mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge branch 'develop' into eventlog-stuff
This commit is contained in:
+5
-4
@@ -1,11 +1,12 @@
|
||||
name: CertUtil Download With URLCache and Split Arguments
|
||||
id: 415b4306-8bfb-11eb-85c4-acde48001122
|
||||
version: 12
|
||||
date: '2025-04-16'
|
||||
version: 13
|
||||
date: '2025-04-24'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
status: deprecated
|
||||
type: TTP
|
||||
description: The following analytic detects the use of certutil.exe to download files
|
||||
description: This analytic has been deprecated in favor of "Windows CertUtil Download".
|
||||
The following analytic detects the use of certutil.exe to download files
|
||||
using the `-urlcache` and `-f` arguments. It leverages Endpoint Detection and Response
|
||||
(EDR) data, focusing on command-line executions that include these specific arguments.
|
||||
This activity is significant because certutil.exe is typically used for certificate
|
||||
+5
-4
@@ -1,11 +1,12 @@
|
||||
name: CertUtil Download With VerifyCtl and Split Arguments
|
||||
id: 801ad9e4-8bfb-11eb-8b31-acde48001122
|
||||
version: 12
|
||||
date: '2025-04-16'
|
||||
version: 13
|
||||
date: '2025-04-24'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
status: deprecated
|
||||
type: TTP
|
||||
description: The following analytic detects the use of `certutil.exe` to download
|
||||
description: This analytic has been deprecated in favor of "Windows CertUtil Download".
|
||||
The following analytic detects the use of `certutil.exe` to download
|
||||
files using the `-VerifyCtl` and `-f` arguments. This behavior is identified by
|
||||
monitoring command-line executions for these specific arguments via Endpoint Detection
|
||||
and Response (EDR) telemetry. This activity is significant because `certutil.exe`
|
||||
+5
-4
@@ -1,11 +1,12 @@
|
||||
name: Windows CertUtil Download With URL Argument
|
||||
id: 4fc5ca00-4c7c-46b3-8772-c98a4b8bd944
|
||||
version: 5
|
||||
date: '2025-04-16'
|
||||
version: 6
|
||||
date: '2025-04-24'
|
||||
author: Nasreddine Bencherchali, Splunk
|
||||
status: production
|
||||
status: deprecated
|
||||
type: TTP
|
||||
description: The following analytic detects the use of `certutil.exe` to download
|
||||
description: This analytic has been deprecated in favor of "Windows CertUtil Download".
|
||||
The following analytic detects the use of `certutil.exe` to download
|
||||
files using the `-URL` arguments. This behavior is identified by monitoring command-line
|
||||
executions for these specific arguments via Endpoint Detection and Response (EDR)
|
||||
telemetry. This activity is significant because `certutil.exe` is a legitimate tool
|
||||
+4
-4
@@ -1,11 +1,11 @@
|
||||
name: Windows Remote Access Software Hunt
|
||||
id: 8bd22c9f-05a2-4db1-b131-29271f28cb0a
|
||||
version: 7
|
||||
date: '2025-04-18'
|
||||
version: 8
|
||||
date: '2025-04-30'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
status: deprecated
|
||||
type: Hunting
|
||||
description: The following analytic identifies the use of remote access software within
|
||||
description: This search is deprecated in favor of the new detection - Detect Remote Access Software Usage Process. The following analytic identifies the use of remote access software within
|
||||
the environment. It leverages data from Endpoint Detection and Response (EDR) agents,
|
||||
focusing on process execution logs. This detection is significant as unauthorized
|
||||
remote access tools can be used by adversaries to maintain persistent access to
|
||||
@@ -1,15 +1,14 @@
|
||||
name: CHCP Command Execution
|
||||
id: 21d236ec-eec1-11eb-b23e-acde48001122
|
||||
version: 6
|
||||
date: '2025-02-19'
|
||||
version: 7
|
||||
date: '2025-04-24'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of the chcp.exe application,
|
||||
type: Anomaly
|
||||
description: The following analytic detects the execution of the chcp.com utility,
|
||||
which is used to change the active code page of the console. This detection leverages
|
||||
data from Endpoint Detection and Response (EDR) agents, focusing on process creation
|
||||
events where chcp.exe is executed by cmd.exe with specific command-line arguments.
|
||||
This activity is significant because it can indicate the presence of malware, such
|
||||
events. This activity is significant because it can indicate the presence of malware, such
|
||||
as IcedID, which uses this technique to determine the locale region, language, or
|
||||
country of the compromised host. If confirmed malicious, this could lead to further
|
||||
system compromise and data exfiltration.
