mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -38,12 +38,14 @@ known_false_positives: A network operator or systems administrator may utilize a
|
||||
references:
|
||||
- https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation
|
||||
- https://attack.mitre.org/groups/G0046/
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- FIN7
|
||||
- Qakbot
|
||||
- CISA AA22-277A
|
||||
- Qakbot
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 70
|
||||
|
||||
@@ -24,9 +24,11 @@ known_false_positives: Legitimate administrator usage of Vssadmin or Wmic will c
|
||||
false positives.
|
||||
references:
|
||||
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 90
|
||||
|
||||
@@ -22,10 +22,12 @@ how_to_implement: To successfully implement this search you need to be ingesting
|
||||
known_false_positives: Legtimate administrator usage of wmic to create a shadow copy.
|
||||
references:
|
||||
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- Living Off The Land
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 90
|
||||
|
||||
@@ -30,7 +30,8 @@ known_false_positives: Administrators can leverage PsExec for accessing remote s
|
||||
and might pass `accepteula` as an argument if they are running this tool for the
|
||||
first time. However, it is not likely that you'd see multiple occurrences of this
|
||||
event on a machine
|
||||
references: []
|
||||
references:
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
tags:
|
||||
analytic_story:
|
||||
- SamSam Ransomware
|
||||
@@ -40,6 +41,7 @@ tags:
|
||||
- Active Directory Lateral Movement
|
||||
- CISA AA22-320A
|
||||
- Sandworm Tools
|
||||
- Volt Typhoon
|
||||
- IcedID
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
|
||||
@@ -22,6 +22,7 @@ known_false_positives: None identified.
|
||||
references:
|
||||
- https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/
|
||||
- https://twitter.com/SBousseaden/status/1167417096374050817
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
@@ -33,6 +34,7 @@ tags:
|
||||
- Living Off The Land
|
||||
- Suspicious Rundll32 Activity
|
||||
- Data Destruction
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
|
||||
@@ -30,9 +30,11 @@ references:
|
||||
- https://attack.mitre.org/techniques/T1069/002/
|
||||
- https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory
|
||||
- https://adsecurity.org/?p=3658
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Discovery
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 30
|
||||
|
||||
@@ -35,6 +35,7 @@ references:
|
||||
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
- https://twitter.com/pr0xylife/status/1590394227758104576
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Azorult
|
||||
@@ -56,6 +57,7 @@ tags:
|
||||
- Brute Ratel C4
|
||||
- Qakbot
|
||||
- Chaos Ransomware
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 40
|
||||
|
||||
@@ -26,11 +26,13 @@ known_false_positives: It is possible some agent based products will generate fa
|
||||
references:
|
||||
- https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
tags:
|
||||
analytic_story:
|
||||
- DarkSide Ransomware
|
||||
- Credential Dumping
|
||||
- CISA AA22-257A
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 80
|
||||
|
||||
@@ -36,6 +36,7 @@ references:
|
||||
- https://github.com/SecureAuthCorp/impacket
|
||||
- https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
@@ -44,6 +45,7 @@ tags:
|
||||
- CISA AA22-277A
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 90
|
||||
|
||||
@@ -27,6 +27,7 @@ references:
|
||||
- https://github.com/SecureAuthCorp/impacket
|
||||
- https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
@@ -35,6 +36,7 @@ tags:
|
||||
- CISA AA22-277A
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
|
||||
@@ -34,6 +34,7 @@ references:
|
||||
- https://github.com/SecureAuthCorp/impacket
|
||||
- https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
@@ -42,6 +43,7 @@ tags:
|
||||
- CISA AA22-277A
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
|
||||
@@ -39,6 +39,7 @@ references:
|
||||
- https://ss64.com/ps/powershell.html
|
||||
- https://twitter.com/M_haggis/status/1440758396534214658?s=20
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
@@ -50,6 +51,7 @@ tags:
|
||||
- CISA AA22-320A
|
||||
- Sandworm Tools
|
||||
- Data Destruction
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 70
|
||||
|
||||
@@ -25,13 +25,15 @@ how_to_implement: To successfully implement this search you need to be ingesting
|
||||
known_false_positives: There may be legitimate reasons to bypass the PowerShell execution
|
||||
policy. The PowerShell script being run with this parameter should be validated
|
||||
to ensure that it is legitimate.
|
||||
references: []
|
||||
references:
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- DHS Report TA18-074A
|
||||
- HAFNIUM Group
|
||||
- DarkCrystal RAT
|
||||
- AsyncRAT
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 60
|
||||
impact: 70
|
||||
|
||||
@@ -26,6 +26,7 @@ known_false_positives: False positives may be present. Tune as needed.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1069/001/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
|
||||
tags:
|
||||
analytic_story:
|
||||
@@ -34,6 +35,7 @@ tags:
|
||||
- Azorult
|
||||
- Windows Post-Exploitation
|
||||
- Prestige Ransomware
|
||||
- Volt Typhoon
|
||||
- IcedID
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
|
||||
@@ -22,6 +22,7 @@ how_to_implement: To successfully implement this search you need to be ingesting
|
||||
known_false_positives: Administrators or power users may use this command for troubleshooting.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1049/
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
|
||||
tags:
|
||||
analytic_story:
|
||||
@@ -29,6 +30,7 @@ tags:
|
||||
- Qakbot
|
||||
- Windows Post-Exploitation
|
||||
- Prestige Ransomware
|
||||
- Volt Typhoon
|
||||
- IcedID
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
|
||||
@@ -23,6 +23,7 @@ how_to_implement: To successfully implement this search you need to be ingesting
|
||||
known_false_positives: Administrators or power users may use this command for troubleshooting.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1049/
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Discovery
|
||||
@@ -30,6 +31,7 @@ tags:
|
||||
- CISA AA22-277A
|
||||
- Windows Post-Exploitation
|
||||
- Prestige Ransomware
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 30
|
||||
|
||||
@@ -35,12 +35,14 @@ references:
|
||||
- https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc753343(v=ws.11)
|
||||
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
|
||||
- https://strontic.github.io/xcyclopedia/library/vss_ps.dll-97B15BDAE9777F454C9A6BA25E938DB3.html
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- HAFNIUM Group
|
||||
- Living Off The Land
|
||||
- Prestige Ransomware
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 100
|
||||
|
||||
@@ -27,13 +27,15 @@ how_to_implement: To successfully implement this search you need to be ingesting
|
||||
known_false_positives: Some VPN applications are known to launch netsh.exe. Outside
|
||||
of these instances, it is unusual for an executable to launch netsh.exe and run
|
||||
commands.
|
||||
references: []
|
||||
references:
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Netsh Abuse
|
||||
- Disabling Security Tools
|
||||
- DHS Report TA18-074A
|
||||
- Azorult
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 20
|
||||
|
||||
@@ -27,11 +27,13 @@ known_false_positives: Administrators may use this legitimately to gather info f
|
||||
remote systems. Filter as needed.
|
||||
references:
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1047/T1047.yaml
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious WMI Use
|
||||
- Living Off The Land
|
||||
- Volt Typhoon
|
||||
- IcedID
|
||||
asset_type: Endpoint
|
||||
confidence: 60
|
||||
|
||||
@@ -28,6 +28,7 @@ how_to_implement: To successfully implement this search you need to be ingesting
|
||||
known_false_positives: every user may do this event but very un-ussual.
|
||||
references:
|
||||
- https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Unusual Processes
|
||||
@@ -35,6 +36,7 @@ tags:
|
||||
- IcedID
|
||||
- AsyncRAT
|
||||
- Sandworm Tools
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 70
|
||||
|
||||
@@ -33,6 +33,7 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
- https://twitter.com/pr0xylife/status/1590394227758104576
|
||||
- https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Azorult
|
||||
@@ -55,6 +56,7 @@ tags:
|
||||
- Brute Ratel C4
|
||||
- Qakbot
|
||||
- Chaos Ransomware
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 70
|
||||
|
||||
@@ -22,9 +22,11 @@ how_to_implement: To successfully implement this search you need to be ingesting
|
||||
known_false_positives: network administrator can execute this command to enumerate DNS record. Filter or add other paths to the exclusion as needed.
