Merge branch 'develop' into eventlog-stuff

This commit is contained in:
Bhavin Patel
2025-05-01 13:09:27 -07:00
committed by GitHub
23 changed files with 449 additions and 141 deletions
@@ -1,11 +1,12 @@
name: CertUtil Download With URLCache and Split Arguments
id: 415b4306-8bfb-11eb-85c4-acde48001122
version: 12
date: '2025-04-16'
version: 13
date: '2025-04-24'
author: Michael Haag, Splunk
status: production
status: deprecated
type: TTP
description: The following analytic detects the use of certutil.exe to download files
description: This analytic has been deprecated in favor of "Windows CertUtil Download".
The following analytic detects the use of certutil.exe to download files
using the `-urlcache` and `-f` arguments. It leverages Endpoint Detection and Response
(EDR) data, focusing on command-line executions that include these specific arguments.
This activity is significant because certutil.exe is typically used for certificate
@@ -1,11 +1,12 @@
name: CertUtil Download With VerifyCtl and Split Arguments
id: 801ad9e4-8bfb-11eb-8b31-acde48001122
version: 12
date: '2025-04-16'
version: 13
date: '2025-04-24'
author: Michael Haag, Splunk
status: production
status: deprecated
type: TTP
description: The following analytic detects the use of `certutil.exe` to download
description: This analytic has been deprecated in favor of "Windows CertUtil Download".
The following analytic detects the use of `certutil.exe` to download
files using the `-VerifyCtl` and `-f` arguments. This behavior is identified by
monitoring command-line executions for these specific arguments via Endpoint Detection
and Response (EDR) telemetry. This activity is significant because `certutil.exe`
@@ -1,11 +1,12 @@
name: Windows CertUtil Download With URL Argument
id: 4fc5ca00-4c7c-46b3-8772-c98a4b8bd944
version: 5
date: '2025-04-16'
version: 6
date: '2025-04-24'
author: Nasreddine Bencherchali, Splunk
status: production
status: deprecated
type: TTP
description: The following analytic detects the use of `certutil.exe` to download
description: This analytic has been deprecated in favor of "Windows CertUtil Download".
The following analytic detects the use of `certutil.exe` to download
files using the `-URL` arguments. This behavior is identified by monitoring command-line
executions for these specific arguments via Endpoint Detection and Response (EDR)
telemetry. This activity is significant because `certutil.exe` is a legitimate tool
@@ -1,11 +1,11 @@
name: Windows Remote Access Software Hunt
id: 8bd22c9f-05a2-4db1-b131-29271f28cb0a
version: 7
date: '2025-04-18'
version: 8
date: '2025-04-30'
author: Michael Haag, Splunk
status: production
status: deprecated
type: Hunting
description: The following analytic identifies the use of remote access software within
description: This search is deprecated in favor of the new detection - Detect Remote Access Software Usage Process. The following analytic identifies the use of remote access software within
the environment. It leverages data from Endpoint Detection and Response (EDR) agents,
focusing on process execution logs. This detection is significant as unauthorized
remote access tools can be used by adversaries to maintain persistent access to
@@ -1,15 +1,14 @@
name: CHCP Command Execution
id: 21d236ec-eec1-11eb-b23e-acde48001122
version: 6
date: '2025-02-19'
version: 7
date: '2025-04-24'
author: Teoderick Contreras, Splunk
status: production
type: TTP
description: The following analytic detects the execution of the chcp.exe application,
type: Anomaly
description: The following analytic detects the execution of the chcp.com utility,
which is used to change the active code page of the console. This detection leverages
data from Endpoint Detection and Response (EDR) agents, focusing on process creation
events where chcp.exe is executed by cmd.exe with specific command-line arguments.
This activity is significant because it can indicate the presence of malware, such
events. This activity is significant because it can indicate the presence of malware, such
as IcedID, which uses this technique to determine the locale region, language, or
country of the compromised host. If confirmed malicious, this could lead to further
system compromise and data exfiltration.
@@ -18,7 +17,6 @@ data_source:
- CrowdStrike ProcessRollup2
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=chcp.com
Processes.parent_process_name = cmd.exe (Processes.parent_process=*/c* OR Processes.parent_process=*/k*)
by Processes.action Processes.dest Processes.original_file_name Processes.parent_process
Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id
Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec
@@ -35,8 +33,7 @@ how_to_implement: The detection is based on data that originates from Endpoint D
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
data model. Use the Splunk Common Information Model (CIM) to normalize the field
names and speed up the data modeling process.