|
||||
@@ -18,7 +17,6 @@ data_source:
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=chcp.com
|
||||
Processes.parent_process_name = cmd.exe (Processes.parent_process=*/c* OR Processes.parent_process=*/k*)
|
||||
by Processes.action Processes.dest Processes.original_file_name Processes.parent_process
|
||||
Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id
|
||||
Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec
|
||||
@@ -35,8 +33,7 @@ how_to_implement: The detection is based on data that originates from Endpoint D
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: other tools or script may used this to change code page to
|
||||
UTF-* or others
|
||||
known_false_positives: other tools or script may used this to change code page to UTF-* or others
|
||||
references:
|
||||
- https://ss64.com/nt/chcp.html
|
||||
- https://twitter.com/tccontre18/status/1419941156633329665?s=20
|
||||
|
||||
@@ -1,12 +1,15 @@
|
||||
name: Check Elevated CMD using whoami
|
||||
id: a9079b18-1633-11ec-859c-acde48001122
|
||||
version: 6
|
||||
date: '2024-11-13'
|
||||
version: 7
|
||||
date: '2025-04-24'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies the execution of the 'whoami' command
|
||||
with specific parameters to check for elevated privileges. It leverages data from
|
||||
description: The following analytic identifies the execution of the "whoami" command
|
||||
with the "/group" flag, where the results are passed to the "find" command in order
|
||||
to look for a the string "12288". This string represents the SID of the group
|
||||
"Mandatory Label\High Mandatory Level" effectively checking if the current process
|
||||
is running as a "High" integrity process or with Administrator privileges. It leverages data from
|
||||
Endpoint Detection and Response (EDR) agents, focusing on process and command-line
|
||||
telemetry. This activity is significant because it is commonly used by attackers,
|
||||
such as FIN7, to perform reconnaissance on a compromised host. If confirmed malicious,
|
||||
@@ -35,7 +38,7 @@ how_to_implement: The detection is based on data that originates from Endpoint D
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: unknown
|
||||
known_false_positives: The combination of these commands is unlikely to occur in a production environment. Any matches should be investigated.
|
||||
references: []
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$dest$" and "$user$"
|
||||
|
||||
@@ -1,15 +1,14 @@
|
||||
name: Detect Remote Access Software Usage Process
|
||||
id: ffd5e001-2e34-48f4-97a2-26dc4bb08178
|
||||
version: 8
|
||||
date: '2025-04-18'
|
||||
author: Steven Dick
|
||||
version: 9
|
||||
date: '2025-04-30'
|
||||
author: Steven Dick, Sebastian Wurl, Splunk Community
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic detects the execution of known remote access software
|
||||
within the environment. It leverages data from Endpoint Detection and Response (EDR)
|
||||
agents, focusing on process names and parent processes mapped to the Endpoint data
|
||||
model. This activity is significant as adversaries often use remote access tools
|
||||
like AnyDesk, GoToMyPC, LogMeIn, and TeamViewer to maintain unauthorized access.
|
||||
model. We then compare with with a list of known remote access software shipped as a lookup file - remote_access_software. This activity is significant as adversaries often use remote access tools like AnyDesk, GoToMyPC, LogMeIn, and TeamViewer to maintain unauthorized access.
|
||||
If confirmed malicious, this could allow attackers to control systems remotely,
|
||||
exfiltrate data, or deploy additional malware, posing a severe threat to the organization's
|
||||
security.
|
||||
@@ -17,18 +16,23 @@ data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime values(Processes.parent_process) as parent_process from datamodel=Endpoint.Processes
|
||||
where Processes.dest!=unknown Processes.process!=unknown by Processes.action Processes.dest
|
||||
Processes.original_file_name Processes.parent_process Processes.parent_process_exec
|
||||
Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name
|
||||
Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid
|
||||
Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name
|
||||
Processes.process_path Processes.user Processes.user_id Processes.vendor_product
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name(Processes)`
|
||||
| lookup remote_access_software remote_utility AS process_name OUTPUT isutility,
|
||||
description as signature, comment_reference as desc, category | search isutility
|
||||
= True | `remote_access_software_usage_exceptions` | `detect_remote_access_software_usage_process_filter`'
|
||||
search: |
|
||||
| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.parent_process) as parent_process
|
||||
from datamodel=Endpoint.Processes
|
||||
where
|
||||
[| inputlookup remote_access_software where isutility=TRUE
|
||||
| rename remote_utility AS Processes.process_name
|
||||
| fields Processes.process_name]
|
||||
AND Processes.dest!="unknown"
|
||||
AND Processes.user!="unknown"
|
||||
by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| lookup remote_access_software remote_utility AS process_name OUTPUT isutility description AS signature comment_reference AS desc category
|
||||
| search isutility = TRUE
|
||||
| `remote_access_software_usage_exceptions`
|
||||
| `detect_remote_access_software_usage_process_filter`
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
@@ -107,3 +111,6 @@ tests:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1219/screenconnect/screenconnect_sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: XmlWinEventLog
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1219/atomic_red_team/windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: XmlWinEventLog
|
||||
@@ -1,10 +1,10 @@
|
||||
name: Detection of tools built by NirSoft
|
||||
id: 3d8d201c-aa03-422d-b0ee-2e5ecf9718c0
|
||||
version: 7
|
||||
date: '2024-11-13'
|
||||
version: 8
|
||||
date: '2025-04-24'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
type: Anomaly
|
||||
description: The following analytic identifies the execution of tools built by NirSoft
|
||||
by detecting specific command-line arguments such as "/stext" and "/scomma". It
|
||||
leverages data from Endpoint Detection and Response (EDR) agents, focusing on process
|
||||
@@ -37,10 +37,10 @@ how_to_implement: The detection is based on data that originates from Endpoint D
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: While legitimate, these NirSoft tools are prone to abuse. You
|
||||
should verfiy that the tool was used for a legitimate purpose.
