Branch was auto-updated.

This commit is contained in:
srv-rr-gh-researchbt
2023-05-26 11:32:11 -07:00
committed by GitHub
50 changed files with 517 additions and 355 deletions
@@ -38,12 +38,14 @@ known_false_positives: A network operator or systems administrator may utilize a
references:
- https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation
- https://attack.mitre.org/groups/G0046/
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- FIN7
- Qakbot
- CISA AA22-277A
- Qakbot
- Volt Typhoon
asset_type: Endpoint
confidence: 80
impact: 70
@@ -24,9 +24,11 @@ known_false_positives: Legitimate administrator usage of Vssadmin or Wmic will c
false positives.
references:
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
tags:
analytic_story:
- Credential Dumping
- Volt Typhoon
asset_type: Endpoint
confidence: 90
impact: 90
@@ -22,10 +22,12 @@ how_to_implement: To successfully implement this search you need to be ingesting
known_false_positives: Legtimate administrator usage of wmic to create a shadow copy.
references:
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
tags:
analytic_story:
- Credential Dumping
- Living Off The Land
- Volt Typhoon
asset_type: Endpoint
confidence: 90
impact: 90
@@ -30,7 +30,8 @@ known_false_positives: Administrators can leverage PsExec for accessing remote s
and might pass `accepteula` as an argument if they are running this tool for the
first time. However, it is not likely that you'd see multiple occurrences of this
event on a machine
references: []
references:
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
tags:
analytic_story:
- SamSam Ransomware
@@ -40,6 +41,7 @@ tags:
- Active Directory Lateral Movement
- CISA AA22-320A
- Sandworm Tools
- Volt Typhoon
- IcedID
asset_type: Endpoint
confidence: 70
@@ -22,6 +22,7 @@ known_false_positives: None identified.
references:
- https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/
- https://twitter.com/SBousseaden/status/1167417096374050817
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Industroyer2
@@ -33,6 +34,7 @@ tags:
- Living Off The Land
- Suspicious Rundll32 Activity
- Data Destruction
- Volt Typhoon
asset_type: Endpoint
confidence: 100
impact: 80
@@ -30,9 +30,11 @@ references:
- https://attack.mitre.org/techniques/T1069/002/
- https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory
- https://adsecurity.org/?p=3658
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
tags:
analytic_story:
- Active Directory Discovery
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 30
@@ -35,6 +35,7 @@ references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
- https://twitter.com/pr0xylife/status/1590394227758104576
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Azorult
@@ -56,6 +57,7 @@ tags:
- Brute Ratel C4
- Qakbot
- Chaos Ransomware
- Volt Typhoon
asset_type: Endpoint
confidence: 50
impact: 40
@@ -26,11 +26,13 @@ known_false_positives: It is possible some agent based products will generate fa
references:
- https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
tags:
analytic_story:
- DarkSide Ransomware
- Credential Dumping
- CISA AA22-257A
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 80
@@ -36,6 +36,7 @@ references:
- https://github.com/SecureAuthCorp/impacket
- https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Industroyer2
@@ -44,6 +45,7 @@ tags:
- CISA AA22-277A
- Data Destruction
- WhisperGate
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 90
@@ -27,6 +27,7 @@ references:
- https://github.com/SecureAuthCorp/impacket
- https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Industroyer2
@@ -35,6 +36,7 @@ tags:
- CISA AA22-277A
- Data Destruction
- WhisperGate
- Volt Typhoon
asset_type: Endpoint
atomic_guid: []
confidence: 70
@@ -34,6 +34,7 @@ references:
- https://github.com/SecureAuthCorp/impacket
- https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Industroyer2
@@ -42,6 +43,7 @@ tags:
- CISA AA22-277A
- Data Destruction
- WhisperGate
- Volt Typhoon
asset_type: Endpoint
atomic_guid: []
confidence: 70
@@ -39,6 +39,7 @@ references:
- https://ss64.com/ps/powershell.html
- https://twitter.com/M_haggis/status/1440758396534214658?s=20
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Hermetic Wiper
@@ -50,6 +51,7 @@ tags:
- CISA AA22-320A
- Sandworm Tools
- Data Destruction
- Volt Typhoon
asset_type: Endpoint
confidence: 50
impact: 70
@@ -25,13 +25,15 @@ how_to_implement: To successfully implement this search you need to be ingesting
known_false_positives: There may be legitimate reasons to bypass the PowerShell execution
policy. The PowerShell script being run with this parameter should be validated
to ensure that it is legitimate.
references: []
references:
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- DHS Report TA18-074A
- HAFNIUM Group
- DarkCrystal RAT
- AsyncRAT
- Volt Typhoon
asset_type: Endpoint
confidence: 60
impact: 70
@@ -26,6 +26,7 @@ known_false_positives: False positives may be present. Tune as needed.
references:
- https://attack.mitre.org/techniques/T1069/001/
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
tags:
analytic_story:
@@ -34,6 +35,7 @@ tags:
- Azorult
- Windows Post-Exploitation
- Prestige Ransomware
- Volt Typhoon
- IcedID
asset_type: Endpoint
confidence: 50
@@ -22,6 +22,7 @@ how_to_implement: To successfully implement this search you need to be ingesting
known_false_positives: Administrators or power users may use this command for troubleshooting.
references:
- https://attack.mitre.org/techniques/T1049/
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
tags:
analytic_story:
@@ -29,6 +30,7 @@ tags:
- Qakbot
- Windows Post-Exploitation
- Prestige Ransomware
- Volt Typhoon
- IcedID
asset_type: Endpoint
confidence: 50
@@ -23,6 +23,7 @@ how_to_implement: To successfully implement this search you need to be ingesting
known_false_positives: Administrators or power users may use this command for troubleshooting.
references:
- https://attack.mitre.org/techniques/T1049/
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Active Directory Discovery
@@ -30,6 +31,7 @@ tags:
- CISA AA22-277A
- Windows Post-Exploitation
- Prestige Ransomware
- Volt Typhoon
asset_type: Endpoint
confidence: 50
impact: 30
@@ -35,12 +35,14 @@ references:
- https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc753343(v=ws.11)
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
- https://strontic.github.io/xcyclopedia/library/vss_ps.dll-97B15BDAE9777F454C9A6BA25E938DB3.html
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Credential Dumping
- HAFNIUM Group
- Living Off The Land
- Prestige Ransomware
- Volt Typhoon
asset_type: Endpoint
confidence: 50
impact: 100
@@ -27,13 +27,15 @@ how_to_implement: To successfully implement this search you need to be ingesting
known_false_positives: Some VPN applications are known to launch netsh.exe. Outside
of these instances, it is unusual for an executable to launch netsh.exe and run
commands.