known_false_positives: other tools or script may used this to change code page to
UTF-* or others
known_false_positives: other tools or script may used this to change code page to UTF-* or others
references:
- https://ss64.com/nt/chcp.html
- https://twitter.com/tccontre18/status/1419941156633329665?s=20
@@ -1,12 +1,15 @@
name: Check Elevated CMD using whoami
id: a9079b18-1633-11ec-859c-acde48001122
version: 6
date: '2024-11-13'
version: 7
date: '2025-04-24'
author: Teoderick Contreras, Splunk
status: production
type: TTP
description: The following analytic identifies the execution of the 'whoami' command
with specific parameters to check for elevated privileges. It leverages data from
description: The following analytic identifies the execution of the "whoami" command
with the "/group" flag, where the results are passed to the "find" command in order
to look for a the string "12288". This string represents the SID of the group
"Mandatory Label\High Mandatory Level" effectively checking if the current process
is running as a "High" integrity process or with Administrator privileges. It leverages data from
Endpoint Detection and Response (EDR) agents, focusing on process and command-line
telemetry. This activity is significant because it is commonly used by attackers,
such as FIN7, to perform reconnaissance on a compromised host. If confirmed malicious,
@@ -35,7 +38,7 @@ how_to_implement: The detection is based on data that originates from Endpoint D
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
data model. Use the Splunk Common Information Model (CIM) to normalize the field
names and speed up the data modeling process.
known_false_positives: unknown
known_false_positives: The combination of these commands is unlikely to occur in a production environment. Any matches should be investigated.
references: []
drilldown_searches:
- name: View the detection results for - "$dest$" and "$user$"
@@ -1,15 +1,14 @@
name: Detect Remote Access Software Usage Process
id: ffd5e001-2e34-48f4-97a2-26dc4bb08178
version: 8
date: '2025-04-18'
author: Steven Dick
version: 9
date: '2025-04-30'
author: Steven Dick, Sebastian Wurl, Splunk Community
status: production
type: Anomaly
description: The following analytic detects the execution of known remote access software
within the environment. It leverages data from Endpoint Detection and Response (EDR)
agents, focusing on process names and parent processes mapped to the Endpoint data
model. This activity is significant as adversaries often use remote access tools
like AnyDesk, GoToMyPC, LogMeIn, and TeamViewer to maintain unauthorized access.
model. We then compare with with a list of known remote access software shipped as a lookup file - remote_access_software. This activity is significant as adversaries often use remote access tools like AnyDesk, GoToMyPC, LogMeIn, and TeamViewer to maintain unauthorized access.
If confirmed malicious, this could allow attackers to control systems remotely,
exfiltrate data, or deploy additional malware, posing a severe threat to the organization's
security.
@@ -17,18 +16,23 @@ data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime values(Processes.parent_process) as parent_process from datamodel=Endpoint.Processes
where Processes.dest!=unknown Processes.process!=unknown by Processes.action Processes.dest
Processes.original_file_name Processes.parent_process Processes.parent_process_exec
Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name
Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid
Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name
Processes.process_path Processes.user Processes.user_id Processes.vendor_product
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name(Processes)`
| lookup remote_access_software remote_utility AS process_name OUTPUT isutility,
description as signature, comment_reference as desc, category | search isutility
= True | `remote_access_software_usage_exceptions` | `detect_remote_access_software_usage_process_filter`'
search: |
| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.parent_process) as parent_process
from datamodel=Endpoint.Processes
where
[| inputlookup remote_access_software where isutility=TRUE
| rename remote_utility AS Processes.process_name
| fields Processes.process_name]
AND Processes.dest!="unknown"
AND Processes.user!="unknown"
by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `drop_dm_object_name(Processes)`
| lookup remote_access_software remote_utility AS process_name OUTPUT isutility description AS signature comment_reference AS desc category
| search isutility = TRUE
| `remote_access_software_usage_exceptions`
| `detect_remote_access_software_usage_process_filter`
how_to_implement: The detection is based on data that originates from Endpoint Detection
and Response (EDR) agents. These agents are designed to provide security-related
telemetry from the endpoints where the agent is installed. To implement this search,
@@ -107,3 +111,6 @@ tests:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1219/screenconnect/screenconnect_sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1219/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
@@ -1,10 +1,10 @@
name: Detection of tools built by NirSoft
id: 3d8d201c-aa03-422d-b0ee-2e5ecf9718c0
version: 7
date: '2024-11-13'
version: 8
date: '2025-04-24'
author: Bhavin Patel, Splunk
status: experimental
type: TTP
type: Anomaly
description: The following analytic identifies the execution of tools built by NirSoft
by detecting specific command-line arguments such as "/stext" and "/scomma". It
leverages data from Endpoint Detection and Response (EDR) agents, focusing on process
@@ -37,10 +37,10 @@ how_to_implement: The detection is based on data that originates from Endpoint D
data model. Use the Splunk Common Information Model (CIM) to normalize the field
names and speed up the data modeling process.
known_false_positives: While legitimate, these NirSoft tools are prone to abuse. You
should verfiy that the tool was used for a legitimate purpose.
should verify that the tool was used for a legitimate purpose.