|
||||
references:
|
||||
- https://cert.gov.ua/article/3718487
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
tags:
|
||||
analytic_story:
|
||||
- Sandworm Tools
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -0,0 +1,83 @@
|
||||
name: Windows Ldifde Directory Object Behavior
|
||||
id: 35cd29ca-f08c-4489-8815-f715c45460d3
|
||||
version: 1
|
||||
date: '2023-05-25'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
data_source:
|
||||
- Sysmon Event ID 1
|
||||
description: The following analytic identifies the use of Ldifde.exe, which provides the ability to create, modify, or delete LDAP directory objects.
|
||||
Natively, the binary is only installed on a domain controller. However, adversaries or administrators may install the Windows Remote Server Admin Tools for ldifde.exe.
|
||||
Ldifde.exe is a Microsoft Windows command-line utility used to import or export LDAP directory entries. LDAP stands for Lightweight Directory Access Protocol, which is a protocol used for accessing and managing directory information services over an IP network. LDIF, on the other hand, stands for LDAP Data Interchange Format, a standard plain-text data interchange format for representing LDAP directory entries.
|
||||
-i This is a flag used with Ldifde.exe to denote import mode. In import mode, Ldifde.exe takes an LDIF file and imports its contents into the LDAP directory. The data in the LDIF file might include new objects to be created, or modifications or deletions to existing objects.
|
||||
-f This flag is used to specify the filename of the LDIF file that Ldifde.exe will import from (in the case of the -i flag) or export to (without the -i flag). For example, if you wanted to import data from a file called data.ldif, you would use the command ldifde -i -f data.ldif.
|
||||
Keep in mind that while the use of Ldifde.exe is legitimate in many contexts, it can also be used maliciously. For instance, an attacker who has gained access to a domain controller could potentially use Ldifde.exe to export sensitive data or make unauthorized changes to the directory. Therefore, it's important to monitor for unusual or unauthorized use of this tool.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=ldifde.exe Processes.process IN ("*-i *", "*-f *")
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_ldifde_directory_object_behavior_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: False positives may be present, filter as needed.
|
||||
references:
|
||||
- https://lolbas-project.github.io/lolbas/Binaries/Ldifde/
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
- https://twitter.com/0gtweet/status/1564968845726580736?s=20
|
||||
- https://strontic.github.io/xcyclopedia/library/ldifde.exe-45D28FB47E9B6ACC5DCA9FDA3E790210.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
atomic_guid:
|
||||
- 22cf8cb9-adb1-4e8c-80ca-7c723dfc8784
|
||||
confidence: 50
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ utilizing ldifde on a domain controller.
|
||||
mitre_attack_id:
|
||||
- T1105
|
||||
- T1069.002
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
role:
|
||||
- Victim
|
||||
- name: dest
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
- name: parent_process_name
|
||||
type: Process
|
||||
role:
|
||||
- Parent Process
|
||||
- name: process_name
|
||||
type: Process
|
||||
role:
|
||||
- Child Process
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 40
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/ldifde_windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
@@ -31,11 +31,13 @@ known_false_positives: False positives should be limited as this is directly loo
|
||||
references:
|
||||
- https://www.cisa.gov/uscert/sites/default/files/publications/aa22-320a_joint_csa_iranian_government-sponsored_apt_actors_compromise_federal%20network_deploy_crypto%20miner_credential_harvester.pdf
|
||||
- https://www.varonis.com/blog/what-is-mimikatz
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- CISA AA22-320A
|
||||
- Sandworm Tools
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 100
|
||||
|
||||
+29
-28
@@ -1,47 +1,47 @@
|
||||
name: Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos
|
||||
id: 98f22d82-9d62-11eb-9fcf-acde48001122
|
||||
version: 2
|
||||
date: '2021-04-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
type: TTP
|
||||
status: production
|
||||
data_source:
|
||||
- Windows Security 4768
|
||||
date: '2021-04-14'
|
||||
description: 'The following analytic identifies one source endpoint failing to authenticate
|
||||
with 30 unique disabled domain users using the Kerberos protocol within 5 minutes. This behavior could
|
||||
represent an adversary performing a Password Spraying attack against an Active Directory
|
||||
environment using Kerberos to obtain initial access or elevate privileges.
|
||||
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
|
||||
As attackers
|
||||
progress in a breach, mistakes will be made. In certain scenarios, adversaries may
|
||||
execute a password spraying attack against disabled users. Event 4768 is generated
|
||||
every time the Key Distribution Center issues a Kerberos Ticket Granting Ticket
|
||||
(TGT). Failure code `0x12` stands for `clients credentials have been revoked` (account
|
||||
disabled, expired or locked out).\
|
||||
with 30 unique disabled domain users using the Kerberos protocol within 5 minutes.
|
||||
This behavior could represent an adversary performing a Password Spraying attack
|
||||
against an Active Directory environment using Kerberos to obtain initial access
|
||||
or elevate privileges. Active Directory environments can be very different depending
|
||||
on the organization. Users should test this detection and customize the arbitrary
|
||||
threshold when needed. As attackers progress in a breach, mistakes will be made.
|
||||
In certain scenarios, adversaries may execute a password spraying attack against
|
||||
disabled users. Event 4768 is generated every time the Key Distribution Center issues
|
||||
a Kerberos Ticket Granting Ticket (TGT). Failure code `0x12` stands for `clients
|
||||
credentials have been revoked` (account disabled, expired or locked out).\
|
||||
|
||||
This logic can be used for real time security monitoring as well as threat hunting exercises.
|
||||
This detection will only trigger on domain controllers, not on member servers or workstations.\
|
||||
This logic can be used for real time security monitoring as well as threat hunting
|
||||
exercises. This detection will only trigger on domain controllers, not on member
|
||||
servers or workstations.\
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source ip and attempted user accounts.'
|
||||
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x12
|
||||
| bucket span=5m _time
|
||||
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress
|
||||
| where unique_accounts > 30
|
||||
| `windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
|
||||
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
|
||||
id: 98f22d82-9d62-11eb-9fcf-acde48001122
|
||||
known_false_positives: A host failing to authenticate with multiple disabled domain
|
||||
users is not a common behavior for legitimate systems. Possible false positive scenarios
|
||||
include but are not limited to vulnerability scanners, multi-user systems missconfigured
|
||||
systems.
|
||||
name: Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x12 | bucket
|
||||
span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
|
||||
as tried_accounts by _time, IpAddress | where unique_accounts > 30 | `windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos_filter`'
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Active Directory Kerberos Attacks
|
||||
- Volt Typhoon
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
message: Potential Kerberos based password spraying attack from $IpAddress$
|
||||
@@ -50,9 +50,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: IpAddress
|
||||
type: Endpoint
|
||||
role:
|
||||
- Attacker
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -65,10 +65,11 @@ tags:
|
||||
- IpAddress
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
asset_type: Endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_disabled_users_kerberos_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: xmlwineventlog
|
||||
sourcetype: xmlwineventlog
|
||||
name: True Positive Test
|
||||
type: TTP
|
||||
version: 2
|
||||
|
||||
+24
-25
@@ -1,48 +1,46 @@
|
||||
name: Windows Multiple Invalid Users Fail To Authenticate Using Kerberos
|
||||
id: 001266a6-9d5b-11eb-829b-acde48001122
|
||||
version: 2
|
||||
date: '2021-04-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
type: TTP
|
||||
status: production
|
||||
data_source:
|
||||
- Windows Security 4768
|
||||
date: '2021-04-14'
|
||||
description: 'The following analytic identifies one source endpoint failing to authenticate
|
||||
with 30 unique invalid domain users using the Kerberos protocol. This behavior could
|
||||
represent an adversary performing a Password Spraying attack against an Active Directory
|
||||
environment using Kerberos to obtain initial access or elevate privileges.