|
||||
should verify that the tool was used for a legitimate purpose.
|
||||
references: []
|
||||
rba:
|
||||
message: NirSoft tools detected on $dest$
|
||||
message: NirSoft tool detected on $dest$
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
|
||||
@@ -1,11 +1,12 @@
|
||||
name: Excessive number of taskhost processes
|
||||
id: f443dac2-c7cf-11eb-ab51-acde48001122
|
||||
version: 7
|
||||
date: '2024-11-13'
|
||||
version: 8
|
||||
date: '2025-04-25'
|
||||
author: Michael Hart
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic identifies an excessive number of taskhost.exe
|
||||
description:
|
||||
The following analytic identifies an excessive number of taskhost.exe
|
||||
and taskhostex.exe processes running within a short time frame. It leverages data
|
||||
from Endpoint Detection and Response (EDR) agents, focusing on process names and
|
||||
their counts. This behavior is significant as it is commonly associated with post-exploitation
|
||||
@@ -14,10 +15,11 @@ description: The following analytic identifies an excessive number of taskhost.e
|
||||
activity could indicate an ongoing attack, allowing attackers to execute code, escalate
|
||||
privileges, or move laterally within the network.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.action) as action
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search:
|
||||
'| tstats `security_content_summariesonly` values(Processes.action) as action
|
||||
values(Processes.original_file_name) as original_file_name values(Processes.parent_process)
|
||||
as parent_process values(Processes.parent_process_exec) as parent_process_exec values(Processes.parent_process_guid)
|
||||
as parent_process_guid values(Processes.parent_process_id) as parent_process_id
|
||||
@@ -41,9 +43,11 @@ search: '| tstats `security_content_summariesonly` values(Processes.action) as a
|
||||
values(process_hash) as process_hash values(process_id) as process_id values(process_integrity_level)
|
||||
as process_integrity_level values(user) as user values(process_path) as process_path
|
||||
values(user_id) as user_id values(vendor_product) as vendor_product values(process_name)
|
||||
as process_name by _time, dest, firstTime, lastTime | `security_content_ctime(firstTime)`
|
||||
as process_name by _time, dest, firstTime, lastTime | where taskhost_count >
|
||||
10 or taskhostex_count > 10 | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `excessive_number_of_taskhost_processes_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
how_to_implement:
|
||||
The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
@@ -52,46 +56,49 @@ how_to_implement: The detection is based on data that originates from Endpoint D
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Administrators, administrative actions or certain applications
|
||||
known_false_positives:
|
||||
Administrators, administrative actions or certain applications
|
||||
may run many instances of taskhost and taskhostex concurrently. Filter as needed.
|
||||
references:
|
||||
- https://attack.mitre.org/software/S0250/
|
||||
- https://attack.mitre.org/software/S0250/
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$dest$"
|
||||
search: '%original_detection_search% | search dest = "$dest$"'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View the detection results for - "$dest$"
|
||||
search: '%original_detection_search% | search dest = "$dest$"'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$dest$"
|
||||
search:
|
||||
'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: An excessive amount of taskhost.exe and taskhostex.exe was executed on
|
||||
message:
|
||||
An excessive amount of taskhost.exe and taskhostex.exe was executed on
|
||||
$dest$ indicative of suspicious behavior.