references: []
rba:
message: NirSoft tools detected on $dest$
message: NirSoft tool detected on $dest$
risk_objects:
- field: user
type: user
@@ -1,11 +1,12 @@
name: Excessive number of taskhost processes
id: f443dac2-c7cf-11eb-ab51-acde48001122
version: 7
date: '2024-11-13'
version: 8
date: '2025-04-25'
author: Michael Hart
status: production
type: Anomaly
description: The following analytic identifies an excessive number of taskhost.exe
description:
The following analytic identifies an excessive number of taskhost.exe
and taskhostex.exe processes running within a short time frame. It leverages data
from Endpoint Detection and Response (EDR) agents, focusing on process names and
their counts. This behavior is significant as it is commonly associated with post-exploitation
@@ -14,10 +15,11 @@ description: The following analytic identifies an excessive number of taskhost.e
activity could indicate an ongoing attack, allowing attackers to execute code, escalate
privileges, or move laterally within the network.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
search: '| tstats `security_content_summariesonly` values(Processes.action) as action
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
search:
'| tstats `security_content_summariesonly` values(Processes.action) as action
values(Processes.original_file_name) as original_file_name values(Processes.parent_process)
as parent_process values(Processes.parent_process_exec) as parent_process_exec values(Processes.parent_process_guid)
as parent_process_guid values(Processes.parent_process_id) as parent_process_id
@@ -41,9 +43,11 @@ search: '| tstats `security_content_summariesonly` values(Processes.action) as a
values(process_hash) as process_hash values(process_id) as process_id values(process_integrity_level)
as process_integrity_level values(user) as user values(process_path) as process_path
values(user_id) as user_id values(vendor_product) as vendor_product values(process_name)
as process_name by _time, dest, firstTime, lastTime | `security_content_ctime(firstTime)`
as process_name by _time, dest, firstTime, lastTime | where taskhost_count >
10 or taskhostex_count > 10 | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `excessive_number_of_taskhost_processes_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
how_to_implement:
The detection is based on data that originates from Endpoint Detection
and Response (EDR) agents. These agents are designed to provide security-related
telemetry from the endpoints where the agent is installed. To implement this search,
you must ingest logs that contain the process GUID, process name, and parent process.
@@ -52,46 +56,49 @@ how_to_implement: The detection is based on data that originates from Endpoint D
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
data model. Use the Splunk Common Information Model (CIM) to normalize the field
names and speed up the data modeling process.
known_false_positives: Administrators, administrative actions or certain applications
known_false_positives:
Administrators, administrative actions or certain applications
may run many instances of taskhost and taskhostex concurrently. Filter as needed.
references:
- https://attack.mitre.org/software/S0250/
- https://attack.mitre.org/software/S0250/
drilldown_searches:
- name: View the detection results for - "$dest$"
search: '%original_detection_search% | search dest = "$dest$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View the detection results for - "$dest$"
search: '%original_detection_search% | search dest = "$dest$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
search:
'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: An excessive amount of taskhost.exe and taskhostex.exe was executed on
message:
An excessive amount of taskhost.exe and taskhostex.exe was executed on
$dest$ indicative of suspicious behavior.
risk_objects:
- field: dest
type: system
score: 56
- field: dest
type: system
score: 56
threat_objects: []
tags:
analytic_story:
- Meterpreter
- Meterpreter
asset_type: Endpoint
mitre_attack_id:
- T1059
- T1059
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/excessive_distinct_processes_from_windows_temp/windows-xml.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/excessive_distinct_processes_from_windows_temp/windows-xml.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
@@ -1,7 +1,7 @@
name: Java Writing JSP File
id: eb65619c-4f8d-4383-a975-d352765d344b
version: 8
date: '2025-04-22'
version: 9
date: '2025-04-28'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -72,6 +72,7 @@ tags:
- Spring4Shell CVE-2022-22965
- Atlassian Confluence Server and Data Center CVE-2022-26134
- SysAid On-Prem Software CVE-2023-47246 Vulnerability
- SAP NetWeaver Exploitation
asset_type: Endpoint
cve:
- CVE-2022-22965
@@ -1,12 +1,12 @@
name: System Processes Run From Unexpected Locations
id: a34aae96-ccf8-4aef-952c-3ea21444444d
version: 11
date: '2025-02-10'
author: David Dorsey, Michael Haag, Splunk
version: 12
date: '2025-04-24'
author: David Dorsey, Michael Haag, Nasreddine Bencherchali, Splunk
status: production
type: Anomaly
description: The following analytic identifies system processes running from unexpected
