From 99681d7f469f9e54eedbb96a2bd3be8769da79d9 Mon Sep 17 00:00:00 2001 From: tccontre Date: Wed, 19 May 2021 16:06:45 +0200 Subject: [PATCH 1/8] lndn1 --- ...allow_inbound_traffic_in_firewall_rule.yml | 38 +++++++++++++++++ .../enable_rdp_in_other_port_number.yml | 42 +++++++++++++++++++ .../endpoint/mailsniper_invoke_functions.yml | 41 ++++++++++++++++++ ..._inbound_traffic_in_firewall_rule.test.yml | 12 ++++++ .../enable_rdp_in_other_port_number.test.yml | 12 ++++++ .../mailsniper_invoke_functions.test.yml | 12 ++++++ 6 files changed, 157 insertions(+) create mode 100644 detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml create mode 100644 detections/endpoint/enable_rdp_in_other_port_number.yml create mode 100644 detections/endpoint/mailsniper_invoke_functions.yml create mode 100644 tests/endpoint/allow_inbound_traffic_in_firewall_rule.test.yml create mode 100644 tests/endpoint/enable_rdp_in_other_port_number.test.yml create mode 100644 tests/endpoint/mailsniper_invoke_functions.test.yml diff --git a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml new file mode 100644 index 0000000000..63e36070eb --- /dev/null +++ b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml @@ -0,0 +1,38 @@ +name: Allow Inbound Traffic In Firewall Rule +id: a5d85486-b89c-11eb-8267-acde48001122 +version: 1 +date: '2021-05-19' +author: Teoderick Contreras, Splunk +type: batch +datamodel: +- Endpoint +description: This search is to detect suspicious powershell command to allow inbound traffic in specific local port with public profile. + This technique was seen in some attacker want to have a remote access to a machine by allowing the traffic in firewall rule. +search: '`powershell` EventCode=4104 Message = "*firewall*" Message = "*Public*" Message = "*Inbound*" Message = "*Allow*" Message = "*-LocalPort*" +| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `allow_inbound_traffic_in_firewall_rule_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the powershell logs from your endpoints. make sure you enable needed + registry to monitor this event. +known_false_positives: administrator may allow inbound traffic in certain network or machine. +references: +tags: + analytic_story: + - UPDATE_STORY_NAME + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1021.001 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - Message + - ComputerName + - User + security_domain: endpoint \ No newline at end of file diff --git a/detections/endpoint/enable_rdp_in_other_port_number.yml b/detections/endpoint/enable_rdp_in_other_port_number.yml new file mode 100644 index 0000000000..aa0ab42279 --- /dev/null +++ b/detections/endpoint/enable_rdp_in_other_port_number.yml @@ -0,0 +1,42 @@ +name: Enable RDP In Other Port Number +id: 99495452-b899-11eb-96dc-acde48001122 +version: 1 +date: '2021-05-19' +author: Teoderick Contreras, Splunk +type: batch +datamodel: +- Endpoint +description: This search is to detect a modification to registry to enable rdp to a machine with different port number. + This technique was seen in some atttacker tries to do lateral movement and remote access to a compromised machine to gain control of it. +search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name) + as registry_key_name values(Registry.registry_path) as registry_path min(_time) + as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp*" + Registry.registry_key_name = "PortNumber" by Registry.dest Registry.user Registry.registry_value_name + | `security_content_ctime(lastTime)` + | `security_content_ctime(firstTime)` + | `drop_dm_object_name(Registry)` + | `enable_rdp_in_other_port_number_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. +known_false_positives: unknown +references: +tags: + analytic_story: + - UPDATE_STORY_NAME + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1021 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.registry_path + - Registry.dest + - Registry.user + - Registry.registry_value_name + security_domain: endpoint \ No newline at end of file diff --git a/detections/endpoint/mailsniper_invoke_functions.yml b/detections/endpoint/mailsniper_invoke_functions.yml new file mode 100644 index 0000000000..2801a7ad11 --- /dev/null +++ b/detections/endpoint/mailsniper_invoke_functions.yml @@ -0,0 +1,41 @@ +name: Mailsniper Invoke functions +id: a36972c8-b894-11eb-9f78-acde48001122 +version: 1 +date: '2021-05-19' +author: Teoderick Contreras, Splunk +type: batch +datamodel: +- Endpoint +description: This search is to detect known mailsniper.ps1 functions executed in a machine. + This technique was seen in some attacker to harvest some sensitive e-mail in a compromised exchange server. +search: '`powershell` EventCode=4104 Message IN ("*Invoke-GlobalO365MailSearch*", + "*Invoke-GlobalMailSearch*", "*Invoke-SelfSearch*", "*Invoke-PasswordSprayOWA*", "*Invoke-PasswordSprayEWS*","*Invoke-DomainHarvestOWA*", + "*Invoke-UsernameHarvestOWA*","*Invoke-OpenInboxFinder*","*Invoke-InjectGEventAPI*","*Invoke-InjectGEvent*","*Invoke-SearchGmail*", + "*Invoke-MonitorCredSniper*", "*Invoke-AddGmailRule*","*Invoke-PasswordSprayEAS*","*Invoke-UsernameHarvestEAS*") + | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `mailsniper_invoke_functions_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the powershell logs from your endpoints. make sure you enable needed + registry to monitor this event. +known_false_positives: unknown +references: +- https://www.blackhillsinfosec.com/introducing-mailsniper-a-tool-for-searching-every-users-email-for-sensitive-data/ +tags: + analytic_story: + - UPDATE_STORY_NAME + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1114.001 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - Message + - ComputerName + - User + security_domain: endpoint \ No newline at end of file diff --git a/tests/endpoint/allow_inbound_traffic_in_firewall_rule.test.yml b/tests/endpoint/allow_inbound_traffic_in_firewall_rule.test.yml new file mode 100644 index 0000000000..81bb7b3b73 --- /dev/null +++ b/tests/endpoint/allow_inbound_traffic_in_firewall_rule.test.yml @@ -0,0 +1,12 @@ +name: Allow Inbound Traffic In Firewall Rule Unit Test +tests: +- name: Allow Inbound Traffic In Firewall Rule + file: detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: UPDATE_FILE_NAME + data: UPDATE_DATASET_URL + source: UPDATE_SPLUNK_SOURCE + sourcetype: UPDATE_SPLUNK_SOURCETYPE \ No newline at end of file diff --git a/tests/endpoint/enable_rdp_in_other_port_number.test.yml b/tests/endpoint/enable_rdp_in_other_port_number.test.yml new file mode 100644 index 0000000000..923a16984b --- /dev/null +++ b/tests/endpoint/enable_rdp_in_other_port_number.test.yml @@ -0,0 +1,12 @@ +name: Enable RDP In Other Port Number Unit Test +tests: +- name: Enable RDP In Other Port Number + file: detections/endpoint/enable_rdp_in_other_port_number.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: UPDATE_FILE_NAME + data: UPDATE_DATASET_URL + source: UPDATE_SPLUNK_SOURCE + sourcetype: UPDATE_SPLUNK_SOURCETYPE \ No newline at end of file diff --git a/tests/endpoint/mailsniper_invoke_functions.test.yml b/tests/endpoint/mailsniper_invoke_functions.test.yml new file mode 100644 index 0000000000..8a7218a8df --- /dev/null +++ b/tests/endpoint/mailsniper_invoke_functions.test.yml @@ -0,0 +1,12 @@ +name: Mailsniper Invoke functions Unit Test +tests: +- name: Mailsniper Invoke functions + file: detections/endpoint/mailsniper_invoke_functions.