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: system
|
||||
score: 56
|
||||
- field: dest
|
||||
type: system
|
||||
score: 56
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Meterpreter
|
||||
- Meterpreter
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1059
|
||||
- T1059
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/excessive_distinct_processes_from_windows_temp/windows-xml.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/excessive_distinct_processes_from_windows_temp/windows-xml.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Java Writing JSP File
|
||||
id: eb65619c-4f8d-4383-a975-d352765d344b
|
||||
version: 8
|
||||
date: '2025-04-22'
|
||||
version: 9
|
||||
date: '2025-04-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -72,6 +72,7 @@ tags:
|
||||
- Spring4Shell CVE-2022-22965
|
||||
- Atlassian Confluence Server and Data Center CVE-2022-26134
|
||||
- SysAid On-Prem Software CVE-2023-47246 Vulnerability
|
||||
- SAP NetWeaver Exploitation
|
||||
asset_type: Endpoint
|
||||
cve:
|
||||
- CVE-2022-22965
|
||||
|
||||
@@ -1,12 +1,12 @@
|
||||
name: System Processes Run From Unexpected Locations
|
||||
id: a34aae96-ccf8-4aef-952c-3ea21444444d
|
||||
version: 11
|
||||
date: '2025-02-10'
|
||||
author: David Dorsey, Michael Haag, Splunk
|
||||
version: 12
|
||||
date: '2025-04-24'
|
||||
author: David Dorsey, Michael Haag, Nasreddine Bencherchali, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic identifies system processes running from unexpected
|
||||
locations outside `C:\Windows\System32\` or `C:\Windows\SysWOW64`. It leverages
|
||||
locations outside of paths such as `C:\Windows\System32\` or `C:\Windows\SysWOW64`. It leverages
|
||||
data from Endpoint Detection and Response (EDR) agents, focusing on process paths,
|
||||
names, and hashes. This activity is significant as it may indicate a malicious process
|
||||
attempting to masquerade as a legitimate system process. If confirmed malicious,
|
||||
@@ -17,15 +17,17 @@ data_source:
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime FROM datamodel=Endpoint.Processes where Processes.process_path !="C:\\Windows\\System32*"
|
||||
Processes.process_path !="C:\\Windows\\SysWOW64*" by Processes.action Processes.dest
|
||||
as lastTime FROM datamodel=Endpoint.Processes where NOT Processes.process_path IN ("C:\\$WINDOWS.~BT\\*", "C:\\$WinREAgent\\*", "C:\\Windows\\SoftwareDistribution\\*", "C:\\Windows\\System32\\*", "C:\\Windows\\SystemTemp\\*", "C:\\Windows\\SysWOW64\\*", "C:\\Windows\\uus\\*", "C:\\Windows\\WinSxS\\*") by Processes.action Processes.dest
|
||||
Processes.original_file_name Processes.parent_process Processes.parent_process_exec
|
||||
Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name
|
||||
Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid
|
||||
Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name
|
||||
Processes.process_path Processes.user Processes.user_id Processes.vendor_product
|
||||
| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
|
||||
`is_windows_system_file_macro` | `system_processes_run_from_unexpected_locations_filter`'
|
||||
| `drop_dm_object_name("Processes")`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `is_windows_system_file_macro`
|
||||
| `system_processes_run_from_unexpected_locations_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
|
||||
@@ -0,0 +1,96 @@
|
||||
name: Windows File Download Via CertUtil
|
||||
id: 7fac8d40-e370-45ea-a4a3-031bbcc18b02
|
||||
version: 1
|
||||
date: '2025-04-24'
|
||||
author: Nasreddine Bencherchali, Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the use of `certutil.exe` to download files using the `-URL`, `-urlcache` or '-verifyctl' arguments. This behavior is identified by monitoring command-line executions for these specific arguments via Endpoint Detection and Response (EDR) telemetry. This activity is significant because `certutil.exe` is a legitimate tool often abused by attackers to download and execute malicious payloads. If confirmed malicious, this could allow an attacker to download and execute arbitrary files, potentially leading to code execution, data exfiltration, or further compromise of the system.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_certutil` AND ((Processes.process IN ("*-URL *", "*/URL *")) OR (Processes.process IN ("*urlcache*", "*verifyctl*") AND Processes.process IN ("*/f *", "*-f *")))
|
||||
by Processes.action Processes.dest
|
||||
Processes.original_file_name Processes.parent_process Processes.parent_process_exec
|
||||
Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name
|
||||
Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid
|
||||
Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name
|
||||
Processes.process_path Processes.user Processes.user_id Processes.vendor_product
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_file_download_via_certutil_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Limited false positives in most environments, however tune
|
||||
as needed based on parent-child relationship or network connection.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1105/
|
||||
- https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/
|
||||
- https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats
|
||||
- https://web.archive.org/web/20210921110637/https://www.fireeye.com/blog/threat-research/2019/10/certutil-qualms-they-came-to-drop-fombs.html
|
||||
- https://lolbas-project.github.io/lolbas/Binaries/Certutil/
|
||||
- https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc732443(v=ws.11)#-verifyctl
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$user$" and "$dest$"
|
||||
search: '%original_detection_search% | search user = "$user$" dest = "$dest$"'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to download a file.