locations outside `C:\Windows\System32\` or `C:\Windows\SysWOW64`. It leverages
locations outside of paths such as `C:\Windows\System32\` or `C:\Windows\SysWOW64`. It leverages
data from Endpoint Detection and Response (EDR) agents, focusing on process paths,
names, and hashes. This activity is significant as it may indicate a malicious process
attempting to masquerade as a legitimate system process. If confirmed malicious,
@@ -17,15 +17,17 @@ data_source:
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime FROM datamodel=Endpoint.Processes where Processes.process_path !="C:\\Windows\\System32*"
Processes.process_path !="C:\\Windows\\SysWOW64*" by Processes.action Processes.dest
as lastTime FROM datamodel=Endpoint.Processes where NOT Processes.process_path IN ("C:\\$WINDOWS.~BT\\*", "C:\\$WinREAgent\\*", "C:\\Windows\\SoftwareDistribution\\*", "C:\\Windows\\System32\\*", "C:\\Windows\\SystemTemp\\*", "C:\\Windows\\SysWOW64\\*", "C:\\Windows\\uus\\*", "C:\\Windows\\WinSxS\\*") by Processes.action Processes.dest
Processes.original_file_name Processes.parent_process Processes.parent_process_exec
Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name
Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid
Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name
Processes.process_path Processes.user Processes.user_id Processes.vendor_product
| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
`is_windows_system_file_macro` | `system_processes_run_from_unexpected_locations_filter`'
| `drop_dm_object_name("Processes")`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `is_windows_system_file_macro`
| `system_processes_run_from_unexpected_locations_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
and Response (EDR) agents. These agents are designed to provide security-related
telemetry from the endpoints where the agent is installed. To implement this search,
@@ -0,0 +1,96 @@
name: Windows File Download Via CertUtil
id: 7fac8d40-e370-45ea-a4a3-031bbcc18b02
version: 1
date: '2025-04-24'
author: Nasreddine Bencherchali, Michael Haag, Splunk
status: production
type: TTP
description: The following analytic detects the use of `certutil.exe` to download files using the `-URL`, `-urlcache` or '-verifyctl' arguments. This behavior is identified by monitoring command-line executions for these specific arguments via Endpoint Detection and Response (EDR) telemetry. This activity is significant because `certutil.exe` is a legitimate tool often abused by attackers to download and execute malicious payloads. If confirmed malicious, this could allow an attacker to download and execute arbitrary files, potentially leading to code execution, data exfiltration, or further compromise of the system.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where `process_certutil` AND ((Processes.process IN ("*-URL *", "*/URL *")) OR (Processes.process IN ("*urlcache*", "*verifyctl*") AND Processes.process IN ("*/f *", "*-f *")))
by Processes.action Processes.dest
Processes.original_file_name Processes.parent_process Processes.parent_process_exec
Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name
Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid
Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name
Processes.process_path Processes.user Processes.user_id Processes.vendor_product
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_file_download_via_certutil_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
and Response (EDR) agents. These agents are designed to provide security-related
telemetry from the endpoints where the agent is installed. To implement this search,
you must ingest logs that contain the process GUID, process name, and parent process.
Additionally, you must ingest complete command-line executions. These logs must
be processed using the appropriate Splunk Technology Add-ons that are specific to
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
data model. Use the Splunk Common Information Model (CIM) to normalize the field
names and speed up the data modeling process.
known_false_positives: Limited false positives in most environments, however tune
as needed based on parent-child relationship or network connection.
references:
- https://attack.mitre.org/techniques/T1105/
- https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/
- https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats
- https://web.archive.org/web/20210921110637/https://www.fireeye.com/blog/threat-research/2019/10/certutil-qualms-they-came-to-drop-fombs.html
- https://lolbas-project.github.io/lolbas/Binaries/Certutil/
- https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc732443(v=ws.11)#-verifyctl
drilldown_searches:
- name: View the detection results for - "$user$" and "$dest$"
search: '%original_detection_search% | search user = "$user$" dest = "$dest$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ attempting to download a file.
risk_objects:
- field: user
type: user
score: 90
- field: dest
type: system
score: 90
threat_objects:
- field: parent_process_name
type: parent_process_name
- field: process_name
type: process_name
tags:
analytic_story:
- Living Off The Land
- Ingress Tool Transfer
- ProxyNotShell
- DarkSide Ransomware