references: []
references:
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Netsh Abuse
- Disabling Security Tools
- DHS Report TA18-074A
- Azorult
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 20
@@ -27,11 +27,13 @@ known_false_positives: Administrators may use this legitimately to gather info f
remote systems. Filter as needed.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1047/T1047.yaml
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
tags:
analytic_story:
- Suspicious WMI Use
- Living Off The Land
- Volt Typhoon
- IcedID
asset_type: Endpoint
confidence: 60
@@ -28,6 +28,7 @@ how_to_implement: To successfully implement this search you need to be ingesting
known_false_positives: every user may do this event but very un-ussual.
references:
- https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Unusual Processes
@@ -35,6 +36,7 @@ tags:
- IcedID
- AsyncRAT
- Sandworm Tools
- Volt Typhoon
asset_type: Endpoint
confidence: 90
impact: 70
@@ -33,6 +33,7 @@ references:
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
- https://twitter.com/pr0xylife/status/1590394227758104576
- https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Azorult
@@ -55,6 +56,7 @@ tags:
- Brute Ratel C4
- Qakbot
- Chaos Ransomware
- Volt Typhoon
asset_type: Endpoint
confidence: 50
impact: 70
@@ -22,9 +22,11 @@ how_to_implement: To successfully implement this search you need to be ingesting
known_false_positives: network administrator can execute this command to enumerate DNS record. Filter or add other paths to the exclusion as needed.
references:
- https://cert.gov.ua/article/3718487
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
tags:
analytic_story:
- Sandworm Tools
- Volt Typhoon
asset_type: Endpoint
confidence: 50
impact: 50
@@ -0,0 +1,83 @@
name: Windows Ldifde Directory Object Behavior
id: 35cd29ca-f08c-4489-8815-f715c45460d3
version: 1
date: '2023-05-25'
author: Michael Haag, Splunk
status: production
type: TTP
data_source:
- Sysmon Event ID 1
description: The following analytic identifies the use of Ldifde.exe, which provides the ability to create, modify, or delete LDAP directory objects.
Natively, the binary is only installed on a domain controller. However, adversaries or administrators may install the Windows Remote Server Admin Tools for ldifde.exe.
Ldifde.exe is a Microsoft Windows command-line utility used to import or export LDAP directory entries. LDAP stands for Lightweight Directory Access Protocol, which is a protocol used for accessing and managing directory information services over an IP network. LDIF, on the other hand, stands for LDAP Data Interchange Format, a standard plain-text data interchange format for representing LDAP directory entries.
-i This is a flag used with Ldifde.exe to denote import mode. In import mode, Ldifde.exe takes an LDIF file and imports its contents into the LDAP directory. The data in the LDIF file might include new objects to be created, or modifications or deletions to existing objects.
-f This flag is used to specify the filename of the LDIF file that Ldifde.exe will import from (in the case of the -i flag) or export to (without the -i flag). For example, if you wanted to import data from a file called data.ldif, you would use the command ldifde -i -f data.ldif.
Keep in mind that while the use of Ldifde.exe is legitimate in many contexts, it can also be used maliciously. For instance, an attacker who has gained access to a domain controller could potentially use Ldifde.exe to export sensitive data or make unauthorized changes to the directory. Therefore, it's important to monitor for unusual or unauthorized use of this tool.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=ldifde.exe Processes.process IN ("*-i *", "*-f *")
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name
Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_ldifde_directory_object_behavior_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: False positives may be present, filter as needed.
references:
- https://lolbas-project.github.io/lolbas/Binaries/Ldifde/
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
- https://twitter.com/0gtweet/status/1564968845726580736?s=20
- https://strontic.github.io/xcyclopedia/library/ldifde.exe-45D28FB47E9B6ACC5DCA9FDA3E790210.html
tags:
analytic_story:
- Volt Typhoon
asset_type: Endpoint
atomic_guid:
- 22cf8cb9-adb1-4e8c-80ca-7c723dfc8784
confidence: 50
impact: 80
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ utilizing ldifde on a domain controller.
mitre_attack_id:
- T1105
- T1069.002
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: parent_process_name
type: Process
role:
- Parent Process
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 40
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/ldifde_windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -31,11 +31,13 @@ known_false_positives: False positives should be limited as this is directly loo
references:
- https://www.cisa.gov/uscert/sites/default/files/publications/aa22-320a_joint_csa_iranian_government-sponsored_apt_actors_compromise_federal%20network_deploy_crypto%20miner_credential_harvester.pdf
- https://www.varonis.com/blog/what-is-mimikatz
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
tags:
analytic_story:
- Credential Dumping
- CISA AA22-320A
- Sandworm Tools
- Volt Typhoon
asset_type: Endpoint
confidence: 100
impact: 100
@@ -1,47 +1,47 @@
name: Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos
id: 98f22d82-9d62-11eb-9fcf-acde48001122
version: 2
date: '2021-04-14'
author: Mauricio Velazco, Splunk
type: TTP
status: production
data_source:
- Windows Security 4768
date: '2021-04-14'
description: 'The following analytic identifies one source endpoint failing to authenticate
with 30 unique disabled domain users using the Kerberos protocol within 5 minutes. This behavior could
represent an adversary performing a Password Spraying attack against an Active Directory
environment using Kerberos to obtain initial access or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
As attackers
progress in a breach, mistakes will be made. In certain scenarios, adversaries may
execute a password spraying attack against disabled users. Event 4768 is generated
every time the Key Distribution Center issues a Kerberos Ticket Granting Ticket
(TGT). Failure code `0x12` stands for `clients credentials have been revoked` (account
disabled, expired or locked out).\
with 30 unique disabled domain users using the Kerberos protocol within 5 minutes.
This behavior could represent an adversary performing a Password Spraying attack
against an Active Directory environment using Kerberos to obtain initial access
or elevate privileges. Active Directory environments can be very different depending
on the organization. Users should test this detection and customize the arbitrary
threshold when needed. As attackers progress in a breach, mistakes will be made.
In certain scenarios, adversaries may execute a password spraying attack against
disabled users. Event 4768 is generated every time the Key Distribution Center issues
a Kerberos Ticket Granting Ticket (TGT). Failure code `0x12` stands for `clients
credentials have been revoked` (account disabled, expired or locked out).\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will only trigger on domain controllers, not on member servers or workstations.\
This logic can be used for real time security monitoring as well as threat hunting
exercises. This detection will only trigger on domain controllers, not on member
servers or workstations.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source ip and attempted user accounts.'