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
score: 90
|
||||
- field: dest
|
||||
type: system
|
||||
score: 90
|
||||
threat_objects:
|
||||
- field: parent_process_name
|
||||
type: parent_process_name
|
||||
- field: process_name
|
||||
type: process_name
|
||||
tags:
|
||||
analytic_story:
|
||||
- Living Off The Land
|
||||
- Ingress Tool Transfer
|
||||
- ProxyNotShell
|
||||
- DarkSide Ransomware
|
||||
- Forest Blizzard
|
||||
- Flax Typhoon
|
||||
- Compromised Windows Host
|
||||
- CISA AA22-277A
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1105
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: XmlWinEventLog
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Java Spawning Shells
|
||||
id: 28c81306-5c47-11ec-bfea-acde48001122
|
||||
version: 9
|
||||
date: '2024-12-16'
|
||||
version: 10
|
||||
date: '2025-04-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -61,6 +61,7 @@ tags:
|
||||
- Log4Shell CVE-2021-44228
|
||||
- SysAid On-Prem Software CVE-2023-47246 Vulnerability
|
||||
- Cleo File Transfer Software
|
||||
- SAP NetWeaver Exploitation
|
||||
asset_type: Endpoint
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Process Injection into Commonly Abused Processes
|
||||
id: 1e1dedc6-f6f3-41a0-9dd7-a1245904fe75
|
||||
version: 2
|
||||
date: '2025-04-16'
|
||||
version: 3
|
||||
date: '2025-04-28'
|
||||
author: 0xC0FFEEEE, Github Community
|
||||
type: Anomaly
|
||||
status: production
|
||||
@@ -70,6 +70,7 @@ tags:
|
||||
analytic_story:
|
||||
- BishopFox Sliver Adversary Emulation Framework
|
||||
- Earth Alux
|
||||
- SAP NetWeaver Exploitation
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1055.002
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Process With NamedPipe CommandLine
|
||||
id: e64399d4-94a8-11ec-a9da-acde48001122
|
||||
version: 5
|
||||
date: '2024-11-13'
|
||||
version: 6
|
||||
date: '2025-04-24'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -19,14 +19,13 @@ data_source:
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process = "*\\\\.\\pipe\\*"
|
||||
NOT (Processes.process_path IN ("*\\program files*")) by Processes.action Processes.dest
|
||||
NOT Processes.process_path IN ("C:\\Program Files\\*", "C:\\Program Files (x86)\\*") by Processes.action Processes.dest
|
||||
Processes.original_file_name Processes.parent_process Processes.parent_process_exec
|
||||
Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name
|
||||
Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid
|
||||
Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name
|
||||
Processes.process_path Processes.user Processes.user_id Processes.vendor_product
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `windows_process_with_namedpipe_commandline_filter`'
|
||||
Processes.process_path Processes.user Processes.user_id Processes.vendor_product | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_process_with_namedpipe_commandline_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Query Registry Browser List Application
|
||||
id: 45ebd21c-f4bf-4ced-bd49-d25b6526cebb
|
||||
version: '6'
|
||||
date: '2025-03-19'
|
||||
version: 7
|
||||
date: '2025-04-24'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -16,8 +16,8 @@ description: The following analytic detects a suspicious process accessing the r
|
||||
confirmed malicious, this behavior could enable attackers to exfiltrate sensitive
|
||||
information and compromise user accounts.
|
||||
search: '`wineventlog_security` EventCode=4663 object_file_path IN ("*\\SOFTWARE\\Clients\\StartMenuInternet\\*",
|
||||
"*\\SOFTWARE\\Clients\\StartMenuInternet\\*") AND NOT (process_path IN ("*:\\Windows\\System32\\*",
|
||||
"*:\\Windows\\SysWow64\\*", "*:\\Program Files*", "*:\\Windows\\*")) | stats count
|
||||
"*\\SOFTWARE\\Clients\\StartMenuInternet\\*") AND NOT process_path IN ("*:\\Windows\\System32\\*",
|
||||
"*:\\Windows\\SysWow64\\*", *:\\Windows\\WinSxS\\*, "*:\\Program Files\\*", "*:\\Program Files (x86)\\*") | stats count
|
||||
min(_time) as firstTime max(_time) as lastTime by object_file_name object_file_path
|
||||
process_name process_path process_id EventCode dest | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_query_registry_browser_list_application_filter`'
|
||||
|
||||
@@ -1,26 +1,25 @@
|
||||
name: Windows User Execution Malicious URL Shortcut File
|
||||
id: 5c7ee6ad-baf4-44fb-b2f0-0cfeddf82dbc
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2025-04-24'
|
||||
author: Teoderick Contreras, Nasreddine Bencherchali, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the creation of suspicious URL shortcut
|
||||
link files, often used by malware like CHAOS ransomware. It leverages the Endpoint.Filesystem
|
||||
datamodel to identify .url files created outside standard directories, such as Program
|
||||
Files. This activity is significant as it may indicate an attempt to execute malicious
|
||||
code upon system reboot. If confirmed malicious, this could allow an attacker to
|
||||
achieve persistence and execute harmful payloads, potentially leading to further
|
||||
system compromise and data loss.
|
||||
type: Anomaly
|
||||
description: The following analytic detects the creation URL shortcut files, often used by malware like CHAOS ransomware.
|
||||
It leverages the Endpoint.Filesystem datamodel to identify ".url" files created outside common directories, such as "Program Files".
|
||||
This activity can be significant as ".URL" files can be used as mean to trick the user into visiting certain websites unknowingly, or when placed in certain locations such as "\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\", it may allow the execution of malicious code upon system reboot. If confirmed malicious, this could allow an attacker to achieve persistence and execute harmful payloads, potentially leading to further system compromise and data loss.
