Branch was auto-updated.

This commit is contained in:
srv-rr-gh-researchbt
2022-10-18 11:42:36 -07:00
committed by GitHub
26 changed files with 349 additions and 29 deletions
@@ -89,8 +89,13 @@
"app_number": 3110,
"app_version": "4.5.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-cloud-services_450.tgz"
}
},
},
"SPLUNK_TA_FOR_IIS": {
"app_number": 3185,
"app_version": "1.2.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-iis_120.tgz"
}
},
"branch": "BRANCH_DOES_NOT_EXIST_USE_CLI_ARGUMENT",
"commit_hash": null,
"container_tag": "latest",
@@ -35,6 +35,8 @@ tags:
- Ingress Tool Transfer
- DarkSide Ransomware
- Living Off The Land
- ProxyNotShell
- CISA AA22-277A
confidence: 100
context:
- Source:Endpoint
@@ -38,6 +38,7 @@ tags:
- Living Off The Land
- Azorult
- DarkCrystal RAT
- ProxyNotShell
automated_detection_testing: passed
confidence: 50
context:
@@ -36,6 +36,7 @@ references:
tags:
analytic_story:
- FIN7
- CISA AA22-277A
confidence: 80
context:
- Source:Endpoint
@@ -26,6 +26,7 @@ references:
tags:
analytic_story:
- Hidden Cobra Malware
- CISA AA22-277A
asset_type: Endpoint
cis20:
- CIS 8
@@ -1,14 +1,14 @@
name: Detect Exchange Web Shell
id: 8c14eeee-2af1-4a4b-bda8-228da0f4862a
version: 3
date: '2021-10-05'
version: 4
date: '2022-09-30'
author: Michael Haag, Shannon Davis, David Dorsey, Splunk
type: TTP
datamodel:
- Endpoint
description: 'The following query identifies suspicious .aspx created in 3 paths identified
by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM
group and recently disclosed vulnerablity named ProxyShell. Paths include: `\HttpProxy\owa\auth\`,
group and recently disclosed vulnerablity named ProxyShell and ProxyNotShell. Paths include: `\HttpProxy\owa\auth\`,
`\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. Upon triage, the suspicious
.aspx file will likely look obvious on the surface. inspect the contents for script
code inside. Identify additional log sources, IIS included, to review source and
@@ -30,7 +30,7 @@ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint
Processes.dest | `drop_dm_object_name(Processes)` | join process_guid, _time [|
tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*",
"*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name="*.aspx"
"*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name IN( "*.aspx", "*.ashx")
by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name
Filesystem.file_path | `drop_dm_object_name(Filesystem)` | fields _time dest file_create_time
file_name file_path process_name process_path process] | dedup file_create_time
@@ -52,6 +52,7 @@ tags:
- HAFNIUM Group
- ProxyShell
- CISA AA22-257A
- ProxyNotShell
confidence: 90
context:
- Source:Endpoint
@@ -30,6 +30,7 @@ references:
tags:
analytic_story:
- Collection and Staging
- CISA AA22-277A
confidence: 90
context:
- Source:Endpoint
@@ -1,7 +1,7 @@
name: Detect SharpHound File Modifications
id: 42b4b438-beed-11eb-ba1d-acde48001122
version: 1
date: '2021-05-27'
version: 2
date: '2022-10-09'
author: Michael Haag, Splunk
type: TTP
datamodel:
@@ -22,7 +22,7 @@ description: SharpHound is used as a reconnaissance collector, ingestor, for Blo
`.ps1` ingestor will be PowerShell.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*bloodhound.zip",
"*_computers.json", "*_gpos.json", "*_domains.json", "*_users.json", "*_groups.json")
"*_computers.json", "*_gpos.json", "*_domains.json", "*_users.json", "*_groups.json", "*_ous.json", "*_containers.json")
by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.file_path
Filesystem.dest | `drop_dm_object_name(Filesystem)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `detect_sharphound_file_modifications_filter`'
@@ -29,6 +29,7 @@ tags:
- Azorult
- CISA AA22-264A
- AgentTesla
- CISA AA22-277A
confidence: 70
context:
- Source:Endpoint
@@ -1,14 +1,12 @@
name: Exchange PowerShell Module Usage
id: 2d10095e-05ae-11ec-8fdf-acde48001122
version: 3
date: '2022-09-22'
version: 4
date: '2022-10-05'
author: Michael Haag, Splunk
type: TTP
datamodel: []
description: 'The following analytic identifies the usage of Exchange PowerShell modules
that were recently used for a proof of concept related to ProxyShell. Currently,
there is no active data shared or data we could re-produce relate to this part of
the ProxyShell chain of exploits. \
that were recently used for a proof of concept related to ProxyShell. Adversaries may abuse a limited set of PwSh Modules related to Exchange once gained access via ProxyShell or ProxyNotShell.\
Inherently, the usage of the modules is not malicious, but reviewing parallel processes,
and user, of the session will assist with determining the intent. \
@@ -40,22 +38,26 @@ references:
- https://www.cisa.gov/uscert/ncas/alerts/aa22-264a
- https://learn.microsoft.com/en-us/powershell/module/exchange/new-mailboxsearch?view=exchange-ps
- https://learn.microsoft.com/en-us/powershell/module/exchange/get-recipient?view=exchange-ps
- https://thedfirreport.com/2022/03/21/apt35-automates-initial-access-using-proxyshell/
tags:
analytic_story:
- ProxyShell
- CISA AA22-264A
- ProxyNotShell
- CISA AA22-277A
asset_type: Endpoint
confidence: 50
confidence: 80
context:
- Source:Endpoint
- Stage:Discovery
- Stage:Recon
dataset: []
impact: 30
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/exchange/windows-powershell.log
impact: 40
kill_chain_phases:
- Reconnaissance
- Exploitation
message: Local user discovery enumeration using PowerShell on $dest$ by $user$
message: Suspicious Exchange PowerShell module usaged was identified on $dest$.
mitre_attack_id:
- T1059
- T1059.001
@@ -75,5 +77,5 @@ tags:
- Computer
- UserID
- EventCode
risk_score: 15
risk_score: 32
security_domain: endpoint
@@ -40,6 +40,7 @@ tags:
- Active Directory Lateral Movement
- WhisperGate
- Industroyer2
- CISA AA22-277A
confidence: 70
context:
- Source:Endpoint
@@ -25,6 +25,7 @@ references:
tags:
analytic_story:
- Active Directory Discovery
- CISA AA22-277A
confidence: 50
context:
- Source:Endpoint
@@ -28,6 +28,7 @@ references:
tags:
analytic_story:
- Active Directory Discovery
- CISA AA22-277A
confidence: 30
context:
- Source:Endpoint
@@ -1,9 +1,9 @@
name: Unified Messaging Service Spawning a Process
id: f1126df0-7bd5-11eb-988f-acde48001122
version: 1
date: '2021-03-02'
version: 2
date: '2022-10-03'
author: Michael Haag, Splunk
type: TTP
type: Anomaly
datamodel:
- Endpoint
description: This detection identifies Microsoft Exchange Server's Unified Messaging
@@ -17,8 +17,7 @@ description: This detection identifies Microsoft Exchange Server's Unified Messa
public access to Exchange. In final, patch the vulnerablity and monitor.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="umworkerprocess.exe"
OR Processes.parent_process_name="UMService.exe" (Processes.process_name!="wermgr.exe"
OR Processes.process_name!="werfault.exe") by Processes.dest Processes.user Processes.parent_process
OR Processes.parent_process_name="UMService.exe" NOT (Processes.process_name IN ("wermgr.exe", "werfault.exe")) by Processes.dest Processes.user Processes.parent_process_name
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `unified_messaging_service_spawning_a_process_filter`'
@@ -35,6 +34,8 @@ references:
tags:
analytic_story:
- HAFNIUM Group
- ProxyShell
- ProxyNotShell
confidence: 80
context:
- Source:Endpoint
@@ -39,6 +39,7 @@ tags:
- HAFNIUM Group
- ProxyShell
- CISA AA22-257A
- ProxyNotShell
- CISA AA22-264A
confidence: 80
context:
@@ -0,0 +1,64 @@
name: Windows Create Local Account
id: 3fb2e8e3-7bc0-4567-9722-c5ab9f8595eb
version: 1
date: '2022-10-05'
author: Michael Haag, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic identifies a new local user account added to a computer. Note that, this should be restricted to critical assets.
search: '| tstats `security_content_summariesonly` values(All_Changes.result_id) as
result_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Change
where All_Changes.result_id=4720 by
All_Changes.user All_Changes.dest All_Changes.result All_Changes.action | `drop_dm_object_name("All_Changes")` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)`
| `windows_create_local_account_filter`'
how_to_implement: 'This search requires you to have enabled your Group Management
Audit Logs in your Local Windows Security Policy and be ingesting those logs. More
information on how to enable them can be found here: http://whatevernetworks.com/auditing-group-membership-changes-in-active-directory/'
known_false_positives: It is possible that an administrator created the account. Verifying activity with an administrator is advised. This analytic is set to anomaly to allow for risk to be added. Filter and tune as needed. Restrict to critical infrastructure to reduce any volume.
references:
- https://thedfirreport.com/2022/03/21/apt35-automates-initial-access-using-proxyshell/
tags:
analytic_story:
- Account Monitoring and Controls
asset_type: Endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 90
context:
- Source:Endpoint
- Stage:Persistence
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/4720.log
impact: 20
kill_chain_phases:
- Installation
- Actions on Objectives
message: The following $user$ was added to $dest$ as a local account.
mitre_attack_id:
- T1136.001
- T1136
nist:
- DE.CM
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- All_Changes.user
- All_Changes.dest
- All_Changes.result
- All_Changes.action
risk_score: 18
security_domain: endpoint
@@ -1,12 +1,12 @@
name: Exchange PowerShell Abuse via SSRF
id: 29228ab4-0762-11ec-94aa-acde48001122
version: 1
date: '2021-08-27'
version: 2
date: '2022-10-02'
author: Michael Haag, Splunk
type: TTP
datamodel: []
description: 'This analytic identifies suspicious behavior related to ProxyShell against
on-premise Microsoft Exchange servers. \
on-premise Microsoft Exchange servers. This analytic has been replaced by GUID d436f9e7-0ee7-4a47-864b-6dea2c4e2752 which utilizes the Web Datamodel. \
Modification of this analytic is requried to ensure fields are mapped accordingly.
\
@@ -20,7 +20,7 @@ description: 'This analytic identifies suspicious behavior related to ProxyShell
Review the source attempting to perform this activity against your environment.
In addition, review PowerShell logs and access recently granted to Exchange roles.'
search: '| `exchange` c_uri="*//autodiscover.json*" cs_uri_query="*PowerShell*" cs_method="POST"
search: '`exchange` c_uri="*//autodiscover*" cs_uri_query="*PowerShell*" cs_method="POST"
| stats count min(_time) as firstTime max(_time) as lastTime by dest, cs_uri_query,
cs_method, c_uri | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `exchange_powershell_abuse_via_ssrf_filter`'
@@ -35,6 +35,7 @@ references:
tags:
analytic_story:
- ProxyShell
- ProxyNotShell
asset_type: Endpoint
confidence: 100
context:
@@ -0,0 +1,60 @@
name: ProxyShell ProxyNotShell Behavior Detected
id: c32fab32-6aaf-492d-bfaf-acbed8e50cdf
version: 1
date: '2022-10-03'
author: Michael Haag, Splunk
type: Correlation
datamodel:
- Risk
description: The following correlation will identify activity related to Windows Exchange being actively exploited by adversaries related to ProxyShell or ProxyNotShell. In addition, the analytic correlates post-exploitation Cobalt Strike analytic story. Common post-exploitation behavior has been seen in the wild includes adversaries running nltest, Cobalt Strike, Mimikatz and adding a new user. The correlation specifically looks for 5 distict analyticstories to trigger, modify or tune as needed for your organization.
5 analytic stories is an arbitrary number but was chosen to reduce the amount of noise but also require the 3 analytic stories to fire. Adversaries will exploit the vulnerable Exchange server, abuse SSRF, drop a web shell, utilize the PowerShell Exchange modules and begin post-exploitation.
search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime sum(All_Risk.calculated_risk_score) as risk_score, count(All_Risk.calculated_risk_score) as risk_event_count, values(All_Risk.annotations.mitre_attack.mitre_tactic_id) as annotations.mitre_attack.mitre_tactic_id, dc(All_Risk.annotations.mitre_attack.mitre_tactic_id) as mitre_tactic_id_count, values(All_Risk.analyticstories) as analyticstories values(All_Risk.annotations.mitre_attack.mitre_technique_id) as annotations.mitre_attack.mitre_technique_id, dc(All_Risk.annotations.mitre_attack.mitre_technique_id) as mitre_technique_id_count, values(All_Risk.tag) as tag, values(source) as source, dc(source) as source_count dc(All_Risk.analyticstories) as dc_analyticstories from datamodel=Risk.All_Risk where All_Risk.analyticstories IN ("ProxyNotShell","ProxyShell", "Cobalt Strike") All_Risk.risk_object_type="system" by _time span=1h All_Risk.risk_object All_Risk.risk_object_type
| `drop_dm_object_name(All_Risk)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| where dc_analyticstories >= 5
| `proxyshell_proxynotshell_behavior_detected_filter`'
how_to_implement: To implement this correlation, you will need to enable ProxyShell, ProxyNotShell and Cobalt Strike analytic stories (the anaytics themselves) and ensure proper data is being collected for Web and Endpoint datamodels. Run the correlation rule seperately to validate it is not triggering too much or generating incorrectly. Validate by running ProxyShell POC code and Cobalt Strike behavior.
known_false_positives: False positives will be limited, however tune or modify the query as needed.
references:
- https://www.gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html
- https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
tags:
analytic_story:
- ProxyShell
- ProxyNotShell
asset_type: Web Server
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 90
context:
- Scope:Network
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/proxyshell/proxyshell-risk.log
impact: 90
kill_chain_phases:
- Exploitation
message: ProxyShell or ProxyNotShell activity has been identified on $risk_object$.
mitre_attack_id:
- T1190
nist:
- DE.CM
observable:
- name: risk_object
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- All_Risk.analyticstories
- All_Risk.risk_object_type
- All_Risk.risk_object
- All_Risk.annotations.mitre_attack.mitre_tactic
- source
risk_score: 81
security_domain: network
@@ -0,0 +1,82 @@
name: Windows Exchange Autodiscover SSRF Abuse
id: d436f9e7-0ee7-4a47-864b-6dea2c4e2752
version: 1
date: '2022-10-03'
author: Michael Haag, Splunk
type: TTP
datamodel:
- Web
description: The following analytic utilizes the Web datamodel and identifies the ProxyShell or ProxyNotShell abuse. This vulnerability is a Server Side Request Forgery (SSRF) vulnerability, which is a web vulnerability that allows an adversary to exploit vulnerable functionality to access server side or local network services by affectively traversing the external firewall using vulnerable web functionality. This analytic looks for the URI path and query of autodiscover, powershell and mapi along with a POST occurring. It will tally a simple score and show the output of the events that match.
This analytic may be added to by simply creating a new eval statement and modifying the hardcode digit for Score.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Web where (Web.status=200 OR Web.status=302 OR Web.status=401) AND Web.http_method=POST by Web.src Web.status Web.uri_path Web.dest Web.http_method Web.uri_query
| `drop_dm_object_name("Web")`
| eval is_autodiscover=if(like(lower(uri_path),"%autodiscover%"),1,0)
| eval powershell = if(match(lower(uri_query),"powershell"), "1",0)
| eval mapi=if(like(uri_query,"%/mapi/%"),1,0)
| addtotals fieldname=Score is_autodiscover, powershell, mapi
| fields Score, src,dest, status, uri_query,uri_path,http_method
| where Score >= 2
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_exchange_autodiscover_ssrf_abuse_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on Web traffic, Exchange OR IIS logs, mapped to `Web` datamodel in the `Web` node. In addition, confirm the latest CIM App 4.20 or higher is installed.
known_false_positives: False positives are limited.
references:
- https://www.gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html
- https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
- https://twitter.com/GossiTheDog/status/1575762721353916417?s=20&t=67gq9xCWuyPm1VEm8ydfyA
- https://twitter.com/cglyer/status/1575793769814728705?s=20&t=67gq9xCWuyPm1VEm8ydfyA
- https://www.gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html
- https://research.splunk.com/stories/proxyshell/
- https://docs.splunk.com/Documentation/AddOns/released/MSIIS
- https://highon.coffee/blog/ssrf-cheat-sheet/
- https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/
tags:
cve:
- CVE-2021-34523
- CVE-2021-34473
- CVE-2021-31207
- CVE-2022-41040
- CVE-2022-41082
analytic_story:
- ProxyShell
- ProxyNotShell
asset_type: Web server
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 80
context:
- Scope:Network
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/proxyshell/proxyshell.log
impact: 90
kill_chain_phases:
- Exploitation
message: Activity related to ProxyShell or ProxyNotShell has been identified on $dest$. Review events
and take action accordingly.
mitre_attack_id:
- T1190
nist:
- DE.CM
observable:
- name: dest
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Web.src
- Web.status
- Web.uri_path
- Web.dest
- Web.http_method
- Web.uri_query
risk_score: 72
security_domain: network
+2 -1
View File
@@ -25,4 +25,5 @@ NLAChecker.exe,A scanner tool that checks for Windows hosts for Network Level Au
ns.exe,A commonly used tool used by attackers to scan and map file shares
SilverBullet.exe,Malware was discovered in our monitoring of honey pots that abuses this open source software for scanning and connecting to hosts.
kportscan3.exe, KPortScan 3.0 is a widely used port scanning tool on Hacking Forums to perform network scanning on the internal networks.
advanced_port_scanner.exe, Advanced Port Scanner is a free network scanner allowing you to quickly find open ports on network computers and retrieve versions of programs running on the detected ports.
advanced_port_scanner.exe,Advanced Port Scanner is a free network scanner allowing you to quickly find open ports on network computers and retrieve versions of programs running on the detected ports.
mimikatz.exe,utility Mimikatz is an open-source application that allows users to view and save authentication credentials such as Kerberos tickets.
1 attacker_tool_names description
25 ns.exe A commonly used tool used by attackers to scan and map file shares
26 SilverBullet.exe Malware was discovered in our monitoring of honey pots that abuses this open source software for scanning and connecting to hosts.
27 kportscan3.exe KPortScan 3.0 is a widely used port scanning tool on Hacking Forums to perform network scanning on the internal networks.
28 advanced_port_scanner.exe Advanced Port Scanner is a free network scanner allowing you to quickly find open ports on network computers and retrieve versions of programs running on the detected ports.
29 mimikatz.exe utility Mimikatz is an open-source application that allows users to view and save authentication credentials such as Kerberos tickets.
+19
View File
@@ -0,0 +1,19 @@
name: CISA AA22-277A
id: db408f93-e915-4215-9962-5fada348bdd7
version: 1
date: '2022-10-05'
author: Michael Haag, Splunk
description: From November 2021 through January 2022, the Cybersecurity and Infrastructure Security Agency (CISA) responded to advanced persistent threat (APT) activity on a Defense Industrial Base (DIB) Sector organization's enterprise network. During incident response activities, multiple utilities were utilized.
narrative: CISA uncovered that likely multiple APT groups compromised the organization's network, and some APT actors had long-term access to the environment. APT actors used an open-source toolkit called Impacket to gain their foothold within the environment and further compromise the network, and also used a custom data exfiltration tool, CovalentStealer, to steal the victim's sensitive data.
references:
- https://www.cisa.gov/uscert/ncas/alerts/aa22-277a
- https://www.cisa.gov/uscert/sites/default/files/publications/aa22-277a-impacket-and-exfiltration-tool-used-to-steal-sensitive-information-from-defense-industrial-base-organization.pdf
tags:
analytic_story: CISA AA22-277A
category:
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection
+22
View File
@@ -0,0 +1,22 @@
name: ProxyNotShell
id: 4e3f17e7-9ed7-425d-a05e-b65464945836
version: 1
date: '2022-09-30'
author: Michael Haag, Splunk
description: Two new zero day Microsoft Exchange vulnerabilities have been identified actively exploited in the wild - CVE-2022-41040 and CVE-2022-41082.
narrative: Microsoft is investigating two reported zero-day vulnerabilities affecting Microsoft Exchange Server 2013, 2016, and 2019. The first vulnerability, identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, while the second, identified as CVE-2022-41082, allows remote code execution (RCE) when PowerShell is accessible to the attacker. Originally identified by GTSC monitoring Exchange, some adversary post-exploitation activity was identified and is tagged to this story.
references:
- https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
- https://twitter.com/GossiTheDog/status/1575762721353916417?s=20&t=67gq9xCWuyPm1VEm8ydfyA
- https://twitter.com/cglyer/status/1575793769814728705?s=20&t=67gq9xCWuyPm1VEm8ydfyA
- https://www.gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html
- https://research.splunk.com/stories/proxyshell/
tags:
analytic_story: ProxyNotShell
category:
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection
@@ -0,0 +1,12 @@
name: Exchange PowerShell Module Usage Unit Test
tests:
- name: Exchange PowerShell Module Usage
file: endpoint/exchange_powershell_module_usage.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-powershell.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/exchange/windows-powershell.log
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
sourcetype: XmlWinEventLog
@@ -0,0 +1,13 @@
name: Windows Create Local Account Unit Test
tests:
- name: Windows Create Local Account
file: endpoint/windows_create_local_account.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: 4720.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1136.001/atomic_red_team/4720.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
update_timestamp: true
@@ -0,0 +1,13 @@
name: ProxyShell ProxyNotShell Behavior Detected Unit Test
tests:
- name: ProxyShell ProxyNotShell Behavior Detected
file: web/proxyshell_proxynotshell_behavior_detected.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: proxyshell-risk.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/proxyshell/proxyshell-risk.log
source: proxyshell
sourcetype: stash
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows Exchange Autodiscover SSRF Abuse Unit Test
tests:
- name: Windows Exchange Autodiscover SSRF Abuse
file: web/windows_exchange_autodiscover_ssrf_abuse.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: proxyshell.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/proxyshell/proxyshell.log
source: ms:iis:splunk
sourcetype: ms:iis:splunk
update_timestamp: true