|
||||
|
||||
| ID | Technique | Tactic |
|
||||
| ----------- | ----------- |--------------|
|
||||
| T1033 | System Owner/User Discovery | Discovery |
|
||||
|
||||
#### Kill Chain Phase
|
||||
|
||||
* Exploitation
|
||||
|
||||
|
||||
#### Reference
|
||||
|
||||
* https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/
|
||||
|
||||
* https://doubleoctopus.com/security-wiki/threats-and-tools/meterpreter/
|
||||
|
||||
* https://www.rapid7.com/products/metasploit/
|
||||
|
||||
|
||||
_version_: 1
|
||||
</details>
|
||||
|
||||
@@ -1546,15 +1622,15 @@ Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and managemen
|
||||
| ID | Technique | Tactic |
|
||||
| ----------- | ----------- |--------------|
|
||||
| T1560.001 | Archive via Utility | Collection |
|
||||
| T1059.003 | Windows Command Shell | Execution |
|
||||
| T1543.003 | Windows Service | Persistence, Privilege Escalation |
|
||||
| T1055 | Process Injection | Defense Evasion, Privilege Escalation |
|
||||
| T1071.002 | File Transfer Protocols | Command and Control |
|
||||
| T1059.003 | Windows Command Shell | Execution |
|
||||
| T1218.010 | Regsvr32 | Defense Evasion |
|
||||
| T1218.005 | Mshta | Defense Evasion |
|
||||
| T1569.002 | Service Execution | Execution |
|
||||
| T1027 | Obfuscated Files or Information | Defense Evasion |
|
||||
| T1218.011 | Rundll32 | Defense Evasion |
|
||||
| T1543.003 | Windows Service | Persistence, Privilege Escalation |
|
||||
| T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation |
|
||||
| T1548 | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation |
|
||||
| T1203 | Exploitation for Client Execution | Execution |
|
||||
@@ -2670,7 +2746,7 @@ _version_: 1
|
||||
### Windows Discovery Techniques
|
||||
Monitors for behaviors associated with adversaries discovering objects in the environment that can be leveraged in the progression of the attack.
|
||||
|
||||
- **Product**: Splunk Behavioral Analytics
|
||||
- **Product**: Splunk Behavioral Analytics, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
- **Datamodel**:
|
||||
- **ATT&CK**: [T1007](https://attack.mitre.org/techniques/T1007/), [T1012](https://attack.mitre.org/techniques/T1012/), [T1021.002](https://attack.mitre.org/techniques/T1021.002/), [T1039](https://attack.mitre.org/techniques/T1039/), [T1046](https://attack.mitre.org/techniques/T1046/), [T1047](https://attack.mitre.org/techniques/T1047/), [T1053](https://attack.mitre.org/techniques/T1053/), [T1055](https://attack.mitre.org/techniques/T1055/), [T1057](https://attack.mitre.org/techniques/T1057/), [T1068](https://attack.mitre.org/techniques/T1068/), [T1078](https://attack.mitre.org/techniques/T1078/), [T1083](https://attack.mitre.org/techniques/T1083/), [T1087](https://attack.mitre.org/techniques/T1087/), [T1098](https://attack.mitre.org/techniques/T1098/), [T1135](https://attack.mitre.org/techniques/T1135/), [T1199](https://attack.mitre.org/techniques/T1199/), [T1482](https://attack.mitre.org/techniques/T1482/), [T1484](https://attack.mitre.org/techniques/T1484/), [T1518](https://attack.mitre.org/techniques/T1518/), [T1543](https://attack.mitre.org/techniques/T1543/), [T1547](https://attack.mitre.org/techniques/T1547/), [T1574](https://attack.mitre.org/techniques/T1574/), [T1589.001](https://attack.mitre.org/techniques/T1589.001/), [T1590](https://attack.mitre.org/techniques/T1590/), [T1590.001](https://attack.mitre.org/techniques/T1590.001/), [T1590.003](https://attack.mitre.org/techniques/T1590.003/), [T1591](https://attack.mitre.org/techniques/T1591/), [T1592](https://attack.mitre.org/techniques/T1592/), [T1592.002](https://attack.mitre.org/techniques/T1592.002/), [T1595](https://attack.mitre.org/techniques/T1595/), [T1595.002](https://attack.mitre.org/techniques/T1595.002/)
|
||||
- **Last Updated**: 2021-03-04
|
||||
@@ -2758,6 +2834,8 @@ Monitors for behaviors associated with adversaries discovering objects in the en
|
||||
|
||||
* https://cyberd.us/penetration-testing
|
||||
|
||||
* https://attack.mitre.org/software/S0521/
|
||||
|
||||
|
||||
_version_: 1
|
||||
</details>
|
||||
@@ -3149,8 +3227,8 @@ _version_: 1
|
||||
Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers.
|
||||
|
||||
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
- **Datamodel**: Network_Resolution, Network_Traffic
|
||||
- **ATT&CK**: [T1048](https://attack.mitre.org/techniques/T1048/), [T1048.003](https://attack.mitre.org/techniques/T1048.003/), [T1071.001](https://attack.mitre.org/techniques/T1071.001/), [T1189](https://attack.mitre.org/techniques/T1189/)
|
||||
- **Datamodel**: Endpoint, Network_Resolution, Network_Traffic
|
||||
- **ATT&CK**: [T1021](https://attack.mitre.org/techniques/T1021/), [T1021.001](https://attack.mitre.org/techniques/T1021.001/), [T1048](https://attack.mitre.org/techniques/T1048/), [T1048.003](https://attack.mitre.org/techniques/T1048.003/), [T1071.001](https://attack.mitre.org/techniques/T1071.001/), [T1189](https://attack.mitre.org/techniques/T1189/)
|
||||
- **Last Updated**: 2017-09-11
|
||||
|
||||
<details>
|
||||
@@ -3158,8 +3236,14 @@ Detect instances of prohibited network traffic allowed in the environment, as we
|
||||
|
||||
#### Detection Profile
|
||||
|
||||
* [Allow Inbound Traffic By Firewall Rule Registry](detections.md#allow-inbound-traffic-by-firewall-rule-registry)
|
||||
|
||||
* [Allow Inbound Traffic In Firewall Rule](detections.md#allow-inbound-traffic-in-firewall-rule)
|
||||
|
||||
* [Detect hosts connecting to dynamic domain providers](detections.md#detect-hosts-connecting-to-dynamic-domain-providers)
|
||||
|
||||
* [Enable RDP In Other Port Number](detections.md#enable-rdp-in-other-port-number)
|
||||
|
||||
* [Prohibited Network Traffic Allowed](detections.md#prohibited-network-traffic-allowed)
|
||||
|
||||
* [Protocol or Port Mismatch](detections.md#protocol-or-port-mismatch)
|
||||
@@ -3171,9 +3255,11 @@ Detect instances of prohibited network traffic allowed in the environment, as we
|
||||
|
||||
| ID | Technique | Tactic |
|
||||
| ----------- | ----------- |--------------|
|
||||
| T1021.001 | Remote Desktop Protocol | Lateral Movement |
|
||||
| T1189 | Drive-by Compromise | Initial Access |
|
||||
| T1048.003 | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration |
|
||||
| T1021 | Remote Services | Lateral Movement |
|
||||
| T1048 | Exfiltration Over Alternative Protocol | Exfiltration |
|
||||
| T1048.003 | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration |
|
||||
| T1071.001 | Web Protocols | Command and Control |
|
||||
|
||||
#### Kill Chain Phase
|
||||
@@ -3184,6 +3270,8 @@ Detect instances of prohibited network traffic allowed in the environment, as we
|
||||
|
||||
* Delivery
|
||||
|
||||
* Exploitation
|
||||
|
||||
|
||||
#### Reference
|
||||
|
||||
@@ -4615,7 +4703,7 @@ Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA
|
||||
|
||||
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
- **Datamodel**: Endpoint, Network_Traffic
|
||||
- **ATT&CK**: [T1021.002](https://attack.mitre.org/techniques/T1021.002/), [T1053.005](https://attack.mitre.org/techniques/T1053.005/), [T1059.001](https://attack.mitre.org/techniques/T1059.001/), [T1059.003](https://attack.mitre.org/techniques/T1059.003/), [T1071.002](https://attack.mitre.org/techniques/T1071.002/), [T1112](https://attack.mitre.org/techniques/T1112/), [T1136.001](https://attack.mitre.org/techniques/T1136.001/), [T1204.002](https://attack.mitre.org/techniques/T1204.002/), [T1543.003](https://attack.mitre.org/techniques/T1543.003/), [T1547.001](https://attack.mitre.org/techniques/T1547.001/), [T1562.004](https://attack.mitre.org/techniques/T1562.004/)
|
||||