|
||||
data_source:
|
||||
- Sysmon EventID 11
|
||||
search: '|tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Filesystem where NOT(Filesystem.file_path IN
|
||||
("*\\Program Files*")) Filesystem.file_name = *.url by Filesystem.action Filesystem.dest
|
||||
as lastTime from datamodel=Endpoint.Filesystem where NOT Filesystem.file_path IN
|
||||
("*:\\Program Files\\*", "*:\\Program Files (x86)\\*", "*\\AppData\\Roaming\\Microsoft\\Office\\Recent\\*", "*:\\Windows\\WinSxS\\*") Filesystem.file_name=*.url
|
||||
by Filesystem.action Filesystem.dest
|
||||
Filesystem.file_access_time Filesystem.file_create_time Filesystem.file_hash Filesystem.file_modify_time
|
||||
Filesystem.file_name Filesystem.file_path Filesystem.file_acl Filesystem.file_size
|
||||
Filesystem.process_guid Filesystem.process_id Filesystem.user Filesystem.vendor_product
|
||||
| `drop_dm_object_name(Filesystem)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
Filesystem.process_guid Filesystem.process_id Filesystem.user Filesystem.vendor_product
|
||||
| `drop_dm_object_name(Filesystem)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_user_execution_malicious_url_shortcut_file_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the Filesystem responsible for the changes from
|
||||
@@ -45,14 +44,14 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: a process created URL shortcut file in $file_path$ of $dest$
|
||||
message: A process created a .URL shortcut file in $file_path$ of $dest$
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
score: 64
|
||||
score: 50
|
||||
- field: dest
|
||||
type: system
|
||||
score: 64
|
||||
score: 50
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
name: Protocols passing authentication in cleartext
|
||||
id: 6923cd64-17a0-453c-b945-81ac2d8c6db9
|
||||
version: 6
|
||||
date: '2024-11-15'
|
||||
version: 7
|
||||
date: '2025-03-03'
|
||||
author: Rico Valdez, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
type: Anomaly
|
||||
description: The following analytic identifies the use of cleartext protocols that
|
||||
risk leaking sensitive information. It detects network traffic on legacy protocols
|
||||
such as Telnet (port 23), POP3 (port 110), IMAP (port 143), and non-anonymous FTP
|
||||
@@ -25,8 +25,7 @@ how_to_implement: This search requires you to be ingesting your network traffic,
|
||||
populating the Network_Traffic data model. For more accurate result it's better
|
||||
to limit destination to organization private and public IP range, like All_Traffic.dest
|
||||
IN(192.168.0.0/16,172.16.0.0/12,10.0.0.0/8, x.x.x.x/22)
|
||||
known_false_positives: Some networks may use kerberized FTP or telnet servers, however,
|
||||
this is rare.
|
||||
known_false_positives: Some networks may use kerberos, FTP or telnet servers, however, this is rare.
|
||||
references:
|
||||
- https://www.rackaid.com/blog/secure-your-email-and-file-transfers/
|
||||
- https://www.infosecmatter.com/capture-passwords-using-wireshark/
|
||||
|
||||
@@ -0,0 +1,52 @@
|
||||
name: SAP NetWeaver Visual Composer Exploitation Attempt
|
||||
id: a583b9f1-9c3a-4402-9441-b981654dea6c
|
||||
version: 1
|
||||
date: '2025-04-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
description: |
|
||||
Detects potential exploitation attempts targeting CVE-2025-31324, a critical unauthenticated file upload vulnerability in SAP NetWeaver Visual Composer. This flaw allows remote attackers to send specially crafted POST requests to the /developmentserver/metadatauploader endpoint, enabling arbitrary file uploads—commonly webshells—resulting in full system compromise. The detection looks for HTTP HEAD or POST requests with a 200 OK status to sensitive Visual Composer endpoints, which may indicate reconnaissance or active exploitation. Successful exploitation can lead to attackers gaining privileged access, deploying malware, and impacting business-critical SAP resources. Immediate patching and investigation of suspicious activity are strongly recommended, as this vulnerability is being actively exploited in the wild.
|
||||
data_source:
|
||||
- Suricata
|
||||
search: '| tstats count min(_time) as firstTime max(_time) as lastTime
|
||||
from datamodel=Web.Web
|
||||
where (Web.url IN ("/CTCWebService/CTCWebServiceBean", "/VisualComposer/services/DesignTimeService", "/ctc/CTCWebService/CTCWebServiceBean"))
|
||||
AND Web.http_method IN ("HEAD", "POST")
|
||||
AND Web.status=200
|
||||
by Web.src, Web.dest, Web.http_method, Web.url, Web.http_user_agent, Web.url_length, sourcetype
|
||||
| `drop_dm_object_name("Web")`
|
||||
| eval action=case(http_method="HEAD", "Recon/Probe", http_method="POST", "Possible Exploitation")
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| table firstTime, lastTime, src, dest, http_method, action, url, user_agent, url_length, sourcetype
|
||||
| `sap_netweaver_visual_composer_exploitation_attempt_filter`'
|
||||
how_to_implement: |
|
||||
Ensure that the Web data model is accelerated and populated with web server or web proxy logs capturing HTTP request and response data.