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: UPDATE_FILE_NAME + data: UPDATE_DATASET_URL + source: UPDATE_SPLUNK_SOURCE + sourcetype: UPDATE_SPLUNK_SOURCETYPE \ No newline at end of file From 80210ef7d8af942862898487214040ef229f42db Mon Sep 17 00:00:00 2001 From: tccontre Date: Wed, 26 May 2021 13:33:47 +0200 Subject: [PATCH 2/8] casper1 --- ...ound_traffic_by_firewall_rule_registry.yml | 45 ++++++++++++++++++ ...allow_inbound_traffic_in_firewall_rule.yml | 3 +- .../enable_rdp_in_other_port_number.yml | 3 +- .../endpoint/mailsniper_invoke_functions.yml | 2 +- .../secretdumps_offline_ntds_dumping_tool.yml | 46 +++++++++++++++++++ ...traffic_by_firewall_rule_registry.test.yml | 12 +++++ ..._inbound_traffic_in_firewall_rule.test.yml | 10 ++-- .../enable_rdp_in_other_port_number.test.yml | 8 ++-- .../mailsniper_invoke_functions.test.yml | 10 ++-- ...etdumps_offline_ntds_dumping_tool.test.yml | 12 +++++ 10 files changed, 134 insertions(+), 17 deletions(-) create mode 100644 detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml create mode 100644 detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml create mode 100644 tests/endpoint/allow_inbound_traffic_by_firewall_rule_registry.test.yml create mode 100644 tests/endpoint/secretdumps_offline_ntds_dumping_tool.test.yml diff --git a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml new file mode 100644 index 0000000000..cb1e0b56d0 --- /dev/null +++ b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml @@ -0,0 +1,45 @@ +name: Allow Inbound Traffic By Firewall Rule Registry +id: 0a46537c-be02-11eb-92ca-acde48001122 +version: 1 +date: '2021-05-26' +author: Teoderick Contreras, Splunk +type: batch +datamodel: +- Endpoint +description: This analytic detects a potential suspicious modification of firewall rule registry allowing inbound traffic in specific port with public profile. + This technique was seen in some attacker want to have a remote access to a machine by allowing the traffic in firewall rule. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*" + Registry.registry_value_name = "*|Action=Allow|*" Registry.registry_value_name = "*|Dir=In|*" Registry.registry_value_name = "*|Profile=Public|*" + Registry.registry_value_name = "*|LPort=*" by Registry.registry_path Registry.registry_key_name Registry.user + Registry.registry_value_name Registry.dest + | `drop_dm_object_name(Registry)` + | `security_content_ctime(firstTime)` + |`security_content_ctime(lastTime)` + | `allow_inbound_traffic_by_firewall_rule_registry_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure + that this registry was included in your config files ex. sysmon config to be monitored. +known_false_positives: network admin may add/remove/modify public inbound firewall rule that may cause this rule to be triggered. +references: +- https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps +tags: + analytic_story: + - Prohibited Traffic Allowed or Protocol Mismatch + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1021.001 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.registry_path + - Registry.registry_value_name + - Registry.registry_key_name + - Registry.dest + - Registry.user + security_domain: endpoint \ No newline at end of file diff --git a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml index 63e36070eb..3a0aabc158 100644 --- a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml +++ b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml @@ -18,9 +18,10 @@ how_to_implement: To successfully implement this search, you need to be ingestin registry to monitor this event. known_false_positives: administrator may allow inbound traffic in certain network or machine. references: +- https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps tags: analytic_story: - - UPDATE_STORY_NAME + - Prohibited Traffic Allowed or Protocol Mismatch kill_chain_phases: - Exploitation mitre_attack_id: diff --git a/detections/endpoint/enable_rdp_in_other_port_number.yml b/detections/endpoint/enable_rdp_in_other_port_number.yml index aa0ab42279..e38a959e7e 100644 --- a/detections/endpoint/enable_rdp_in_other_port_number.yml +++ b/detections/endpoint/enable_rdp_in_other_port_number.yml @@ -22,9 +22,10 @@ how_to_implement: To successfully implement this search, you need to be ingestin Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. known_false_positives: unknown