- **ATT&CK**: [T1021.002](https://attack.mitre.org/techniques/T1021.002/), [T1053.005](https://attack.mitre.org/techniques/T1053.005/), [T1059.001](https://attack.mitre.org/techniques/T1059.001/), [T1059.003](https://attack.mitre.org/techniques/T1059.003/), [T1071.002](https://attack.mitre.org/techniques/T1071.002/), [T1112](https://attack.mitre.org/techniques/T1112/), [T1136.001](https://attack.mitre.org/techniques/T1136.001/), [T1204.002](https://attack.mitre.org/techniques/T1204.002/), [T1543.003](https://attack.mitre.org/techniques/T1543.003/), [T1547.001](https://attack.mitre.org/techniques/T1547.001/), [T1562.004](https://attack.mitre.org/techniques/T1562.004/), [T1569.002](https://attack.mitre.org/techniques/T1569.002/)
|
||||
- **Last Updated**: 2020-01-22
|
||||
|
||||
<details>
|
||||
@@ -4631,6 +4719,8 @@ Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA
|
||||
|
||||
* [Detect PsExec With accepteula Flag](detections.md#detect-psexec-with-accepteula-flag)
|
||||
|
||||
* [Detect Renamed PSExec](detections.md#detect-renamed-psexec)
|
||||
|
||||
* [First time seen command line argument](detections.md#first-time-seen-command-line-argument)
|
||||
|
||||
* [Malicious PowerShell Process - Execution Policy Bypass](detections.md#malicious-powershell-process---execution-policy-bypass)
|
||||
@@ -4659,6 +4749,7 @@ Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA
|
||||
| T1136.001 | Local Account | Persistence |
|
||||
| T1071.002 | File Transfer Protocols | Command and Control |
|
||||
| T1021.002 | SMB/Windows Admin Shares | Lateral Movement |
|
||||
| T1569.002 | Service Execution | Execution |
|
||||
| T1059.001 | PowerShell | Execution |
|
||||
| T1059.003 | Windows Command Shell | Execution |
|
||||
| T1562.004 | Disable or Modify System Firewall | Defense Evasion |
|
||||
@@ -4674,8 +4765,14 @@ Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA
|
||||
|
||||
* Command and Control
|
||||
|
||||
* Execution
|
||||
|
||||
* Exploitation
|
||||
|
||||
* Installation
|
||||
|
||||
* Lateral Movement
|
||||
|
||||
|
||||
#### Reference
|
||||
|
||||
@@ -4692,7 +4789,7 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
- **Datamodel**: Endpoint
|
||||
- **ATT&CK**: [T1003.001](https://attack.mitre.org/techniques/T1003.001/), [T1003.002](https://attack.mitre.org/techniques/T1003.002/), [T1020](https://attack.mitre.org/techniques/T1020/), [T1021.002](https://attack.mitre.org/techniques/T1021.002/), [T1055](https://attack.mitre.org/techniques/T1055/), [T1105](https://attack.mitre.org/techniques/T1105/), [T1197](https://attack.mitre.org/techniques/T1197/), [T1218.003](https://attack.mitre.org/techniques/T1218.003/), [T1486](https://attack.mitre.org/techniques/T1486/), [T1490](https://attack.mitre.org/techniques/T1490/), [T1548.002](https://attack.mitre.org/techniques/T1548.002/)
|
||||
- **ATT&CK**: [T1003.001](https://attack.mitre.org/techniques/T1003.001/), [T1003.002](https://attack.mitre.org/techniques/T1003.002/), [T1020](https://attack.mitre.org/techniques/T1020/), [T1021.002](https://attack.mitre.org/techniques/T1021.002/), [T1055](https://attack.mitre.org/techniques/T1055/), [T1105](https://attack.mitre.org/techniques/T1105/), [T1197](https://attack.mitre.org/techniques/T1197/), [T1218.003](https://attack.mitre.org/techniques/T1218.003/), [T1486](https://attack.mitre.org/techniques/T1486/), [T1490](https://attack.mitre.org/techniques/T1490/), [T1548.002](https://attack.mitre.org/techniques/T1548.002/), [T1569.002](https://attack.mitre.org/techniques/T1569.002/)
|
||||
- **Last Updated**: 2021-05-12
|
||||
|
||||
<details>
|
||||
@@ -4720,6 +4817,8 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* [Detect RClone Command-Line Usage](detections.md#detect-rclone-command-line-usage)
|
||||
|
||||
* [Detect Renamed PSExec](detections.md#detect-renamed-psexec)
|
||||
|
||||
* [Detect Renamed RClone](detections.md#detect-renamed-rclone)
|
||||
|
||||
* [Extract SAM from Registry](detections.md#extract-sam-from-registry)
|
||||
@@ -4744,6 +4843,7 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
| T1003.001 | LSASS Memory | Credential Access |
|
||||
| T1021.002 | SMB/Windows Admin Shares | Lateral Movement |
|
||||
| T1020 | Automated Exfiltration | Exfiltration |
|
||||
| T1569.002 | Service Execution | Execution |
|
||||
| T1486 | Data Encrypted for Impact | Impact |
|
||||
| T1548.002 | Bypass User Account Control | Defense Evasion, Privilege Escalation |
|
||||
|
||||
@@ -4751,10 +4851,14 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* Actions on Objectives
|
||||
|
||||
* Execution
|
||||
|
||||
* Exfiltration
|
||||
|
||||
* Exploitation
|
||||
|
||||
* Lateral Movement
|
||||
|
||||
* Obfuscation
|
||||
|
||||
|
||||
@@ -5019,7 +5123,7 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
- **Datamodel**: Endpoint, Network_Traffic
|
||||
- **ATT&CK**: [T1020](https://attack.mitre.org/techniques/T1020/), [T1021.002](https://attack.mitre.org/techniques/T1021.002/), [T1036.003](https://attack.mitre.org/techniques/T1036.003/), [T1047](https://attack.mitre.org/techniques/T1047/), [T1048](https://attack.mitre.org/techniques/T1048/), [T1053.005](https://attack.mitre.org/techniques/T1053.005/), [T1070](https://attack.mitre.org/techniques/T1070/), [T1070.001](https://attack.mitre.org/techniques/T1070.001/), [T1071.001](https://attack.mitre.org/techniques/T1071.001/), [T1218.003](https://attack.mitre.org/techniques/T1218.003/), [T1485](https://attack.mitre.org/techniques/T1485/), [T1490](https://attack.mitre.org/techniques/T1490/), [T1547.001](https://attack.mitre.org/techniques/T1547.001/)
|
||||
- **ATT&CK**: [T1020](https://attack.mitre.org/techniques/T1020/), [T1021.002](https://attack.mitre.org/techniques/T1021.002/), [T1036.003](https://attack.mitre.org/techniques/T1036.003/), [T1047](https://attack.mitre.org/techniques/T1047/), [T1048](https://attack.mitre.org/techniques/T1048/), [T1053.005](https://attack.mitre.org/techniques/T1053.005/), [T1069.001](https://attack.mitre.org/techniques/T1069.001/), [T1069.002](https://attack.mitre.org/techniques/T1069.002/), [T1070](https://attack.mitre.org/techniques/T1070/), [T1070.001](https://attack.mitre.org/techniques/T1070.001/), [T1071.001](https://attack.mitre.org/techniques/T1071.001/), [T1087.001](https://attack.mitre.org/techniques/T1087.001/), [T1087.002](https://attack.mitre.org/techniques/T1087.002/), [T1112](https://attack.mitre.org/techniques/T1112/), [T1204](https://attack.mitre.org/techniques/T1204/), [T1218.003](https://attack.mitre.org/techniques/T1218.003/), [T1482](https://attack.mitre.org/techniques/T1482/), [T1485](https://attack.mitre.org/techniques/T1485/), [T1490](https://attack.mitre.org/techniques/T1490/), [T1491](https://attack.mitre.org/techniques/T1491/), [T1547.001](https://attack.mitre.org/techniques/T1547.001/)
|
||||
- **Last Updated**: 2020-02-04
|
||||
|
||||
<details>
|
||||
@@ -5035,18 +5139,36 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* [Common Ransomware Notes](detections.md#common-ransomware-notes)
|
||||
|
||||
* [Conti Common Exec parameter](detections.md#conti-common-exec-parameter)
|
||||
|
||||
* [Delete ShadowCopy With PowerShell](detections.md#delete-shadowcopy-with-powershell)
|
||||
|
||||
* [Deleting Shadow Copies](detections.md#deleting-shadow-copies)
|
||||
|
||||
* [Detect RClone Command-Line Usage](detections.md#detect-rclone-command-line-usage)
|
||||
|
||||
* [Detect Renamed RClone](detections.md#detect-renamed-rclone)
|
||||
|
||||
* [Detect SharpHound Command-Line Arguments](detections.md#detect-sharphound-command-line-arguments)
|
||||
|
||||
* [Detect SharpHound File Modifications](detections.md#detect-sharphound-file-modifications)