|
||||
This search relies on HTTP method, status code, and URL path fields to identify suspicious access patterns against SAP NetWeaver endpoints.
|
||||
known_false_positives: |
|
||||
Some legitimate administrative activity may access SAP NetWeaver services. However, HEAD or POST requests directly resulting in a 200 OK
|
||||
to Visual Composer endpoints are uncommon and should be investigated carefully.
|
||||
references:
|
||||
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
|
||||
- https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/
|
||||
- https://www.rapid7.com/blog/post/2025/04/28/etr-active-exploitation-of-sap-netweaver-visual-composer-cve-2025-31324/
|
||||
tags:
|
||||
analytic_story:
|
||||
- SAP NetWeaver Exploitation
|
||||
asset_type: Web Server
|
||||
mitre_attack_id:
|
||||
- T1190
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
security_domain: network
|
||||
cve:
|
||||
- CVE-2025-31324
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/sap/suricata_sapnetweaver.log
|
||||
sourcetype: suricata
|
||||
source: suricata
|
||||
@@ -1,15 +1,108 @@
|
||||
filename,nirsoftFile
|
||||
AdvancedRun.exe,True
|
||||
awatch.exe,True
|
||||
BrowsingHistoryView.exe,True
|
||||
BulletsPassView.exe,True
|
||||
ChromeCacheView.exe,True
|
||||
ChromeHistoryView.exe,True
|
||||
ChromePass.exe,True
|
||||
cports.exe,True
|
||||
CredentialsFileView.exe,True
|
||||
CredHistView.exe,True
|
||||
DataProtectionDecryptor.exe,True
|
||||
DeviceIOView.exe,True
|
||||
Dialupass.exe,True
|
||||
dllexp.exe,True
|
||||
DNSDataView.exe,True
|
||||
DNSQuerySniffer.exe,True
|
||||
DotNetResourcesExtract.exe,True
|
||||
DownTester.exe,True
|
||||
DriverView.exe,True
|
||||
EncryptedRegView.exe,True
|
||||
ESEDatabaseView.exe,True
|
||||
EventLogChannelsView.exe,True
|
||||
FastResolver.exe,True
|
||||
faview.exe,True
|
||||
FBCacheView.exe,True
|
||||
FileTypesMan.exe,True
|
||||
FirefoxDownloadsView.exe,True
|
||||
FlashCookiesView.exe,True
|
||||
FolderChangesView.exe,True
|
||||
FolderTimeUpdate.exe,True
|
||||
FullEventLogView.exe,True
|
||||
gacview.exe,True
|
||||
GDIView.exe,True
|
||||
HeapMemView.exe,True
|
||||
HTTPNetworkSniffer.exe,True
|
||||
IECacheView.exe,True
|
||||
iecv.exe,True
|
||||
iehv.exe,True
|
||||
iepv.exe,True
|
||||
ImageCacheViewer.exe,True
|
||||
InstalledPackagesView.exe,True
|
||||
IPNetInfo.exe,True
|
||||
LastActivityView.exe,True
|
||||
LostMyPassword.exe,True
|
||||
mailpv.exe,True
|
||||
MozillaCacheView.exe,True
|
||||
MozillaHistoryView.exe,True
|
||||
mspass.exe,True
|
||||
MyLastSearch.exe,True
|
||||
mzcv.exe,True
|
||||
NetBScanner.exe,True
|
||||
NetConnectChoose.exe,True
|
||||
netpass.exe,True
|
||||
NetResView.exe,True
|
||||
NetRouteView.exe,True
|
||||
NetworkLatencyView.exe,True
|
||||
NetworkTrafficView.exe,True
|
||||
OpenedFilesView.exe,True
|
||||
OperaCacheView.exe,True
|
||||
PasswordFox.exe,True
|
||||
PasswordHashesView.exe,True
|
||||
PingInfoView.exe,True
|
||||
ProcessActivityView.exe,True
|
||||
ProcessThreadsView.exe,True
|
||||
ProduKey.exe,True
|
||||
PstPassword.exe,True
|
||||
QuickSetDNS.exe,True
|
||||
RegDllView.exe,True
|
||||
RegFromApp.exe,True
|
||||
RegHiveBackup.exe,True
|
||||
WebBrowserPassView.exe,True
|
||||
RegScanner.exe,True
|
||||
ResourcesExtract.exe,True
|
||||
RouterPassView.exe,True
|
||||
RunAsDate.exe,True
|
||||
SafariCacheView.exe,True
|
||||
SafariHistoryView.exe,True
|
||||
SearchMyFiles.exe,True
|
||||
shexview.exe,True
|
||||
shmnview.exe,True
|
||||
SimpleProgramDebugger.exe,True
|
||||
SiteShoter.exe,True
|
||||
smsniff.exe,True
|
||||
SniffPass.exe,True
|
||||
SocketSniff.exe,True
|
||||
SpecialFoldersView.exe,True
|
||||
sysexp.exe,True
|
||||
TaskSchedulerView.exe,True
|
||||
TcpLogView.exe,True
|
||||
TurnedOnTimesView.exe,True
|
||||
UninstallView.exe,True
|
||||
URLProtocolView.exe,True
|
||||
USBDeview.exe,True
|
||||
VaultPasswordView.exe,True
|
||||
volumouse.exe,True
|
||||
WebBrowserPassView.exe,True
|
||||
WebCacheImageInfo.exe,True
|
||||
WebCookiesSniffer.exe,True
|
||||
WebSiteSniffer.exe,True
|
||||
WhatIsHang.exe,True
|
||||
WhoisTD.exe,True
|
||||
WifiChannelMonitor.exe,True
|
||||
WifiInfoView.exe,True
|
||||
WinCrashReport.exe,True
|