- Forest Blizzard
- Flax Typhoon
- Compromised Windows Host
- CISA AA22-277A
asset_type: Endpoint
mitre_attack_id:
- T1105
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
@@ -1,7 +1,7 @@
name: Windows Java Spawning Shells
id: 28c81306-5c47-11ec-bfea-acde48001122
version: 9
date: '2024-12-16'
version: 10
date: '2025-04-28'
author: Michael Haag, Splunk
status: experimental
type: TTP
@@ -61,6 +61,7 @@ tags:
- Log4Shell CVE-2021-44228
- SysAid On-Prem Software CVE-2023-47246 Vulnerability
- Cleo File Transfer Software
- SAP NetWeaver Exploitation
asset_type: Endpoint
cve:
- CVE-2021-44228
@@ -1,7 +1,7 @@
name: Windows Process Injection into Commonly Abused Processes
id: 1e1dedc6-f6f3-41a0-9dd7-a1245904fe75
version: 2
date: '2025-04-16'
version: 3
date: '2025-04-28'
author: 0xC0FFEEEE, Github Community
type: Anomaly
status: production
@@ -70,6 +70,7 @@ tags:
analytic_story:
- BishopFox Sliver Adversary Emulation Framework
- Earth Alux
- SAP NetWeaver Exploitation
asset_type: Endpoint
mitre_attack_id:
- T1055.002
@@ -1,7 +1,7 @@
name: Windows Process With NamedPipe CommandLine
id: e64399d4-94a8-11ec-a9da-acde48001122
version: 5
date: '2024-11-13'
version: 6
date: '2025-04-24'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -19,14 +19,13 @@ data_source:
- CrowdStrike ProcessRollup2
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process = "*\\\\.\\pipe\\*"
NOT (Processes.process_path IN ("*\\program files*")) by Processes.action Processes.dest
NOT Processes.process_path IN ("C:\\Program Files\\*", "C:\\Program Files (x86)\\*") by Processes.action Processes.dest
Processes.original_file_name Processes.parent_process Processes.parent_process_exec
Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name
Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid
Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name
Processes.process_path Processes.user Processes.user_id Processes.vendor_product
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `windows_process_with_namedpipe_commandline_filter`'
Processes.process_path Processes.user Processes.user_id Processes.vendor_product | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_process_with_namedpipe_commandline_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
and Response (EDR) agents. These agents are designed to provide security-related
telemetry from the endpoints where the agent is installed. To implement this search,
@@ -1,7 +1,7 @@
name: Windows Query Registry Browser List Application
id: 45ebd21c-f4bf-4ced-bd49-d25b6526cebb
version: '6'
date: '2025-03-19'
version: 7
date: '2025-04-24'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -16,8 +16,8 @@ description: The following analytic detects a suspicious process accessing the r
confirmed malicious, this behavior could enable attackers to exfiltrate sensitive
information and compromise user accounts.
search: '`wineventlog_security` EventCode=4663 object_file_path IN ("*\\SOFTWARE\\Clients\\StartMenuInternet\\*",
"*\\SOFTWARE\\Clients\\StartMenuInternet\\*") AND NOT (process_path IN ("*:\\Windows\\System32\\*",
"*:\\Windows\\SysWow64\\*", "*:\\Program Files*", "*:\\Windows\\*")) | stats count
"*\\SOFTWARE\\Clients\\StartMenuInternet\\*") AND NOT process_path IN ("*:\\Windows\\System32\\*",
"*:\\Windows\\SysWow64\\*", *:\\Windows\\WinSxS\\*, "*:\\Program Files\\*", "*:\\Program Files (x86)\\*") | stats count
min(_time) as firstTime max(_time) as lastTime by object_file_name object_file_path
process_name process_path process_id EventCode dest | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_query_registry_browser_list_application_filter`'
@@ -1,26 +1,25 @@
name: Windows User Execution Malicious URL Shortcut File
id: 5c7ee6ad-baf4-44fb-b2f0-0cfeddf82dbc
version: 6
date: '2025-02-10'
author: Teoderick Contreras, Splunk
version: 7
date: '2025-04-24'
author: Teoderick Contreras, Nasreddine Bencherchali, Splunk
status: production
type: TTP
description: The following analytic detects the creation of suspicious URL shortcut
link files, often used by malware like CHAOS ransomware. It leverages the Endpoint.Filesystem
datamodel to identify .url files created outside standard directories, such as Program
Files. This activity is significant as it may indicate an attempt to execute malicious
code upon system reboot. If confirmed malicious, this could allow an attacker to
achieve persistence and execute harmful payloads, potentially leading to further
system compromise and data loss.
type: Anomaly
description: The following analytic detects the creation URL shortcut files, often used by malware like CHAOS ransomware.
It leverages the Endpoint.Filesystem datamodel to identify ".url" files created outside common directories, such as "Program Files".
This activity can be significant as ".URL" files can be used as mean to trick the user into visiting certain websites unknowingly, or when placed in certain locations such as "\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\", it may allow the execution of malicious code upon system reboot. If confirmed malicious, this could allow an attacker to achieve persistence and execute harmful payloads, potentially leading to further system compromise and data loss.
