diff --git a/detections/endpoint/ssa___disable_net_user_account.yml b/detections/endpoint/ssa___disable_net_user_account.yml deleted file mode 100644 index e7de2b496b..0000000000 --- a/detections/endpoint/ssa___disable_net_user_account.yml +++ /dev/null @@ -1,48 +0,0 @@ -name: Disable Net User Account -id: ba858b08-d26c-11eb-af9b-acde48001122 -version: 1 -date: '2021-06-21' -author: Teoderick Contreras, Splunk -type: streaming -datamodel: -- Endpoint -description: This analytic will identify a suspicious command-line that disables a - user account using the `net.exe` utility native to Windows. This technique may used - by the adversaries to interrupt availability of such users to do their malicious - act. -search: '| from read_ssa_enriched_events() - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), - process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null) - | where cmd_line IS NOT NULL AND like(cmd_line, "%/active:no%") AND (process_name="net1.exe" OR process_name="net.exe") - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed net.exe/net1.exe may be - used. -known_false_positives: network operator may use this approach to quickly disable an account but not a common practice. -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -tags: - analytic_story: - - XMRig - - Ransomware - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_dis.log - kill_chain_phases: - - Exploitation - mitre_attack_id: - - T1489 - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - security_domain: endpoint \ No newline at end of file