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x12
| bucket span=5m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress
| where unique_accounts > 30
| `windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
id: 98f22d82-9d62-11eb-9fcf-acde48001122
known_false_positives: A host failing to authenticate with multiple disabled domain
users is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners, multi-user systems missconfigured
systems.
name: Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos
references:
- https://attack.mitre.org/techniques/T1110/003/
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x12 | bucket
span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
as tried_accounts by _time, IpAddress | where unique_accounts > 30 | `windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos_filter`'
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Active Directory Kerberos Attacks
- Volt Typhoon
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
message: Potential Kerberos based password spraying attack from $IpAddress$
@@ -50,9 +50,9 @@ tags:
- T1110
observable:
- name: IpAddress
type: Endpoint
role:
- Attacker
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -65,10 +65,11 @@ tags:
- IpAddress
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_disabled_users_kerberos_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
sourcetype: xmlwineventlog
name: True Positive Test
type: TTP
version: 2
@@ -1,48 +1,46 @@
name: Windows Multiple Invalid Users Fail To Authenticate Using Kerberos
id: 001266a6-9d5b-11eb-829b-acde48001122
version: 2
date: '2021-04-14'
author: Mauricio Velazco, Splunk
type: TTP
status: production
data_source:
- Windows Security 4768
date: '2021-04-14'
description: 'The following analytic identifies one source endpoint failing to authenticate
with 30 unique invalid domain users using the Kerberos protocol. This behavior could
represent an adversary performing a Password Spraying attack against an Active Directory
environment using Kerberos to obtain initial access or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
As attackers
progress in a breach, mistakes will be made. In certain scenarios, adversaries may
execute a password spraying attack using an invalid list of users. Event 4768 is
generated every time the Key Distribution Center issues a Kerberos Ticket Granting
environment using Kerberos to obtain initial access or elevate privileges. Active
Directory environments can be very different depending on the organization. Users
should test this detection and customize the arbitrary threshold when needed. As
attackers progress in a breach, mistakes will be made. In certain scenarios, adversaries
may execute a password spraying attack using an invalid list of users. Event 4768
is generated every time the Key Distribution Center issues a Kerberos Ticket Granting
Ticket (TGT). Failure code 0x6 stands for `client not found in Kerberos database`
(the attempted user is not a valid domain user).\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will only trigger on domain controllers, not on member servers or
workstations.\
This logic can be used for real time security monitoring as well as threat hunting
exercises. This detection will only trigger on domain controllers, not on member
servers or workstations.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source ip and attempted user accounts.'
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x6
| bucket span=5m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress
| where unique_accounts > 30
| `windows_multiple_invalid_users_fail_to_authenticate_using_kerberos_filter` '
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
id: 001266a6-9d5b-11eb-829b-acde48001122
known_false_positives: A host failing to authenticate with multiple invalid domain
users is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners, multi-user systems and missconfigured
systems.
name: Windows Multiple Invalid Users Fail To Authenticate Using Kerberos
references:
- https://attack.mitre.org/techniques/T1110/003/
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x6 | bucket
span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
as tried_accounts by _time, IpAddress | where unique_accounts > 30 | `windows_multiple_invalid_users_fail_to_authenticate_using_kerberos_filter` '
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Active Directory Kerberos Attacks
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
message: Potential Kerberos based password spraying attack from $IpAddress$
@@ -51,9 +49,9 @@ tags:
- T1110
observable:
- name: IpAddress
type: Endpoint
role:
- Attacker
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -66,10 +64,11 @@ tags:
- IpAddress
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
sourcetype: XmlWinEventLog
name: True Positive Test
type: TTP
version: 2
@@ -1,51 +1,49 @@
name: Windows Multiple Invalid Users Failed To Authenticate Using NTLM
id: 57ad5a64-9df7-11eb-a290-acde48001122
version: 2
date: '2021-04-15'
author: Mauricio Velazco, Splunk
type: TTP
status: production
data_source:
- Windows Security 4776
date: '2021-04-15'
description: 'The following analytic identifies one source endpoint failing to authenticate
with 30 unique invalid users using the NTLM protocol. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
using NTLM to obtain initial access or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
As attackers progress
in a breach, mistakes will be made. In certain scenarios, adversaries may execute
a password spraying attack using an invalid list of users. Event 4776 is generated
on the computer that is authoritative for the provided credentials. For domain accounts,
the domain controller is authoritative. For local accounts, the local computer is
authoritative. Error code 0xC0000064 stands for `The username you typed does not
exist` (the attempted user is a legitimate domain user).\
using NTLM to obtain initial access or elevate privileges. Active Directory environments
can be very different depending on the organization. Users should test this detection
and customize the arbitrary threshold when needed. As attackers progress in a breach,
mistakes will be made. In certain scenarios, adversaries may execute a password
spraying attack using an invalid list of users. Event 4776 is generated on the computer
that is authoritative for the provided credentials. For domain accounts, the domain
controller is authoritative. For local accounts, the local computer is authoritative.
Error code 0xC0000064 stands for `The username you typed does not exist` (the attempted
user is a legitimate domain user).\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will only trigger on domain controllers, not on member servers or
workstations.\
This logic can be used for real time security monitoring as well as threat hunting
exercises. This detection will only trigger on domain controllers, not on member
servers or workstations.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source workstation name and attempted user accounts.'
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xc0000064
| bucket span=5m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, Workstation
| where unique_accounts > 30
| `windows_multiple_invalid_users_failed_to_authenticate_using_ntlm_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller events. The Advanced Security Audit policy setting `Audit Credential
Validation' within `Account Logon` needs to be enabled.
id: 57ad5a64-9df7-11eb-a290-acde48001122
known_false_positives: A host failing to authenticate with multiple invalid domain
users is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners and missconfigured systems.
If this detection triggers on a host other than a Domain Controller, the behavior
could represent a password spraying attack against the host's local accounts.
name: Windows Multiple Invalid Users Failed To Authenticate Using NTLM
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xc0000064
| bucket span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
as tried_accounts by _time, Workstation | where unique_accounts > 30 | `windows_multiple_invalid_users_failed_to_authenticate_using_ntlm_filter`'
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
message: Potential NTLM based password spraying attack from $Workstation$
@@ -54,9 +52,9 @@ tags:
- T1110
observable:
- name: Workstation
type: Endpoint
role:
- Attacker
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -69,10 +67,11 @@ tags:
- Status
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_ntlm_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
sourcetype: XmlWinEventLog
name: True Positive Test
type: TTP
version: 2
@@ -1,51 +1,50 @@
name: Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials
id: e61918fa-9ca4-11eb-836c-acde48001122
version: 2
date: '2021-04-13'
author: Mauricio Velazco, Splunk
type: TTP
status: production
data_source:
- Windows Security 4648
date: '2021-04-13'
description: 'The following analytic identifies a source user failing to authenticate
with 30 unique users using explicit credentials on a host. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
to obtain initial access or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
Event 4648 is generated when a process
attempts an account logon by explicitly specifying that accounts credentials. This
event generates on domain controllers, member servers, and workstations.\
to obtain initial access or elevate privileges. Active Directory environments can
be very different depending on the organization. Users should test this detection
and customize the arbitrary threshold when needed. Event 4648 is generated when
a process attempts an account logon by explicitly specifying that accounts credentials.