data_source:
- Sysmon EventID 11
search: '|tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Filesystem where NOT(Filesystem.file_path IN
("*\\Program Files*")) Filesystem.file_name = *.url by Filesystem.action Filesystem.dest
as lastTime from datamodel=Endpoint.Filesystem where NOT Filesystem.file_path IN
("*:\\Program Files\\*", "*:\\Program Files (x86)\\*", "*\\AppData\\Roaming\\Microsoft\\Office\\Recent\\*", "*:\\Windows\\WinSxS\\*") Filesystem.file_name=*.url
by Filesystem.action Filesystem.dest
Filesystem.file_access_time Filesystem.file_create_time Filesystem.file_hash Filesystem.file_modify_time
Filesystem.file_name Filesystem.file_path Filesystem.file_acl Filesystem.file_size
Filesystem.process_guid Filesystem.process_id Filesystem.user Filesystem.vendor_product
| `drop_dm_object_name(Filesystem)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
Filesystem.process_guid Filesystem.process_id Filesystem.user Filesystem.vendor_product
| `drop_dm_object_name(Filesystem)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_user_execution_malicious_url_shortcut_file_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the Filesystem responsible for the changes from
@@ -45,14 +44,14 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: a process created URL shortcut file in $file_path$ of $dest$
message: A process created a .URL shortcut file in $file_path$ of $dest$
risk_objects:
- field: user
type: user
score: 64
score: 50
- field: dest
type: system
score: 64
score: 50
threat_objects: []
tags:
analytic_story:
@@ -1,10 +1,10 @@
name: Protocols passing authentication in cleartext
id: 6923cd64-17a0-453c-b945-81ac2d8c6db9
version: 6
date: '2024-11-15'
version: 7
date: '2025-03-03'
author: Rico Valdez, Splunk
status: experimental
type: TTP
type: Anomaly
description: The following analytic identifies the use of cleartext protocols that
risk leaking sensitive information. It detects network traffic on legacy protocols
such as Telnet (port 23), POP3 (port 110), IMAP (port 143), and non-anonymous FTP
@@ -25,8 +25,7 @@ how_to_implement: This search requires you to be ingesting your network traffic,
populating the Network_Traffic data model. For more accurate result it's better
to limit destination to organization private and public IP range, like All_Traffic.dest
IN(192.168.0.0/16,172.16.0.0/12,10.0.0.0/8, x.x.x.x/22)
known_false_positives: Some networks may use kerberized FTP or telnet servers, however,
this is rare.
known_false_positives: Some networks may use kerberos, FTP or telnet servers, however, this is rare.
references:
- https://www.rackaid.com/blog/secure-your-email-and-file-transfers/
- https://www.infosecmatter.com/capture-passwords-using-wireshark/
@@ -0,0 +1,52 @@
name: SAP NetWeaver Visual Composer Exploitation Attempt
id: a583b9f1-9c3a-4402-9441-b981654dea6c
version: 1
date: '2025-04-28'
author: Michael Haag, Splunk
status: production
type: Hunting
description: |
Detects potential exploitation attempts targeting CVE-2025-31324, a critical unauthenticated file upload vulnerability in SAP NetWeaver Visual Composer. This flaw allows remote attackers to send specially crafted POST requests to the /developmentserver/metadatauploader endpoint, enabling arbitrary file uploads—commonly webshells—resulting in full system compromise. The detection looks for HTTP HEAD or POST requests with a 200 OK status to sensitive Visual Composer endpoints, which may indicate reconnaissance or active exploitation. Successful exploitation can lead to attackers gaining privileged access, deploying malware, and impacting business-critical SAP resources. Immediate patching and investigation of suspicious activity are strongly recommended, as this vulnerability is being actively exploited in the wild.
data_source:
- Suricata
search: '| tstats count min(_time) as firstTime max(_time) as lastTime
from datamodel=Web.Web
where (Web.url IN ("/CTCWebService/CTCWebServiceBean", "/VisualComposer/services/DesignTimeService", "/ctc/CTCWebService/CTCWebServiceBean"))
AND Web.http_method IN ("HEAD", "POST")
AND Web.status=200
by Web.src, Web.dest, Web.http_method, Web.url, Web.http_user_agent, Web.url_length, sourcetype
| `drop_dm_object_name("Web")`
| eval action=case(http_method="HEAD", "Recon/Probe", http_method="POST", "Possible Exploitation")
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| table firstTime, lastTime, src, dest, http_method, action, url, user_agent, url_length, sourcetype
| `sap_netweaver_visual_composer_exploitation_attempt_filter`'
how_to_implement: |
Ensure that the Web data model is accelerated and populated with web server or web proxy logs capturing HTTP request and response data.
This search relies on HTTP method, status code, and URL path fields to identify suspicious access patterns against SAP NetWeaver endpoints.
known_false_positives: |
Some legitimate administrative activity may access SAP NetWeaver services. However, HEAD or POST requests directly resulting in a 200 OK
to Visual Composer endpoints are uncommon and should be investigated carefully.