|
||||
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
|
||||
As attackers
|
||||
progress in a breach, mistakes will be made. In certain scenarios, adversaries may
|
||||
execute a password spraying attack using an invalid list of users. Event 4768 is
|
||||
generated every time the Key Distribution Center issues a Kerberos Ticket Granting
|
||||
environment using Kerberos to obtain initial access or elevate privileges. Active
|
||||
Directory environments can be very different depending on the organization. Users
|
||||
should test this detection and customize the arbitrary threshold when needed. As
|
||||
attackers progress in a breach, mistakes will be made. In certain scenarios, adversaries
|
||||
may execute a password spraying attack using an invalid list of users. Event 4768
|
||||
is generated every time the Key Distribution Center issues a Kerberos Ticket Granting
|
||||
Ticket (TGT). Failure code 0x6 stands for `client not found in Kerberos database`
|
||||
(the attempted user is not a valid domain user).\
|
||||
|
||||
This logic can be used for real time security monitoring as well as threat hunting exercises.
|
||||
This detection will only trigger on domain controllers, not on member servers or
|
||||
workstations.\
|
||||
This logic can be used for real time security monitoring as well as threat hunting
|
||||
exercises. This detection will only trigger on domain controllers, not on member
|
||||
servers or workstations.\
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source ip and attempted user accounts.'
|
||||
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x6
|
||||
| bucket span=5m _time
|
||||
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress
|
||||
| where unique_accounts > 30
|
||||
| `windows_multiple_invalid_users_fail_to_authenticate_using_kerberos_filter` '
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
|
||||
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
|
||||
id: 001266a6-9d5b-11eb-829b-acde48001122
|
||||
known_false_positives: A host failing to authenticate with multiple invalid domain
|
||||
users is not a common behavior for legitimate systems. Possible false positive scenarios
|
||||
include but are not limited to vulnerability scanners, multi-user systems and missconfigured
|
||||
systems.
|
||||
name: Windows Multiple Invalid Users Fail To Authenticate Using Kerberos
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x6 | bucket
|
||||
span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
|
||||
as tried_accounts by _time, IpAddress | where unique_accounts > 30 | `windows_multiple_invalid_users_fail_to_authenticate_using_kerberos_filter` '
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Active Directory Kerberos Attacks
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
message: Potential Kerberos based password spraying attack from $IpAddress$
|
||||
@@ -51,9 +49,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: IpAddress
|
||||
type: Endpoint
|
||||
role:
|
||||
- Attacker
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -66,10 +64,11 @@ tags:
|
||||
- IpAddress
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
asset_type: Endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: TTP
|
||||
version: 2
|
||||
|
||||
+27
-28
@@ -1,51 +1,49 @@
|
||||
name: Windows Multiple Invalid Users Failed To Authenticate Using NTLM
|
||||
id: 57ad5a64-9df7-11eb-a290-acde48001122
|
||||
version: 2
|
||||
date: '2021-04-15'
|
||||
author: Mauricio Velazco, Splunk
|
||||
type: TTP
|
||||
status: production
|
||||
data_source:
|
||||
- Windows Security 4776
|
||||
date: '2021-04-15'
|
||||
description: 'The following analytic identifies one source endpoint failing to authenticate
|
||||
with 30 unique invalid users using the NTLM protocol. This behavior could represent
|
||||
an adversary performing a Password Spraying attack against an Active Directory environment
|
||||
using NTLM to obtain initial access or elevate privileges.
|
||||
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
|
||||
As attackers progress
|
||||
in a breach, mistakes will be made. In certain scenarios, adversaries may execute
|
||||
a password spraying attack using an invalid list of users. Event 4776 is generated
|
||||
on the computer that is authoritative for the provided credentials. For domain accounts,
|
||||
the domain controller is authoritative. For local accounts, the local computer is
|
||||
authoritative. Error code 0xC0000064 stands for `The username you typed does not
|
||||
exist` (the attempted user is a legitimate domain user).\
|
||||
using NTLM to obtain initial access or elevate privileges. Active Directory environments
|
||||
can be very different depending on the organization. Users should test this detection
|
||||
and customize the arbitrary threshold when needed. As attackers progress in a breach,
|
||||
mistakes will be made. In certain scenarios, adversaries may execute a password
|
||||
spraying attack using an invalid list of users. Event 4776 is generated on the computer
|
||||
that is authoritative for the provided credentials. For domain accounts, the domain
|
||||
controller is authoritative. For local accounts, the local computer is authoritative.
|
||||
Error code 0xC0000064 stands for `The username you typed does not exist` (the attempted
|
||||
user is a legitimate domain user).\
|
||||
|
||||
This logic can be used for real time security monitoring as well as threat hunting exercises.
|
||||
This detection will only trigger on domain controllers, not on member servers or
|
||||
workstations.\
|
||||
This logic can be used for real time security monitoring as well as threat hunting
|
||||
exercises. This detection will only trigger on domain controllers, not on member
|
||||
servers or workstations.\
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source workstation name and attempted user accounts.'
|
||||
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xc0000064
|
||||
| bucket span=5m _time
|
||||
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, Workstation
|
||||
| where unique_accounts > 30
|
||||
| `windows_multiple_invalid_users_failed_to_authenticate_using_ntlm_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Domain Controller events. The Advanced Security Audit policy setting `Audit Credential
|
||||
Validation' within `Account Logon` needs to be enabled.
|
||||
id: 57ad5a64-9df7-11eb-a290-acde48001122
|
||||
known_false_positives: A host failing to authenticate with multiple invalid domain
|
||||
users is not a common behavior for legitimate systems. Possible false positive scenarios
|
||||
include but are not limited to vulnerability scanners and missconfigured systems.
|
||||
If this detection triggers on a host other than a Domain Controller, the behavior
|
||||
could represent a password spraying attack against the host's local accounts.
|
||||
name: Windows Multiple Invalid Users Failed To Authenticate Using NTLM
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776
|
||||
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xc0000064
|
||||
| bucket span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
|
||||
as tried_accounts by _time, Workstation | where unique_accounts > 30 | `windows_multiple_invalid_users_failed_to_authenticate_using_ntlm_filter`'
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
message: Potential NTLM based password spraying attack from $Workstation$
|
||||
@@ -54,9 +52,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: Workstation
|
||||
type: Endpoint
|
||||
role:
|
||||
- Attacker
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -69,10 +67,11 @@ tags:
|
||||
- Status
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
asset_type: Endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_ntlm_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: TTP
|
||||
version: 2
|
||||
|
||||
+25
-25
@@ -1,51 +1,50 @@
|
||||
name: Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials
|
||||
id: e61918fa-9ca4-11eb-836c-acde48001122
|
||||
version: 2
|
||||
date: '2021-04-13'
|
||||
author: Mauricio Velazco, Splunk
|
||||
type: TTP
|
||||
status: production
|
||||
data_source:
|
||||
- Windows Security 4648
|
||||
date: '2021-04-13'
|
||||
description: 'The following analytic identifies a source user failing to authenticate
|
||||
with 30 unique users using explicit credentials on a host. This behavior could represent
|
||||
an adversary performing a Password Spraying attack against an Active Directory environment
|
||||
to obtain initial access or elevate privileges.
|
||||
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
|
||||
Event 4648 is generated when a process
|
||||
attempts an account logon by explicitly specifying that accounts credentials. This
|
||||
event generates on domain controllers, member servers, and workstations.\
|
||||
to obtain initial access or elevate privileges. Active Directory environments can
|
||||
be very different depending on the organization. Users should test this detection
|
||||
and customize the arbitrary threshold when needed. Event 4648 is generated when
|
||||
a process attempts an account logon by explicitly specifying that accounts credentials.
|
||||
This event generates on domain controllers, member servers, and workstations.\
|
||||
|
||||
This logic can be used for real time security monitoring as well as threat hunting exercises.