|
||||
|
||||
* [Detect SharpHound Usage](detections.md#detect-sharphound-usage)
|
||||
|
||||
* [Known Services Killed by Ransomware](detections.md#known-services-killed-by-ransomware)
|
||||
|
||||
* [Modification Of Wallpaper](detections.md#modification-of-wallpaper)
|
||||
|
||||
* [Prohibited Network Traffic Allowed](detections.md#prohibited-network-traffic-allowed)
|
||||
|
||||
* [Registry Keys Used For Persistence](detections.md#registry-keys-used-for-persistence)
|
||||
|
||||
* [Remote Process Instantiation via WMI](detections.md#remote-process-instantiation-via-wmi)
|
||||
|
||||
* [Revil Common Exec Parameter](detections.md#revil-common-exec-parameter)
|
||||
|
||||
* [Revil Registry Entry](detections.md#revil-registry-entry)
|
||||
|
||||
* [SMB Traffic Spike](detections.md#smb-traffic-spike)
|
||||
|
||||
* [SMB Traffic Spike - MLTK](detections.md#smb-traffic-spike---mltk)
|
||||
@@ -5073,6 +5195,8 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* [WBAdmin Delete System Backups](detections.md#wbadmin-delete-system-backups)
|
||||
|
||||
* [Wbemprox COM Object Execution](detections.md#wbemprox-com-object-execution)
|
||||
|
||||
* [WinEvent Scheduled Task Created Within Public Path](detections.md#winevent-scheduled-task-created-within-public-path)
|
||||
|
||||
* [WinEvent Scheduled Task Created to Spawn Shell](detections.md#winevent-scheduled-task-created-to-spawn-shell)
|
||||
@@ -5087,12 +5211,19 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
| T1490 | Inhibit System Recovery | Impact |
|
||||
| T1218.003 | CMSTP | Defense Evasion |
|
||||
| T1485 | Data Destruction | Impact |
|
||||
| T1204 | User Execution | Execution |
|
||||
| T1020 | Automated Exfiltration | Exfiltration |
|
||||
| T1087.002 | Domain Account | Discovery |
|
||||
| T1087.001 | Local Account | Discovery |
|
||||
| T1482 | Domain Trust Discovery | Discovery |
|
||||
| T1069.002 | Domain Groups | Discovery |
|
||||
| T1069.001 | Local Groups | Discovery |
|
||||
| T1491 | Defacement | Impact |
|
||||
| T1048 | Exfiltration Over Alternative Protocol | Exfiltration |
|
||||
| T1547.001 | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation |
|
||||
| T1021.001 | Remote Desktop Protocol | Lateral Movement |
|
||||
| T1047 | Windows Management Instrumentation | Execution |
|
||||
| T1112 | Modify Registry | Defense Evasion |
|
||||
| T1486 | Data Encrypted for Impact | Impact |
|
||||
| T1059.003 | Windows Command Shell | Execution |
|
||||
| T1021.002 | SMB/Windows Admin Shares | Lateral Movement |
|
||||
@@ -5118,6 +5249,8 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* Privilege Escalation
|
||||
|
||||
* Reconnaissance
|
||||
|
||||
|
||||
#### Reference
|
||||
|
||||
@@ -5167,6 +5300,57 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
* https://www.youtube.com/watch?v=PgzNib37g0M
|
||||
|
||||
|
||||
_version_: 1
|
||||
</details>
|
||||
|
||||
---
|
||||
|
||||
### Revil Ransomware
|
||||
Leverage searches that allow you to detect and investigate unusual activities that might relate to the Revil ransomware, including looking for file writes associated with Revil, encrypting network shares, deleting shadow volume storage, registry key modification, deleting of security logs, and more.
|
||||
|
||||
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
- **Datamodel**: Endpoint
|
||||
- **ATT&CK**: [T1112](https://attack.mitre.org/techniques/T1112/), [T1204](https://attack.mitre.org/techniques/T1204/), [T1218.003](https://attack.mitre.org/techniques/T1218.003/), [T1490](https://attack.mitre.org/techniques/T1490/), [T1491](https://attack.mitre.org/techniques/T1491/)
|
||||
- **Last Updated**: 2021-06-04
|
||||
|
||||
<details>
|
||||
<summary>details</summary>
|
||||
|
||||
#### Detection Profile
|
||||
|
||||
* [Delete ShadowCopy With PowerShell](detections.md#delete-shadowcopy-with-powershell)
|
||||
|
||||
* [Modification Of Wallpaper](detections.md#modification-of-wallpaper)
|
||||
|
||||
* [Revil Common Exec Parameter](detections.md#revil-common-exec-parameter)
|
||||
|
||||
* [Revil Registry Entry](detections.md#revil-registry-entry)
|
||||
|
||||
* [Wbemprox COM Object Execution](detections.md#wbemprox-com-object-execution)
|
||||
|
||||
|
||||
#### ATT&CK
|
||||
|
||||
| ID | Technique | Tactic |
|
||||
| ----------- | ----------- |--------------|
|
||||
| T1490 | Inhibit System Recovery | Impact |
|
||||
| T1491 | Defacement | Impact |
|
||||
| T1204 | User Execution | Execution |
|
||||
| T1112 | Modify Registry | Defense Evasion |
|
||||
| T1218.003 | CMSTP | Defense Evasion |
|
||||
|
||||
#### Kill Chain Phase
|
||||
|
||||
* Exploitation
|
||||
|
||||
|
||||
#### Reference
|
||||
|
||||
* https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/
|
||||
|
||||
* https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/
|
||||
|
||||
|
||||
_version_: 1
|
||||
</details>
|
||||
|
||||
@@ -5225,12 +5409,19 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
| T1490 | Inhibit System Recovery | Impact |
|
||||
| T1218.003 | CMSTP | Defense Evasion |
|
||||
| T1485 | Data Destruction | Impact |
|
||||
| T1204 | User Execution | Execution |
|
||||
| T1020 | Automated Exfiltration | Exfiltration |
|
||||
| T1087.002 | Domain Account | Discovery |
|
||||
| T1087.001 | Local Account | Discovery |
|
||||
| T1482 | Domain Trust Discovery | Discovery |
|
||||
| T1069.002 | Domain Groups | Discovery |
|
||||
| T1069.001 | Local Groups | Discovery |
|
||||
| T1491 | Defacement | Impact |
|
||||
| T1048 | Exfiltration Over Alternative Protocol | Exfiltration |
|
||||
| T1547.001 | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation |
|
||||
| T1021.001 | Remote Desktop Protocol | Lateral Movement |
|
||||
| T1047 | Windows Management Instrumentation | Execution |
|
||||
| T1112 | Modify Registry | Defense Evasion |
|
||||
| T1486 | Data Encrypted for Impact | Impact |
|
||||
| T1059.003 | Windows Command Shell | Execution |
|
||||
| T1021.002 | SMB/Windows Admin Shares | Lateral Movement |
|
||||
@@ -5276,7 +5467,7 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
- **Datamodel**: Endpoint, Network_Traffic, Web
|
||||
- **ATT&CK**: [T1021.001](https://attack.mitre.org/techniques/T1021.001/), [T1021.002](https://attack.mitre.org/techniques/T1021.002/), [T1082](https://attack.mitre.org/techniques/T1082/), [T1204.002](https://attack.mitre.org/techniques/T1204.002/), [T1485](https://attack.mitre.org/techniques/T1485/), [T1486](https://attack.mitre.org/techniques/T1486/), [T1490](https://attack.mitre.org/techniques/T1490/)
|
||||
- **ATT&CK**: [T1021.001](https://attack.mitre.org/techniques/T1021.001/), [T1021.002](https://attack.mitre.org/techniques/T1021.002/), [T1082](https://attack.mitre.org/techniques/T1082/), [T1204.002](https://attack.mitre.org/techniques/T1204.002/), [T1485](https://attack.mitre.org/techniques/T1485/), [T1486](https://attack.mitre.org/techniques/T1486/), [T1490](https://attack.mitre.org/techniques/T1490/), [T1569.002](https://attack.mitre.org/techniques/T1569.002/)
|
||||
- **Last Updated**: 2018-12-13
|
||||
|
||||
<details>
|
||||
@@ -5294,6 +5485,8 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* [Detect PsExec With accepteula Flag](detections.md#detect-psexec-with-accepteula-flag)
|
||||
|
||||
* [Detect Renamed PSExec](detections.md#detect-renamed-psexec)
|
||||
|
||||
* [Detect attackers scanning for vulnerable JBoss servers](detections.md#detect-attackers-scanning-for-vulnerable-jboss-servers)
|
||||
|
||||
* [Detect malicious requests to exploit JBoss servers](detections.md#detect-malicious-requests-to-exploit-jboss-servers)
|
||||
@@ -5319,6 +5512,7 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
| T1485 | Data Destruction | Impact |
|
||||
| T1490 | Inhibit System Recovery | Impact |
|
||||
| T1021.002 | SMB/Windows Admin Shares | Lateral Movement |
|
||||
| T1569.002 | Service Execution | Execution |
|
||||
| T1082 | System Information Discovery | Discovery |
|
||||
| T1021.001 | Remote Desktop Protocol | Lateral Movement |
|
||||
| T1486 | Data Encrypted for Impact | Impact |
|
||||
@@ -5331,8 +5525,14 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* Delivery
|
||||
|
||||
* Execution
|
||||
|
||||
* Exploitation
|
||||
|
||||
* Installation
|
||||
|
||||
* Lateral Movement
|
||||
|
||||
* Reconnaissance
|
||||
|
||||
|
||||
|
||||
+338
-44
@@ -102,7 +102,7 @@ Fortify your data-protection arsenal--while continuing to ensure data confidenti
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''': Change_Analysis, Network_Resolution
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1189/ T1189], [https://attack.mitre.org/techniques/T1048.003/ T1048.003], [https://attack.mitre.org/techniques/T1048/ T1048], [https://attack.mitre.org/techniques/T1071.001/ T1071.001]
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1189/ T1189], [https://attack.mitre.org/techniques/T1048.003/ T1048.003]
|
||||
* '''Last Updated''': 2017-09-14
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
@@ -131,14 +131,6 @@ Fortify your data-protection arsenal--while continuing to ensure data confidenti
|
||||
| T1048.003
|
||||
| Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
|
||||
| Exfiltration
|
||||
|-
|
||||
| T1048
|
||||
| Exfiltration Over Alternative Protocol
|
||||
| Exfiltration
|
||||
|-
|
||||
| T1071.001
|
||||
| Web Protocols
|
||||
| Command and Control
|
||||
|}
|
||||
|
||||
|
||||
@@ -518,7 +510,7 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''': Endpoint
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560.001/ T1560.001], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1071.002/ T1071.002], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1218.010/ T1218.010], [https://attack.mitre.org/techniques/T1218.005/ T1218.005], [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1027/ T1027], [https://attack.mitre.org/techniques/T1218.011/ T1218.011], [https://attack.mitre.org/techniques/T1543.003/ T1543.003], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1203/ T1203], [https://attack.mitre.org/techniques/T1505.003/ T1505.003], [https://attack.mitre.org/techniques/T1127.001/ T1127.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1071.001/ T1071.001], [https://attack.mitre.org/techniques/T1018/ T1018]
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560.001/ T1560.001], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1543.003/ T1543.003], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1071.002/ T1071.002], [https://attack.mitre.org/techniques/T1218.010/ T1218.010], [https://attack.mitre.org/techniques/T1218.005/ T1218.005], [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1027/ T1027], [https://attack.mitre.org/techniques/T1218.011/ T1218.011], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1203/ T1203], [https://attack.mitre.org/techniques/T1505.003/ T1505.003], [https://attack.mitre.org/techniques/T1127.001/ T1127.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1071.001/ T1071.001], [https://attack.mitre.org/techniques/T1018/ T1018]
|
||||
* '''Last Updated''': 2021-02-16
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
@@ -528,6 +520,8 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Anomalous_usage_of_7zip|Anomalous usage of 7zip]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Cmd_echo_pipe_-_escalation|CMD Echo Pipe - Escalation]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Cobalt_strike_named_pipes|Cobalt Strike Named Pipes]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Dllhost_with_no_command_line_arguments_with_network|DLLHost with no Command Line Arguments with Network]]
|
||||
@@ -570,6 +564,14 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
|
||||
| Archive via Utility
|
||||
| Collection
|
||||
|-
|
||||
| T1059.003
|
||||
| Windows Command Shell
|
||||
| Execution
|
||||
|-
|
||||
| T1543.003
|
||||
| Windows Service
|
||||
| Persistence, Privilege Escalation
|
||||
|-
|
||||
| T1055
|
||||
| Process Injection
|
||||
| Defense Evasion, Privilege Escalation
|
||||
@@ -578,10 +580,6 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
|
||||
| File Transfer Protocols
|
||||
| Command and Control
|
||||
|-
|
||||
| T1059.003
|
||||
| Windows Command Shell
|
||||
| Execution
|
||||
|-
|
||||
| T1218.010
|
||||
| Regsvr32
|
||||
| Defense Evasion
|
||||
@@ -602,10 +600,6 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us
|
||||
| Rundll32
|
||||
| Defense Evasion
|
||||
|-
|
||||
| T1543.003
|
||||
| Windows Service
|
||||
| Persistence, Privilege Escalation
|
||||
|-
|
||||
| T1053.005
|
||||
| Scheduled Task
|
||||
| Execution, Persistence, Privilege Escalation
|
||||
@@ -683,7 +677,7 @@ Monitor for and investigate activities--such as suspicious writes to the Windows
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''': Endpoint, Network_Traffic
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1114.001/ T1114.001], [https://attack.mitre.org/techniques/T1114.002/ T1114.002], [https://attack.mitre.org/techniques/T1036/ T1036]
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560.001/ T1560.001], [https://attack.mitre.org/techniques/T1114.001/ T1114.001], [https://attack.mitre.org/techniques/T1114.002/ T1114.002], [https://attack.mitre.org/techniques/T1036/ T1036]
|
||||
* '''Last Updated''': 2020-02-03
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
@@ -691,6 +685,10 @@ Monitor for and investigate activities--such as suspicious writes to the Windows
|
||||
|
||||
====Detection Profile====
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_renamed_7-zip|Detect Renamed 7-Zip]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_renamed_winrar|Detect Renamed WinRAR]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Email_files_written_outside_of_the_outlook_directory|Email files written outside of the Outlook directory]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Email_servers_sending_high_volume_traffic_to_hosts|Email servers sending high volume traffic to hosts]]
|
||||
@@ -709,6 +707,10 @@ Monitor for and investigate activities--such as suspicious writes to the Windows
|
||||
! Technique
|
||||
! Tactic
|
||||
|-
|
||||
| T1560.001
|
||||
| Archive via Utility
|
||||
| Collection
|
||||
|-
|
||||
| T1114.001
|
||||
| Local Email Collection
|
||||
| Collection
|
||||
@@ -727,6 +729,10 @@ Monitor for and investigate activities--such as suspicious writes to the Windows
|
||||
|
||||
* Actions on Objectives
|
||||
|
||||
* Exfiltration
|
||||
|
||||
* Exploitation
|
||||
|
||||
|
||||
====Reference====
|
||||
|
||||
@@ -972,6 +978,8 @@ Uncover activity consistent with credential dumping, a technique wherein attacke
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Ntdsutil_export_ntds|Ntdsutil Export NTDS]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Secretdumps_offline_ntds_dumping_tool|SecretDumps Offline NTDS Dumping Tool]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Set_default_powershell_execution_policy_to_unrestricted_or_bypass|Set Default PowerShell Execution Policy To Unrestricted or Bypass]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Unsigned_image_loaded_by_lsass|Unsigned Image Loaded by LSASS]]
|
||||
@@ -1175,8 +1183,8 @@ Secure your environment against DNS hijacks with searches that help you detect a
|
||||
The stealing of data by an adversary.
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''':
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1041/ T1041], [https://attack.mitre.org/techniques/T1114/ T1114], [https://attack.mitre.org/techniques/T1114.003/ T1114.003]
|
||||
* '''Datamodel''': Endpoint
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1041/ T1041], [https://attack.mitre.org/techniques/T1114.001/ T1114.001], [https://attack.mitre.org/techniques/T1114/ T1114], [https://attack.mitre.org/techniques/T1114.003/ T1114.003]
|
||||
* '''Last Updated''': 2020-10-21
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
@@ -1186,6 +1194,8 @@ The stealing of data by an adversary.
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_snicat_sni_exfiltration|Detect SNICat SNI Exfiltration]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Mailsniper_invoke_functions|Mailsniper Invoke functions]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#O365_pst_export_alert|O365 PST export alert]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#O365_suspicious_admin_email_forwarding|O365 Suspicious Admin Email Forwarding]]
|
||||
@@ -1204,6 +1214,10 @@ The stealing of data by an adversary.
|
||||
| Exfiltration Over C2 Channel
|
||||
| Exfiltration
|
||||
|-
|
||||
| T1114.001
|
||||
| Local Email Collection
|
||||
| Collection
|
||||
|-
|
||||
| T1114
|
||||
| Email Collection
|
||||
| Collection
|
||||
@@ -1220,6 +1234,8 @@ The stealing of data by an adversary.
|
||||
|
||||
* Actions on Objectives
|
||||
|
||||
* Exploitation
|
||||
|
||||
|
||||
====Reference====
|
||||
|
||||
@@ -1528,7 +1544,7 @@ HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVE
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''': Endpoint, Network_Traffic
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1505.003/ T1505.003], [https://attack.mitre.org/techniques/T1136.001/ T1136.001], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1003.001/ T1003.001], [https://attack.mitre.org/techniques/T1114.002/ T1114.002], [https://attack.mitre.org/techniques/T1003.003/ T1003.003], [https://attack.mitre.org/techniques/T1190/ T1190]
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1505.003/ T1505.003], [https://attack.mitre.org/techniques/T1136.001/ T1136.001], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1003.001/ T1003.001], [https://attack.mitre.org/techniques/T1114.002/ T1114.002], [https://attack.mitre.org/techniques/T1003.003/ T1003.003], [https://attack.mitre.org/techniques/T1190/ T1190]
|
||||
* '''Last Updated''': 2021-03-03
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
@@ -1544,6 +1560,8 @@ HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVE
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_comsvcs_dll|Dump LSASS via comsvcs DLL]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_procdump|Dump LSASS via procdump]]
|
||||
@@ -1590,6 +1608,10 @@ HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVE
|
||||
| SMB/Windows Admin Shares
|
||||
| Lateral Movement
|
||||
|-
|
||||
| T1569.002
|
||||
| Service Execution
|
||||
| Execution
|
||||
|-
|
||||
| T1003.001
|
||||
| LSASS Memory
|
||||
| Credential Access
|
||||
@@ -1614,10 +1636,14 @@ HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVE
|
||||
|
||||
* Command and Control
|
||||
|
||||
* Execution
|
||||
|
||||
* Exploitation
|
||||
|
||||
* Installation
|
||||
|
||||
* Lateral Movement
|
||||
|
||||
|
||||
====Reference====
|
||||
|
||||
@@ -1754,7 +1780,7 @@ Detect and investigate tactics, techniques, and procedures around how attackers
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''': Endpoint, Network_Traffic
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550.002/ T1550.002], [https://attack.mitre.org/techniques/T1558.003/ T1558.003], [https://attack.mitre.org/techniques/T1021.001/ T1021.001], [https://attack.mitre.org/techniques/T1053.005/ T1053.005]
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1550.002/ T1550.002], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1558.003/ T1558.003], [https://attack.mitre.org/techniques/T1021.001/ T1021.001], [https://attack.mitre.org/techniques/T1053.005/ T1053.005]
|
||||
* '''Last Updated''': 2020-02-04
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
@@ -1766,6 +1792,10 @@ Detect and investigate tactics, techniques, and procedures around how attackers
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_pass_the_hash|Detect Pass the Hash]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Kerberoasting_spn_request_with_rc4_encryption|Kerberoasting spn request with RC4 encryption]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Remote_desktop_network_traffic|Remote Desktop Network Traffic]]
|
||||
@@ -1786,6 +1816,14 @@ Detect and investigate tactics, techniques, and procedures around how attackers
|
||||
| Pass the Hash
|
||||
| Defense Evasion, Lateral Movement
|
||||
|-
|
||||
| T1021.002
|
||||
| SMB/Windows Admin Shares
|
||||
| Lateral Movement
|
||||
|-
|
||||
| T1569.002
|
||||
| Service Execution
|
||||
| Execution
|
||||
|-
|
||||
| T1558.003
|
||||
| Kerberoasting
|
||||
| Credential Access
|
||||
@@ -1804,6 +1842,12 @@ Detect and investigate tactics, techniques, and procedures around how attackers
|
||||
|
||||
* Actions on Objectives
|
||||
|
||||
* Execution
|
||||
|
||||
* Exploitation
|
||||
|
||||
* Lateral Movement
|
||||
|
||||
|
||||
====Reference====
|
||||
|
||||
@@ -2026,6 +2070,55 @@ Adversaries may rename legitimate system utilities to try to evade security mech
|
||||
* https://attack.mitre.org/techniques/T1036/003/
|
||||
|
||||
|
||||
''version'': 1
|
||||
</div>
|
||||
</div>
|
||||
|
||||
----
|
||||
|
||||
===Meterpreter===
|
||||
Meterpreter provides red teams, pen testers and threat actors interactive access to a compromised host to run commands, upload payloads, download files, and other actions.
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''': Endpoint
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1033/ T1033]
|
||||
* '''Last Updated''': 2021-06-08
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
<div class="mw-collapsible-content">
|
||||
|
||||
====Detection Profile====
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Excessive_number_of_taskhost_processes|Excessive number of taskhost processes]]
|
||||
|
||||
|
||||
|
||||
====ATT&CK====
|
||||
{|
|
||||
! style="text-align:left;"| ID
|
||||
! Technique
|
||||
! Tactic
|
||||
|-
|
||||
| T1033
|
||||
| System Owner/User Discovery
|
||||
| Discovery
|
||||
|}
|
||||
|
||||
|
||||
====Kill Chain Phase====
|
||||
|
||||
* Exploitation
|
||||
|
||||
|
||||
====Reference====
|
||||
|
||||
* https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/
|
||||
|
||||
* https://doubleoctopus.com/security-wiki/threats-and-tools/meterpreter/
|
||||
|
||||
* https://www.rapid7.com/products/metasploit/
|
||||
|
||||
|
||||
''version'': 1
|
||||
</div>
|
||||
</div>
|
||||
@@ -2037,7 +2130,7 @@ Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and managemen
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''': Endpoint, Network_Traffic, Web
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560.001/ T1560.001], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1071.002/ T1071.002], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1218.010/ T1218.010], [https://attack.mitre.org/techniques/T1218.005/ T1218.005], [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1027/ T1027], [https://attack.mitre.org/techniques/T1218.011/ T1218.011], [https://attack.mitre.org/techniques/T1543.003/ T1543.003], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1203/ T1203], [https://attack.mitre.org/techniques/T1505.003/ T1505.003], [https://attack.mitre.org/techniques/T1127.001/ T1127.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1071.001/ T1071.001], [https://attack.mitre.org/techniques/T1018/ T1018]
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1560.001/ T1560.001], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1543.003/ T1543.003], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1071.002/ T1071.002], [https://attack.mitre.org/techniques/T1218.010/ T1218.010], [https://attack.mitre.org/techniques/T1218.005/ T1218.005], [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1027/ T1027], [https://attack.mitre.org/techniques/T1218.011/ T1218.011], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1203/ T1203], [https://attack.mitre.org/techniques/T1505.003/ T1505.003], [https://attack.mitre.org/techniques/T1127.001/ T1127.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1071.001/ T1071.001], [https://attack.mitre.org/techniques/T1018/ T1018]
|
||||
* '''Last Updated''': 2020-12-14
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
@@ -2083,6 +2176,14 @@ Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and managemen
|
||||
| Archive via Utility
|
||||
| Collection
|
||||
|-
|
||||
| T1059.003
|
||||
| Windows Command Shell
|
||||
| Execution
|
||||
|-
|
||||
| T1543.003
|
||||
| Windows Service
|
||||
| Persistence, Privilege Escalation
|
||||
|-
|
||||
| T1055
|
||||
| Process Injection
|
||||
| Defense Evasion, Privilege Escalation
|
||||
@@ -2091,10 +2192,6 @@ Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and managemen
|
||||
| File Transfer Protocols
|
||||
| Command and Control
|
||||
|-
|
||||
| T1059.003
|
||||
| Windows Command Shell
|
||||
| Execution
|
||||
|-
|
||||
| T1218.010
|
||||
| Regsvr32
|
||||
| Defense Evasion
|
||||
@@ -2115,10 +2212,6 @@ Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and managemen
|
||||
| Rundll32
|
||||
| Defense Evasion
|
||||
|-
|
||||
| T1543.003
|
||||
| Windows Service
|
||||
| Persistence, Privilege Escalation
|
||||
|-
|
||||
| T1053.005
|
||||
| Scheduled Task
|
||||
| Execution, Persistence, Privilege Escalation
|
||||
@@ -3540,7 +3633,7 @@ Detect tactics used by malware to evade defenses on Windows endpoints. A few of
|
||||
===Windows discovery techniques===
|
||||
Monitors for behaviors associated with adversaries discovering objects in the environment that can be leveraged in the progression of the attack.