references:
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
- https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/
- https://www.rapid7.com/blog/post/2025/04/28/etr-active-exploitation-of-sap-netweaver-visual-composer-cve-2025-31324/
tags:
analytic_story:
- SAP NetWeaver Exploitation
asset_type: Web Server
mitre_attack_id:
- T1190
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
security_domain: network
cve:
- CVE-2025-31324
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/sap/suricata_sapnetweaver.log
sourcetype: suricata
source: suricata
+94 -1
View File
@@ -1,15 +1,108 @@
filename,nirsoftFile
AdvancedRun.exe,True
awatch.exe,True
BrowsingHistoryView.exe,True
BulletsPassView.exe,True
ChromeCacheView.exe,True
ChromeHistoryView.exe,True
ChromePass.exe,True
cports.exe,True
CredentialsFileView.exe,True
CredHistView.exe,True
DataProtectionDecryptor.exe,True
DeviceIOView.exe,True
Dialupass.exe,True
dllexp.exe,True
DNSDataView.exe,True
DNSQuerySniffer.exe,True
DotNetResourcesExtract.exe,True
DownTester.exe,True
DriverView.exe,True
EncryptedRegView.exe,True
ESEDatabaseView.exe,True
EventLogChannelsView.exe,True
FastResolver.exe,True
faview.exe,True
FBCacheView.exe,True
FileTypesMan.exe,True
FirefoxDownloadsView.exe,True
FlashCookiesView.exe,True
FolderChangesView.exe,True
FolderTimeUpdate.exe,True
FullEventLogView.exe,True
gacview.exe,True
GDIView.exe,True
HeapMemView.exe,True
HTTPNetworkSniffer.exe,True
IECacheView.exe,True
iecv.exe,True
iehv.exe,True
iepv.exe,True
ImageCacheViewer.exe,True
InstalledPackagesView.exe,True
IPNetInfo.exe,True
LastActivityView.exe,True
LostMyPassword.exe,True
mailpv.exe,True
MozillaCacheView.exe,True
MozillaHistoryView.exe,True
mspass.exe,True
MyLastSearch.exe,True
mzcv.exe,True
NetBScanner.exe,True
NetConnectChoose.exe,True
netpass.exe,True
NetResView.exe,True
NetRouteView.exe,True
NetworkLatencyView.exe,True
NetworkTrafficView.exe,True
OpenedFilesView.exe,True
OperaCacheView.exe,True
PasswordFox.exe,True
PasswordHashesView.exe,True
PingInfoView.exe,True
ProcessActivityView.exe,True
ProcessThreadsView.exe,True
ProduKey.exe,True
PstPassword.exe,True
QuickSetDNS.exe,True
RegDllView.exe,True
RegFromApp.exe,True
RegHiveBackup.exe,True
WebBrowserPassView.exe,True
RegScanner.exe,True
ResourcesExtract.exe,True
RouterPassView.exe,True
RunAsDate.exe,True
SafariCacheView.exe,True
SafariHistoryView.exe,True
SearchMyFiles.exe,True
shexview.exe,True
shmnview.exe,True
SimpleProgramDebugger.exe,True
SiteShoter.exe,True
smsniff.exe,True
SniffPass.exe,True
SocketSniff.exe,True
SpecialFoldersView.exe,True
sysexp.exe,True
TaskSchedulerView.exe,True
TcpLogView.exe,True
TurnedOnTimesView.exe,True
UninstallView.exe,True
URLProtocolView.exe,True
USBDeview.exe,True
VaultPasswordView.exe,True
volumouse.exe,True
WebBrowserPassView.exe,True
WebCacheImageInfo.exe,True
WebCookiesSniffer.exe,True
WebSiteSniffer.exe,True
WhatIsHang.exe,True
WhoisTD.exe,True
WifiChannelMonitor.exe,True
WifiInfoView.exe,True
WinCrashReport.exe,True
WinLogOnView.exe,True
WirelessKeyView.exe,True
WirelessNetView.exe,True
WNetWatcher.exe,True
1 filename nirsoftFile
2 AdvancedRun.exe True
3 awatch.exe True
4 BrowsingHistoryView.exe True
5 BulletsPassView.exe True
6 ChromeCacheView.exe True
7 ChromeHistoryView.exe True
8 ChromePass.exe True
9 cports.exe True
10 CredentialsFileView.exe True
11 CredHistView.exe True
12 DataProtectionDecryptor.exe True
13 DeviceIOView.exe True
14 Dialupass.exe True
15 dllexp.exe True
16 DNSDataView.exe True
17 DNSQuerySniffer.exe True
18 DotNetResourcesExtract.exe True
19 DownTester.exe True
20 DriverView.exe True
21 EncryptedRegView.exe True
22 ESEDatabaseView.exe True
23 EventLogChannelsView.exe True
24 FastResolver.exe True
25 faview.exe True
26 FBCacheView.exe True
27 FileTypesMan.exe True
28 FirefoxDownloadsView.exe True
29 FlashCookiesView.exe True
30 FolderChangesView.exe True
31 FolderTimeUpdate.exe True
32 FullEventLogView.exe True
33 gacview.exe True
34 GDIView.exe True
35 HeapMemView.exe True
36 HTTPNetworkSniffer.exe True
37 IECacheView.exe True
38 iecv.exe True
39 iehv.exe True
40 iepv.exe True
41 ImageCacheViewer.exe True
42 InstalledPackagesView.exe True
43 IPNetInfo.exe True
44 LastActivityView.exe True
45 LostMyPassword.exe True
46 mailpv.exe True
47 MozillaCacheView.exe True
48 MozillaHistoryView.exe True
49 mspass.exe True
50 MyLastSearch.exe True
51 mzcv.exe True
52 NetBScanner.exe True
53 NetConnectChoose.exe True
54 netpass.exe True
55 NetResView.exe True
56 NetRouteView.exe True
57 NetworkLatencyView.exe True
58 NetworkTrafficView.exe True
59 OpenedFilesView.exe True
60 OperaCacheView.exe True
61 PasswordFox.exe True
62 PasswordHashesView.exe True
63 PingInfoView.exe True