This event generates on domain controllers, member servers, and workstations.\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will trigger on the potenfially malicious host, perhaps controlled
via a trojan or operated by an insider threat, from where a password spraying attack
is being executed.\
This logic can be used for real time security monitoring as well as threat hunting
exercises. This detection will trigger on the potenfially malicious host, perhaps
controlled via a trojan or operated by an insider threat, from where a password
spraying attack is being executed.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source account, attempted user accounts and the endpoint were
the behavior was identified.'
search: ' `wineventlog_security` EventCode=4648 Caller_User_Name!=*$ Target_User_Name!=*$
| bucket span=5m _time
| stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as tried_account by _time, Computer, Caller_User_Name
| where unique_accounts > 30
| `windows_multiple_users_fail_to_authenticate_wth_explicitcredentials_filter` '
how_to_implement: To successfully implement this search, you need to be ingesting
Windows Event Logs from domain controllers as well as member servers and workstations.
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
to be enabled.
id: e61918fa-9ca4-11eb-836c-acde48001122
known_false_positives: A source user failing attempting to authenticate multiple users
on a host is not a common behavior for regular systems. Some applications, however,
may exhibit this behavior in which case sets of users hosts can be added to an allow
list. Possible false positive scenarios include systems where several users connect
to like Mail servers, identity providers, remote desktop services, Citrix, etc.
name: Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
search: ' `wineventlog_security` EventCode=4648 Caller_User_Name!=*$ Target_User_Name!=*$
| bucket span=5m _time | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name)
as tried_account by _time, Computer, Caller_User_Name | where unique_accounts >
30 | `windows_multiple_users_fail_to_authenticate_wth_explicitcredentials_filter` '
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Insider Threat
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
message: Potential password spraying attack from $Computer$
@@ -54,9 +53,9 @@ tags:
- T1110
observable:
- name: Computer
type: Endpoint
role:
- Victim
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -69,10 +68,11 @@ tags:
- Computer
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_explicit_credential_spray_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
sourcetype: XmlWinEventLog
name: True Positive Test
type: TTP
version: 2
@@ -1,49 +1,47 @@
name: Windows Multiple Users Failed To Authenticate From Host Using NTLM
id: 7ed272a4-9c77-11eb-af22-acde48001122
version: 2
date: '2021-04-13'
author: Mauricio Velazco, Splunk
type: TTP
status: production
data_source:
- Windows Security 4776
date: '2021-04-13'
description: 'The following analytic identifies one source endpoint failing to authenticate
with 30 unique valid users using the NTLM protocol. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
using NTLM to obtain initial access or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
Event 4776 is generated
on the computer that is authoritative for the provided credentials. For domain accounts,
using NTLM to obtain initial access or elevate privileges. Active Directory environments
can be very different depending on the organization. Users should test this detection
and customize the arbitrary threshold when needed. Event 4776 is generated on the
computer that is authoritative for the provided credentials. For domain accounts,
the domain controller is authoritative. For local accounts, the local computer is
authoritative. Error code 0xC000006A means: misspelled or bad password (the attempted
user is a legitimate domain user).\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will only trigger on domain controllers, not on member servers or
workstations.\
This logic can be used for real time security monitoring as well as threat hunting
exercises. This detection will only trigger on domain controllers, not on member
servers or workstations.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source workstation name and attempted user accounts.'
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xC000006A
| bucket span=5m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, Workstation
| where unique_accounts > 30
| `windows_multiple_users_failed_to_authenticate_from_host_using_ntlm_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller events. The Advanced Security Audit policy setting `Audit Credential
Validation` within `Account Logon` needs to be enabled.
id: 7ed272a4-9c77-11eb-af22-acde48001122
known_false_positives: A host failing to authenticate with multiple valid domain users
is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners and missconfigured systems.
If this detection triggers on a host other than a Domain Controller, the behavior
could represent a password spraying attack against the host's local accounts.
name: Windows Multiple Users Failed To Authenticate From Host Using NTLM
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xC000006A
| bucket span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
as tried_accounts by _time, Workstation | where unique_accounts > 30 | `windows_multiple_users_failed_to_authenticate_from_host_using_ntlm_filter`'
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
message: Potential NTLM based password spraying attack from $Workstation$
@@ -52,9 +50,9 @@ tags:
- T1110
observable:
- name: Workstation
type: Endpoint
role:
- Attacker
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -67,10 +65,11 @@ tags:
- Workstation
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_ntlm_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
sourcetype: XmlWinEventLog
name: True Positive Test
type: TTP
version: 2
@@ -1,50 +1,49 @@
name: Windows Multiple Users Failed To Authenticate From Process
id: 9015385a-9c84-11eb-bef2-acde48001122
version: 2
date: '2021-04-13'
author: Mauricio Velazco, Splunk
type: TTP
status: production
data_source:
- Windows Security 4625
date: '2021-04-13'
description: 'The following analytic identifies a source process name failing to authenticate
with 30 uniquer users. This behavior could represent an adversary performing a Password
Spraying attack against an Active Directory environment to obtain initial access
or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
Event 4625 generates on domain controllers, member servers,
or elevate privileges. Active Directory environments can be very different depending
on the organization. Users should test this detection and customize the arbitrary
threshold when needed. Event 4625 generates on domain controllers, member servers,
and workstations when an account fails to logon. Logon Type 2 describes an iteractive
logon attempt.\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will trigger on the potenfially malicious host, perhaps controlled
via a trojan or operated by an insider threat, from where a password spraying attack
is being executed. This could be a domain controller as well as a member server
or workstation.\
This logic can be used for real time security monitoring as well as threat hunting
exercises. This detection will trigger on the potenfially malicious host, perhaps
controlled via a trojan or operated by an insider threat, from where a password
spraying attack is being executed. This could be a domain controller as well as
a member server or workstation.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source process name, source account and attempted user accounts.'
search: ' `wineventlog_security` EventCode=4625 Logon_Type=2 ProcessName!="-"
| bucket span=5m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, ProcessName, SubjectUserName, Computer
| where unique_accounts > 30
| `windows_multiple_users_failed_to_authenticate_from_process_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
Windows Event Logs from domain controllers aas well as member servers and workstations.