|
||||
|
||||
* '''Product''': Splunk Behavioral Analytics
|
||||
* '''Product''': Splunk Behavioral Analytics, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''':
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1484/ T1484], [https://attack.mitre.org/techniques/T1199/ T1199], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1590/ T1590], [https://attack.mitre.org/techniques/T1591/ T1591], [https://attack.mitre.org/techniques/T1595/ T1595], [https://attack.mitre.org/techniques/T1592/ T1592], [https://attack.mitre.org/techniques/T1007/ T1007], [https://attack.mitre.org/techniques/T1012/ T1012], [https://attack.mitre.org/techniques/T1046/ T1046], [https://attack.mitre.org/techniques/T1047/ T1047], [https://attack.mitre.org/techniques/T1057/ T1057], [https://attack.mitre.org/techniques/T1083/ T1083], [https://attack.mitre.org/techniques/T1518/ T1518], [https://attack.mitre.org/techniques/T1592.002/ T1592.002], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1135/ T1135], [https://attack.mitre.org/techniques/T1039/ T1039], [https://attack.mitre.org/techniques/T1053/ T1053], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1547/ T1547], [https://attack.mitre.org/techniques/T1574/ T1574], [https://attack.mitre.org/techniques/T1589.001/ T1589.001], [https://attack.mitre.org/techniques/T1590.001/ T1590.001], [https://attack.mitre.org/techniques/T1590.003/ T1590.003], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1595.002/ T1595.002], [https://attack.mitre.org/techniques/T1055/ T1055]
|
||||
* '''Last Updated''': 2021-03-04
|
||||
@@ -3725,6 +3818,8 @@ Monitors for behaviors associated with adversaries discovering objects in the en
|
||||
|
||||
* https://cyberd.us/penetration-testing
|
||||
|
||||
* https://attack.mitre.org/software/S0521/
|
||||
|
||||
|
||||
''version'': 1
|
||||
</div>
|
||||
@@ -4210,8 +4305,8 @@ Monitor your enterprise to ensure that your endpoints are being patched and upda
|
||||
Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers.
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''': Network_Resolution, Network_Traffic
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1189/ T1189], [https://attack.mitre.org/techniques/T1048.003/ T1048.003], [https://attack.mitre.org/techniques/T1048/ T1048], [https://attack.mitre.org/techniques/T1071.001/ T1071.001]
|
||||
* '''Datamodel''': Endpoint, Network_Resolution, Network_Traffic
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1021.001/ T1021.001], [https://attack.mitre.org/techniques/T1189/ T1189], [https://attack.mitre.org/techniques/T1021/ T1021], [https://attack.mitre.org/techniques/T1048/ T1048], [https://attack.mitre.org/techniques/T1048.003/ T1048.003], [https://attack.mitre.org/techniques/T1071.001/ T1071.001]
|
||||
* '''Last Updated''': 2017-09-11
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
@@ -4219,8 +4314,14 @@ Detect instances of prohibited network traffic allowed in the environment, as we
|
||||
|
||||
====Detection Profile====
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Allow_inbound_traffic_by_firewall_rule_registry|Allow Inbound Traffic By Firewall Rule Registry]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Allow_inbound_traffic_in_firewall_rule|Allow Inbound Traffic In Firewall Rule]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_hosts_connecting_to_dynamic_domain_providers|Detect hosts connecting to dynamic domain providers]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Enable_rdp_in_other_port_number|Enable RDP In Other Port Number]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Prohibited_network_traffic_allowed|Prohibited Network Traffic Allowed]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Protocol_or_port_mismatch|Protocol or Port Mismatch]]
|
||||
@@ -4235,18 +4336,26 @@ Detect instances of prohibited network traffic allowed in the environment, as we
|
||||
! Technique
|
||||
! Tactic
|
||||
|-
|
||||
| T1021.001
|
||||
| Remote Desktop Protocol
|
||||
| Lateral Movement
|
||||
|-
|
||||
| T1189
|
||||
| Drive-by Compromise
|
||||
| Initial Access
|
||||
|-
|
||||
| T1048.003
|
||||
| Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
|
||||
| Exfiltration
|
||||
| T1021
|
||||
| Remote Services
|
||||
| Lateral Movement
|
||||
|-
|
||||
| T1048
|
||||
| Exfiltration Over Alternative Protocol
|
||||
| Exfiltration
|
||||
|-
|
||||
| T1048.003
|
||||
| Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
|
||||
| Exfiltration
|
||||
|-
|
||||
| T1071.001
|
||||
| Web Protocols
|
||||
| Command and Control
|
||||
@@ -4261,6 +4370,8 @@ Detect instances of prohibited network traffic allowed in the environment, as we
|
||||
|
||||
* Delivery
|
||||
|
||||
* Exploitation
|
||||
|
||||
|
||||
====Reference====
|
||||
|
||||
@@ -5977,7 +6088,7 @@ Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''': Endpoint, Network_Traffic
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136.001/ T1136.001], [https://attack.mitre.org/techniques/T1071.002/ T1071.002], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1562.004/ T1562.004], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1543.003/ T1543.003], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1204.002/ T1204.002], [https://attack.mitre.org/techniques/T1112/ T1112]
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136.001/ T1136.001], [https://attack.mitre.org/techniques/T1071.002/ T1071.002], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1562.004/ T1562.004], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1543.003/ T1543.003], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1204.002/ T1204.002], [https://attack.mitre.org/techniques/T1112/ T1112]
|
||||
* '''Last Updated''': 2020-01-22
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
@@ -5993,6 +6104,8 @@ Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#First_time_seen_command_line_argument|First time seen command line argument]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_execution_policy_bypass|Malicious PowerShell Process - Execution Policy Bypass]]
|
||||
@@ -6033,6 +6146,10 @@ Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA
|
||||
| SMB/Windows Admin Shares
|
||||
| Lateral Movement
|
||||
|-
|
||||
| T1569.002
|
||||
| Service Execution
|
||||
| Execution
|
||||
|-
|
||||
| T1059.001
|
||||
| PowerShell
|
||||
| Execution
|
||||
@@ -6073,8 +6190,14 @@ Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA
|
||||
|
||||
* Command and Control
|
||||
|
||||
* Execution
|
||||
|
||||
* Exploitation
|
||||
|
||||
* Installation
|
||||
|
||||
* Lateral Movement
|
||||
|
||||
|
||||
====Reference====
|
||||
|
||||
@@ -6092,7 +6215,7 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''': Endpoint
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.002/ T1003.002], [https://attack.mitre.org/techniques/T1197/ T1197], [https://attack.mitre.org/techniques/T1105/ T1105], [https://attack.mitre.org/techniques/T1218.003/ T1218.003], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1003.001/ T1003.001], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1020/ T1020], [https://attack.mitre.org/techniques/T1486/ T1486], [https://attack.mitre.org/techniques/T1548.002/ T1548.002]
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.002/ T1003.002], [https://attack.mitre.org/techniques/T1197/ T1197], [https://attack.mitre.org/techniques/T1105/ T1105], [https://attack.mitre.org/techniques/T1218.003/ T1218.003], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1003.001/ T1003.001], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1020/ T1020], [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1486/ T1486], [https://attack.mitre.org/techniques/T1548.002/ T1548.002]