|
||||
This detection will trigger on the potenfially malicious host, perhaps controlled
|
||||
via a trojan or operated by an insider threat, from where a password spraying attack
|
||||
is being executed.\
|
||||
This logic can be used for real time security monitoring as well as threat hunting
|
||||
exercises. This detection will trigger on the potenfially malicious host, perhaps
|
||||
controlled via a trojan or operated by an insider threat, from where a password
|
||||
spraying attack is being executed.\
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source account, attempted user accounts and the endpoint were
|
||||
the behavior was identified.'
|
||||
search: ' `wineventlog_security` EventCode=4648 Caller_User_Name!=*$ Target_User_Name!=*$
|
||||
| bucket span=5m _time
|
||||
| stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as tried_account by _time, Computer, Caller_User_Name
|
||||
| where unique_accounts > 30
|
||||
| `windows_multiple_users_fail_to_authenticate_wth_explicitcredentials_filter` '
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Windows Event Logs from domain controllers as well as member servers and workstations.
|
||||
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
|
||||
to be enabled.
|
||||
id: e61918fa-9ca4-11eb-836c-acde48001122
|
||||
known_false_positives: A source user failing attempting to authenticate multiple users
|
||||
on a host is not a common behavior for regular systems. Some applications, however,
|
||||
may exhibit this behavior in which case sets of users hosts can be added to an allow
|
||||
list. Possible false positive scenarios include systems where several users connect
|
||||
to like Mail servers, identity providers, remote desktop services, Citrix, etc.
|
||||
name: Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
|
||||
search: ' `wineventlog_security` EventCode=4648 Caller_User_Name!=*$ Target_User_Name!=*$
|
||||
| bucket span=5m _time | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name)
|
||||
as tried_account by _time, Computer, Caller_User_Name | where unique_accounts >
|
||||
30 | `windows_multiple_users_fail_to_authenticate_wth_explicitcredentials_filter` '
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Insider Threat
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
message: Potential password spraying attack from $Computer$
|
||||
@@ -54,9 +53,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: Computer
|
||||
type: Endpoint
|
||||
role:
|
||||
- Victim
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -69,10 +68,11 @@ tags:
|
||||
- Computer
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
asset_type: Endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_explicit_credential_spray_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: TTP
|
||||
version: 2
|
||||
|
||||
+22
-23
@@ -1,49 +1,47 @@
|
||||
name: Windows Multiple Users Failed To Authenticate From Host Using NTLM
|
||||
id: 7ed272a4-9c77-11eb-af22-acde48001122
|
||||
version: 2
|
||||
date: '2021-04-13'
|
||||
author: Mauricio Velazco, Splunk
|
||||
type: TTP
|
||||
status: production
|
||||
data_source:
|
||||
- Windows Security 4776
|
||||
date: '2021-04-13'
|
||||
description: 'The following analytic identifies one source endpoint failing to authenticate
|
||||
with 30 unique valid users using the NTLM protocol. This behavior could represent
|
||||
an adversary performing a Password Spraying attack against an Active Directory environment
|
||||
using NTLM to obtain initial access or elevate privileges.
|
||||
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
|
||||
Event 4776 is generated
|
||||
on the computer that is authoritative for the provided credentials. For domain accounts,
|
||||
using NTLM to obtain initial access or elevate privileges. Active Directory environments
|
||||
can be very different depending on the organization. Users should test this detection
|
||||
and customize the arbitrary threshold when needed. Event 4776 is generated on the
|
||||
computer that is authoritative for the provided credentials. For domain accounts,
|
||||
the domain controller is authoritative. For local accounts, the local computer is
|
||||
authoritative. Error code 0xC000006A means: misspelled or bad password (the attempted
|
||||
user is a legitimate domain user).\
|
||||
|
||||
This logic can be used for real time security monitoring as well as threat hunting exercises.
|
||||
This detection will only trigger on domain controllers, not on member servers or
|
||||
workstations.\
|
||||
This logic can be used for real time security monitoring as well as threat hunting
|
||||
exercises. This detection will only trigger on domain controllers, not on member
|
||||
servers or workstations.\
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source workstation name and attempted user accounts.'
|
||||
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xC000006A
|
||||
| bucket span=5m _time
|
||||
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, Workstation
|
||||
| where unique_accounts > 30
|
||||
| `windows_multiple_users_failed_to_authenticate_from_host_using_ntlm_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Domain Controller events. The Advanced Security Audit policy setting `Audit Credential
|
||||
Validation` within `Account Logon` needs to be enabled.
|
||||
id: 7ed272a4-9c77-11eb-af22-acde48001122
|
||||
known_false_positives: A host failing to authenticate with multiple valid domain users
|
||||
is not a common behavior for legitimate systems. Possible false positive scenarios
|
||||
include but are not limited to vulnerability scanners and missconfigured systems.
|
||||
If this detection triggers on a host other than a Domain Controller, the behavior
|
||||
could represent a password spraying attack against the host's local accounts.
|
||||
name: Windows Multiple Users Failed To Authenticate From Host Using NTLM
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776
|
||||
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xC000006A
|
||||
| bucket span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
|
||||
as tried_accounts by _time, Workstation | where unique_accounts > 30 | `windows_multiple_users_failed_to_authenticate_from_host_using_ntlm_filter`'
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
message: Potential NTLM based password spraying attack from $Workstation$
|
||||
@@ -52,9 +50,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: Workstation
|
||||
type: Endpoint
|
||||
role:
|
||||
- Attacker
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -67,10 +65,11 @@ tags:
|
||||
- Workstation
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
asset_type: Endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_ntlm_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: TTP
|
||||
version: 2
|
||||
|
||||
+24
-24
@@ -1,50 +1,49 @@
|
||||
name: Windows Multiple Users Failed To Authenticate From Process
|
||||
id: 9015385a-9c84-11eb-bef2-acde48001122
|
||||
version: 2
|
||||
date: '2021-04-13'
|
||||
author: Mauricio Velazco, Splunk
|
||||
type: TTP
|
||||
status: production
|
||||
data_source:
|
||||
- Windows Security 4625
|
||||
date: '2021-04-13'
|
||||
description: 'The following analytic identifies a source process name failing to authenticate
|
||||
with 30 uniquer users. This behavior could represent an adversary performing a Password
|
||||
Spraying attack against an Active Directory environment to obtain initial access
|
||||
or elevate privileges.
|
||||
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
|
||||
Event 4625 generates on domain controllers, member servers,
|
||||
or elevate privileges. Active Directory environments can be very different depending
|
||||
on the organization. Users should test this detection and customize the arbitrary
|
||||
threshold when needed. Event 4625 generates on domain controllers, member servers,
|
||||
and workstations when an account fails to logon. Logon Type 2 describes an iteractive
|
||||
logon attempt.\
|
||||
|
||||
This logic can be used for real time security monitoring as well as threat hunting exercises.
|
||||
This detection will trigger on the potenfially malicious host, perhaps controlled
|
||||
via a trojan or operated by an insider threat, from where a password spraying attack
|
||||
is being executed. This could be a domain controller as well as a member server
|
||||
or workstation.\
|
||||
This logic can be used for real time security monitoring as well as threat hunting
|
||||
exercises. This detection will trigger on the potenfially malicious host, perhaps
|
||||
controlled via a trojan or operated by an insider threat, from where a password
|
||||
spraying attack is being executed. This could be a domain controller as well as
|
||||
a member server or workstation.\
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source process name, source account and attempted user accounts.'
|
||||
search: ' `wineventlog_security` EventCode=4625 Logon_Type=2 ProcessName!="-"
|
||||
| bucket span=5m _time
|
||||
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, ProcessName, SubjectUserName, Computer
|
||||
| where unique_accounts > 30
|
||||
| `windows_multiple_users_failed_to_authenticate_from_process_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Windows Event Logs from domain controllers aas well as member servers and workstations.
|
||||
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
|
||||
to be enabled.
|
||||
id: 9015385a-9c84-11eb-bef2-acde48001122
|
||||
known_false_positives: A process failing to authenticate with multiple users is not
|
||||
a common behavior for legitimate user sessions. Possible false positive scenarios
|
||||
include but are not limited to vulnerability scanners and missconfigured systems.
|
||||
name: Windows Multiple Users Failed To Authenticate From Process
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625
|
||||
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
|
||||
search: ' `wineventlog_security` EventCode=4625 Logon_Type=2 ProcessName!="-" | bucket
|
||||
span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
|
||||
as tried_accounts by _time, ProcessName, SubjectUserName, Computer | where unique_accounts
|
||||
> 30 | `windows_multiple_users_failed_to_authenticate_from_process_filter`'
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Insider Threat
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
message: Potential password spraying attack from $Computer$
|
||||
@@ -53,9 +52,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: ComputerName
|
||||
type: Endpoint
|
||||
role:
|
||||
- Victim
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -70,10 +69,11 @@ tags:
|
||||
- Computer
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
asset_type: Endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_multiple_users_from_process_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: TTP
|
||||
version: 2
|
||||
|
||||
+24
-25
@@ -1,48 +1,46 @@
|
||||
name: Windows Multiple Users Failed To Authenticate Using Kerberos
|
||||
id: 3a91a212-98a9-11eb-b86a-acde48001122
|
||||
version: 2
|
||||
date: '2021-04-08'
|
||||
author: Mauricio Velazco, Splunk
|
||||
type: TTP
|
||||
status: production
|
||||
data_source:
|
||||
- Windows Security 4771
|
||||
date: '2021-04-08'
|
||||
description: 'The following analytic identifies one source endpoint failing to authenticate
|
||||
with 30 unique users using the Kerberos protocol. This behavior could represent
|
||||
an adversary performing a Password Spraying attack against an Active Directory environment
|
||||
using Kerberos to obtain initial access or elevate privileges.
|
||||
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
|
||||
Event 4771 is generated
|
||||
when the Key Distribution Center fails to issue a Kerberos Ticket Granting Ticket
|
||||
(TGT). Failure code 0x18 stands for `wrong password provided` (the attempted user
|
||||
is a legitimate domain user).\
|
||||
using Kerberos to obtain initial access or elevate privileges. Active Directory
|
||||
environments can be very different depending on the organization. Users should test
|
||||
this detection and customize the arbitrary threshold when needed. Event 4771 is
|
||||
generated when the Key Distribution Center fails to issue a Kerberos Ticket Granting
|
||||
Ticket (TGT). Failure code 0x18 stands for `wrong password provided` (the attempted
|
||||
user is a legitimate domain user).\
|
||||
|
||||
This logic can be used for real time security monitoring as well as threat hunting exercises.
|
||||
This detection will only trigger on domain controllers, not on member servers or
|
||||
workstations.\
|
||||
This logic can be used for real time security monitoring as well as threat hunting
|
||||
exercises. This detection will only trigger on domain controllers, not on member
|
||||
servers or workstations.\
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source ip and attempted user accounts.'
|
||||
search: '`wineventlog_security` EventCode=4771 TargetUserName!="*$" Status=0x18
|
||||
| bucket span=5m _time
|
||||
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress
|
||||
| where unique_accounts > 30
|
||||
| `windows_multiple_users_failed_to_authenticate_using_kerberos_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
|
||||
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
|
||||
id: 3a91a212-98a9-11eb-b86a-acde48001122
|
||||
known_false_positives: A host failing to authenticate with multiple valid domain users
|
||||
is not a common behavior for legitimate systems. Possible false positive scenarios
|
||||
include but are not limited to vulnerability scanners, missconfigured systems and
|
||||
multi-user systems like Citrix farms.
|
||||
name: Windows Multiple Users Failed To Authenticate Using Kerberos
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
- https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn319109(v=ws.11)
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4771
|
||||
search: '`wineventlog_security` EventCode=4771 TargetUserName!="*$" Status=0x18 |
|
||||
bucket span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
|
||||
as tried_accounts by _time, IpAddress | where unique_accounts > 30 | `windows_multiple_users_failed_to_authenticate_using_kerberos_filter`'
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Active Directory Kerberos Attacks
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
message: Potential Kerberos based password spraying attack from $IpAddress$
|
||||
@@ -51,9 +49,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: IpAddress
|
||||
type: Endpoint
|
||||
role:
|
||||
- Attacker
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -66,10 +64,11 @@ tags:
|
||||
- IpAddress
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
asset_type: Endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_kerberos_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: TTP
|
||||
version: 2
|
||||
|
||||
+22
-22
@@ -1,49 +1,48 @@
|
||||
name: Windows Multiple Users Remotely Failed To Authenticate From Host
|
||||
id: 80f9d53e-9ca1-11eb-b0d6-acde48001122
|
||||
version: 2
|
||||
date: '2021-04-13'
|
||||
author: Mauricio Velazco, Splunk
|
||||
type: TTP
|
||||
status: production
|
||||
data_source:
|
||||
- Windows Security 4625
|
||||
date: '2021-04-13'
|
||||
description: 'The following analytic identifies a source host failing to authenticate
|
||||
against a remote host with 30 unique users. This behavior could represent an adversary
|
||||
performing a Password Spraying attack against an Active Directory environment to
|
||||
obtain initial access or elevate privileges.
|
||||
Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed.
|
||||
Event 4625 documents each and every
|
||||
obtain initial access or elevate privileges. Active Directory environments can be
|
||||
very different depending on the organization. Users should test this detection and
|
||||
customize the arbitrary threshold when needed. Event 4625 documents each and every
|
||||
failed attempt to logon to the local computer. This event generates on domain controllers,
|
||||
member servers, and workstations. Logon Type 3 describes an remote authentication
|
||||
attempt.\
|
||||
|
||||
This logic can be used for real time security monitoring as well as threat hunting exercises.
|
||||
This detection will trigger on the host that is the target of the password spraying
|
||||
attack. This could be a domain controller as well as a member server or workstation.\
|
||||
This logic can be used for real time security monitoring as well as threat hunting
|
||||
exercises. This detection will trigger on the host that is the target of the password
|
||||
spraying attack. This could be a domain controller as well as a member server or
|
||||
workstation.\
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source process name, source account and attempted user accounts.'
|
||||
search: ' `wineventlog_security` EventCode=4625 Logon_Type=3 IpAddress!="-"
|
||||
| bucket span=5m _time
|
||||
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress, Computer
|
||||
| where unique_accounts > 30
|
||||
| `windows_multiple_users_remotely_failed_to_authenticate_from_host_filter` '
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Windows Event Logs from domain controllers as as well as member servers and workstations.
|
||||
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
|
||||
to be enabled.
|
||||
id: 80f9d53e-9ca1-11eb-b0d6-acde48001122
|
||||
known_false_positives: A host failing to authenticate with multiple valid users against
|
||||
a remote host is not a common behavior for legitimate systems. Possible false positive
|
||||
scenarios include but are not limited to vulnerability scanners, remote administration
|
||||
tools, missconfigyred systems, etc.
|
||||
name: Windows Multiple Users Remotely Failed To Authenticate From Host
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625
|
||||
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
|
||||
search: ' `wineventlog_security` EventCode=4625 Logon_Type=3 IpAddress!="-" | bucket
|
||||
span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
|
||||
as tried_accounts by _time, IpAddress, Computer | where unique_accounts > 30 | `windows_multiple_users_remotely_failed_to_authenticate_from_host_filter` '
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
message: Potential password spraying attack on $ComputerName$
|
||||
@@ -52,9 +51,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: ComputerName
|
||||
type: Endpoint
|
||||
role:
|
||||
- Victim
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -68,10 +67,11 @@ tags:
|
||||
- IpAddress
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
asset_type: Endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_remote_spray_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: TTP
|
||||
version: 2
|
||||
|
||||
+18
-19
@@ -1,10 +1,7 @@
|
||||
name: Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos
|
||||
id: f65aa026-b811-42ab-b4b9-d9088137648f
|
||||
version: 1
|
||||
date: '2022-09-22'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
data_source:
|
||||
- Windows Security 4768
|
||||
date: '2022-09-22'
|
||||
description: 'The following analytic identifies one source endpoint failing to authenticate
|
||||
with multiple disabled domain users using the Kerberos protocol. This behavior could
|
||||
represent an adversary performing a Password Spraying attack against an Active Directory
|
||||
@@ -26,29 +23,29 @@ description: 'The following analytic identifies one source endpoint failing to a
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source ip and attempted user accounts.'
|
||||
data_source:
|
||||
- Windows Security 4768
|
||||
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x12
|
||||
| bucket span=5m _time
|
||||
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress
|
||||
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by IpAddress
|
||||
| eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1
|
||||
| `windows_unusual_count_of_disabled_users_failed_auth_using_kerberos_filter` '
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
|
||||
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
|
||||
id: f65aa026-b811-42ab-b4b9-d9088137648f
|
||||
known_false_positives: A host failing to authenticate with multiple disabled domain
|
||||
users is not a common behavior for legitimate systems. Possible false positive scenarios
|
||||
include but are not limited to vulnerability scanners, multi-user systems missconfigured
|
||||
systems.
|
||||
name: Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x12 | bucket
|
||||
span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
|
||||
as tried_accounts by _time, IpAddress | eventstats avg(unique_accounts) as comp_avg
|
||||
, stdev(unique_accounts) as comp_std by IpAddress | eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1 | `windows_unusual_count_of_disabled_users_failed_auth_using_kerberos_filter` '
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Active Directory Kerberos Attacks
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
@@ -58,9 +55,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: IpAddress
|
||||
type: Endpoint
|
||||
role:
|
||||
- Attacker
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -74,8 +71,10 @@ tags:
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_disabled_users_kerberos_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: Anomaly
|
||||
version: 1
|
||||
|
||||
+18
-19
@@ -1,10 +1,7 @@
|
||||
name: Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos
|
||||
id: f122cb2e-d773-4f11-8399-62a3572d8dd7
|
||||
version: 1
|
||||
date: '2022-09-22'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
data_source:
|
||||
- Windows Security 4768
|
||||
date: '2022-09-22'
|
||||
description: 'The following analytic identifies one source endpoint failing to authenticate
|
||||
with multiple invalid domain users using the Kerberos protocol. This behavior could
|
||||
represent an adversary performing a Password Spraying attack against an Active Directory
|
||||
@@ -26,29 +23,29 @@ description: 'The following analytic identifies one source endpoint failing to a
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source ip and attempted user accounts.'
|
||||
data_source:
|
||||
- Windows Security 4768
|
||||
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x6
|
||||
| bucket span=5m _time
|
||||
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress
|
||||
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by IpAddress
|
||||
| eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1
|
||||
| `windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos_filter` '
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
|
||||
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
|
||||
id: f122cb2e-d773-4f11-8399-62a3572d8dd7
|
||||
known_false_positives: A host failing to authenticate with multiple invalid domain
|
||||
users is not a common behavior for legitimate systems. Possible false positive scenarios
|
||||
include but are not limited to vulnerability scanners, multi-user systems and missconfigured
|
||||
systems.
|
||||
name: Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x6 | bucket
|
||||
span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
|
||||
as tried_accounts by _time, IpAddress | eventstats avg(unique_accounts) as comp_avg
|
||||
, stdev(unique_accounts) as comp_std by IpAddress | eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1 | `windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos_filter` '
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Active Directory Kerberos Attacks
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
@@ -58,9 +55,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: IpAddress
|
||||
type: Endpoint
|
||||
role:
|
||||
- Attacker
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -74,8 +71,10 @@ tags:
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: Anomaly
|
||||
version: 1
|
||||
|
||||
+18
-19
@@ -1,10 +1,7 @@
|
||||
name: Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM
|
||||
id: 15603165-147d-4a6e-9778-bd0ff39e668f
|
||||
version: 1
|
||||
date: '2022-09-22'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
data_source:
|
||||
- Windows Security 4776
|
||||
date: '2022-09-22'
|
||||
description: 'The following analytic identifies one source endpoint failing to authenticate
|
||||
with multiple invalid users using the NTLM protocol. This behavior could represent
|
||||
an adversary performing a Password Spraying attack against an Active Directory environment
|
||||
@@ -27,31 +24,31 @@ description: 'The following analytic identifies one source endpoint failing to a
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source workstation name and attempted user accounts.'
|
||||
data_source:
|
||||
- Windows Security 4776
|
||||
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xc0000064
|
||||
| bucket span=2m _time
|
||||
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, Workstation
|
||||
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Workstation
|
||||
| eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1
|
||||
| `windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Domain Controller events. The Advanced Security Audit policy setting `Audit Credential
|
||||
Validation' within `Account Logon` needs to be enabled.
|
||||
id: 15603165-147d-4a6e-9778-bd0ff39e668f
|
||||
known_false_positives: A host failing to authenticate with multiple invalid domain
|
||||
users is not a common behavior for legitimate systems. Possible false positive scenarios
|
||||
include but are not limited to vulnerability scanners and missconfigured systems.
|
||||
If this detection triggers on a host other than a Domain Controller, the behavior
|
||||
could represent a password spraying attack against the host's local accounts.
|
||||
name: Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776
|
||||
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xc0000064
|
||||
| bucket span=2m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
|
||||
as tried_accounts by _time, Workstation | eventstats avg(unique_accounts) as comp_avg
|
||||
, stdev(unique_accounts) as comp_std by Workstation | eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1 | `windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm_filter`'
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
@@ -61,9 +58,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: Workstation
|
||||
type: Endpoint
|
||||
role:
|
||||
- Attacker
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -77,8 +74,10 @@ tags:
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_ntlm_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: Anomaly
|
||||
version: 1
|
||||
|
||||
+18
-19
@@ -1,10 +1,7 @@
|
||||
name: Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials
|
||||
id: 14f414cf-3080-4b9b-aaf6-55a4ce947b93
|
||||
version: 1
|
||||
date: '2022-09-22'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
data_source:
|
||||
- Windows Security 4648
|
||||
date: '2022-09-22'
|
||||
description: 'The following analytic identifies a source user failing to authenticate
|
||||
with multiple users using explicit credentials on a host. This behavior could represent
|
||||
an adversary performing a Password Spraying attack against an Active Directory environment
|
||||
@@ -25,33 +22,33 @@ description: 'The following analytic identifies a source user failing to authent
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source account, attempted user accounts and the endpoint were
|
||||
the behavior was identified.'
|
||||
data_source:
|
||||
- Windows Security 4648
|
||||
search: ' `wineventlog_security` EventCode=4648 Caller_User_Name!=*$ Target_User_Name!=*$
|
||||
| bucket span=5m _time
|
||||
| stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as tried_account by _time, Computer, Caller_User_Name
|
||||
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Computer
|
||||
| eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1
|
||||
| `windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials_filter` '
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Windows Event Logs from domain controllers as well as member servers and workstations.
|
||||
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
|
||||
to be enabled.
|
||||
id: 14f414cf-3080-4b9b-aaf6-55a4ce947b93
|
||||
known_false_positives: A source user failing attempting to authenticate multiple users
|
||||
on a host is not a common behavior for regular systems. Some applications, however,
|
||||
may exhibit this behavior in which case sets of users hosts can be added to an allow
|
||||
list. Possible false positive scenarios include systems where several users connect
|
||||
to like Mail servers, identity providers, remote desktop services, Citrix, etc.
|
||||
name: Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
|
||||
search: ' `wineventlog_security` EventCode=4648 Caller_User_Name!=*$ Target_User_Name!=*$
|
||||
| bucket span=5m _time | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name)
|
||||
as tried_account by _time, Computer, Caller_User_Name | eventstats avg(unique_accounts)
|
||||
as comp_avg , stdev(unique_accounts) as comp_std by Computer | eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1 | `windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials_filter` '
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Insider Threat
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
@@ -61,9 +58,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: Computer
|
||||
type: Endpoint
|
||||
role:
|
||||
- Attacker
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -77,8 +74,10 @@ tags:
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_explicit_credential_spray_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: Anomaly
|
||||
version: 1
|
||||
|
||||
+18
-19
@@ -1,10 +1,7 @@
|
||||
name: Windows Unusual Count Of Users Failed To Auth Using Kerberos
|
||||
id: bc9cb715-08ba-40c3-9758-6e2b26e455cb
|
||||
version: 1
|
||||
date: '2022-09-22'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
data_source:
|
||||
- Windows Security 4771
|
||||
date: '2022-09-22'
|
||||
description: 'The following analytic identifies one source endpoint failing to authenticate
|
||||
with multiple valid users using the Kerberos protocol. This behavior could represent
|
||||
an adversary performing a Password Spraying attack against an Active Directory environment
|
||||
@@ -24,31 +21,31 @@ description: 'The following analytic identifies one source endpoint failing to a
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source ip and attempted user accounts.'
|
||||
data_source:
|
||||
- Windows Security 4771
|
||||
search: '`wineventlog_security` EventCode=4771 TargetUserName!="*$" Status=0x18
|
||||
| bucket span=5m _time
|
||||
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress
|
||||
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by IpAddress
|
||||
| eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1
|
||||
| `windows_unusual_count_of_users_failed_to_auth_using_kerberos_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Domain Controller and Kerberos events. The Advanced Security Audit policy setting
|
||||
`Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
|
||||
id: bc9cb715-08ba-40c3-9758-6e2b26e455cb
|
||||
known_false_positives: A host failing to authenticate with multiple valid domain users
|
||||
is not a common behavior for legitimate systems. Possible false positive scenarios
|
||||
include but are not limited to vulnerability scanners, missconfigured systems and
|
||||
multi-user systems like Citrix farms.
|
||||
name: Windows Unusual Count Of Users Failed To Auth Using Kerberos
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
- https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn319109(v=ws.11)
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4771
|
||||
search: '`wineventlog_security` EventCode=4771 TargetUserName!="*$" Status=0x18 |
|
||||
bucket span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
|
||||
as tried_accounts by _time, IpAddress | eventstats avg(unique_accounts) as comp_avg
|
||||
, stdev(unique_accounts) as comp_std by IpAddress | eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1 | `windows_unusual_count_of_users_failed_to_auth_using_kerberos_filter`'
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Active Directory Kerberos Attacks
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
@@ -58,9 +55,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: IpAddress
|
||||
type: Endpoint
|
||||
role:
|
||||
- Attacker
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -74,8 +71,10 @@ tags:
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_kerberos_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: Anomaly
|
||||
version: 1
|
||||
|
||||
+18
-19
@@ -1,10 +1,7 @@
|
||||
name: Windows Unusual Count Of Users Failed To Authenticate From Process
|
||||
id: 25bdb6cb-2e49-4d34-a93c-d6c567c122fe
|
||||
version: 1
|
||||
date: '2022-09-22'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
data_source:
|
||||
- Windows Security 4625
|
||||
date: '2022-09-22'
|
||||
description: 'The following analytic identifies a source process name failing to authenticate
|
||||
with multiple users. This behavior could represent an adversary performing a Password
|
||||
Spraying attack against an Active Directory environment to obtain initial access
|
||||
@@ -25,32 +22,32 @@ description: 'The following analytic identifies a source process name failing to
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source process name, source account and attempted user accounts.'
|
||||
data_source:
|
||||
- Windows Security 4625
|
||||
search: ' `wineventlog_security` EventCode=4625 Logon_Type=2 ProcessName!="-"
|
||||
| bucket span=2m _time
|
||||
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, ProcessName, SubjectUserName, Computer
|
||||
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by ProcessName, SubjectUserName, Computer
|
||||
| eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1
|
||||
| `windows_unusual_count_of_users_failed_to_authenticate_from_process_filter` '
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Windows Event Logs from domain controllers aas well as member servers and workstations.
|
||||
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
|
||||
to be enabled.
|
||||
id: 25bdb6cb-2e49-4d34-a93c-d6c567c122fe
|
||||
known_false_positives: A process failing to authenticate with multiple users is not
|
||||
a common behavior for legitimate user sessions. Possible false positive scenarios
|
||||
include but are not limited to vulnerability scanners and missconfigured systems.
|
||||
name: Windows Unusual Count Of Users Failed To Authenticate From Process
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625
|
||||
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
|
||||
search: ' `wineventlog_security` EventCode=4625 Logon_Type=2 ProcessName!="-" | bucket
|
||||
span=2m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
|
||||
as tried_accounts by _time, ProcessName, SubjectUserName, Computer | eventstats
|
||||
avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by ProcessName,
|
||||
SubjectUserName, Computer | eval upperBound=(comp_avg+comp_std*3) | eval isOutlier=if(unique_accounts
|
||||
> 10 and unique_accounts >= upperBound, 1, 0) | search isOutlier=1 | `windows_unusual_count_of_users_failed_to_authenticate_from_process_filter` '
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Insider Threat
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
@@ -60,9 +57,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: Computer
|
||||
type: Endpoint
|
||||
role:
|
||||
- Attacker
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -78,8 +75,10 @@ tags:
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_multiple_users_from_process_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: Anomaly
|
||||
version: 1
|
||||
|
||||
+18
-19
@@ -1,10 +1,7 @@
|
||||
name: Windows Unusual Count Of Users Failed To Authenticate Using NTLM
|
||||
id: 6f6c8fd7-6a6b-4af9-a0e9-57cfc47a58b4
|
||||
version: 1
|
||||
date: '2022-09-22'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
data_source:
|
||||
- Windows Security 4776
|
||||
date: '2022-09-22'
|
||||
description: 'The following analytic identifies one source endpoint failing to authenticate
|
||||
with multiple valid users using the NTLM protocol. This behavior could represent
|
||||
an adversary performing a Password Spraying attack against an Active Directory environment
|
||||
@@ -25,31 +22,31 @@ description: 'The following analytic identifies one source endpoint failing to a
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source workstation name and attempted user accounts.'
|
||||
data_source:
|
||||
- Windows Security 4776
|
||||
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xC000006A
|
||||
| bucket span=2m _time
|
||||
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, Workstation
|
||||
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Workstation
|
||||
| eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1
|
||||
| `windows_unusual_count_of_users_failed_to_authenticate_using_ntlm_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Domain Controller events. The Advanced Security Audit policy setting `Audit Credential
|
||||
Validation` within `Account Logon` needs to be enabled.
|
||||
id: 6f6c8fd7-6a6b-4af9-a0e9-57cfc47a58b4
|
||||
known_false_positives: A host failing to authenticate with multiple valid domain users
|
||||
is not a common behavior for legitimate systems. Possible false positive scenarios
|
||||
include but are not limited to vulnerability scanners and missconfigured systems.
|
||||
If this detection triggers on a host other than a Domain Controller, the behavior
|
||||
could represent a password spraying attack against the host's local accounts.
|
||||
name: Windows Unusual Count Of Users Failed To Authenticate Using NTLM
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776
|
||||
search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xC000006A
|
||||
| bucket span=2m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
|
||||
as tried_accounts by _time, Workstation | eventstats avg(unique_accounts) as comp_avg
|
||||
, stdev(unique_accounts) as comp_std by Workstation | eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1 | `windows_unusual_count_of_users_failed_to_authenticate_using_ntlm_filter`'
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
@@ -59,9 +56,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: Workstation
|
||||
type: Endpoint
|
||||
role:
|
||||
- Attacker
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -75,8 +72,10 @@ tags:
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_ntlm_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: Anomaly
|
||||
version: 1
|
||||
|
||||
+18
-19
@@ -1,10 +1,7 @@
|
||||
name: Windows Unusual Count Of Users Remotely Failed To Auth From Host
|
||||
id: cf06a0ee-ffa9-4ed3-be77-0670ed9bab52
|
||||
version: 1
|
||||
date: '2022-09-22'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
data_source:
|
||||
- Windows Security 4625
|
||||
date: '2022-09-22'
|
||||
description: 'The following analytic identifies a source host failing to authenticate
|
||||
against a remote host with multiple users. This behavior could represent an adversary
|
||||
performing a Password Spraying attack against an Active Directory environment to
|
||||
@@ -24,32 +21,32 @@ description: 'The following analytic identifies a source host failing to authent
|
||||
|
||||
The analytics returned fields allow analysts to investigate the event further by
|
||||
providing fields like source process name, source account and attempted user accounts.'
|
||||
data_source:
|
||||
- Windows Security 4625
|
||||
search: ' `wineventlog_security` EventCode=4625 Logon_Type=3 IpAddress!="-"
|
||||
| bucket span=2m _time
|
||||
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress, Computer
|
||||
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by IpAddress, Computer
|
||||
| eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1
|
||||
| `windows_unusual_count_of_users_remotely_failed_to_auth_from_host_filter` '
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Windows Event Logs from domain controllers as as well as member servers and workstations.
|
||||
The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs
|
||||
to be enabled.
|
||||
id: cf06a0ee-ffa9-4ed3-be77-0670ed9bab52
|
||||
known_false_positives: A host failing to authenticate with multiple valid users against
|
||||
a remote host is not a common behavior for legitimate systems. Possible false positive
|
||||
scenarios include but are not limited to vulnerability scanners, remote administration
|
||||
tools, missconfigyred systems, etc.
|
||||
name: Windows Unusual Count Of Users Remotely Failed To Auth From Host
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625
|
||||
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625
|
||||
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events
|
||||
search: ' `wineventlog_security` EventCode=4625 Logon_Type=3 IpAddress!="-" | bucket
|
||||
span=2m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName)
|
||||
as tried_accounts by _time, IpAddress, Computer | eventstats avg(unique_accounts)
|
||||
as comp_avg , stdev(unique_accounts) as comp_std by IpAddress, Computer | eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0)
|
||||
| search isOutlier=1 | `windows_unusual_count_of_users_remotely_failed_to_auth_from_host_filter` '
|
||||
status: production
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Password Spraying
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
@@ -59,9 +56,9 @@ tags:
|
||||
- T1110
|
||||
observable:
|
||||
- name: Computer
|
||||
type: Endpoint
|
||||
role:
|
||||
- Attacker
|
||||
type: Endpoint
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -76,8 +73,10 @@ tags:
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_remote_spray_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
name: True Positive Test
|
||||
type: Anomaly
|
||||
version: 1
|
||||
|
||||
@@ -28,11 +28,13 @@ known_false_positives: Administrators may execute this command for testing or au
|
||||
references:
|
||||
- https://github.com/NVISOsecurity/sigma-public/blob/master/rules/windows/process_creation/win_susp_wmi_execution.yml
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/2b804d25418004a5f1ba50e9dc637946ab8733c7/atomics/T1047/T1047.md
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious WMI Use
|
||||
- Qakbot
|
||||
- Volt Typhoon
|
||||
- IcedID
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
|
||||
@@ -32,10 +32,12 @@ how_to_implement: To successfully implement this search you need to be ingesting
|
||||
known_false_positives: Legtimate administrator usage of wmic to create a shadow copy.
|
||||
references:
|
||||
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- Living Off The Land
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 90
|
||||
|
||||
@@ -39,9 +39,11 @@ references:
|
||||
- https://attack.mitre.org/techniques/T1069/002/
|
||||
- https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory
|
||||
- https://adsecurity.org/?p=3658
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Discovery
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 30
|
||||
|
||||
@@ -34,11 +34,13 @@ known_false_positives: It is possible some agent based products will generate fa
|
||||
references:
|
||||
- https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
tags:
|
||||
analytic_story:
|
||||
- DarkSide Ransomware
|
||||
- Credential Dumping
|
||||
- CISA AA22-257A
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 80
|
||||
|
||||
@@ -36,6 +36,7 @@ references:
|
||||
- https://github.com/SecureAuthCorp/impacket
|
||||
- https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Lateral Movement
|
||||
@@ -43,6 +44,7 @@ tags:
|
||||
- Industroyer2
|
||||
- CISA AA22-277A
|
||||
- Prestige Ransomware
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 90
|
||||
|
||||
@@ -26,6 +26,7 @@ known_false_positives: False positives may be present. Tune as needed.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1069/001/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Discovery
|
||||
@@ -33,6 +34,7 @@ tags:
|
||||
- Azorult
|
||||
- Windows Post-Exploitation
|
||||
- Prestige Ransomware
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 30
|
||||
|
||||
@@ -36,12 +36,14 @@ references:
|
||||
- https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc753343(v=ws.11)
|
||||
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
|
||||
- https://strontic.github.io/xcyclopedia/library/vss_ps.dll-97B15BDAE9777F454C9A6BA25E938DB3.html
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- HAFNIUM Group
|
||||
- Living Off The Land
|
||||
- Prestige Ransomware
|
||||
- Ntdsutil Export NTDS
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 100
|
||||
|
||||
@@ -31,10 +31,12 @@ known_false_positives: False positives should be limited as this is directly loo
|
||||
references:
|
||||
- https://www.cisa.gov/uscert/sites/default/files/publications/aa22-320a_joint_csa_iranian_government-sponsored_apt_actors_compromise_federal%20network_deploy_crypto%20miner_credential_harvester.pdf
|
||||
- https://www.varonis.com/blog/what-is-mimikatz
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- CISA AA22-320A
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 100
|
||||
|
||||
@@ -37,11 +37,13 @@ references:
|
||||
- https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc753343(v=ws.11)
|
||||
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
|
||||
- https://strontic.github.io/xcyclopedia/library/vss_ps.dll-97B15BDAE9777F454C9A6BA25E938DB3.html
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- HAFNIUM Group
|
||||
- Living Off The Land
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 100
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
name: Volt Typhoon
|
||||
id: f73010e4-49eb-44ef-9f3f-2c25a1ae5415
|
||||
version: 1
|
||||
date: '2023-05-25'
|
||||
author: Teoderick Contreras, Splunk
|
||||
description: This analytic story contains detections that allow security analysts to detect and investigate unusual activities that might relate to the "Volt Typhoon" group targeting critical infrastructure organizations in United States and Guam. The affected organizations include the communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education sectors. This Analytic story looks for suspicious process execution, lolbin execution, command-line activity, lsass dump and many more.
|
||||
narrative: Volt Typhoon is a state sponsored group typically focuses on espionage and information gathering.\
|
||||
Based on Microsoft Threat Intelligence, This threat actor group puts strong emphasis on stealth in this campaign by relying almost exclusively on living-off-the-land techniques and hands-on-keyboard activity. \
|
||||
They issue commands via the command line to :\
|
||||
(1) collect data, including credentials from local and network systems, \
|
||||
(2) put the data into an archive file to stage it for exfiltration, and then \
|
||||
(3) use the stolen valid credentials to maintain persistence. \
|
||||
In addition, Volt Typhoon tries to blend into normal network activity by routing traffic through compromised small office and home office (SOHO) network equipment, including routers, firewalls, and VPN hardware. They have also been observed using custom versions of open-source tools to establish a command and control (C2) channel over proxy to further stay under the radar.
|
||||
references:
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story: Volt Typhoon
|
||||
category:
|
||||
- Data Destruction
|
||||
- Malware
|
||||
- Adversary Tactics
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
usecase: Advanced Threat Detection
|
||||
Reference in New Issue
Block a user