references: +- https://www.mvps.net/docs/how-to-secure-remote-desktop-rdp/ tags: analytic_story: - - UPDATE_STORY_NAME + - Prohibited Traffic Allowed or Protocol Mismatch kill_chain_phases: - Exploitation mitre_attack_id: diff --git a/detections/endpoint/mailsniper_invoke_functions.yml b/detections/endpoint/mailsniper_invoke_functions.yml index 2801a7ad11..709011989b 100644 --- a/detections/endpoint/mailsniper_invoke_functions.yml +++ b/detections/endpoint/mailsniper_invoke_functions.yml @@ -23,7 +23,7 @@ references: - https://www.blackhillsinfosec.com/introducing-mailsniper-a-tool-for-searching-every-users-email-for-sensitive-data/ tags: analytic_story: - - UPDATE_STORY_NAME + - Data Exfiltration kill_chain_phases: - Exploitation mitre_attack_id: diff --git a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml new file mode 100644 index 0000000000..faf8d9e151 --- /dev/null +++ b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml @@ -0,0 +1,46 @@ +name: SecretDumps Offline NTDS Dumping Tool +id: 5672819c-be09-11eb-bbfb-acde48001122 +version: 1 +date: '2021-05-26' +author: Teoderick Contreras, Splunk +type: batch +datamodel: +- Endpoint +description: This analytic detects a potential usage of secretsdump.py tool for dumping credentials (ntlm hash) from a copy of ntds.dit and SAM.Security,SYSTEM registrry hive. + This technique was seen in some attacker that dump ntlm hashes offline after having a copy of ntds.dit and SAM/SYSTEM/SECURITY registry hive. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where Processes.process_name = "python*.exe" Processes.process = "*.py*" Processes.process = "*-ntds*" + (Processes.process = "*-system*" OR Processes.process = "*-sam*" OR Processes.process = "*-security*" OR Processes.process = "*-bootkey*") + by Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.dest Processes.user Processes.process_id Processes.process_guid + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `secretdumps_offline_ntds_dumping_tool_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: unknown +references: +- https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py +tags: + analytic_story: + - Credential Dumping + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1003.003 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.process_name + - Processes.process + - Processes.parent_process_name + - Processes.parent_process + - Processes.dest Processes.user + - Processes.process_id + - Processes.process_guid + security_domain: endpoint \ No newline at end of file diff --git a/tests/endpoint/allow_inbound_traffic_by_firewall_rule_registry.test.yml b/tests/endpoint/allow_inbound_traffic_by_firewall_rule_registry.test.yml new file mode 100644 index 0000000000..39d282bf2b --- /dev/null +++ b/tests/endpoint/allow_inbound_traffic_by_firewall_rule_registry.test.yml @@ -0,0 +1,12 @@ +name: Allow Inbound Traffic By Firewall Rule Registry Unit Test +tests: +- name: Allow Inbound Traffic By Firewall Rule Registry + file: endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/allow_inbound_traffic_in_firewall_rule.test.yml b/tests/endpoint/allow_inbound_traffic_in_firewall_rule.test.yml index 81bb7b3b73..ac2dd09fa0 100644 --- a/tests/endpoint/allow_inbound_traffic_in_firewall_rule.test.yml +++ b/tests/endpoint/allow_inbound_traffic_in_firewall_rule.test.yml @@ -1,12 +1,12 @@ name: Allow Inbound Traffic In Firewall Rule Unit Test tests: - name: Allow Inbound Traffic In Firewall Rule - file: detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml + file: endpoint/allow_inbound_traffic_in_firewall_rule.yml pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' attack_data: - - file_name: UPDATE_FILE_NAME - data: UPDATE_DATASET_URL - source: UPDATE_SPLUNK_SOURCE - sourcetype: UPDATE_SPLUNK_SOURCETYPE \ No newline at end of file + - file_name: windows-powershell.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log + source: WinEventLog:Microsoft-Windows-PowerShell/Operational + sourcetype: WinEventLog \ No newline at end of file diff --git a/tests/endpoint/enable_rdp_in_other_port_number.test.yml b/tests/endpoint/enable_rdp_in_other_port_number.test.yml index 923a16984b..0dc6954b03 100644 --- a/tests/endpoint/enable_rdp_in_other_port_number.test.yml +++ b/tests/endpoint/enable_rdp_in_other_port_number.test.yml @@ -6,7 +6,7 @@ tests: earliest_time: '-24h' latest_time: 'now' attack_data: - - file_name: UPDATE_FILE_NAME - data: UPDATE_DATASET_URL - source: UPDATE_SPLUNK_SOURCE - sourcetype: UPDATE_SPLUNK_SOURCETYPE \ No newline at end of file + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/mailsniper_invoke_functions.test.yml b/tests/endpoint/mailsniper_invoke_functions.test.yml index 8a7218a8df..067c1bc19f 100644 --- a/tests/endpoint/mailsniper_invoke_functions.test.yml +++ b/tests/endpoint/mailsniper_invoke_functions.test.yml @@ -1,12 +1,12 @@ name: Mailsniper Invoke functions Unit Test tests: - name: Mailsniper Invoke functions - file: detections/endpoint/mailsniper_invoke_functions.yml + file: endpoint/mailsniper_invoke_functions.yml pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' attack_data: - - file_name: UPDATE_FILE_NAME - data: UPDATE_DATASET_URL - source: UPDATE_SPLUNK_SOURCE - sourcetype: UPDATE_SPLUNK_SOURCETYPE \ No newline at end of file + - file_name: windows-powershell.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log + source: WinEventLog:Microsoft-Windows-PowerShell/Operational + sourcetype: WinEventLog \ No newline at end of file diff --git a/tests/endpoint/secretdumps_offline_ntds_dumping_tool.test.yml b/tests/endpoint/secretdumps_offline_ntds_dumping_tool.test.yml new file mode 100644 index 0000000000..061bd35c35 --- /dev/null +++ b/tests/endpoint/secretdumps_offline_ntds_dumping_tool.test.yml @@ -0,0 +1,12 @@ +name: SecretDumps Offline NTDS Dumping Tool Unit Test +tests: +- name: SecretDumps Offline NTDS Dumping Tool + file: endpoint/secretdumps_offline_ntds_dumping_tool.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file From 91978e5c10fec1390bfa90cb727fe748cc3a5545 Mon Sep 17 00:00:00 2001 From: tccontre Date: Wed, 26 May 2021 13:37:03 +0200 Subject: [PATCH 3/8] Update enable_rdp_in_other_port_number.test.yml --- tests/endpoint/enable_rdp_in_other_port_number.test.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tests/endpoint/enable_rdp_in_other_port_number.test.yml b/tests/endpoint/enable_rdp_in_other_port_number.test.yml index 0dc6954b03..25e3995cc1 100644 --- a/tests/endpoint/enable_rdp_in_other_port_number.test.yml +++ b/tests/endpoint/enable_rdp_in_other_port_number.test.yml @@ -1,7 +1,7 @@ name: Enable RDP In Other Port Number Unit Test tests: - name: Enable RDP In Other Port Number - file: detections/endpoint/enable_rdp_in_other_port_number.yml + file: endpoint/enable_rdp_in_other_port_number.yml pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' From e824025040fb01bb4316bb4f4e38cb10924479ea Mon Sep 17 00:00:00 2001 From: root Date: Wed, 26 May 2021 14:15:44 +0000 Subject: [PATCH 4/8] Added detection testing service results inAllow Inbound Traffic By Firewall Rule Registry --- ...ound_traffic_by_firewall_rule_registry.yml | 28 +++++++++++-------- 1 file changed, 16 insertions(+), 12 deletions(-) diff --git a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml index cb1e0b56d0..c991e648d7 100644 --- a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml +++ b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml @@ -6,22 +6,23 @@ author: Teoderick Contreras, Splunk type: batch datamodel: - Endpoint -description: This analytic detects a potential suspicious modification of firewall rule registry allowing inbound traffic in specific port with public profile. - This technique was seen in some attacker want to have a remote access to a machine by allowing the traffic in firewall rule. +description: This analytic detects a potential suspicious modification of firewall + rule registry allowing inbound traffic in specific port with public profile. This + technique was seen in some attacker want to have a remote access to a machine by + allowing the traffic in firewall rule. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*" - Registry.registry_value_name = "*|Action=Allow|*" Registry.registry_value_name = "*|Dir=In|*" Registry.registry_value_name = "*|Profile=Public|*" - Registry.registry_value_name = "*|LPort=*" by Registry.registry_path Registry.registry_key_name Registry.user - Registry.registry_value_name Registry.dest - | `drop_dm_object_name(Registry)` - | `security_content_ctime(firstTime)` - |`security_content_ctime(lastTime)` - | `allow_inbound_traffic_by_firewall_rule_registry_filter`' + Registry.registry_value_name = "*|Action=Allow|*" Registry.registry_value_name = + "*|Dir=In|*" Registry.registry_value_name = "*|Profile=Public|*" Registry.registry_value_name + = "*|LPort=*" by Registry.registry_path Registry.registry_key_name Registry.user + Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` + |`security_content_ctime(lastTime)` | `allow_inbound_traffic_by_firewall_rule_registry_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. -known_false_positives: network admin may add/remove/modify public inbound firewall rule that may cause this rule to be triggered. +known_false_positives: network admin may add/remove/modify public inbound firewall + rule that may cause this rule to be triggered. references: - https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps tags: @@ -41,5 +42,8 @@ tags: - Registry.registry_value_name - Registry.registry_key_name - Registry.dest - - Registry.user - security_domain: endpoint \ No newline at end of file + - Registry.user + security_domain: endpoint + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log From affae55ecf1776c012eb251de080ff7abcd0fdf1 Mon Sep 17 00:00:00 2001 From: root Date: Wed, 26 May 2021 15:07:28 +0000 Subject: [PATCH 5/8] Added detection testing service results inEnable RDP In Other Port Number --- .../enable_rdp_in_other_port_number.yml | 21 +++++++++++-------- 1 file changed, 12 insertions(+), 9 deletions(-) diff --git a/detections/endpoint/enable_rdp_in_other_port_number.yml b/detections/endpoint/enable_rdp_in_other_port_number.yml index e38a959e7e..eaf7807ce6 100644 --- a/detections/endpoint/enable_rdp_in_other_port_number.yml +++ b/detections/endpoint/enable_rdp_in_other_port_number.yml @@ -6,16 +6,16 @@ author: Teoderick Contreras, Splunk type: batch datamodel: - Endpoint -description: This search is to detect a modification to registry to enable rdp to a machine with different port number. - This technique was seen in some atttacker tries to do lateral movement and remote access to a compromised machine to gain control of it. +description: This search is to detect a modification to registry to enable rdp to + a machine with different port number. This technique was seen in some atttacker + tries to do lateral movement and remote access to a compromised machine to gain + control of it. search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) - as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp*" - Registry.registry_key_name = "PortNumber" by Registry.dest Registry.user Registry.registry_value_name - | `security_content_ctime(lastTime)` - | `security_content_ctime(firstTime)` - | `drop_dm_object_name(Registry)` - | `enable_rdp_in_other_port_number_filter`' + as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal + Server\\WinStations\\RDP-Tcp*" Registry.registry_key_name = "PortNumber" by Registry.dest + Registry.user Registry.registry_value_name | `security_content_ctime(lastTime)` + | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `enable_rdp_in_other_port_number_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the @@ -40,4 +40,7 @@ tags: - Registry.dest - Registry.user - Registry.registry_value_name - security_domain: endpoint \ No newline at end of file + security_domain: endpoint + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log From 819c8f4db82e9a1141ba50cdb92743eb31adca71 Mon Sep 17 00:00:00 2001 From: root Date: Wed, 26 May 2021 15:51:03 +0000 Subject: [PATCH 6/8] Added detection testing service results inSecretDumps Offline NTDS Dumping Tool --- .../secretdumps_offline_ntds_dumping_tool.yml | 27 +++++++++++-------- 1 file changed, 16 insertions(+), 11 deletions(-) diff --git a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml index faf8d9e151..1a91a7be88 100644 --- a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml +++ b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml @@ -6,15 +6,17 @@ author: Teoderick Contreras, Splunk type: batch datamodel: - Endpoint -description: This analytic detects a potential usage of secretsdump.py tool for dumping credentials (ntlm hash) from a copy of ntds.dit and SAM.Security,SYSTEM registrry hive. - This technique was seen in some attacker that dump ntlm hashes offline after having a copy of ntds.dit and SAM/SYSTEM/SECURITY registry hive. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes - where Processes.process_name = "python*.exe" Processes.process = "*.py*" Processes.process = "*-ntds*" - (Processes.process = "*-system*" OR Processes.process = "*-sam*" OR Processes.process = "*-security*" OR Processes.process = "*-bootkey*") - by Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.dest Processes.user Processes.process_id Processes.process_guid - | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` +description: This analytic detects a potential usage of secretsdump.py tool for dumping + credentials (ntlm hash) from a copy of ntds.dit and SAM.Security,SYSTEM registrry + hive. This technique was seen in some attacker that dump ntlm hashes offline after + having a copy of ntds.dit and SAM/SYSTEM/SECURITY registry hive. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "python*.exe" + Processes.process = "*.py*" Processes.process = "*-ntds*" (Processes.process = "*-system*" + OR Processes.process = "*-sam*" OR Processes.process = "*-security*" OR Processes.process + = "*-bootkey*") by Processes.process_name Processes.process Processes.parent_process_name + Processes.parent_process Processes.dest Processes.user Processes.process_id Processes.process_guid + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `secretdumps_offline_ntds_dumping_tool_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your @@ -42,5 +44,8 @@ tags: - Processes.parent_process - Processes.dest Processes.user - Processes.process_id - - Processes.process_guid - security_domain: endpoint \ No newline at end of file + - Processes.process_guid + security_domain: endpoint + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log From 27007cc19d34f0654fdeac64575c0548c79800f0 Mon Sep 17 00:00:00 2001 From: root Date: Wed, 26 May 2021 16:17:03 +0000 Subject: [PATCH 7/8] Added detection testing service results inAllow Inbound Traffic In Firewall Rule --- ...allow_inbound_traffic_in_firewall_rule.yml | 23 +++++++++++-------- 1 file changed, 14 insertions(+), 9 deletions(-) diff --git a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml index 3a0aabc158..8193070f70 100644 --- a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml +++ b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml @@ -6,17 +6,19 @@ author: Teoderick Contreras, Splunk type: batch datamodel: - Endpoint -description: This search is to detect suspicious powershell command to allow inbound traffic in specific local port with public profile. - This technique was seen in some attacker want to have a remote access to a machine by allowing the traffic in firewall rule. -search: '`powershell` EventCode=4104 Message = "*firewall*" Message = "*Public*" Message = "*Inbound*" Message = "*Allow*" Message = "*-LocalPort*" -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `allow_inbound_traffic_in_firewall_rule_filter`' +description: This search is to detect suspicious powershell command to allow inbound + traffic in specific local port with public profile. This technique was seen in some + attacker want to have a remote access to a machine by allowing the traffic in firewall + rule. +search: '`powershell` EventCode=4104 Message = "*firewall*" Message = "*Public*" Message + = "*Inbound*" Message = "*Allow*" Message = "*-LocalPort*" | stats count min(_time) + as firstTime max(_time) as lastTime by EventCode Message ComputerName User | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `allow_inbound_traffic_in_firewall_rule_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event. -known_false_positives: administrator may allow inbound traffic in certain network or machine. +known_false_positives: administrator may allow inbound traffic in certain network + or machine. references: - https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps tags: @@ -36,4 +38,7 @@ tags: - Message - ComputerName - User - security_domain: endpoint \ No newline at end of file + security_domain: endpoint + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log From 259842d958d172fa809dd9e4a61f6ba70922dd81 Mon Sep 17 00:00:00 2001 From: root Date: Wed, 26 May 2021 16:41:52 +0000 Subject: [PATCH 8/8] Added detection testing service results inMailsniper Invoke functions --- .../endpoint/mailsniper_invoke_functions.yml | 30 +++++++++++-------- 1 file changed, 17 insertions(+), 13 deletions(-) diff --git a/detections/endpoint/mailsniper_invoke_functions.yml b/detections/endpoint/mailsniper_invoke_functions.yml index 709011989b..b91f27648b 100644 --- a/detections/endpoint/mailsniper_invoke_functions.yml +++ b/detections/endpoint/mailsniper_invoke_functions.yml @@ -6,15 +6,16 @@ author: Teoderick Contreras, Splunk type: batch datamodel: - Endpoint -description: This search is to detect known mailsniper.ps1 functions executed in a machine. - This technique was seen in some attacker to harvest some sensitive e-mail in a compromised exchange server. -search: '`powershell` EventCode=4104 Message IN ("*Invoke-GlobalO365MailSearch*", - "*Invoke-GlobalMailSearch*", "*Invoke-SelfSearch*", "*Invoke-PasswordSprayOWA*", "*Invoke-PasswordSprayEWS*","*Invoke-DomainHarvestOWA*", - "*Invoke-UsernameHarvestOWA*","*Invoke-OpenInboxFinder*","*Invoke-InjectGEventAPI*","*Invoke-InjectGEvent*","*Invoke-SearchGmail*", - "*Invoke-MonitorCredSniper*", "*Invoke-AddGmailRule*","*Invoke-PasswordSprayEAS*","*Invoke-UsernameHarvestEAS*") - | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` | `mailsniper_invoke_functions_filter`' +description: This search is to detect known mailsniper.ps1 functions executed in a + machine. This technique was seen in some attacker to harvest some sensitive e-mail + in a compromised exchange server. +search: '`powershell` EventCode=4104 Message IN ("*Invoke-GlobalO365MailSearch*", + "*Invoke-GlobalMailSearch*", "*Invoke-SelfSearch*", "*Invoke-PasswordSprayOWA*", + "*Invoke-PasswordSprayEWS*","*Invoke-DomainHarvestOWA*", "*Invoke-UsernameHarvestOWA*","*Invoke-OpenInboxFinder*","*Invoke-InjectGEventAPI*","*Invoke-InjectGEvent*","*Invoke-SearchGmail*", + "*Invoke-MonitorCredSniper*", "*Invoke-AddGmailRule*","*Invoke-PasswordSprayEAS*","*Invoke-UsernameHarvestEAS*") + | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message + ComputerName User | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `mailsniper_invoke_functions_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the powershell logs from your endpoints. make sure you enable needed registry to monitor this event. @@ -34,8 +35,11 @@ tags: - Splunk Cloud required_fields: - _time - - EventCode - - Message - - ComputerName + - EventCode + - Message + - ComputerName - User - security_domain: endpoint \ No newline at end of file + security_domain: endpoint + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log