|
||||
* '''Last Updated''': 2021-05-12
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
@@ -6120,6 +6243,8 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_rclone_command-line_usage|Detect RClone Command-Line Usage]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_renamed_rclone|Detect Renamed RClone]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Extract_sam_from_registry|Extract SAM from Registry]]
|
||||
@@ -6174,6 +6299,10 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
| Automated Exfiltration
|
||||
| Exfiltration
|
||||
|-
|
||||
| T1569.002
|
||||
| Service Execution
|
||||
| Execution
|
||||
|-
|
||||
| T1486
|
||||
| Data Encrypted for Impact
|
||||
| Impact
|
||||
@@ -6188,10 +6317,14 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* Actions on Objectives
|
||||
|
||||
* Execution
|
||||
|
||||
* Exfiltration
|
||||
|
||||
* Exploitation
|
||||
|
||||
* Lateral Movement
|
||||
|
||||
* Obfuscation
|
||||
|
||||
|
||||
@@ -6549,7 +6682,7 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''': Endpoint, Network_Traffic
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1218.003/ T1218.003], [https://attack.mitre.org/techniques/T1485/ T1485], [https://attack.mitre.org/techniques/T1020/ T1020], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1048/ T1048], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1021.001/ T1021.001], [https://attack.mitre.org/techniques/T1047/ T1047], [https://attack.mitre.org/techniques/T1486/ T1486], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1070.001/ T1070.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1071.001/ T1071.001], [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1562.001/ T1562.001], [https://attack.mitre.org/techniques/T1489/ T1489]
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1218.003/ T1218.003], [https://attack.mitre.org/techniques/T1485/ T1485], [https://attack.mitre.org/techniques/T1204/ T1204], [https://attack.mitre.org/techniques/T1020/ T1020], [https://attack.mitre.org/techniques/T1087.002/ T1087.002], [https://attack.mitre.org/techniques/T1087.001/ T1087.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1069.002/ T1069.002], [https://attack.mitre.org/techniques/T1069.001/ T1069.001], [https://attack.mitre.org/techniques/T1491/ T1491], [https://attack.mitre.org/techniques/T1048/ T1048], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1021.001/ T1021.001], [https://attack.mitre.org/techniques/T1047/ T1047], [https://attack.mitre.org/techniques/T1112/ T1112], [https://attack.mitre.org/techniques/T1486/ T1486], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1070.001/ T1070.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1071.001/ T1071.001], [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1562.001/ T1562.001], [https://attack.mitre.org/techniques/T1489/ T1489]
|
||||
* '''Last Updated''': 2020-02-04
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
@@ -6565,18 +6698,36 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Common_ransomware_notes|Common Ransomware Notes]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Conti_common_exec_parameter|Conti Common Exec parameter]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Delete_shadowcopy_with_powershell|Delete ShadowCopy With PowerShell]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Deleting_shadow_copies|Deleting Shadow Copies]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_rclone_command-line_usage|Detect RClone Command-Line Usage]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_renamed_rclone|Detect Renamed RClone]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_sharphound_command-line_arguments|Detect SharpHound Command-Line Arguments]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_sharphound_file_modifications|Detect SharpHound File Modifications]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_sharphound_usage|Detect SharpHound Usage]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Known_services_killed_by_ransomware|Known Services Killed by Ransomware]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Modification_of_wallpaper|Modification Of Wallpaper]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Prohibited_network_traffic_allowed|Prohibited Network Traffic Allowed]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_persistence|Registry Keys Used For Persistence]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Remote_process_instantiation_via_wmi|Remote Process Instantiation via WMI]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Revil_common_exec_parameter|Revil Common Exec Parameter]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Revil_registry_entry|Revil Registry Entry]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike|SMB Traffic Spike]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Smb_traffic_spike_-_mltk|SMB Traffic Spike - MLTK]]
|
||||
@@ -6603,6 +6754,8 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Wbadmin_delete_system_backups|WBAdmin Delete System Backups]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Wbemprox_com_object_execution|Wbemprox COM Object Execution]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_within_public_path|WinEvent Scheduled Task Created Within Public Path]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Winevent_scheduled_task_created_to_spawn_shell|WinEvent Scheduled Task Created to Spawn Shell]]
|
||||
@@ -6629,14 +6782,38 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
| Data Destruction
|
||||
| Impact
|
||||
|-
|
||||
| T1204
|
||||
| User Execution
|
||||
| Execution
|
||||
|-
|
||||
| T1020
|
||||
| Automated Exfiltration
|
||||
| Exfiltration
|
||||
|-
|
||||
| T1087.002
|
||||
| Domain Account
|
||||
| Discovery
|
||||
|-
|
||||
| T1087.001
|
||||
| Local Account
|
||||
| Discovery
|
||||
|-
|
||||
| T1482
|
||||
| Domain Trust Discovery
|
||||
| Discovery
|
||||
|-
|
||||
| T1069.002
|
||||
| Domain Groups
|
||||
| Discovery
|
||||
|-
|
||||
| T1069.001
|
||||
| Local Groups
|
||||
| Discovery
|
||||
|-
|
||||
| T1491
|
||||
| Defacement
|
||||
| Impact
|
||||
|-
|
||||
| T1048
|
||||
| Exfiltration Over Alternative Protocol
|
||||
| Exfiltration
|
||||
@@ -6653,6 +6830,10 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
| Windows Management Instrumentation
|
||||
| Execution
|
||||
|-
|
||||
| T1112
|
||||
| Modify Registry
|
||||
| Defense Evasion
|
||||
|-
|
||||
| T1486
|
||||
| Data Encrypted for Impact
|
||||
| Impact
|
||||
@@ -6709,6 +6890,8 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* Privilege Escalation
|
||||
|
||||
* Reconnaissance
|
||||
|
||||
|
||||
====Reference====
|
||||
|
||||
@@ -6766,6 +6949,77 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
* https://www.youtube.com/watch?v=PgzNib37g0M
|
||||
|
||||
|
||||
''version'': 1
|
||||
</div>
|
||||
</div>
|
||||
|
||||
----
|
||||
|
||||
===Revil ransomware===
|
||||
Leverage searches that allow you to detect and investigate unusual activities that might relate to the Revil ransomware, including looking for file writes associated with Revil, encrypting network shares, deleting shadow volume storage, registry key modification, deleting of security logs, and more.
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''': Endpoint
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1491/ T1491], [https://attack.mitre.org/techniques/T1204/ T1204], [https://attack.mitre.org/techniques/T1112/ T1112], [https://attack.mitre.org/techniques/T1218.003/ T1218.003]
|
||||
* '''Last Updated''': 2021-06-04
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
<div class="mw-collapsible-content">
|
||||
|
||||
====Detection Profile====
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Delete_shadowcopy_with_powershell|Delete ShadowCopy With PowerShell]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Modification_of_wallpaper|Modification Of Wallpaper]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Revil_common_exec_parameter|Revil Common Exec Parameter]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Revil_registry_entry|Revil Registry Entry]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Wbemprox_com_object_execution|Wbemprox COM Object Execution]]
|
||||
|
||||
|
||||
|
||||
====ATT&CK====
|
||||
{|
|
||||
! style="text-align:left;"| ID
|
||||
! Technique
|
||||
! Tactic
|
||||
|-
|
||||
| T1490
|
||||
| Inhibit System Recovery
|
||||
| Impact
|
||||
|-
|
||||
| T1491
|
||||
| Defacement
|
||||
| Impact
|
||||
|-
|
||||
| T1204
|
||||
| User Execution
|
||||
| Execution
|
||||
|-
|
||||
| T1112
|
||||
| Modify Registry
|
||||
| Defense Evasion
|
||||
|-
|
||||
| T1218.003
|
||||
| CMSTP
|
||||
| Defense Evasion
|
||||
|}
|
||||
|
||||
|
||||
====Kill Chain Phase====
|
||||
|
||||
* Exploitation
|
||||
|
||||
|
||||
====Reference====
|
||||
|
||||
* https://krebsonsecurity.com/2021/05/a-closer-look-at-the-darkside-ransomware-gang/
|
||||
|
||||
* https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/
|
||||
|
||||
|
||||
''version'': 1
|
||||
</div>
|
||||
</div>
|
||||
@@ -6777,7 +7031,7 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''': Endpoint, Network_Traffic
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1218.003/ T1218.003], [https://attack.mitre.org/techniques/T1485/ T1485], [https://attack.mitre.org/techniques/T1020/ T1020], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1048/ T1048], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1021.001/ T1021.001], [https://attack.mitre.org/techniques/T1047/ T1047], [https://attack.mitre.org/techniques/T1486/ T1486], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1070.001/ T1070.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1071.001/ T1071.001], [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1562.001/ T1562.001], [https://attack.mitre.org/techniques/T1489/ T1489]
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1218.003/ T1218.003], [https://attack.mitre.org/techniques/T1485/ T1485], [https://attack.mitre.org/techniques/T1204/ T1204], [https://attack.mitre.org/techniques/T1020/ T1020], [https://attack.mitre.org/techniques/T1087.002/ T1087.002], [https://attack.mitre.org/techniques/T1087.001/ T1087.001], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1069.002/ T1069.002], [https://attack.mitre.org/techniques/T1069.001/ T1069.001], [https://attack.mitre.org/techniques/T1491/ T1491], [https://attack.mitre.org/techniques/T1048/ T1048], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1021.001/ T1021.001], [https://attack.mitre.org/techniques/T1047/ T1047], [https://attack.mitre.org/techniques/T1112/ T1112], [https://attack.mitre.org/techniques/T1486/ T1486], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1070.001/ T1070.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1071.001/ T1071.001], [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1562.001/ T1562.001], [https://attack.mitre.org/techniques/T1489/ T1489]
|
||||
* '''Last Updated''': 2020-11-06
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
@@ -6837,14 +7091,38 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
| Data Destruction
|
||||
| Impact
|
||||
|-
|
||||
| T1204
|
||||
| User Execution
|
||||
| Execution
|
||||
|-
|
||||
| T1020
|
||||
| Automated Exfiltration
|
||||
| Exfiltration
|
||||
|-
|
||||
| T1087.002
|
||||
| Domain Account
|
||||
| Discovery
|
||||
|-
|
||||
| T1087.001
|
||||
| Local Account
|
||||
| Discovery
|
||||
|-
|
||||
| T1482
|
||||
| Domain Trust Discovery
|
||||
| Discovery
|
||||
|-
|
||||
| T1069.002
|
||||
| Domain Groups
|
||||
| Discovery
|
||||
|-
|
||||
| T1069.001
|
||||
| Local Groups
|
||||
| Discovery
|
||||
|-
|
||||
| T1491
|
||||
| Defacement
|
||||
| Impact
|
||||
|-
|
||||
| T1048
|
||||
| Exfiltration Over Alternative Protocol
|
||||
| Exfiltration
|
||||
@@ -6861,6 +7139,10 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
| Windows Management Instrumentation
|
||||
| Execution
|
||||
|-
|
||||
| T1112
|
||||
| Modify Registry
|
||||
| Defense Evasion
|
||||
|-
|
||||
| T1486
|
||||
| Data Encrypted for Impact
|
||||
| Impact
|
||||
@@ -6938,7 +7220,7 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
||||
* '''Datamodel''': Endpoint, Network_Traffic, Web
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204.002/ T1204.002], [https://attack.mitre.org/techniques/T1485/ T1485], [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1082/ T1082], [https://attack.mitre.org/techniques/T1021.001/ T1021.001], [https://attack.mitre.org/techniques/T1486/ T1486]
|
||||
* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204.002/ T1204.002], [https://attack.mitre.org/techniques/T1485/ T1485], [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1082/ T1082], [https://attack.mitre.org/techniques/T1021.001/ T1021.001], [https://attack.mitre.org/techniques/T1486/ T1486]
|
||||
* '''Last Updated''': 2018-12-13
|
||||
|
||||
<div class="toccolours mw-collapsible mw-collapsed">
|
||||
@@ -6956,6 +7238,8 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_renamed_psexec|Detect Renamed PSExec]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_attackers_scanning_for_vulnerable_jboss_servers|Detect attackers scanning for vulnerable JBoss servers]]
|
||||
|
||||
* [[Documentation:ESSOC:detections:Detections#Detect_malicious_requests_to_exploit_jboss_servers|Detect malicious requests to exploit JBoss servers]]
|
||||
@@ -6996,6 +7280,10 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
| SMB/Windows Admin Shares
|
||||
| Lateral Movement
|
||||
|-
|
||||
| T1569.002
|
||||
| Service Execution
|
||||
| Execution
|
||||
|-
|
||||
| T1082
|
||||
| System Information Discovery
|
||||
| Discovery
|
||||
@@ -7018,8 +7306,14 @@ Leverage searches that allow you to detect and investigate unusual activities th
|
||||
|
||||
* Delivery
|
||||
|
||||
* Execution
|
||||
|
||||
* Exploitation
|
||||
|
||||
* Installation
|
||||
|
||||
* Lateral Movement
|
||||
|
||||
* Reconnaissance
|
||||
|
||||
|
||||
@@ -7784,7 +8078,7 @@ Reduce the risk of CVE-2018-11409, an information disclosure vulnerability withi
|
||||
<pre>
|
||||
#############
|
||||
# Automatically generated by doc_gen.py in https://github.com/splunk/security_content
|
||||
# On Date: 2021-05-24 20:50:07.268835 UTC
|
||||
# On Date: 2021-06-10 18:37:22.207469 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
@@ -0,0 +1,33 @@
|
||||
name: Meterpreter
|
||||
id: d5f8e298-c85a-11eb-9fea-acde48001122
|
||||
version: 1
|
||||
date: '2021-06-08'
|
||||
author: Michael Hart
|
||||
type: batch
|
||||
description: Meterpreter provides red teams, pen testers and threat actors interactive access to a compromised host to run commands, upload payloads, download files, and other actions.
|
||||
narrative: 'This Analytic Story supports you to detect Tactics, Techniques and Procedures (TTPs) from Meterpreter.
|
||||
Meterpreter is a Metasploit payload for remote execution that leverages DLL injection to make it extremely difficult to detect. Since the software
|
||||
runs in memory, no new processes are created upon injection. It also leverages encrypted communication channels.\
|
||||
|
||||
Meterpreter enables the operator to remotely run commands on the target machine, upload payloads, download files, dump password hashes,
|
||||
and much more. It is difficult to determine from the forensic evidence what actions the operator performed. Splunk Research, however, has observed
|
||||
anomalous behaviors on the compromised hosts that seem to only appear when Meterpreter is executing various commands. With that, we have written new
|
||||
detections targeted to these detections.\
|
||||
|
||||
While investigating a detection related to this analytic story, please bear in mind that the detections look for anomalies in system behavior. It will be
|
||||
imperative to look for other signs in the endpoint and network logs for lateral movement, discovery and other actions to confirm that the host was compromised
|
||||
and a remote actor used it to progress on their objectives.'
|
||||
references:
|
||||
- https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/
|
||||
- https://doubleoctopus.com/security-wiki/threats-and-tools/meterpreter/
|
||||
- https://www.rapid7.com/products/metasploit/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Meterpreter
|
||||
category:
|
||||
- Adversary Tactics
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
usecase: Advanced Threat Detection
|
||||
@@ -0,0 +1,13 @@
|
||||
name: Excessive number of taskhost processes Unit Test
|
||||
tests:
|
||||
- name: Excessive number of taskhost processes
|
||||
file: endpoint/excessive_number_of_taskhost_processes.yml
|
||||
pass_condition: '| stats count | where count > 0'
|
||||
earliest_time: '-24h'
|
||||
latest_time: 'now'
|
||||
attack_data:
|
||||
- file_name: windows-security.log
|
||||
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/meterpreter/taskhost_processes/logExcessiveTaskHost.log
|
||||
source: WinEventLog:Security
|
||||
sourcetype: WinEventLog
|
||||
update_timestamp: True
|
||||
Reference in New Issue
Block a user