64 ProcessActivityView.exe True
65 ProcessThreadsView.exe True
66 ProduKey.exe True
67 PstPassword.exe True
68 QuickSetDNS.exe True
69 RegDllView.exe True
70 RegFromApp.exe True
71 RegHiveBackup.exe True
72 WebBrowserPassView.exe RegScanner.exe True
73 ResourcesExtract.exe True
74 RouterPassView.exe True
75 RunAsDate.exe True
76 SafariCacheView.exe True
77 SafariHistoryView.exe True
78 SearchMyFiles.exe True
79 shexview.exe True
80 shmnview.exe True
81 SimpleProgramDebugger.exe True
82 SiteShoter.exe True
83 smsniff.exe True
84 SniffPass.exe True
85 SocketSniff.exe True
86 SpecialFoldersView.exe True
87 sysexp.exe True
88 TaskSchedulerView.exe True
89 TcpLogView.exe True
90 TurnedOnTimesView.exe True
91 UninstallView.exe True
92 URLProtocolView.exe True
93 USBDeview.exe True
94 VaultPasswordView.exe True
95 volumouse.exe True
96 WebBrowserPassView.exe True
97 WebCacheImageInfo.exe True
98 WebCookiesSniffer.exe True
99 WebSiteSniffer.exe True
100 WhatIsHang.exe True
101 WhoisTD.exe True
102 WifiChannelMonitor.exe True
103 WifiInfoView.exe True
104 WinCrashReport.exe True
105 WinLogOnView.exe True
106 WirelessKeyView.exe True
107 WirelessNetView.exe True
108 WNetWatcher.exe True
+2 -2
View File
@@ -1,6 +1,6 @@
name: is_nirsoft_software
date: 2024-12-23
version: 2
date: 2025-04-24
version: 3
id: 28966a08-55e4-4ccb-a20d-dc4cc154b09c
author: Splunk Threat Research Team
lookup_type: csv
+21 -1
View File
@@ -1,4 +1,24 @@
detections:
- content: Windows Remote Access Software Hunt
removed_in_version: 5.8.0
reason: Detection has been replaced by a new detection with a more specific name and logic
replacement_content:
- Detect Remote Access Software Usage Process
- content: CertUtil Download With URLCache and Split Arguments
removed_in_version: 5.8.0
reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert
replacement_content:
- Windows File Download Via CertUtil
- content: Windows CertUtil Download With URL Argument
removed_in_version: 5.8.0
reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert
replacement_content:
- Windows File Download Via CertUtil
- content: CertUtil Download With VerifyCtl and Split Arguments
removed_in_version: 5.8.0
reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert
replacement_content:
- Windows File Download Via CertUtil
- content: Detect Large Outbound ICMP Packets
removed_in_version: 5.6.0
reason: Detection has been replaced by a new detection with a more specific name
@@ -1030,4 +1050,4 @@ stories:
- Suspicious Cloud Instance Activities
- content: Web Fraud Detection
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
+28
View File
@@ -0,0 +1,28 @@
name: SAP NetWeaver Exploitation
id: a52f77e2-0632-46a5-b750-6c059bc7bbb4
version: 1
status: production
date: '2025-04-28'
author: Michael Haag, Splunk
description: |
This Analytic Story covers the detection of exploitation attempts and reconnaissance activity targeting SAP NetWeaver platforms, with a focus on the critical unauthenticated file upload vulnerability CVE-2025-31324 in Visual Composer. Attackers are actively exploiting this flaw to upload arbitrary files—often webshells—via POST requests to the /developmentserver/metadatauploader endpoint, leading to full system compromise, remote code execution, and persistent access. The story includes detections for both probing (e.g., HEAD requests) and active exploitation, and highlights the significant business risks, such as data theft, operational disruption, and potential regulatory impact. Defenders can use this story to monitor, hunt, and respond to suspicious activity across SAP NetWeaver services, helping to identify both initial access and post-exploitation behaviors.
narrative: |
Attackers are actively targeting SAP NetWeaver environments through newly disclosed vulnerabilities like CVE-2025-31324, affecting the Visual Composer service.
Successful exploitation can lead to remote code execution (RCE) and the deployment of webshells, giving adversaries persistent access to SAP systems.
This story provides detections for reconnaissance patterns (e.g., HEAD requests receiving HTTP 200 responses) and potential exploitation behavior
(e.g., POST requests leading to successful uploads), empowering defenders to quickly identify compromise attempts and mitigate them before escalation.
references:
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
- https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/
- https://www.rapid7.com/blog/post/2025/04/28/etr-active-exploitation-of-sap-netweaver-visual-composer-cve-2025-31324/
- https://www.splunk.com/en_us/blog/security/the-final-shell-introducing-shellsweepx.html
tags:
category:
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection
cve:
- CVE-2025-31324