||||
WinLogOnView.exe,True
|
||||
WirelessKeyView.exe,True
|
||||
WirelessNetView.exe,True
|
||||
WNetWatcher.exe,True
|
||||
|
@@ -1,6 +1,6 @@
|
||||
name: is_nirsoft_software
|
||||
date: 2024-12-23
|
||||
version: 2
|
||||
date: 2025-04-24
|
||||
version: 3
|
||||
id: 28966a08-55e4-4ccb-a20d-dc4cc154b09c
|
||||
author: Splunk Threat Research Team
|
||||
lookup_type: csv
|
||||
|
||||
@@ -1,4 +1,24 @@
|
||||
detections:
|
||||
- content: Windows Remote Access Software Hunt
|
||||
removed_in_version: 5.8.0
|
||||
reason: Detection has been replaced by a new detection with a more specific name and logic
|
||||
replacement_content:
|
||||
- Detect Remote Access Software Usage Process
|
||||
- content: CertUtil Download With URLCache and Split Arguments
|
||||
removed_in_version: 5.8.0
|
||||
reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert
|
||||
replacement_content:
|
||||
- Windows File Download Via CertUtil
|
||||
- content: Windows CertUtil Download With URL Argument
|
||||
removed_in_version: 5.8.0
|
||||
reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert
|
||||
replacement_content:
|
||||
- Windows File Download Via CertUtil
|
||||
- content: CertUtil Download With VerifyCtl and Split Arguments
|
||||
removed_in_version: 5.8.0
|
||||
reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert
|
||||
replacement_content:
|
||||
- Windows File Download Via CertUtil
|
||||
- content: Detect Large Outbound ICMP Packets
|
||||
removed_in_version: 5.6.0
|
||||
reason: Detection has been replaced by a new detection with a more specific name
|
||||
@@ -1030,4 +1050,4 @@ stories:
|
||||
- Suspicious Cloud Instance Activities
|
||||
- content: Web Fraud Detection
|
||||
removed_in_version: 5.2.0
|
||||
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
||||
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
|
||||
|
||||
@@ -0,0 +1,28 @@
|
||||
name: SAP NetWeaver Exploitation
|
||||
id: a52f77e2-0632-46a5-b750-6c059bc7bbb4
|
||||
version: 1
|
||||
status: production
|
||||
date: '2025-04-28'
|
||||
author: Michael Haag, Splunk
|
||||
description: |
|
||||
This Analytic Story covers the detection of exploitation attempts and reconnaissance activity targeting SAP NetWeaver platforms, with a focus on the critical unauthenticated file upload vulnerability CVE-2025-31324 in Visual Composer. Attackers are actively exploiting this flaw to upload arbitrary files—often webshells—via POST requests to the /developmentserver/metadatauploader endpoint, leading to full system compromise, remote code execution, and persistent access. The story includes detections for both probing (e.g., HEAD requests) and active exploitation, and highlights the significant business risks, such as data theft, operational disruption, and potential regulatory impact. Defenders can use this story to monitor, hunt, and respond to suspicious activity across SAP NetWeaver services, helping to identify both initial access and post-exploitation behaviors.
|
||||
narrative: |
|
||||
Attackers are actively targeting SAP NetWeaver environments through newly disclosed vulnerabilities like CVE-2025-31324, affecting the Visual Composer service.
|
||||
Successful exploitation can lead to remote code execution (RCE) and the deployment of webshells, giving adversaries persistent access to SAP systems.
|
||||
This story provides detections for reconnaissance patterns (e.g., HEAD requests receiving HTTP 200 responses) and potential exploitation behavior
|
||||
(e.g., POST requests leading to successful uploads), empowering defenders to quickly identify compromise attempts and mitigate them before escalation.
|
||||
references:
|
||||
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
|
||||
- https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/
|
||||
- https://www.rapid7.com/blog/post/2025/04/28/etr-active-exploitation-of-sap-netweaver-visual-composer-cve-2025-31324/
|
||||
- https://www.splunk.com/en_us/blog/security/the-final-shell-introducing-shellsweepx.html
|
||||
tags:
|
||||
category:
|
||||
- Adversary Tactics
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
usecase: Advanced Threat Detection
|
||||
cve:
|
||||
- CVE-2025-31324
|
||||
Reference in New Issue
Block a user