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
to be enabled.
id: 9015385a-9c84-11eb-bef2-acde48001122
known_false_positives: A process failing to authenticate with multiple users is not
a common behavior for legitimate user sessions. Possible false positive scenarios
include but are not limited to vulnerability scanners and missconfigured systems.
name: Windows Multiple Users Failed To Authenticate From Process
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
search: ' `wineventlog_security` EventCode=4625 Logon_Type=2 ProcessName!="-" | bucket
span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
as tried_accounts by _time, ProcessName, SubjectUserName, Computer | where unique_accounts
> 30 | `windows_multiple_users_failed_to_authenticate_from_process_filter`'
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Insider Threat
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
message: Potential password spraying attack from $Computer$
@@ -53,9 +52,9 @@ tags:
- T1110
observable:
- name: ComputerName
type: Endpoint
role:
- Victim
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -70,10 +69,11 @@ tags:
- Computer
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_multiple_users_from_process_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
sourcetype: XmlWinEventLog
name: True Positive Test
type: TTP
version: 2
@@ -1,48 +1,46 @@
name: Windows Multiple Users Failed To Authenticate Using Kerberos
id: 3a91a212-98a9-11eb-b86a-acde48001122
version: 2
date: '2021-04-08'
author: Mauricio Velazco, Splunk
type: TTP
status: production
data_source:
- Windows Security 4771
date: '2021-04-08'
description: 'The following analytic identifies one source endpoint failing to authenticate
with 30 unique users using the Kerberos protocol. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
using Kerberos to obtain initial access or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
Event 4771 is generated
when the Key Distribution Center fails to issue a Kerberos Ticket Granting Ticket
(TGT). Failure code 0x18 stands for `wrong password provided` (the attempted user
is a legitimate domain user).\
using Kerberos to obtain initial access or elevate privileges. Active Directory
environments can be very different depending on the organization. Users should test
this detection and customize the arbitrary threshold when needed. Event 4771 is
generated when the Key Distribution Center fails to issue a Kerberos Ticket Granting
Ticket (TGT). Failure code 0x18 stands for `wrong password provided` (the attempted
user is a legitimate domain user).\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will only trigger on domain controllers, not on member servers or
workstations.\
This logic can be used for real time security monitoring as well as threat hunting
exercises. This detection will only trigger on domain controllers, not on member
servers or workstations.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source ip and attempted user accounts.'
search: '`wineventlog_security` EventCode=4771 TargetUserName!="*$" Status=0x18
| bucket span=5m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress
| where unique_accounts > 30
| `windows_multiple_users_failed_to_authenticate_using_kerberos_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
id: 3a91a212-98a9-11eb-b86a-acde48001122
known_false_positives: A host failing to authenticate with multiple valid domain users
is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners, missconfigured systems and
multi-user systems like Citrix farms.
name: Windows Multiple Users Failed To Authenticate Using Kerberos
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn319109(v=ws.11)
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4771
search: '`wineventlog_security` EventCode=4771 TargetUserName!="*$" Status=0x18 |
bucket span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
as tried_accounts by _time, IpAddress | where unique_accounts > 30 | `windows_multiple_users_failed_to_authenticate_using_kerberos_filter`'
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Active Directory Kerberos Attacks
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
message: Potential Kerberos based password spraying attack from $IpAddress$
@@ -51,9 +49,9 @@ tags:
- T1110
observable:
- name: IpAddress
type: Endpoint
role:
- Attacker
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -66,10 +64,11 @@ tags:
- IpAddress
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_kerberos_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
sourcetype: XmlWinEventLog
name: True Positive Test
type: TTP
version: 2
@@ -1,49 +1,48 @@
name: Windows Multiple Users Remotely Failed To Authenticate From Host
id: 80f9d53e-9ca1-11eb-b0d6-acde48001122
version: 2
date: '2021-04-13'
author: Mauricio Velazco, Splunk
type: TTP
status: production
data_source:
- Windows Security 4625
date: '2021-04-13'
description: 'The following analytic identifies a source host failing to authenticate
against a remote host with 30 unique users. This behavior could represent an adversary
performing a Password Spraying attack against an Active Directory environment to
obtain initial access or elevate privileges.
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
Event 4625 documents each and every
obtain initial access or elevate privileges. Active Directory environments can be
very different depending on the organization. Users should test this detection and
customize the arbitrary threshold when needed. Event 4625 documents each and every
failed attempt to logon to the local computer. This event generates on domain controllers,
member servers, and workstations. Logon Type 3 describes an remote authentication
attempt.\
This logic can be used for real time security monitoring as well as threat hunting exercises.
This detection will trigger on the host that is the target of the password spraying
attack. This could be a domain controller as well as a member server or workstation.\
This logic can be used for real time security monitoring as well as threat hunting
exercises. This detection will trigger on the host that is the target of the password
spraying attack. This could be a domain controller as well as a member server or
workstation.\
The analytics returned fields allow analysts to investigate the event further by
providing fields like source process name, source account and attempted user accounts.'
search: ' `wineventlog_security` EventCode=4625 Logon_Type=3 IpAddress!="-"
| bucket span=5m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress, Computer
| where unique_accounts > 30
| `windows_multiple_users_remotely_failed_to_authenticate_from_host_filter` '
how_to_implement: To successfully implement this search, you need to be ingesting
Windows Event Logs from domain controllers as as well as member servers and workstations.
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
to be enabled.
id: 80f9d53e-9ca1-11eb-b0d6-acde48001122
known_false_positives: A host failing to authenticate with multiple valid users against
a remote host is not a common behavior for legitimate systems. Possible false positive
scenarios include but are not limited to vulnerability scanners, remote administration
tools, missconfigyred systems, etc.
name: Windows Multiple Users Remotely Failed To Authenticate From Host
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
search: ' `wineventlog_security` EventCode=4625 Logon_Type=3 IpAddress!="-" | bucket
span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
as tried_accounts by _time, IpAddress, Computer | where unique_accounts > 30 | `windows_multiple_users_remotely_failed_to_authenticate_from_host_filter` '
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
message: Potential password spraying attack on $ComputerName$
@@ -52,9 +51,9 @@ tags:
- T1110
observable:
- name: ComputerName
type: Endpoint
role:
- Victim
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -68,10 +67,11 @@ tags:
- IpAddress
risk_score: 49
security_domain: endpoint
asset_type: Endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_remote_spray_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
sourcetype: XmlWinEventLog
name: True Positive Test
type: TTP
version: 2
@@ -1,10 +1,7 @@
name: Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos
id: f65aa026-b811-42ab-b4b9-d9088137648f
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
status: production
type: Anomaly
data_source:
- Windows Security 4768
date: '2022-09-22'
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple disabled domain users using the Kerberos protocol. This behavior could
represent an adversary performing a Password Spraying attack against an Active Directory
@@ -26,29 +23,29 @@ description: 'The following analytic identifies one source endpoint failing to a
The analytics returned fields allow analysts to investigate the event further by
providing fields like source ip and attempted user accounts.'
data_source:
- Windows Security 4768
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x12
| bucket span=5m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by IpAddress
| eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1
| `windows_unusual_count_of_disabled_users_failed_auth_using_kerberos_filter` '
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
id: f65aa026-b811-42ab-b4b9-d9088137648f
known_false_positives: A host failing to authenticate with multiple disabled domain
users is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners, multi-user systems missconfigured
systems.
name: Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos
references:
- https://attack.mitre.org/techniques/T1110/003/
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x12 | bucket
span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
as tried_accounts by _time, IpAddress | eventstats avg(unique_accounts) as comp_avg
, stdev(unique_accounts) as comp_std by IpAddress | eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1 | `windows_unusual_count_of_disabled_users_failed_auth_using_kerberos_filter` '
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Active Directory Kerberos Attacks
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
@@ -58,9 +55,9 @@ tags:
- T1110
observable:
- name: IpAddress
type: Endpoint
role:
- Attacker
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -74,8 +71,10 @@ tags:
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_disabled_users_kerberos_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
name: True Positive Test
type: Anomaly
version: 1
@@ -1,10 +1,7 @@
name: Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos
id: f122cb2e-d773-4f11-8399-62a3572d8dd7
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
status: production
type: Anomaly
data_source:
- Windows Security 4768
date: '2022-09-22'
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple invalid domain users using the Kerberos protocol. This behavior could
represent an adversary performing a Password Spraying attack against an Active Directory
@@ -26,29 +23,29 @@ description: 'The following analytic identifies one source endpoint failing to a
The analytics returned fields allow analysts to investigate the event further by
providing fields like source ip and attempted user accounts.'
data_source:
- Windows Security 4768
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x6
| bucket span=5m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by IpAddress
| eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1
| `windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos_filter` '
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
id: f122cb2e-d773-4f11-8399-62a3572d8dd7
known_false_positives: A host failing to authenticate with multiple invalid domain
users is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners, multi-user systems and missconfigured
systems.
name: Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos
references:
- https://attack.mitre.org/techniques/T1110/003/
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x6 | bucket
span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
as tried_accounts by _time, IpAddress | eventstats avg(unique_accounts) as comp_avg
, stdev(unique_accounts) as comp_std by IpAddress | eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1 | `windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos_filter` '
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Active Directory Kerberos Attacks
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
@@ -58,9 +55,9 @@ tags:
- T1110
observable:
- name: IpAddress
type: Endpoint
role:
- Attacker
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -74,8 +71,10 @@ tags:
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
name: True Positive Test
type: Anomaly
version: 1
@@ -1,10 +1,7 @@
name: Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM
id: 15603165-147d-4a6e-9778-bd0ff39e668f
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
status: production
type: Anomaly
data_source:
- Windows Security 4776
date: '2022-09-22'
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple invalid users using the NTLM protocol. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
@@ -27,31 +24,31 @@ description: 'The following analytic identifies one source endpoint failing to a
The analytics returned fields allow analysts to investigate the event further by
providing fields like source workstation name and attempted user accounts.'
data_source:
- Windows Security 4776
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xc0000064
| bucket span=2m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, Workstation
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Workstation
| eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1
| `windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller events. The Advanced Security Audit policy setting `Audit Credential
Validation' within `Account Logon` needs to be enabled.
id: 15603165-147d-4a6e-9778-bd0ff39e668f
known_false_positives: A host failing to authenticate with multiple invalid domain
users is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners and missconfigured systems.
If this detection triggers on a host other than a Domain Controller, the behavior
could represent a password spraying attack against the host's local accounts.
name: Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xc0000064
| bucket span=2m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
as tried_accounts by _time, Workstation | eventstats avg(unique_accounts) as comp_avg
, stdev(unique_accounts) as comp_std by Workstation | eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1 | `windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm_filter`'
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
@@ -61,9 +58,9 @@ tags:
- T1110
observable:
- name: Workstation
type: Endpoint
role:
- Attacker
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -77,8 +74,10 @@ tags:
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_ntlm_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
name: True Positive Test
type: Anomaly
version: 1
@@ -1,10 +1,7 @@
name: Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials
id: 14f414cf-3080-4b9b-aaf6-55a4ce947b93
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
status: production
type: Anomaly
data_source:
- Windows Security 4648
date: '2022-09-22'
description: 'The following analytic identifies a source user failing to authenticate
with multiple users using explicit credentials on a host. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
@@ -25,33 +22,33 @@ description: 'The following analytic identifies a source user failing to authent
The analytics returned fields allow analysts to investigate the event further by
providing fields like source account, attempted user accounts and the endpoint were
the behavior was identified.'
data_source:
- Windows Security 4648
search: ' `wineventlog_security` EventCode=4648 Caller_User_Name!=*$ Target_User_Name!=*$
| bucket span=5m _time
| stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as tried_account by _time, Computer, Caller_User_Name
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Computer
| eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1
| `windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials_filter` '
how_to_implement: To successfully implement this search, you need to be ingesting
Windows Event Logs from domain controllers as well as member servers and workstations.
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
to be enabled.
id: 14f414cf-3080-4b9b-aaf6-55a4ce947b93
known_false_positives: A source user failing attempting to authenticate multiple users
on a host is not a common behavior for regular systems. Some applications, however,
may exhibit this behavior in which case sets of users hosts can be added to an allow
list. Possible false positive scenarios include systems where several users connect
to like Mail servers, identity providers, remote desktop services, Citrix, etc.
name: Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
search: ' `wineventlog_security` EventCode=4648 Caller_User_Name!=*$ Target_User_Name!=*$
| bucket span=5m _time | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name)
as tried_account by _time, Computer, Caller_User_Name | eventstats avg(unique_accounts)
as comp_avg , stdev(unique_accounts) as comp_std by Computer | eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1 | `windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials_filter` '
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Insider Threat
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
@@ -61,9 +58,9 @@ tags:
- T1110
observable:
- name: Computer
type: Endpoint
role:
- Attacker
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -77,8 +74,10 @@ tags:
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_explicit_credential_spray_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
name: True Positive Test
type: Anomaly
version: 1
@@ -1,10 +1,7 @@
name: Windows Unusual Count Of Users Failed To Auth Using Kerberos
id: bc9cb715-08ba-40c3-9758-6e2b26e455cb
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
status: production
type: Anomaly
data_source:
- Windows Security 4771
date: '2022-09-22'
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple valid users using the Kerberos protocol. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
@@ -24,31 +21,31 @@ description: 'The following analytic identifies one source endpoint failing to a
The analytics returned fields allow analysts to investigate the event further by
providing fields like source ip and attempted user accounts.'
data_source:
- Windows Security 4771
search: '`wineventlog_security` EventCode=4771 TargetUserName!="*$" Status=0x18
| bucket span=5m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by IpAddress
| eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1
| `windows_unusual_count_of_users_failed_to_auth_using_kerberos_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
id: bc9cb715-08ba-40c3-9758-6e2b26e455cb
known_false_positives: A host failing to authenticate with multiple valid domain users
is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners, missconfigured systems and
multi-user systems like Citrix farms.
name: Windows Unusual Count Of Users Failed To Auth Using Kerberos
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn319109(v=ws.11)
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4771
search: '`wineventlog_security` EventCode=4771 TargetUserName!="*$" Status=0x18 |
bucket span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
as tried_accounts by _time, IpAddress | eventstats avg(unique_accounts) as comp_avg
, stdev(unique_accounts) as comp_std by IpAddress | eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1 | `windows_unusual_count_of_users_failed_to_auth_using_kerberos_filter`'
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Active Directory Kerberos Attacks
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
@@ -58,9 +55,9 @@ tags:
- T1110
observable:
- name: IpAddress
type: Endpoint
role:
- Attacker
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -74,8 +71,10 @@ tags:
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_kerberos_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
name: True Positive Test
type: Anomaly
version: 1
@@ -1,10 +1,7 @@
name: Windows Unusual Count Of Users Failed To Authenticate From Process
id: 25bdb6cb-2e49-4d34-a93c-d6c567c122fe
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
status: production
type: Anomaly
data_source:
- Windows Security 4625
date: '2022-09-22'
description: 'The following analytic identifies a source process name failing to authenticate
with multiple users. This behavior could represent an adversary performing a Password
Spraying attack against an Active Directory environment to obtain initial access
@@ -25,32 +22,32 @@ description: 'The following analytic identifies a source process name failing to
The analytics returned fields allow analysts to investigate the event further by
providing fields like source process name, source account and attempted user accounts.'
data_source:
- Windows Security 4625
search: ' `wineventlog_security` EventCode=4625 Logon_Type=2 ProcessName!="-"
| bucket span=2m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, ProcessName, SubjectUserName, Computer
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by ProcessName, SubjectUserName, Computer
| eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1
| `windows_unusual_count_of_users_failed_to_authenticate_from_process_filter` '
how_to_implement: To successfully implement this search, you need to be ingesting
Windows Event Logs from domain controllers aas well as member servers and workstations.
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
to be enabled.
id: 25bdb6cb-2e49-4d34-a93c-d6c567c122fe
known_false_positives: A process failing to authenticate with multiple users is not
a common behavior for legitimate user sessions. Possible false positive scenarios
include but are not limited to vulnerability scanners and missconfigured systems.
name: Windows Unusual Count Of Users Failed To Authenticate From Process
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
search: ' `wineventlog_security` EventCode=4625 Logon_Type=2 ProcessName!="-" | bucket
span=2m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
as tried_accounts by _time, ProcessName, SubjectUserName, Computer | eventstats
avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by ProcessName,
SubjectUserName, Computer | eval upperBound=(comp_avg+comp_std*3) | eval isOutlier=if(unique_accounts
> 10 and unique_accounts >= upperBound, 1, 0) | search isOutlier=1 | `windows_unusual_count_of_users_failed_to_authenticate_from_process_filter` '
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Insider Threat
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
@@ -60,9 +57,9 @@ tags:
- T1110
observable:
- name: Computer
type: Endpoint
role:
- Attacker
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -78,8 +75,10 @@ tags:
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_multiple_users_from_process_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
name: True Positive Test
type: Anomaly
version: 1
@@ -1,10 +1,7 @@
name: Windows Unusual Count Of Users Failed To Authenticate Using NTLM
id: 6f6c8fd7-6a6b-4af9-a0e9-57cfc47a58b4
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
status: production
type: Anomaly
data_source:
- Windows Security 4776
date: '2022-09-22'
description: 'The following analytic identifies one source endpoint failing to authenticate
with multiple valid users using the NTLM protocol. This behavior could represent
an adversary performing a Password Spraying attack against an Active Directory environment
@@ -25,31 +22,31 @@ description: 'The following analytic identifies one source endpoint failing to a
The analytics returned fields allow analysts to investigate the event further by
providing fields like source workstation name and attempted user accounts.'
data_source:
- Windows Security 4776
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xC000006A
| bucket span=2m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, Workstation
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Workstation
| eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1
| `windows_unusual_count_of_users_failed_to_authenticate_using_ntlm_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
Domain Controller events. The Advanced Security Audit policy setting `Audit Credential
Validation` within `Account Logon` needs to be enabled.
id: 6f6c8fd7-6a6b-4af9-a0e9-57cfc47a58b4
known_false_positives: A host failing to authenticate with multiple valid domain users
is not a common behavior for legitimate systems. Possible false positive scenarios
include but are not limited to vulnerability scanners and missconfigured systems.
If this detection triggers on a host other than a Domain Controller, the behavior
could represent a password spraying attack against the host's local accounts.
name: Windows Unusual Count Of Users Failed To Authenticate Using NTLM
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xC000006A
| bucket span=2m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
as tried_accounts by _time, Workstation | eventstats avg(unique_accounts) as comp_avg
, stdev(unique_accounts) as comp_std by Workstation | eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1 | `windows_unusual_count_of_users_failed_to_authenticate_using_ntlm_filter`'
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
@@ -59,9 +56,9 @@ tags:
- T1110
observable:
- name: Workstation
type: Endpoint
role:
- Attacker
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -75,8 +72,10 @@ tags:
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_ntlm_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
name: True Positive Test
type: Anomaly
version: 1
@@ -1,10 +1,7 @@
name: Windows Unusual Count Of Users Remotely Failed To Auth From Host
id: cf06a0ee-ffa9-4ed3-be77-0670ed9bab52
version: 1
date: '2022-09-22'
author: Mauricio Velazco, Splunk
status: production
type: Anomaly
data_source:
- Windows Security 4625
date: '2022-09-22'
description: 'The following analytic identifies a source host failing to authenticate
against a remote host with multiple users. This behavior could represent an adversary
performing a Password Spraying attack against an Active Directory environment to
@@ -24,32 +21,32 @@ description: 'The following analytic identifies a source host failing to authent
The analytics returned fields allow analysts to investigate the event further by
providing fields like source process name, source account and attempted user accounts.'
data_source:
- Windows Security 4625
search: ' `wineventlog_security` EventCode=4625 Logon_Type=3 IpAddress!="-"
| bucket span=2m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress, Computer
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by IpAddress, Computer
| eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1
| `windows_unusual_count_of_users_remotely_failed_to_auth_from_host_filter` '
how_to_implement: To successfully implement this search, you need to be ingesting
Windows Event Logs from domain controllers as as well as member servers and workstations.
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
to be enabled.
id: cf06a0ee-ffa9-4ed3-be77-0670ed9bab52
known_false_positives: A host failing to authenticate with multiple valid users against
a remote host is not a common behavior for legitimate systems. Possible false positive
scenarios include but are not limited to vulnerability scanners, remote administration
tools, missconfigyred systems, etc.
name: Windows Unusual Count Of Users Remotely Failed To Auth From Host
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
search: ' `wineventlog_security` EventCode=4625 Logon_Type=3 IpAddress!="-" | bucket
span=2m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
as tried_accounts by _time, IpAddress, Computer | eventstats avg(unique_accounts)
as comp_avg , stdev(unique_accounts) as comp_std by IpAddress, Computer | eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
| search isOutlier=1 | `windows_unusual_count_of_users_remotely_failed_to_auth_from_host_filter` '
status: production
tags:
analytic_story:
- Active Directory Password Spraying
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 70
@@ -59,9 +56,9 @@ tags:
- T1110
observable:
- name: Computer
type: Endpoint
role:
- Attacker
type: Endpoint
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -76,8 +73,10 @@ tags:
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_remote_spray_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
name: True Positive Test
type: Anomaly
version: 1
@@ -28,11 +28,13 @@ known_false_positives: Administrators may execute this command for testing or au
references:
- https://github.com/NVISOsecurity/sigma-public/blob/master/rules/windows/process_creation/win_susp_wmi_execution.yml
- https://github.com/redcanaryco/atomic-red-team/blob/2b804d25418004a5f1ba50e9dc637946ab8733c7/atomics/T1047/T1047.md
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
tags:
analytic_story:
- Suspicious WMI Use
- Qakbot
- Volt Typhoon
- IcedID
asset_type: Endpoint
confidence: 50
@@ -32,10 +32,12 @@ how_to_implement: To successfully implement this search you need to be ingesting
known_false_positives: Legtimate administrator usage of wmic to create a shadow copy.
references:
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
tags:
analytic_story:
- Credential Dumping
- Living Off The Land
- Volt Typhoon
asset_type: Endpoint
confidence: 90
impact: 90
@@ -39,9 +39,11 @@ references:
- https://attack.mitre.org/techniques/T1069/002/
- https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory
- https://adsecurity.org/?p=3658
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
tags:
analytic_story:
- Active Directory Discovery
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 30
@@ -34,11 +34,13 @@ known_false_positives: It is possible some agent based products will generate fa
references:
- https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
tags:
analytic_story:
- DarkSide Ransomware
- Credential Dumping
- CISA AA22-257A
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 80
@@ -36,6 +36,7 @@ references:
- https://github.com/SecureAuthCorp/impacket
- https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Active Directory Lateral Movement
@@ -43,6 +44,7 @@ tags:
- Industroyer2
- CISA AA22-277A
- Prestige Ransomware
- Volt Typhoon
asset_type: Endpoint
confidence: 70
impact: 90
@@ -26,6 +26,7 @@ known_false_positives: False positives may be present. Tune as needed.
references:
- https://attack.mitre.org/techniques/T1069/001/
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
tags:
analytic_story:
- Active Directory Discovery
@@ -33,6 +34,7 @@ tags:
- Azorult
- Windows Post-Exploitation
- Prestige Ransomware
- Volt Typhoon
asset_type: Endpoint
confidence: 50
impact: 30
+2
View File
@@ -36,12 +36,14 @@ references:
- https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc753343(v=ws.11)
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
- https://strontic.github.io/xcyclopedia/library/vss_ps.dll-97B15BDAE9777F454C9A6BA25E938DB3.html
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Credential Dumping
- HAFNIUM Group
- Living Off The Land
- Prestige Ransomware
- Ntdsutil Export NTDS
asset_type: Endpoint
confidence: 50
impact: 100
@@ -31,10 +31,12 @@ known_false_positives: False positives should be limited as this is directly loo
references:
- https://www.cisa.gov/uscert/sites/default/files/publications/aa22-320a_joint_csa_iranian_government-sponsored_apt_actors_compromise_federal%20network_deploy_crypto%20miner_credential_harvester.pdf
- https://www.varonis.com/blog/what-is-mimikatz
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
tags:
analytic_story:
- Credential Dumping
- CISA AA22-320A
- Volt Typhoon
asset_type: Endpoint
confidence: 100
impact: 100
@@ -37,11 +37,13 @@ references:
- https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc753343(v=ws.11)
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
- https://strontic.github.io/xcyclopedia/library/vss_ps.dll-97B15BDAE9777F454C9A6BA25E938DB3.html
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Credential Dumping
- HAFNIUM Group
- Living Off The Land
- Volt Typhoon
asset_type: Endpoint
confidence: 50
impact: 100
+26
View File
@@ -0,0 +1,26 @@
name: Volt Typhoon
id: f73010e4-49eb-44ef-9f3f-2c25a1ae5415
version: 1
date: '2023-05-25'
author: Teoderick Contreras, Splunk
description: This analytic story contains detections that allow security analysts to detect and investigate unusual activities that might relate to the "Volt Typhoon" group targeting critical infrastructure organizations in United States and Guam. The affected organizations include the communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education sectors. This Analytic story looks for suspicious process execution, lolbin execution, command-line activity, lsass dump and many more.
narrative: Volt Typhoon is a state sponsored group typically focuses on espionage and information gathering.\
Based on Microsoft Threat Intelligence, This threat actor group puts strong emphasis on stealth in this campaign by relying almost exclusively on living-off-the-land techniques and hands-on-keyboard activity. \
They issue commands via the command line to :\
(1) collect data, including credentials from local and network systems, \
(2) put the data into an archive file to stage it for exfiltration, and then \
(3) use the stolen valid credentials to maintain persistence. \
In addition, Volt Typhoon tries to blend into normal network activity by routing traffic through compromised small office and home office (SOHO) network equipment, including routers, firewalls, and VPN hardware. They have also been observed using custom versions of open-source tools to establish a command and control (C2) channel over proxy to further stay under the radar.
references:
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story: Volt Typhoon
category:
- Data Destruction
- Malware
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection