From aad413f44c6f478d02769d6147da31d26e9c7aa3 Mon Sep 17 00:00:00 2001 From: tccontre Date: Thu, 25 May 2023 12:16:00 +0200 Subject: [PATCH 01/13] volt_typhoon --- .../endpoint/dump_lsass_via_comsvcs_dll.yml | 2 ++ ...ateral_movement_commandline_parameters.yml | 2 ++ ...ovement_smbexec_commandline_parameters.yml | 2 ++ ...ovement_wmiexec_commandline_parameters.yml | 2 ++ ...s_powershell_process___encoded_command.yml | 2 ++ ...hell_process___execution_policy_bypass.yml | 4 ++- .../endpoint/remote_wmi_command_attempt.yml | 2 ++ .../windows_wmi_process_call_create.yml | 2 ++ ...ateral_movement_commandline_parameters.yml | 2 ++ stories/volt_typhoon.yml | 31 +++++++++++++++++++ 10 files changed, 50 insertions(+), 1 deletion(-) create mode 100644 stories/volt_typhoon.yml diff --git a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml index 0bd9449319..54086f1e85 100644 --- a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml +++ b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml @@ -22,6 +22,7 @@ known_false_positives: None identified. references: - https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/ - https://twitter.com/SBousseaden/status/1167417096374050817 +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Industroyer2 @@ -33,6 +34,7 @@ tags: - Living Off The Land - Suspicious Rundll32 Activity - Data Destruction + - Volt Typhoon asset_type: Endpoint confidence: 100 impact: 80 diff --git a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml index 5fe55839a2..7dec17d390 100644 --- a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml @@ -36,6 +36,7 @@ references: - https://github.com/SecureAuthCorp/impacket - https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/ - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Industroyer2 @@ -44,6 +45,7 @@ tags: - CISA AA22-277A - Data Destruction - WhisperGate + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 90 diff --git a/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml index 2a3406695b..0b850fd266 100644 --- a/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml @@ -27,6 +27,7 @@ references: - https://github.com/SecureAuthCorp/impacket - https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/ - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Industroyer2 @@ -35,6 +36,7 @@ tags: - CISA AA22-277A - Data Destruction - WhisperGate + - Volt Typhoon asset_type: Endpoint atomic_guid: [] confidence: 70 diff --git a/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml index cfce4e4ad0..8ce04734b9 100644 --- a/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml @@ -34,6 +34,7 @@ references: - https://github.com/SecureAuthCorp/impacket - https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/ - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Industroyer2 @@ -42,6 +43,7 @@ tags: - CISA AA22-277A - Data Destruction - WhisperGate + - Volt Typhoon asset_type: Endpoint atomic_guid: [] confidence: 70 diff --git a/detections/endpoint/malicious_powershell_process___encoded_command.yml b/detections/endpoint/malicious_powershell_process___encoded_command.yml index bed1a5e098..aac0b4a334 100644 --- a/detections/endpoint/malicious_powershell_process___encoded_command.yml +++ b/detections/endpoint/malicious_powershell_process___encoded_command.yml @@ -39,6 +39,7 @@ references: - https://ss64.com/ps/powershell.html - https://twitter.com/M_haggis/status/1440758396534214658?s=20 - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Hermetic Wiper @@ -50,6 +51,7 @@ tags: - CISA AA22-320A - Sandworm Tools - Data Destruction + - Volt Typhoon asset_type: Endpoint confidence: 50 impact: 70 diff --git a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml index 7a462911d8..52222b5fef 100644 --- a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml +++ b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml @@ -25,13 +25,15 @@ how_to_implement: To successfully implement this search you need to be ingesting known_false_positives: There may be legitimate reasons to bypass the PowerShell execution policy. The PowerShell script being run with this parameter should be validated to ensure that it is legitimate. -references: [] +references: +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - DHS Report TA18-074A - HAFNIUM Group - DarkCrystal RAT - AsyncRAT + - Volt Typhoon asset_type: Endpoint confidence: 60 impact: 70 diff --git a/detections/endpoint/remote_wmi_command_attempt.yml b/detections/endpoint/remote_wmi_command_attempt.yml index 07e0adf9d7..26e1e2bdf1 100644 --- a/detections/endpoint/remote_wmi_command_attempt.yml +++ b/detections/endpoint/remote_wmi_command_attempt.yml @@ -27,10 +27,12 @@ known_false_positives: Administrators may use this legitimately to gather info f remote systems. Filter as needed. references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1047/T1047.yaml +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Suspicious WMI Use - Living Off The Land + - Volt Typhoon asset_type: Endpoint confidence: 60 impact: 60 diff --git a/detections/endpoint/windows_wmi_process_call_create.yml b/detections/endpoint/windows_wmi_process_call_create.yml index f0f143cdd3..6486002f50 100644 --- a/detections/endpoint/windows_wmi_process_call_create.yml +++ b/detections/endpoint/windows_wmi_process_call_create.yml @@ -28,10 +28,12 @@ known_false_positives: Administrators may execute this command for testing or au references: - https://github.com/NVISOsecurity/sigma-public/blob/master/rules/windows/process_creation/win_susp_wmi_execution.yml - https://github.com/redcanaryco/atomic-red-team/blob/2b804d25418004a5f1ba50e9dc637946ab8733c7/atomics/T1047/T1047.md +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Suspicious WMI Use - Qakbot + - Volt Typhoon asset_type: Endpoint confidence: 50 impact: 50 diff --git a/dev/endpoint/impacket_lateral_movement_commandline_parameters.yml b/dev/endpoint/impacket_lateral_movement_commandline_parameters.yml index 1de5c8ad27..2f95e9e9e1 100644 --- a/dev/endpoint/impacket_lateral_movement_commandline_parameters.yml +++ b/dev/endpoint/impacket_lateral_movement_commandline_parameters.yml @@ -36,6 +36,7 @@ references: - https://github.com/SecureAuthCorp/impacket - https://vk9-sec.com/impacket-remote-code-execution-rce-on-windows-from-linux/ - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Active Directory Lateral Movement @@ -43,6 +44,7 @@ tags: - Industroyer2 - CISA AA22-277A - Prestige Ransomware + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 90 diff --git a/stories/volt_typhoon.yml b/stories/volt_typhoon.yml new file mode 100644 index 0000000000..67c0236408 --- /dev/null +++ b/stories/volt_typhoon.yml @@ -0,0 +1,31 @@ +name: Volt Typhoon +id: f73010e4-49eb-44ef-9f3f-2c25a1ae5415 +version: 1 +date: '2023-05-25' +author: Teoderick Contreras, Splunk +description: This analytic story contains detections that allow security analysts to detect and investigate unusual activities + that might relate to the "Volt Typhoon" group targeting critical infrastructure organizations in United States and Guam. The affected + organizations include the communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education sectors. + This Analytic story looks for suspicious process execution, lolbin execution, command-line activity, lsass dump and many more. +narrative: Volt Typhoon is a state sponsored group typically focuses on espionage and information gathering. + Based on Microsoft Threat Intelligence, This threat actor group puts strong emphasis on stealth in this campaign by relying almost exclusively on living-off-the-land techniques and hands-on-keyboard activity. + They issue commands via the command line to + (1) collect data, including credentials from local and network systems, + (2) put the data into an archive file to stage it for exfiltration, and then + (3) use the stolen valid credentials to maintain persistence. + In addition, Volt Typhoon tries to blend into normal network activity by routing traffic through compromised small office and home office (SOHO) network equipment, + including routers, firewalls, and VPN hardware. They have also been observed using custom versions of open-source tools to establish a command and control (C2) + channel over proxy to further stay under the radar. +references: +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ +tags: + analytic_story: Volt Typhoon + category: + - Data Destruction + - Malware + - Adversary Tactics + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection From 4110afa0bc912be693ec468a914a22fed295bc91 Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Thu, 25 May 2023 05:52:07 -0600 Subject: [PATCH 02/13] volts --- detections/endpoint/ntdsutil_export_ntds.yml | 2 ++ dev/endpoint/ntdsutil_export_ntds.yml | 2 ++ ..._windows_os_credential_dumping_with_ntdsutil_export_ntds.yml | 2 ++ 3 files changed, 6 insertions(+) diff --git a/detections/endpoint/ntdsutil_export_ntds.yml b/detections/endpoint/ntdsutil_export_ntds.yml index 041ef1830a..51f06bb2a1 100644 --- a/detections/endpoint/ntdsutil_export_ntds.yml +++ b/detections/endpoint/ntdsutil_export_ntds.yml @@ -35,12 +35,14 @@ references: - https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc753343(v=ws.11) - https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf - https://strontic.github.io/xcyclopedia/library/vss_ps.dll-97B15BDAE9777F454C9A6BA25E938DB3.html +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Credential Dumping - HAFNIUM Group - Living Off The Land - Prestige Ransomware + - Volt Typhoon asset_type: Endpoint confidence: 50 impact: 100 diff --git a/dev/endpoint/ntdsutil_export_ntds.yml b/dev/endpoint/ntdsutil_export_ntds.yml index 76705b7644..6a7bbda08a 100644 --- a/dev/endpoint/ntdsutil_export_ntds.yml +++ b/dev/endpoint/ntdsutil_export_ntds.yml @@ -36,12 +36,14 @@ references: - https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc753343(v=ws.11) - https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf - https://strontic.github.io/xcyclopedia/library/vss_ps.dll-97B15BDAE9777F454C9A6BA25E938DB3.html +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Credential Dumping - HAFNIUM Group - Living Off The Land - Prestige Ransomware + - Ntdsutil Export NTDS asset_type: Endpoint confidence: 50 impact: 100 diff --git a/dev_ssa/endpoint/ssa___windows_os_credential_dumping_with_ntdsutil_export_ntds.yml b/dev_ssa/endpoint/ssa___windows_os_credential_dumping_with_ntdsutil_export_ntds.yml index 83e3c3e99c..70cdec2fe9 100644 --- a/dev_ssa/endpoint/ssa___windows_os_credential_dumping_with_ntdsutil_export_ntds.yml +++ b/dev_ssa/endpoint/ssa___windows_os_credential_dumping_with_ntdsutil_export_ntds.yml @@ -37,11 +37,13 @@ references: - https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc753343(v=ws.11) - https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf - https://strontic.github.io/xcyclopedia/library/vss_ps.dll-97B15BDAE9777F454C9A6BA25E938DB3.html +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Credential Dumping - HAFNIUM Group - Living Off The Land + - Volt Typhoon asset_type: Endpoint confidence: 50 impact: 100 From 9d15cfbf7e92c7508a84c7c0dfd69598c29e25c3 Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Thu, 25 May 2023 05:59:55 -0600 Subject: [PATCH 03/13] few more --- detections/endpoint/creation_of_shadow_copy.yml | 2 ++ .../creation_of_shadow_copy_with_wmic_and_powershell.yml | 2 ++ .../creation_of_shadow_copy_with_wmic_and_powershell.yml | 2 ++ 3 files changed, 6 insertions(+) diff --git a/detections/endpoint/creation_of_shadow_copy.yml b/detections/endpoint/creation_of_shadow_copy.yml index 9e82fe84f0..d84d1821ed 100644 --- a/detections/endpoint/creation_of_shadow_copy.yml +++ b/detections/endpoint/creation_of_shadow_copy.yml @@ -24,9 +24,11 @@ known_false_positives: Legitimate administrator usage of Vssadmin or Wmic will c false positives. references: - https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf +- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF tags: analytic_story: - Credential Dumping + - Volt Typhoon asset_type: Endpoint confidence: 90 impact: 90 diff --git a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml index 1564c314db..39f1124cc1 100644 --- a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml +++ b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml @@ -22,10 +22,12 @@ how_to_implement: To successfully implement this search you need to be ingesting known_false_positives: Legtimate administrator usage of wmic to create a shadow copy. references: - https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf +- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF tags: analytic_story: - Credential Dumping - Living Off The Land + - Volt Typhoon asset_type: Endpoint confidence: 90 impact: 90 diff --git a/dev/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml b/dev/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml index c00962d380..7da206ee40 100644 --- a/dev/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml +++ b/dev/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml @@ -32,10 +32,12 @@ how_to_implement: To successfully implement this search you need to be ingesting known_false_positives: Legtimate administrator usage of wmic to create a shadow copy. references: - https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf +- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF tags: analytic_story: - Credential Dumping - Living Off The Land + - Volt Typhoon asset_type: Endpoint confidence: 90 impact: 90 From 20c60fb5899ed17970b161427b052c14df6e48f2 Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Thu, 25 May 2023 06:00:45 -0600 Subject: [PATCH 04/13] 1 more --- detections/endpoint/extraction_of_registry_hives.yml | 2 ++ dev/endpoint/extraction_of_registry_hives.yml | 2 ++ 2 files changed, 4 insertions(+) diff --git a/detections/endpoint/extraction_of_registry_hives.yml b/detections/endpoint/extraction_of_registry_hives.yml index 16b8d8a960..63bfd73dd4 100644 --- a/detections/endpoint/extraction_of_registry_hives.yml +++ b/detections/endpoint/extraction_of_registry_hives.yml @@ -26,11 +26,13 @@ known_false_positives: It is possible some agent based products will generate fa references: - https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md +- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF tags: analytic_story: - DarkSide Ransomware - Credential Dumping - CISA AA22-257A + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 80 diff --git a/dev/endpoint/extraction_of_registry_hives.yml b/dev/endpoint/extraction_of_registry_hives.yml index 6fde9ec6f5..3fe99bcfef 100644 --- a/dev/endpoint/extraction_of_registry_hives.yml +++ b/dev/endpoint/extraction_of_registry_hives.yml @@ -34,11 +34,13 @@ known_false_positives: It is possible some agent based products will generate fa references: - https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md +- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF tags: analytic_story: - DarkSide Ransomware - Credential Dumping - CISA AA22-257A + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 80 From b76d701acf73e049ab7956e11871e493432bf109 Mon Sep 17 00:00:00 2001 From: tccontre Date: Thu, 25 May 2023 14:01:24 +0200 Subject: [PATCH 05/13] volt_typhoon --- detections/endpoint/processes_launching_netsh.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/detections/endpoint/processes_launching_netsh.yml b/detections/endpoint/processes_launching_netsh.yml index c60990088b..881ca3cd3a 100644 --- a/detections/endpoint/processes_launching_netsh.yml +++ b/detections/endpoint/processes_launching_netsh.yml @@ -27,13 +27,15 @@ how_to_implement: To successfully implement this search you need to be ingesting known_false_positives: Some VPN applications are known to launch netsh.exe. Outside of these instances, it is unusual for an executable to launch netsh.exe and run commands. -references: [] +references: +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Netsh Abuse - Disabling Security Tools - DHS Report TA18-074A - Azorult + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 20 From ec897a5cbb82fe93f54bfbe55cda3ddf4445c309 Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Thu, 25 May 2023 06:07:25 -0600 Subject: [PATCH 06/13] more --- detections/endpoint/net_localgroup_discovery.yml | 2 ++ detections/endpoint/windows_mimikatz_binary_execution.yml | 2 ++ dev/endpoint/net_localgroup_discovery.yml | 2 ++ dev/endpoint/windows_mimikatz_binary_execution.yml | 2 ++ 4 files changed, 8 insertions(+) diff --git a/detections/endpoint/net_localgroup_discovery.yml b/detections/endpoint/net_localgroup_discovery.yml index 6766944d33..8409e77493 100644 --- a/detections/endpoint/net_localgroup_discovery.yml +++ b/detections/endpoint/net_localgroup_discovery.yml @@ -26,6 +26,7 @@ known_false_positives: False positives may be present. Tune as needed. references: - https://attack.mitre.org/techniques/T1069/001/ - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md +- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF tags: analytic_story: - Active Directory Discovery @@ -33,6 +34,7 @@ tags: - Azorult - Windows Post-Exploitation - Prestige Ransomware + - Volt Typhoon asset_type: Endpoint confidence: 50 impact: 30 diff --git a/detections/endpoint/windows_mimikatz_binary_execution.yml b/detections/endpoint/windows_mimikatz_binary_execution.yml index 47093447ac..9a876ef214 100644 --- a/detections/endpoint/windows_mimikatz_binary_execution.yml +++ b/detections/endpoint/windows_mimikatz_binary_execution.yml @@ -31,11 +31,13 @@ known_false_positives: False positives should be limited as this is directly loo references: - https://www.cisa.gov/uscert/sites/default/files/publications/aa22-320a_joint_csa_iranian_government-sponsored_apt_actors_compromise_federal%20network_deploy_crypto%20miner_credential_harvester.pdf - https://www.varonis.com/blog/what-is-mimikatz +- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF tags: analytic_story: - Credential Dumping - CISA AA22-320A - Sandworm Tools + - Volt Typhoon asset_type: Endpoint confidence: 100 impact: 100 diff --git a/dev/endpoint/net_localgroup_discovery.yml b/dev/endpoint/net_localgroup_discovery.yml index c862f1c6fc..230232b494 100644 --- a/dev/endpoint/net_localgroup_discovery.yml +++ b/dev/endpoint/net_localgroup_discovery.yml @@ -26,6 +26,7 @@ known_false_positives: False positives may be present. Tune as needed. references: - https://attack.mitre.org/techniques/T1069/001/ - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md +- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF tags: analytic_story: - Active Directory Discovery @@ -33,6 +34,7 @@ tags: - Azorult - Windows Post-Exploitation - Prestige Ransomware + - Volt Typhoon asset_type: Endpoint confidence: 50 impact: 30 diff --git a/dev/endpoint/windows_mimikatz_binary_execution.yml b/dev/endpoint/windows_mimikatz_binary_execution.yml index 8a6431decd..07ccefde0a 100644 --- a/dev/endpoint/windows_mimikatz_binary_execution.yml +++ b/dev/endpoint/windows_mimikatz_binary_execution.yml @@ -31,10 +31,12 @@ known_false_positives: False positives should be limited as this is directly loo references: - https://www.cisa.gov/uscert/sites/default/files/publications/aa22-320a_joint_csa_iranian_government-sponsored_apt_actors_compromise_federal%20network_deploy_crypto%20miner_credential_harvester.pdf - https://www.varonis.com/blog/what-is-mimikatz +- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF tags: analytic_story: - Credential Dumping - CISA AA22-320A + - Volt Typhoon asset_type: Endpoint confidence: 100 impact: 100 From 435764203d1c65cb880c63afe8b12f58abd8ca67 Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Thu, 25 May 2023 06:08:14 -0600 Subject: [PATCH 07/13] Update windows_dns_gather_network_info.yml --- detections/endpoint/windows_dns_gather_network_info.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/detections/endpoint/windows_dns_gather_network_info.yml b/detections/endpoint/windows_dns_gather_network_info.yml index 330b426154..6940e99e5e 100644 --- a/detections/endpoint/windows_dns_gather_network_info.yml +++ b/detections/endpoint/windows_dns_gather_network_info.yml @@ -22,9 +22,11 @@ how_to_implement: To successfully implement this search you need to be ingesting known_false_positives: network administrator can execute this command to enumerate DNS record. Filter or add other paths to the exclusion as needed. references: - https://cert.gov.ua/article/3718487 +- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF tags: analytic_story: - Sandworm Tools + - Volt Typhoon asset_type: Endpoint confidence: 50 impact: 50 From 29985a3e6cf2e25b1e3df7ebb5494d0cf7e233df Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Thu, 25 May 2023 06:35:11 -0600 Subject: [PATCH 08/13] password spray --- .../detect_psexec_with_accepteula_flag.yml | 4 +- .../elevated_group_discovery_with_net.yml | 2 + ...rs_failed_to_authenticate_wth_kerberos.yml | 57 ++++++++++--------- ...rs_fail_to_authenticate_using_kerberos.yml | 49 ++++++++-------- ...sers_failed_to_authenticate_using_ntlm.yml | 55 +++++++++--------- ...o_authenticate_wth_explicitcredentials.yml | 50 ++++++++-------- ...d_to_authenticate_from_host_using_ntlm.yml | 45 +++++++-------- ...rs_failed_to_authenticate_from_process.yml | 48 ++++++++-------- ..._failed_to_authenticate_using_kerberos.yml | 49 ++++++++-------- ...otely_failed_to_authenticate_from_host.yml | 44 +++++++------- ...ed_users_failed_to_auth_using_kerberos.yml | 37 ++++++------ ...alid_users_fail_to_auth_using_kerberos.yml | 37 ++++++------ ...nvalid_users_failed_to_auth_using_ntlm.yml | 37 ++++++------ ...s_fail_to_auth_wth_explicitcredentials.yml | 37 ++++++------ ...of_users_failed_to_auth_using_kerberos.yml | 37 ++++++------ ...rs_failed_to_authenticate_from_process.yml | 37 ++++++------ ...sers_failed_to_authenticate_using_ntlm.yml | 37 ++++++------ ...sers_remotely_failed_to_auth_from_host.yml | 37 ++++++------ .../elevated_group_discovery_with_net.yml | 2 + 19 files changed, 348 insertions(+), 353 deletions(-) diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index b1d8c8ee72..8dfbcd1d5d 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -30,7 +30,8 @@ known_false_positives: Administrators can leverage PsExec for accessing remote s and might pass `accepteula` as an argument if they are running this tool for the first time. However, it is not likely that you'd see multiple occurrences of this event on a machine -references: [] +references: +- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF tags: analytic_story: - SamSam Ransomware @@ -40,6 +41,7 @@ tags: - Active Directory Lateral Movement - CISA AA22-320A - Sandworm Tools + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 50 diff --git a/detections/endpoint/elevated_group_discovery_with_net.yml b/detections/endpoint/elevated_group_discovery_with_net.yml index 0fe71367bf..285bcae103 100644 --- a/detections/endpoint/elevated_group_discovery_with_net.yml +++ b/detections/endpoint/elevated_group_discovery_with_net.yml @@ -30,9 +30,11 @@ references: - https://attack.mitre.org/techniques/T1069/002/ - https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory - https://adsecurity.org/?p=3658 +- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF tags: analytic_story: - Active Directory Discovery + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 30 diff --git a/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml b/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml index 92964496cd..abfed4d315 100644 --- a/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml +++ b/detections/endpoint/windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos.yml @@ -1,47 +1,47 @@ -name: Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos -id: 98f22d82-9d62-11eb-9fcf-acde48001122 -version: 2 -date: '2021-04-14' author: Mauricio Velazco, Splunk -type: TTP -status: production data_source: - Windows Security 4768 +date: '2021-04-14' description: 'The following analytic identifies one source endpoint failing to authenticate - with 30 unique disabled domain users using the Kerberos protocol within 5 minutes. This behavior could - represent an adversary performing a Password Spraying attack against an Active Directory - environment using Kerberos to obtain initial access or elevate privileges. - Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed. - As attackers - progress in a breach, mistakes will be made. In certain scenarios, adversaries may - execute a password spraying attack against disabled users. Event 4768 is generated - every time the Key Distribution Center issues a Kerberos Ticket Granting Ticket - (TGT). Failure code `0x12` stands for `clients credentials have been revoked` (account - disabled, expired or locked out).\ + with 30 unique disabled domain users using the Kerberos protocol within 5 minutes. + This behavior could represent an adversary performing a Password Spraying attack + against an Active Directory environment using Kerberos to obtain initial access + or elevate privileges. Active Directory environments can be very different depending + on the organization. Users should test this detection and customize the arbitrary + threshold when needed. As attackers progress in a breach, mistakes will be made. + In certain scenarios, adversaries may execute a password spraying attack against + disabled users. Event 4768 is generated every time the Key Distribution Center issues + a Kerberos Ticket Granting Ticket (TGT). Failure code `0x12` stands for `clients + credentials have been revoked` (account disabled, expired or locked out).\ - This logic can be used for real time security monitoring as well as threat hunting exercises. - This detection will only trigger on domain controllers, not on member servers or workstations.\ + This logic can be used for real time security monitoring as well as threat hunting + exercises. This detection will only trigger on domain controllers, not on member + servers or workstations.\ The analytics returned fields allow analysts to investigate the event further by providing fields like source ip and attempted user accounts.' -search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x12 - | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress - | where unique_accounts > 30 - | `windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos_filter`' how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. +id: 98f22d82-9d62-11eb-9fcf-acde48001122 known_false_positives: A host failing to authenticate with multiple disabled domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, multi-user systems missconfigured systems. +name: Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos references: - https://attack.mitre.org/techniques/T1110/003/ +search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x12 | bucket + span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) + as tried_accounts by _time, IpAddress | where unique_accounts > 30 | `windows_multiple_disabled_users_failed_to_authenticate_wth_kerberos_filter`' +status: production tags: analytic_story: - Active Directory Password Spraying - Active Directory Kerberos Attacks + - Volt Typhoon + - Volt Typhoon + asset_type: Endpoint confidence: 70 impact: 70 message: Potential Kerberos based password spraying attack from $IpAddress$ @@ -50,9 +50,9 @@ tags: - T1110 observable: - name: IpAddress - type: Endpoint role: - Attacker + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -65,10 +65,11 @@ tags: - IpAddress risk_score: 49 security_domain: endpoint - asset_type: Endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_disabled_users_kerberos_xml/windows-security.log source: XmlWinEventLog:Security - sourcetype: xmlwineventlog \ No newline at end of file + sourcetype: xmlwineventlog + name: True Positive Test +type: TTP +version: 2 diff --git a/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml b/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml index 6c32930374..dd753b246c 100644 --- a/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml +++ b/detections/endpoint/windows_multiple_invalid_users_fail_to_authenticate_using_kerberos.yml @@ -1,48 +1,46 @@ -name: Windows Multiple Invalid Users Fail To Authenticate Using Kerberos -id: 001266a6-9d5b-11eb-829b-acde48001122 -version: 2 -date: '2021-04-14' author: Mauricio Velazco, Splunk -type: TTP -status: production data_source: - Windows Security 4768 +date: '2021-04-14' description: 'The following analytic identifies one source endpoint failing to authenticate with 30 unique invalid domain users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory - environment using Kerberos to obtain initial access or elevate privileges. - Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed. - As attackers - progress in a breach, mistakes will be made. In certain scenarios, adversaries may - execute a password spraying attack using an invalid list of users. Event 4768 is - generated every time the Key Distribution Center issues a Kerberos Ticket Granting + environment using Kerberos to obtain initial access or elevate privileges. Active + Directory environments can be very different depending on the organization. Users + should test this detection and customize the arbitrary threshold when needed. As + attackers progress in a breach, mistakes will be made. In certain scenarios, adversaries + may execute a password spraying attack using an invalid list of users. Event 4768 + is generated every time the Key Distribution Center issues a Kerberos Ticket Granting Ticket (TGT). Failure code 0x6 stands for `client not found in Kerberos database` (the attempted user is not a valid domain user).\ - This logic can be used for real time security monitoring as well as threat hunting exercises. - This detection will only trigger on domain controllers, not on member servers or - workstations.\ + This logic can be used for real time security monitoring as well as threat hunting + exercises. This detection will only trigger on domain controllers, not on member + servers or workstations.\ The analytics returned fields allow analysts to investigate the event further by providing fields like source ip and attempted user accounts.' -search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x6 - | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress - | where unique_accounts > 30 - | `windows_multiple_invalid_users_fail_to_authenticate_using_kerberos_filter` ' how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. +id: 001266a6-9d5b-11eb-829b-acde48001122 known_false_positives: A host failing to authenticate with multiple invalid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, multi-user systems and missconfigured systems. +name: Windows Multiple Invalid Users Fail To Authenticate Using Kerberos references: - https://attack.mitre.org/techniques/T1110/003/ +search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x6 | bucket + span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) + as tried_accounts by _time, IpAddress | where unique_accounts > 30 | `windows_multiple_invalid_users_fail_to_authenticate_using_kerberos_filter` ' +status: production tags: analytic_story: - Active Directory Password Spraying - Active Directory Kerberos Attacks + - Volt Typhoon + asset_type: Endpoint confidence: 70 impact: 70 message: Potential Kerberos based password spraying attack from $IpAddress$ @@ -51,9 +49,9 @@ tags: - T1110 observable: - name: IpAddress - type: Endpoint role: - Attacker + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -66,10 +64,11 @@ tags: - IpAddress risk_score: 49 security_domain: endpoint - asset_type: Endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos_xml/windows-security.log source: XmlWinEventLog:Security - sourcetype: XmlWinEventLog \ No newline at end of file + sourcetype: XmlWinEventLog + name: True Positive Test +type: TTP +version: 2 diff --git a/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml b/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml index 84ad39290c..d18dce3214 100644 --- a/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml +++ b/detections/endpoint/windows_multiple_invalid_users_failed_to_authenticate_using_ntlm.yml @@ -1,51 +1,49 @@ -name: Windows Multiple Invalid Users Failed To Authenticate Using NTLM -id: 57ad5a64-9df7-11eb-a290-acde48001122 -version: 2 -date: '2021-04-15' author: Mauricio Velazco, Splunk -type: TTP -status: production data_source: - Windows Security 4776 +date: '2021-04-15' description: 'The following analytic identifies one source endpoint failing to authenticate with 30 unique invalid users using the NTLM protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment - using NTLM to obtain initial access or elevate privileges. - Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed. - As attackers progress - in a breach, mistakes will be made. In certain scenarios, adversaries may execute - a password spraying attack using an invalid list of users. Event 4776 is generated - on the computer that is authoritative for the provided credentials. For domain accounts, - the domain controller is authoritative. For local accounts, the local computer is - authoritative. Error code 0xC0000064 stands for `The username you typed does not - exist` (the attempted user is a legitimate domain user).\ + using NTLM to obtain initial access or elevate privileges. Active Directory environments + can be very different depending on the organization. Users should test this detection + and customize the arbitrary threshold when needed. As attackers progress in a breach, + mistakes will be made. In certain scenarios, adversaries may execute a password + spraying attack using an invalid list of users. Event 4776 is generated on the computer + that is authoritative for the provided credentials. For domain accounts, the domain + controller is authoritative. For local accounts, the local computer is authoritative. + Error code 0xC0000064 stands for `The username you typed does not exist` (the attempted + user is a legitimate domain user).\ - This logic can be used for real time security monitoring as well as threat hunting exercises. - This detection will only trigger on domain controllers, not on member servers or - workstations.\ + This logic can be used for real time security monitoring as well as threat hunting + exercises. This detection will only trigger on domain controllers, not on member + servers or workstations.\ The analytics returned fields allow analysts to investigate the event further by providing fields like source workstation name and attempted user accounts.' -search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xc0000064 - | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, Workstation - | where unique_accounts > 30 - | `windows_multiple_invalid_users_failed_to_authenticate_using_ntlm_filter`' how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller events. The Advanced Security Audit policy setting `Audit Credential Validation' within `Account Logon` needs to be enabled. +id: 57ad5a64-9df7-11eb-a290-acde48001122 known_false_positives: A host failing to authenticate with multiple invalid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners and missconfigured systems. If this detection triggers on a host other than a Domain Controller, the behavior could represent a password spraying attack against the host's local accounts. +name: Windows Multiple Invalid Users Failed To Authenticate Using NTLM references: - https://attack.mitre.org/techniques/T1110/003/ - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776 +search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xc0000064 + | bucket span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) + as tried_accounts by _time, Workstation | where unique_accounts > 30 | `windows_multiple_invalid_users_failed_to_authenticate_using_ntlm_filter`' +status: production tags: analytic_story: - Active Directory Password Spraying + - Volt Typhoon + asset_type: Endpoint confidence: 70 impact: 70 message: Potential NTLM based password spraying attack from $Workstation$ @@ -54,9 +52,9 @@ tags: - T1110 observable: - name: Workstation - type: Endpoint role: - Attacker + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -69,10 +67,11 @@ tags: - Status risk_score: 49 security_domain: endpoint - asset_type: Endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_ntlm_xml/windows-security.log source: XmlWinEventLog:Security - sourcetype: XmlWinEventLog \ No newline at end of file + sourcetype: XmlWinEventLog + name: True Positive Test +type: TTP +version: 2 diff --git a/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml b/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml index 608660765e..b463749e4a 100644 --- a/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml +++ b/detections/endpoint/windows_multiple_users_fail_to_authenticate_wth_explicitcredentials.yml @@ -1,51 +1,50 @@ -name: Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials -id: e61918fa-9ca4-11eb-836c-acde48001122 -version: 2 -date: '2021-04-13' author: Mauricio Velazco, Splunk -type: TTP -status: production data_source: - Windows Security 4648 +date: '2021-04-13' description: 'The following analytic identifies a source user failing to authenticate with 30 unique users using explicit credentials on a host. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment - to obtain initial access or elevate privileges. - Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed. - Event 4648 is generated when a process - attempts an account logon by explicitly specifying that accounts credentials. This - event generates on domain controllers, member servers, and workstations.\ + to obtain initial access or elevate privileges. Active Directory environments can + be very different depending on the organization. Users should test this detection + and customize the arbitrary threshold when needed. Event 4648 is generated when + a process attempts an account logon by explicitly specifying that accounts credentials. + This event generates on domain controllers, member servers, and workstations.\ - This logic can be used for real time security monitoring as well as threat hunting exercises. - This detection will trigger on the potenfially malicious host, perhaps controlled - via a trojan or operated by an insider threat, from where a password spraying attack - is being executed.\ + This logic can be used for real time security monitoring as well as threat hunting + exercises. This detection will trigger on the potenfially malicious host, perhaps + controlled via a trojan or operated by an insider threat, from where a password + spraying attack is being executed.\ The analytics returned fields allow analysts to investigate the event further by providing fields like source account, attempted user accounts and the endpoint were the behavior was identified.' -search: ' `wineventlog_security` EventCode=4648 Caller_User_Name!=*$ Target_User_Name!=*$ - | bucket span=5m _time - | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as tried_account by _time, Computer, Caller_User_Name - | where unique_accounts > 30 - | `windows_multiple_users_fail_to_authenticate_wth_explicitcredentials_filter` ' how_to_implement: To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers as well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. +id: e61918fa-9ca4-11eb-836c-acde48001122 known_false_positives: A source user failing attempting to authenticate multiple users on a host is not a common behavior for regular systems. Some applications, however, may exhibit this behavior in which case sets of users hosts can be added to an allow list. Possible false positive scenarios include systems where several users connect to like Mail servers, identity providers, remote desktop services, Citrix, etc. +name: Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials references: - https://attack.mitre.org/techniques/T1110/003/ - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648 - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events +search: ' `wineventlog_security` EventCode=4648 Caller_User_Name!=*$ Target_User_Name!=*$ + | bucket span=5m _time | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) + as tried_account by _time, Computer, Caller_User_Name | where unique_accounts > + 30 | `windows_multiple_users_fail_to_authenticate_wth_explicitcredentials_filter` ' +status: production tags: analytic_story: - Active Directory Password Spraying - Insider Threat + - Volt Typhoon + asset_type: Endpoint confidence: 70 impact: 70 message: Potential password spraying attack from $Computer$ @@ -54,9 +53,9 @@ tags: - T1110 observable: - name: Computer - type: Endpoint role: - Victim + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -69,10 +68,11 @@ tags: - Computer risk_score: 49 security_domain: endpoint - asset_type: Endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_explicit_credential_spray_xml/windows-security.log source: XmlWinEventLog:Security - sourcetype: XmlWinEventLog \ No newline at end of file + sourcetype: XmlWinEventLog + name: True Positive Test +type: TTP +version: 2 diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml index cebe824aa1..6d090f8c77 100644 --- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml +++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_host_using_ntlm.yml @@ -1,49 +1,47 @@ -name: Windows Multiple Users Failed To Authenticate From Host Using NTLM -id: 7ed272a4-9c77-11eb-af22-acde48001122 -version: 2 -date: '2021-04-13' author: Mauricio Velazco, Splunk -type: TTP -status: production data_source: - Windows Security 4776 +date: '2021-04-13' description: 'The following analytic identifies one source endpoint failing to authenticate with 30 unique valid users using the NTLM protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment - using NTLM to obtain initial access or elevate privileges. - Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed. - Event 4776 is generated - on the computer that is authoritative for the provided credentials. For domain accounts, + using NTLM to obtain initial access or elevate privileges. Active Directory environments + can be very different depending on the organization. Users should test this detection + and customize the arbitrary threshold when needed. Event 4776 is generated on the + computer that is authoritative for the provided credentials. For domain accounts, the domain controller is authoritative. For local accounts, the local computer is authoritative. Error code 0xC000006A means: misspelled or bad password (the attempted user is a legitimate domain user).\ - This logic can be used for real time security monitoring as well as threat hunting exercises. - This detection will only trigger on domain controllers, not on member servers or - workstations.\ + This logic can be used for real time security monitoring as well as threat hunting + exercises. This detection will only trigger on domain controllers, not on member + servers or workstations.\ The analytics returned fields allow analysts to investigate the event further by providing fields like source workstation name and attempted user accounts.' -search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xC000006A - | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, Workstation - | where unique_accounts > 30 - | `windows_multiple_users_failed_to_authenticate_from_host_using_ntlm_filter`' how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller events. The Advanced Security Audit policy setting `Audit Credential Validation` within `Account Logon` needs to be enabled. +id: 7ed272a4-9c77-11eb-af22-acde48001122 known_false_positives: A host failing to authenticate with multiple valid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners and missconfigured systems. If this detection triggers on a host other than a Domain Controller, the behavior could represent a password spraying attack against the host's local accounts. +name: Windows Multiple Users Failed To Authenticate From Host Using NTLM references: - https://attack.mitre.org/techniques/T1110/003/ - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776 +search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xC000006A + | bucket span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) + as tried_accounts by _time, Workstation | where unique_accounts > 30 | `windows_multiple_users_failed_to_authenticate_from_host_using_ntlm_filter`' +status: production tags: analytic_story: - Active Directory Password Spraying + - Volt Typhoon + asset_type: Endpoint confidence: 70 impact: 70 message: Potential NTLM based password spraying attack from $Workstation$ @@ -52,9 +50,9 @@ tags: - T1110 observable: - name: Workstation - type: Endpoint role: - Attacker + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -67,10 +65,11 @@ tags: - Workstation risk_score: 49 security_domain: endpoint - asset_type: Endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_ntlm_xml/windows-security.log source: XmlWinEventLog:Security - sourcetype: XmlWinEventLog \ No newline at end of file + sourcetype: XmlWinEventLog + name: True Positive Test +type: TTP +version: 2 diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml index 5b98853c81..9a1e75e568 100644 --- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml +++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_from_process.yml @@ -1,50 +1,49 @@ -name: Windows Multiple Users Failed To Authenticate From Process -id: 9015385a-9c84-11eb-bef2-acde48001122 -version: 2 -date: '2021-04-13' author: Mauricio Velazco, Splunk -type: TTP -status: production data_source: - Windows Security 4625 +date: '2021-04-13' description: 'The following analytic identifies a source process name failing to authenticate with 30 uniquer users. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment to obtain initial access - or elevate privileges. - Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed. - Event 4625 generates on domain controllers, member servers, + or elevate privileges. Active Directory environments can be very different depending + on the organization. Users should test this detection and customize the arbitrary + threshold when needed. Event 4625 generates on domain controllers, member servers, and workstations when an account fails to logon. Logon Type 2 describes an iteractive logon attempt.\ - This logic can be used for real time security monitoring as well as threat hunting exercises. - This detection will trigger on the potenfially malicious host, perhaps controlled - via a trojan or operated by an insider threat, from where a password spraying attack - is being executed. This could be a domain controller as well as a member server - or workstation.\ + This logic can be used for real time security monitoring as well as threat hunting + exercises. This detection will trigger on the potenfially malicious host, perhaps + controlled via a trojan or operated by an insider threat, from where a password + spraying attack is being executed. This could be a domain controller as well as + a member server or workstation.\ The analytics returned fields allow analysts to investigate the event further by providing fields like source process name, source account and attempted user accounts.' -search: ' `wineventlog_security` EventCode=4625 Logon_Type=2 ProcessName!="-" - | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, ProcessName, SubjectUserName, Computer - | where unique_accounts > 30 - | `windows_multiple_users_failed_to_authenticate_from_process_filter`' how_to_implement: To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers aas well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. +id: 9015385a-9c84-11eb-bef2-acde48001122 known_false_positives: A process failing to authenticate with multiple users is not a common behavior for legitimate user sessions. Possible false positive scenarios include but are not limited to vulnerability scanners and missconfigured systems. +name: Windows Multiple Users Failed To Authenticate From Process references: - https://attack.mitre.org/techniques/T1110/003/ - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625 - https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625 - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events +search: ' `wineventlog_security` EventCode=4625 Logon_Type=2 ProcessName!="-" | bucket + span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) + as tried_accounts by _time, ProcessName, SubjectUserName, Computer | where unique_accounts + > 30 | `windows_multiple_users_failed_to_authenticate_from_process_filter`' +status: production tags: analytic_story: - Active Directory Password Spraying - Insider Threat + - Volt Typhoon + asset_type: Endpoint confidence: 70 impact: 70 message: Potential password spraying attack from $Computer$ @@ -53,9 +52,9 @@ tags: - T1110 observable: - name: ComputerName - type: Endpoint role: - Victim + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -70,10 +69,11 @@ tags: - Computer risk_score: 49 security_domain: endpoint - asset_type: Endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_multiple_users_from_process_xml/windows-security.log source: XmlWinEventLog:Security - sourcetype: XmlWinEventLog \ No newline at end of file + sourcetype: XmlWinEventLog + name: True Positive Test +type: TTP +version: 2 diff --git a/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml b/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml index 14e5436bf1..b3f6f562d3 100644 --- a/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml +++ b/detections/endpoint/windows_multiple_users_failed_to_authenticate_using_kerberos.yml @@ -1,48 +1,46 @@ -name: Windows Multiple Users Failed To Authenticate Using Kerberos -id: 3a91a212-98a9-11eb-b86a-acde48001122 -version: 2 -date: '2021-04-08' author: Mauricio Velazco, Splunk -type: TTP -status: production data_source: - Windows Security 4771 +date: '2021-04-08' description: 'The following analytic identifies one source endpoint failing to authenticate with 30 unique users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment - using Kerberos to obtain initial access or elevate privileges. - Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed. - Event 4771 is generated - when the Key Distribution Center fails to issue a Kerberos Ticket Granting Ticket - (TGT). Failure code 0x18 stands for `wrong password provided` (the attempted user - is a legitimate domain user).\ + using Kerberos to obtain initial access or elevate privileges. Active Directory + environments can be very different depending on the organization. Users should test + this detection and customize the arbitrary threshold when needed. Event 4771 is + generated when the Key Distribution Center fails to issue a Kerberos Ticket Granting + Ticket (TGT). Failure code 0x18 stands for `wrong password provided` (the attempted + user is a legitimate domain user).\ - This logic can be used for real time security monitoring as well as threat hunting exercises. - This detection will only trigger on domain controllers, not on member servers or - workstations.\ + This logic can be used for real time security monitoring as well as threat hunting + exercises. This detection will only trigger on domain controllers, not on member + servers or workstations.\ The analytics returned fields allow analysts to investigate the event further by providing fields like source ip and attempted user accounts.' -search: '`wineventlog_security` EventCode=4771 TargetUserName!="*$" Status=0x18 - | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress - | where unique_accounts > 30 - | `windows_multiple_users_failed_to_authenticate_using_kerberos_filter`' how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. +id: 3a91a212-98a9-11eb-b86a-acde48001122 known_false_positives: A host failing to authenticate with multiple valid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, missconfigured systems and multi-user systems like Citrix farms. +name: Windows Multiple Users Failed To Authenticate Using Kerberos references: - https://attack.mitre.org/techniques/T1110/003/ - https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn319109(v=ws.11) - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4771 +search: '`wineventlog_security` EventCode=4771 TargetUserName!="*$" Status=0x18 | + bucket span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) + as tried_accounts by _time, IpAddress | where unique_accounts > 30 | `windows_multiple_users_failed_to_authenticate_using_kerberos_filter`' +status: production tags: analytic_story: - Active Directory Password Spraying - Active Directory Kerberos Attacks + - Volt Typhoon + asset_type: Endpoint confidence: 70 impact: 70 message: Potential Kerberos based password spraying attack from $IpAddress$ @@ -51,9 +49,9 @@ tags: - T1110 observable: - name: IpAddress - type: Endpoint role: - Attacker + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -66,10 +64,11 @@ tags: - IpAddress risk_score: 49 security_domain: endpoint - asset_type: Endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_kerberos_xml/windows-security.log source: XmlWinEventLog:Security - sourcetype: XmlWinEventLog \ No newline at end of file + sourcetype: XmlWinEventLog + name: True Positive Test +type: TTP +version: 2 diff --git a/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml b/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml index 9cf4f8a566..6cc3cbd1e5 100644 --- a/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml +++ b/detections/endpoint/windows_multiple_users_remotely_failed_to_authenticate_from_host.yml @@ -1,49 +1,48 @@ -name: Windows Multiple Users Remotely Failed To Authenticate From Host -id: 80f9d53e-9ca1-11eb-b0d6-acde48001122 -version: 2 -date: '2021-04-13' author: Mauricio Velazco, Splunk -type: TTP -status: production data_source: - Windows Security 4625 +date: '2021-04-13' description: 'The following analytic identifies a source host failing to authenticate against a remote host with 30 unique users. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment to - obtain initial access or elevate privileges. - Active Directory environments can be very different depending on the organization. Users should test this detection and customize the arbitrary threshold when needed. - Event 4625 documents each and every + obtain initial access or elevate privileges. Active Directory environments can be + very different depending on the organization. Users should test this detection and + customize the arbitrary threshold when needed. Event 4625 documents each and every failed attempt to logon to the local computer. This event generates on domain controllers, member servers, and workstations. Logon Type 3 describes an remote authentication attempt.\ - This logic can be used for real time security monitoring as well as threat hunting exercises. - This detection will trigger on the host that is the target of the password spraying - attack. This could be a domain controller as well as a member server or workstation.\ + This logic can be used for real time security monitoring as well as threat hunting + exercises. This detection will trigger on the host that is the target of the password + spraying attack. This could be a domain controller as well as a member server or + workstation.\ The analytics returned fields allow analysts to investigate the event further by providing fields like source process name, source account and attempted user accounts.' -search: ' `wineventlog_security` EventCode=4625 Logon_Type=3 IpAddress!="-" - | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress, Computer - | where unique_accounts > 30 - | `windows_multiple_users_remotely_failed_to_authenticate_from_host_filter` ' how_to_implement: To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers as as well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. +id: 80f9d53e-9ca1-11eb-b0d6-acde48001122 known_false_positives: A host failing to authenticate with multiple valid users against a remote host is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, remote administration tools, missconfigyred systems, etc. +name: Windows Multiple Users Remotely Failed To Authenticate From Host references: - https://attack.mitre.org/techniques/T1110/003/ - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625 - https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625 - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events +search: ' `wineventlog_security` EventCode=4625 Logon_Type=3 IpAddress!="-" | bucket + span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) + as tried_accounts by _time, IpAddress, Computer | where unique_accounts > 30 | `windows_multiple_users_remotely_failed_to_authenticate_from_host_filter` ' +status: production tags: analytic_story: - Active Directory Password Spraying + - Volt Typhoon + asset_type: Endpoint confidence: 70 impact: 70 message: Potential password spraying attack on $ComputerName$ @@ -52,9 +51,9 @@ tags: - T1110 observable: - name: ComputerName - type: Endpoint role: - Victim + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -68,10 +67,11 @@ tags: - IpAddress risk_score: 49 security_domain: endpoint - asset_type: Endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_remote_spray_xml/windows-security.log source: XmlWinEventLog:Security - sourcetype: XmlWinEventLog \ No newline at end of file + sourcetype: XmlWinEventLog + name: True Positive Test +type: TTP +version: 2 diff --git a/detections/endpoint/windows_unusual_count_of_disabled_users_failed_to_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_disabled_users_failed_to_auth_using_kerberos.yml index 185f324b2e..58ccb959ae 100644 --- a/detections/endpoint/windows_unusual_count_of_disabled_users_failed_to_auth_using_kerberos.yml +++ b/detections/endpoint/windows_unusual_count_of_disabled_users_failed_to_auth_using_kerberos.yml @@ -1,10 +1,7 @@ -name: Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos -id: f65aa026-b811-42ab-b4b9-d9088137648f -version: 1 -date: '2022-09-22' author: Mauricio Velazco, Splunk -status: production -type: Anomaly +data_source: +- Windows Security 4768 +date: '2022-09-22' description: 'The following analytic identifies one source endpoint failing to authenticate with multiple disabled domain users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory @@ -26,29 +23,29 @@ description: 'The following analytic identifies one source endpoint failing to a The analytics returned fields allow analysts to investigate the event further by providing fields like source ip and attempted user accounts.' -data_source: -- Windows Security 4768 -search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x12 - | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress - | eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by IpAddress - | eval upperBound=(comp_avg+comp_std*3) - | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) - | search isOutlier=1 - | `windows_unusual_count_of_disabled_users_failed_auth_using_kerberos_filter` ' how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. +id: f65aa026-b811-42ab-b4b9-d9088137648f known_false_positives: A host failing to authenticate with multiple disabled domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, multi-user systems missconfigured systems. +name: Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos references: - https://attack.mitre.org/techniques/T1110/003/ +search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x12 | bucket + span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) + as tried_accounts by _time, IpAddress | eventstats avg(unique_accounts) as comp_avg + , stdev(unique_accounts) as comp_std by IpAddress | eval upperBound=(comp_avg+comp_std*3) + | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) + | search isOutlier=1 | `windows_unusual_count_of_disabled_users_failed_auth_using_kerberos_filter` ' +status: production tags: analytic_story: - Active Directory Password Spraying - Active Directory Kerberos Attacks + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 70 @@ -58,9 +55,9 @@ tags: - T1110 observable: - name: IpAddress - type: Endpoint role: - Attacker + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -74,8 +71,10 @@ tags: risk_score: 49 security_domain: endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_disabled_users_kerberos_xml/windows-security.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog + name: True Positive Test +type: Anomaly +version: 1 diff --git a/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml index acd564fb68..5cfe826c2e 100644 --- a/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml +++ b/detections/endpoint/windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos.yml @@ -1,10 +1,7 @@ -name: Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos -id: f122cb2e-d773-4f11-8399-62a3572d8dd7 -version: 1 -date: '2022-09-22' author: Mauricio Velazco, Splunk -status: production -type: Anomaly +data_source: +- Windows Security 4768 +date: '2022-09-22' description: 'The following analytic identifies one source endpoint failing to authenticate with multiple invalid domain users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory @@ -26,29 +23,29 @@ description: 'The following analytic identifies one source endpoint failing to a The analytics returned fields allow analysts to investigate the event further by providing fields like source ip and attempted user accounts.' -data_source: -- Windows Security 4768 -search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x6 - | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress - | eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by IpAddress - | eval upperBound=(comp_avg+comp_std*3) - | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) - | search isOutlier=1 - | `windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos_filter` ' how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. +id: f122cb2e-d773-4f11-8399-62a3572d8dd7 known_false_positives: A host failing to authenticate with multiple invalid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, multi-user systems and missconfigured systems. +name: Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos references: - https://attack.mitre.org/techniques/T1110/003/ +search: '`wineventlog_security` EventCode=4768 TargetUserName!=*$ Status=0x6 | bucket + span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) + as tried_accounts by _time, IpAddress | eventstats avg(unique_accounts) as comp_avg + , stdev(unique_accounts) as comp_std by IpAddress | eval upperBound=(comp_avg+comp_std*3) + | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) + | search isOutlier=1 | `windows_unusual_count_of_invalid_users_fail_to_auth_using_kerberos_filter` ' +status: production tags: analytic_story: - Active Directory Password Spraying - Active Directory Kerberos Attacks + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 70 @@ -58,9 +55,9 @@ tags: - T1110 observable: - name: IpAddress - type: Endpoint role: - Attacker + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -74,8 +71,10 @@ tags: risk_score: 49 security_domain: endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos_xml/windows-security.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog + name: True Positive Test +type: Anomaly +version: 1 diff --git a/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml b/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml index 57c3ba7f17..1e60e7ac16 100644 --- a/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml +++ b/detections/endpoint/windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm.yml @@ -1,10 +1,7 @@ -name: Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM -id: 15603165-147d-4a6e-9778-bd0ff39e668f -version: 1 -date: '2022-09-22' author: Mauricio Velazco, Splunk -status: production -type: Anomaly +data_source: +- Windows Security 4776 +date: '2022-09-22' description: 'The following analytic identifies one source endpoint failing to authenticate with multiple invalid users using the NTLM protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment @@ -27,31 +24,31 @@ description: 'The following analytic identifies one source endpoint failing to a The analytics returned fields allow analysts to investigate the event further by providing fields like source workstation name and attempted user accounts.' -data_source: -- Windows Security 4776 -search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xc0000064 - | bucket span=2m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, Workstation - | eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Workstation - | eval upperBound=(comp_avg+comp_std*3) - | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) - | search isOutlier=1 - | `windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm_filter`' how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller events. The Advanced Security Audit policy setting `Audit Credential Validation' within `Account Logon` needs to be enabled. +id: 15603165-147d-4a6e-9778-bd0ff39e668f known_false_positives: A host failing to authenticate with multiple invalid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners and missconfigured systems. If this detection triggers on a host other than a Domain Controller, the behavior could represent a password spraying attack against the host's local accounts. +name: Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM references: - https://attack.mitre.org/techniques/T1110/003/ - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776 +search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xc0000064 + | bucket span=2m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) + as tried_accounts by _time, Workstation | eventstats avg(unique_accounts) as comp_avg + , stdev(unique_accounts) as comp_std by Workstation | eval upperBound=(comp_avg+comp_std*3) + | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) + | search isOutlier=1 | `windows_unusual_count_of_invalid_users_failed_to_auth_using_ntlm_filter`' +status: production tags: analytic_story: - Active Directory Password Spraying + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 70 @@ -61,9 +58,9 @@ tags: - T1110 observable: - name: Workstation - type: Endpoint role: - Attacker + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -77,8 +74,10 @@ tags: risk_score: 49 security_domain: endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_ntlm_xml/windows-security.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog + name: True Positive Test +type: Anomaly +version: 1 diff --git a/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml b/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml index 10fce2663a..6d55bb53e9 100644 --- a/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml +++ b/detections/endpoint/windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials.yml @@ -1,10 +1,7 @@ -name: Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials -id: 14f414cf-3080-4b9b-aaf6-55a4ce947b93 -version: 1 -date: '2022-09-22' author: Mauricio Velazco, Splunk -status: production -type: Anomaly +data_source: +- Windows Security 4648 +date: '2022-09-22' description: 'The following analytic identifies a source user failing to authenticate with multiple users using explicit credentials on a host. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment @@ -25,33 +22,33 @@ description: 'The following analytic identifies a source user failing to authent The analytics returned fields allow analysts to investigate the event further by providing fields like source account, attempted user accounts and the endpoint were the behavior was identified.' -data_source: -- Windows Security 4648 -search: ' `wineventlog_security` EventCode=4648 Caller_User_Name!=*$ Target_User_Name!=*$ - | bucket span=5m _time - | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as tried_account by _time, Computer, Caller_User_Name - | eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Computer - | eval upperBound=(comp_avg+comp_std*3) - | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) - | search isOutlier=1 - | `windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials_filter` ' how_to_implement: To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers as well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. +id: 14f414cf-3080-4b9b-aaf6-55a4ce947b93 known_false_positives: A source user failing attempting to authenticate multiple users on a host is not a common behavior for regular systems. Some applications, however, may exhibit this behavior in which case sets of users hosts can be added to an allow list. Possible false positive scenarios include systems where several users connect to like Mail servers, identity providers, remote desktop services, Citrix, etc. +name: Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials references: - https://attack.mitre.org/techniques/T1110/003/ - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648 - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events +search: ' `wineventlog_security` EventCode=4648 Caller_User_Name!=*$ Target_User_Name!=*$ + | bucket span=5m _time | stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) + as tried_account by _time, Computer, Caller_User_Name | eventstats avg(unique_accounts) + as comp_avg , stdev(unique_accounts) as comp_std by Computer | eval upperBound=(comp_avg+comp_std*3) + | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) + | search isOutlier=1 | `windows_unusual_count_of_users_fail_to_auth_wth_explicitcredentials_filter` ' +status: production tags: analytic_story: - Active Directory Password Spraying - Insider Threat + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 70 @@ -61,9 +58,9 @@ tags: - T1110 observable: - name: Computer - type: Endpoint role: - Attacker + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -77,8 +74,10 @@ tags: risk_score: 49 security_domain: endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_explicit_credential_spray_xml/windows-security.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog + name: True Positive Test +type: Anomaly +version: 1 diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml index d2d1d624fc..a246741e2a 100644 --- a/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml +++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_auth_using_kerberos.yml @@ -1,10 +1,7 @@ -name: Windows Unusual Count Of Users Failed To Auth Using Kerberos -id: bc9cb715-08ba-40c3-9758-6e2b26e455cb -version: 1 -date: '2022-09-22' author: Mauricio Velazco, Splunk -status: production -type: Anomaly +data_source: +- Windows Security 4771 +date: '2022-09-22' description: 'The following analytic identifies one source endpoint failing to authenticate with multiple valid users using the Kerberos protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment @@ -24,31 +21,31 @@ description: 'The following analytic identifies one source endpoint failing to a The analytics returned fields allow analysts to investigate the event further by providing fields like source ip and attempted user accounts.' -data_source: -- Windows Security 4771 -search: '`wineventlog_security` EventCode=4771 TargetUserName!="*$" Status=0x18 - | bucket span=5m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress - | eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by IpAddress - | eval upperBound=(comp_avg+comp_std*3) - | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) - | search isOutlier=1 - | `windows_unusual_count_of_users_failed_to_auth_using_kerberos_filter`' how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. +id: bc9cb715-08ba-40c3-9758-6e2b26e455cb known_false_positives: A host failing to authenticate with multiple valid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, missconfigured systems and multi-user systems like Citrix farms. +name: Windows Unusual Count Of Users Failed To Auth Using Kerberos references: - https://attack.mitre.org/techniques/T1110/003/ - https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn319109(v=ws.11) - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4771 +search: '`wineventlog_security` EventCode=4771 TargetUserName!="*$" Status=0x18 | + bucket span=5m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) + as tried_accounts by _time, IpAddress | eventstats avg(unique_accounts) as comp_avg + , stdev(unique_accounts) as comp_std by IpAddress | eval upperBound=(comp_avg+comp_std*3) + | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) + | search isOutlier=1 | `windows_unusual_count_of_users_failed_to_auth_using_kerberos_filter`' +status: production tags: analytic_story: - Active Directory Password Spraying - Active Directory Kerberos Attacks + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 70 @@ -58,9 +55,9 @@ tags: - T1110 observable: - name: IpAddress - type: Endpoint role: - Attacker + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -74,8 +71,10 @@ tags: risk_score: 49 security_domain: endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_kerberos_xml/windows-security.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog + name: True Positive Test +type: Anomaly +version: 1 diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml index 9b7c7e26ac..1965682c7b 100644 --- a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml +++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_from_process.yml @@ -1,10 +1,7 @@ -name: Windows Unusual Count Of Users Failed To Authenticate From Process -id: 25bdb6cb-2e49-4d34-a93c-d6c567c122fe -version: 1 -date: '2022-09-22' author: Mauricio Velazco, Splunk -status: production -type: Anomaly +data_source: +- Windows Security 4625 +date: '2022-09-22' description: 'The following analytic identifies a source process name failing to authenticate with multiple users. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment to obtain initial access @@ -25,32 +22,32 @@ description: 'The following analytic identifies a source process name failing to The analytics returned fields allow analysts to investigate the event further by providing fields like source process name, source account and attempted user accounts.' -data_source: -- Windows Security 4625 -search: ' `wineventlog_security` EventCode=4625 Logon_Type=2 ProcessName!="-" - | bucket span=2m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, ProcessName, SubjectUserName, Computer - | eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by ProcessName, SubjectUserName, Computer - | eval upperBound=(comp_avg+comp_std*3) - | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) - | search isOutlier=1 - | `windows_unusual_count_of_users_failed_to_authenticate_from_process_filter` ' how_to_implement: To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers aas well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. +id: 25bdb6cb-2e49-4d34-a93c-d6c567c122fe known_false_positives: A process failing to authenticate with multiple users is not a common behavior for legitimate user sessions. Possible false positive scenarios include but are not limited to vulnerability scanners and missconfigured systems. +name: Windows Unusual Count Of Users Failed To Authenticate From Process references: - https://attack.mitre.org/techniques/T1110/003/ - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625 - https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625 - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events +search: ' `wineventlog_security` EventCode=4625 Logon_Type=2 ProcessName!="-" | bucket + span=2m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) + as tried_accounts by _time, ProcessName, SubjectUserName, Computer | eventstats + avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by ProcessName, + SubjectUserName, Computer | eval upperBound=(comp_avg+comp_std*3) | eval isOutlier=if(unique_accounts + > 10 and unique_accounts >= upperBound, 1, 0) | search isOutlier=1 | `windows_unusual_count_of_users_failed_to_authenticate_from_process_filter` ' +status: production tags: analytic_story: - Active Directory Password Spraying - Insider Threat + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 70 @@ -60,9 +57,9 @@ tags: - T1110 observable: - name: Computer - type: Endpoint role: - Attacker + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -78,8 +75,10 @@ tags: risk_score: 49 security_domain: endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_multiple_users_from_process_xml/windows-security.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog + name: True Positive Test +type: Anomaly +version: 1 diff --git a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml index b0f0ffc365..b3aa0bee59 100644 --- a/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml +++ b/detections/endpoint/windows_unusual_count_of_users_failed_to_authenticate_using_ntlm.yml @@ -1,10 +1,7 @@ -name: Windows Unusual Count Of Users Failed To Authenticate Using NTLM -id: 6f6c8fd7-6a6b-4af9-a0e9-57cfc47a58b4 -version: 1 -date: '2022-09-22' author: Mauricio Velazco, Splunk -status: production -type: Anomaly +data_source: +- Windows Security 4776 +date: '2022-09-22' description: 'The following analytic identifies one source endpoint failing to authenticate with multiple valid users using the NTLM protocol. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment @@ -25,31 +22,31 @@ description: 'The following analytic identifies one source endpoint failing to a The analytics returned fields allow analysts to investigate the event further by providing fields like source workstation name and attempted user accounts.' -data_source: -- Windows Security 4776 -search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xC000006A - | bucket span=2m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, Workstation - | eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by Workstation - | eval upperBound=(comp_avg+comp_std*3) - | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) - | search isOutlier=1 - | `windows_unusual_count_of_users_failed_to_authenticate_using_ntlm_filter`' how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller events. The Advanced Security Audit policy setting `Audit Credential Validation` within `Account Logon` needs to be enabled. +id: 6f6c8fd7-6a6b-4af9-a0e9-57cfc47a58b4 known_false_positives: A host failing to authenticate with multiple valid domain users is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners and missconfigured systems. If this detection triggers on a host other than a Domain Controller, the behavior could represent a password spraying attack against the host's local accounts. +name: Windows Unusual Count Of Users Failed To Authenticate Using NTLM references: - https://attack.mitre.org/techniques/T1110/003/ - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-credential-validation - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776 +search: ' `wineventlog_security` EventCode=4776 TargetUserName!=*$ Status=0xC000006A + | bucket span=2m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) + as tried_accounts by _time, Workstation | eventstats avg(unique_accounts) as comp_avg + , stdev(unique_accounts) as comp_std by Workstation | eval upperBound=(comp_avg+comp_std*3) + | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) + | search isOutlier=1 | `windows_unusual_count_of_users_failed_to_authenticate_using_ntlm_filter`' +status: production tags: analytic_story: - Active Directory Password Spraying + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 70 @@ -59,9 +56,9 @@ tags: - T1110 observable: - name: Workstation - type: Endpoint role: - Attacker + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -75,8 +72,10 @@ tags: risk_score: 49 security_domain: endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_valid_users_ntlm_xml/windows-security.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog + name: True Positive Test +type: Anomaly +version: 1 diff --git a/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml b/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml index e2e34de94c..d50a41176e 100644 --- a/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml +++ b/detections/endpoint/windows_unusual_count_of_users_remotely_failed_to_auth_from_host.yml @@ -1,10 +1,7 @@ -name: Windows Unusual Count Of Users Remotely Failed To Auth From Host -id: cf06a0ee-ffa9-4ed3-be77-0670ed9bab52 -version: 1 -date: '2022-09-22' author: Mauricio Velazco, Splunk -status: production -type: Anomaly +data_source: +- Windows Security 4625 +date: '2022-09-22' description: 'The following analytic identifies a source host failing to authenticate against a remote host with multiple users. This behavior could represent an adversary performing a Password Spraying attack against an Active Directory environment to @@ -24,32 +21,32 @@ description: 'The following analytic identifies a source host failing to authent The analytics returned fields allow analysts to investigate the event further by providing fields like source process name, source account and attempted user accounts.' -data_source: -- Windows Security 4625 -search: ' `wineventlog_security` EventCode=4625 Logon_Type=3 IpAddress!="-" - | bucket span=2m _time - | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts by _time, IpAddress, Computer - | eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std by IpAddress, Computer - | eval upperBound=(comp_avg+comp_std*3) - | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) - | search isOutlier=1 - | `windows_unusual_count_of_users_remotely_failed_to_auth_from_host_filter` ' how_to_implement: To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers as as well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. +id: cf06a0ee-ffa9-4ed3-be77-0670ed9bab52 known_false_positives: A host failing to authenticate with multiple valid users against a remote host is not a common behavior for legitimate systems. Possible false positive scenarios include but are not limited to vulnerability scanners, remote administration tools, missconfigyred systems, etc. +name: Windows Unusual Count Of Users Remotely Failed To Auth From Host references: - https://attack.mitre.org/techniques/T1110/003/ - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625 - https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625 - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events +search: ' `wineventlog_security` EventCode=4625 Logon_Type=3 IpAddress!="-" | bucket + span=2m _time | stats dc(TargetUserName) AS unique_accounts values(TargetUserName) + as tried_accounts by _time, IpAddress, Computer | eventstats avg(unique_accounts) + as comp_avg , stdev(unique_accounts) as comp_std by IpAddress, Computer | eval upperBound=(comp_avg+comp_std*3) + | eval isOutlier=if(unique_accounts > 10 and unique_accounts >= upperBound, 1, 0) + | search isOutlier=1 | `windows_unusual_count_of_users_remotely_failed_to_auth_from_host_filter` ' +status: production tags: analytic_story: - Active Directory Password Spraying + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 70 @@ -59,9 +56,9 @@ tags: - T1110 observable: - name: Computer - type: Endpoint role: - Attacker + type: Endpoint product: - Splunk Enterprise - Splunk Enterprise Security @@ -76,8 +73,10 @@ tags: risk_score: 49 security_domain: endpoint tests: -- name: True Positive Test - attack_data: +- attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_remote_spray_xml/windows-security.log source: XmlWinEventLog:Security sourcetype: XmlWinEventLog + name: True Positive Test +type: Anomaly +version: 1 diff --git a/dev/endpoint/elevated_group_discovery_with_net.yml b/dev/endpoint/elevated_group_discovery_with_net.yml index d92cdf0674..ea78b2ed44 100644 --- a/dev/endpoint/elevated_group_discovery_with_net.yml +++ b/dev/endpoint/elevated_group_discovery_with_net.yml @@ -39,9 +39,11 @@ references: - https://attack.mitre.org/techniques/T1069/002/ - https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b--privileged-accounts-and-groups-in-active-directory - https://adsecurity.org/?p=3658 +- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF tags: analytic_story: - Active Directory Discovery + - Volt Typhoon asset_type: Endpoint confidence: 70 impact: 30 From b881799d7fab8bcfcb67fe04d8e83387b42ebd11 Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Thu, 25 May 2023 06:44:12 -0600 Subject: [PATCH 09/13] Update suspicious_copy_on_system32.yml --- detections/endpoint/suspicious_copy_on_system32.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/detections/endpoint/suspicious_copy_on_system32.yml b/detections/endpoint/suspicious_copy_on_system32.yml index bfb596e6aa..b6abeb1c6b 100644 --- a/detections/endpoint/suspicious_copy_on_system32.yml +++ b/detections/endpoint/suspicious_copy_on_system32.yml @@ -35,6 +35,7 @@ tags: - IcedID - AsyncRAT - Sandworm Tools + - Volt Typhoon asset_type: Endpoint confidence: 90 impact: 70 From 2c935bb402f3922aefe28114a4f109b21faf6395 Mon Sep 17 00:00:00 2001 From: tccontre Date: Thu, 25 May 2023 15:05:13 +0200 Subject: [PATCH 10/13] volt_typhoon --- detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml | 2 ++ .../executables_or_script_creation_in_suspicious_path.yml | 2 ++ detections/endpoint/network_connection_discovery_with_arp.yml | 2 ++ .../endpoint/network_connection_discovery_with_netstat.yml | 2 ++ detections/endpoint/suspicious_copy_on_system32.yml | 2 ++ detections/endpoint/suspicious_process_file_path.yml | 2 ++ detections/endpoint/windows_dns_gather_network_info.yml | 2 ++ 7 files changed, 14 insertions(+) diff --git a/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml b/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml index 01427e9911..61fb949ee9 100644 --- a/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml +++ b/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml @@ -38,12 +38,14 @@ known_false_positives: A network operator or systems administrator may utilize a references: - https://www.mandiant.com/resources/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation - https://attack.mitre.org/groups/G0046/ +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - FIN7 - Qakbot - CISA AA22-277A - Qakbot + - Volt Typhoon asset_type: Endpoint confidence: 80 impact: 70 diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml index 81fdee3e91..df154d2328 100644 --- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml @@ -35,6 +35,7 @@ references: - https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ - https://twitter.com/pr0xylife/status/1590394227758104576 +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Azorult @@ -56,6 +57,7 @@ tags: - Brute Ratel C4 - Qakbot - Chaos Ransomware + - Volt Typhoon asset_type: Endpoint confidence: 50 impact: 40 diff --git a/detections/endpoint/network_connection_discovery_with_arp.yml b/detections/endpoint/network_connection_discovery_with_arp.yml index a554919d35..a6488cab5f 100644 --- a/detections/endpoint/network_connection_discovery_with_arp.yml +++ b/detections/endpoint/network_connection_discovery_with_arp.yml @@ -22,12 +22,14 @@ how_to_implement: To successfully implement this search you need to be ingesting known_false_positives: Administrators or power users may use this command for troubleshooting. references: - https://attack.mitre.org/techniques/T1049/ +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Active Directory Discovery - Qakbot - Windows Post-Exploitation - Prestige Ransomware + - Volt Typhoon asset_type: Endpoint confidence: 50 impact: 30 diff --git a/detections/endpoint/network_connection_discovery_with_netstat.yml b/detections/endpoint/network_connection_discovery_with_netstat.yml index 1d631edf7d..7696de1c66 100644 --- a/detections/endpoint/network_connection_discovery_with_netstat.yml +++ b/detections/endpoint/network_connection_discovery_with_netstat.yml @@ -23,6 +23,7 @@ how_to_implement: To successfully implement this search you need to be ingesting known_false_positives: Administrators or power users may use this command for troubleshooting. references: - https://attack.mitre.org/techniques/T1049/ +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Active Directory Discovery @@ -30,6 +31,7 @@ tags: - CISA AA22-277A - Windows Post-Exploitation - Prestige Ransomware + - Volt Typhoon asset_type: Endpoint confidence: 50 impact: 30 diff --git a/detections/endpoint/suspicious_copy_on_system32.yml b/detections/endpoint/suspicious_copy_on_system32.yml index bfb596e6aa..c054897ab5 100644 --- a/detections/endpoint/suspicious_copy_on_system32.yml +++ b/detections/endpoint/suspicious_copy_on_system32.yml @@ -28,6 +28,7 @@ how_to_implement: To successfully implement this search you need to be ingesting known_false_positives: every user may do this event but very un-ussual. references: - https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120 +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Unusual Processes @@ -35,6 +36,7 @@ tags: - IcedID - AsyncRAT - Sandworm Tools + - Volt Typhoon asset_type: Endpoint confidence: 90 impact: 70 diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/endpoint/suspicious_process_file_path.yml index c56f48c9ad..23a65c16e3 100644 --- a/detections/endpoint/suspicious_process_file_path.yml +++ b/detections/endpoint/suspicious_process_file_path.yml @@ -33,6 +33,7 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ - https://twitter.com/pr0xylife/status/1590394227758104576 - https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Azorult @@ -55,6 +56,7 @@ tags: - Brute Ratel C4 - Qakbot - Chaos Ransomware + - Volt Typhoon asset_type: Endpoint confidence: 50 impact: 70 diff --git a/detections/endpoint/windows_dns_gather_network_info.yml b/detections/endpoint/windows_dns_gather_network_info.yml index 330b426154..44abcbdca0 100644 --- a/detections/endpoint/windows_dns_gather_network_info.yml +++ b/detections/endpoint/windows_dns_gather_network_info.yml @@ -22,9 +22,11 @@ how_to_implement: To successfully implement this search you need to be ingesting known_false_positives: network administrator can execute this command to enumerate DNS record. Filter or add other paths to the exclusion as needed. references: - https://cert.gov.ua/article/3718487 +- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - Sandworm Tools + - Volt Typhoon asset_type: Endpoint confidence: 50 impact: 50 From 4ed5741a8a74cb6b088c7eb14632d71339ebc896 Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Thu, 25 May 2023 07:44:14 -0600 Subject: [PATCH 11/13] Create windows_ldifde_directory_object_behavior.yml --- ...ndows_ldifde_directory_object_behavior.yml | 83 +++++++++++++++++++ 1 file changed, 83 insertions(+) create mode 100644 detections/endpoint/windows_ldifde_directory_object_behavior.yml diff --git a/detections/endpoint/windows_ldifde_directory_object_behavior.yml b/detections/endpoint/windows_ldifde_directory_object_behavior.yml new file mode 100644 index 0000000000..d55a58c9ac --- /dev/null +++ b/detections/endpoint/windows_ldifde_directory_object_behavior.yml @@ -0,0 +1,83 @@ +name: Windows Ldifde Directory Object Behavior +id: 35cd29ca-f08c-4489-8815-f715c45460d3 +version: 1 +date: '2023-05-25' +author: Michael Haag, Splunk +status: production +type: TTP +data_source: +- Sysmon Event ID 1 +description: The following analytic identifies the use of Ldifde.exe, which provides the ability to create, modify, or delete LDAP directory objects. + The binary is only installed on a domain controller. + Ldifde.exe is a Microsoft Windows command-line utility used to import or export LDAP directory entries. LDAP stands for Lightweight Directory Access Protocol, which is a protocol used for accessing and managing directory information services over an IP network. LDIF, on the other hand, stands for LDAP Data Interchange Format, a standard plain-text data interchange format for representing LDAP directory entries. + -i This is a flag used with Ldifde.exe to denote import mode. In import mode, Ldifde.exe takes an LDIF file and imports its contents into the LDAP directory. The data in the LDIF file might include new objects to be created, or modifications or deletions to existing objects. + -f This flag is used to specify the filename of the LDIF file that Ldifde.exe will import from (in the case of the -i flag) or export to (without the -i flag). For example, if you wanted to import data from a file called data.ldif, you would use the command ldifde -i -f data.ldif. + Keep in mind that while the use of Ldifde.exe is legitimate in many contexts, it can also be used maliciously. For instance, an attacker who has gained access to a domain controller could potentially use Ldifde.exe to export sensitive data or make unauthorized changes to the directory. Therefore, it's important to monitor for unusual or unauthorized use of this tool. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name=ldifde.exe Processes.process IN ("*-i *", "*-f *") + by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name + Processes.process Processes.process_id Processes.parent_process_id + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_ldifde_directory_object_behavior_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +known_false_positives: False positives may be present, filter as needed. +references: +- https://lolbas-project.github.io/lolbas/Binaries/Ldifde/ +- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF +- https://twitter.com/0gtweet/status/1564968845726580736?s=20 +- https://strontic.github.io/xcyclopedia/library/ldifde.exe-45D28FB47E9B6ACC5DCA9FDA3E790210.html +tags: + analytic_story: + - Volt Typhoon + asset_type: Endpoint + atomic_guid: + - 22cf8cb9-adb1-4e8c-80ca-7c723dfc8784 + confidence: 50 + impact: 80 + message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ utilizing ldifde on a domain controller. + mitre_attack_id: + - T1105 + - T1069.002 + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name #parent process name + - Processes.parent_process #parent cmdline + - Processes.original_file_name + - Processes.process_name #process name + - Processes.process #process cmdline + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 40 + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1069.002/AD_discovery/ldifde_windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog From 8d768f513f50d98fa4a0b010f0df409e8414b428 Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Thu, 25 May 2023 10:47:03 -0600 Subject: [PATCH 12/13] name fixes --- .../endpoint/windows_ldifde_directory_object_behavior.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/windows_ldifde_directory_object_behavior.yml b/detections/endpoint/windows_ldifde_directory_object_behavior.yml index d55a58c9ac..8e8edb3325 100644 --- a/detections/endpoint/windows_ldifde_directory_object_behavior.yml +++ b/detections/endpoint/windows_ldifde_directory_object_behavior.yml @@ -8,7 +8,7 @@ type: TTP data_source: - Sysmon Event ID 1 description: The following analytic identifies the use of Ldifde.exe, which provides the ability to create, modify, or delete LDAP directory objects. - The binary is only installed on a domain controller. + Natively, the binary is only installed on a domain controller. However, adversaries or administrators may install the Windows Remote Server Admin Tools for ldifde.exe. Ldifde.exe is a Microsoft Windows command-line utility used to import or export LDAP directory entries. LDAP stands for Lightweight Directory Access Protocol, which is a protocol used for accessing and managing directory information services over an IP network. LDIF, on the other hand, stands for LDAP Data Interchange Format, a standard plain-text data interchange format for representing LDAP directory entries. -i This is a flag used with Ldifde.exe to denote import mode. In import mode, Ldifde.exe takes an LDIF file and imports its contents into the LDAP directory. The data in the LDIF file might include new objects to be created, or modifications or deletions to existing objects. -f This flag is used to specify the filename of the LDIF file that Ldifde.exe will import from (in the case of the -i flag) or export to (without the -i flag). For example, if you wanted to import data from a file called data.ldif, you would use the command ldifde -i -f data.ldif. From 435cf8c8eb3f34d5c10266f04d1a3ad15ba54911 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Thu, 25 May 2023 18:01:02 -0700 Subject: [PATCH 13/13] Update volt_typhoon.yml fix yml for app inspect --- stories/volt_typhoon.yml | 21 ++++++++------------- 1 file changed, 8 insertions(+), 13 deletions(-) diff --git a/stories/volt_typhoon.yml b/stories/volt_typhoon.yml index 67c0236408..8c500a9fd4 100644 --- a/stories/volt_typhoon.yml +++ b/stories/volt_typhoon.yml @@ -3,19 +3,14 @@ id: f73010e4-49eb-44ef-9f3f-2c25a1ae5415 version: 1 date: '2023-05-25' author: Teoderick Contreras, Splunk -description: This analytic story contains detections that allow security analysts to detect and investigate unusual activities - that might relate to the "Volt Typhoon" group targeting critical infrastructure organizations in United States and Guam. The affected - organizations include the communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education sectors. - This Analytic story looks for suspicious process execution, lolbin execution, command-line activity, lsass dump and many more. -narrative: Volt Typhoon is a state sponsored group typically focuses on espionage and information gathering. - Based on Microsoft Threat Intelligence, This threat actor group puts strong emphasis on stealth in this campaign by relying almost exclusively on living-off-the-land techniques and hands-on-keyboard activity. - They issue commands via the command line to - (1) collect data, including credentials from local and network systems, - (2) put the data into an archive file to stage it for exfiltration, and then - (3) use the stolen valid credentials to maintain persistence. - In addition, Volt Typhoon tries to blend into normal network activity by routing traffic through compromised small office and home office (SOHO) network equipment, - including routers, firewalls, and VPN hardware. They have also been observed using custom versions of open-source tools to establish a command and control (C2) - channel over proxy to further stay under the radar. +description: This analytic story contains detections that allow security analysts to detect and investigate unusual activities that might relate to the "Volt Typhoon" group targeting critical infrastructure organizations in United States and Guam. The affected organizations include the communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education sectors. This Analytic story looks for suspicious process execution, lolbin execution, command-line activity, lsass dump and many more. +narrative: Volt Typhoon is a state sponsored group typically focuses on espionage and information gathering.\ + Based on Microsoft Threat Intelligence, This threat actor group puts strong emphasis on stealth in this campaign by relying almost exclusively on living-off-the-land techniques and hands-on-keyboard activity. \ + They issue commands via the command line to :\ + (1) collect data, including credentials from local and network systems, \ + (2) put the data into an archive file to stage it for exfiltration, and then \ + (3) use the stolen valid credentials to maintain persistence. \ + In addition, Volt Typhoon tries to blend into normal network activity by routing traffic through compromised small office and home office (SOHO) network equipment, including routers, firewalls, and VPN hardware. They have also been observed using custom versions of open-source tools to establish a command and control (C2) channel over proxy to further stay under the radar. references: - https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: