mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
fixes
This commit is contained in:
@@ -13,9 +13,9 @@ description: The following analytic identifies non SYSTEM accounts requesting ac
|
||||
data_source:
|
||||
- Sysmon Event ID 1
|
||||
search: '`sysmon` EventCode=10 TargetImage=*lsass.exe NOT (SourceUser="NT AUTHORITY\\*")
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage,
|
||||
GrantedAccess, SourceImage, SourceProcessId, SourceUser, TargetUser, ImageLoaded | rename SourceUser
|
||||
as user | rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by dest, parent_process_name, parent_process_path ,parent_process_id, TargetImage,
|
||||
GrantedAccess, SourceUser, TargetUser | rename TargetUser
|
||||
as user | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `windows_non_system_account_targeting_lsass_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
@@ -35,7 +35,7 @@ tags:
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
message: A process, $SourceImage$, has loaded $ImageLoaded$ that are typically related
|
||||
message: A process, $parent_process_path$, has loaded $ImageLoaded$ that are typically related
|
||||
to credential dumping on $dest$. Review for further details.
|
||||
mitre_attack_id:
|
||||
- T1003.001
|
||||
@@ -49,14 +49,10 @@ tags:
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
- name: ImageLoaded
|
||||
- name: parent_process_path
|
||||
type: Process
|
||||
role:
|
||||
- Other
|
||||
- name: SourceImage
|
||||
type: Process
|
||||
role:
|
||||
- Child Process
|
||||
- Parent Process
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -25,14 +25,16 @@ description: 'The following analytic is an enhanced version of two previous anal
|
||||
used to execute this module which is related to lsass dumping.'
|
||||
data_source:
|
||||
- Sysmon Event ID 1
|
||||
search: '`sysmon` EventCode=10 TargetImage=*\\lsass.exe GrantedAccess IN ("0x01000",
|
||||
"0x1010", "0x1038", "0x40", "0x1400", "0x1fffff", "0x1410", "0x143a", "0x1438",
|
||||
"0x1000") CallTrace IN ("*dbgcore.dll*", "*dbghelp.dll*", "*ntdll.dll*", "*kernelbase.dll*",
|
||||
"*kernel32.dll*") NOT SourceUser IN ("NT AUTHORITY\\SYSTEM", "NT AUTHORITY\\NETWORK
|
||||
SERVICE")| stats count min(_time) as firstTime max(_time) as lastTime by, Computer,
|
||||
SourceImage, GrantedAccess, TargetImage, SourceProcessId, SourceUser, TargetUser, ImageLoaded
|
||||
| rename Computer as dest | rename SourceUser as user | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`
|
||||
| `windows_possible_credential_dumping_filter`'
|
||||
search: '`sysmon` EventCode=10 TargetImage=*\\lsass.exe granted_access IN ("0x01000",
|
||||
"0x1010", "0x1038", "0x40", "0x1400", "0x1fffff", "0x1410", "0x143a", "0x1438",
|
||||
"0x1000") CallTrace IN ("*dbgcore.dll*", "*dbghelp.dll*", "*ntdll.dll*", "*kernelbase.dll*",
|
||||
"*kernel32.dll*") NOT SourceUser IN ("NT AUTHORITY\\SYSTEM", "NT AUTHORITY\\NETWORK
|
||||
SERVICE")
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by dest, SourceImage, GrantedAccess, TargetImage, SourceProcessId, SourceUser, TargetUser
|
||||
| rename SourceUser as user
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_possible_credential_dumping_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
@@ -57,7 +59,7 @@ tags:
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
message: A process, $SourceImage$, has loaded $ImageLoaded$ that are typically related
|
||||
message: A process, $SourceImage$, has loaded $TargetImage$ that are typically related
|
||||
to credential dumping on $dest$. Review for further details.
|
||||
mitre_attack_id:
|
||||
- T1003.001
|
||||
@@ -71,10 +73,6 @@ tags:
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
- name: ImageLoaded
|
||||
type: Process
|
||||
role:
|
||||
- Other
|
||||
- name: SourceImage
|
||||
type: Process
|
||||
role:
|
||||
|
||||
@@ -10,7 +10,7 @@ data_source:
|
||||
description: The following analytic utilizes Sysmon to identify process injection into Notepad.exe, based on GrantedAccess requests - 0x40 and 0x1fffff. This particular behavior is attributed to the defaults of the SliverC2 framework by BishopFox.
|
||||
By default, the analytic filters out any SourceImage paths of System32, Syswow64 and program files. Add more as needed, or remove and monitor what is consistently injecting into notepad.exe.
|
||||
This particular behavior will occur from a source image that is the initial payload dropped.
|
||||
search: '`sysmon` EventCode=10 TargetImage IN (*\\notepad.exe) NOT (SourceImage IN ("*\\system32\\*","*\\syswow64\\*","*\\Program Files\\*")) GrantedAccess IN ("0x40","0x1fffff") | stats count min(_time) as firstTime max(_time) as lastTime by dest user SourceImage TargetImage GrantedAccess CallTrace
|
||||
search: '`sysmon` EventCode=10 TargetImage IN (*\\notepad.exe) NOT (SourceImage IN ("*\\system32\\*","*\\syswow64\\*","*\\Program Files\\*")) GrantedAccess IN ("0x40","0x1fffff") | stats count min(_time) as firstTime max(_time) as lastTime by dest SourceImage TargetImage GrantedAccess CallTrace
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_process_injection_into_notepad_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
@@ -32,10 +32,6 @@ tags:
|
||||
- T1055
|
||||
- T1055.002
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
role:
|
||||
- Victim
|
||||
- name: dest
|
||||
type: Hostname
|
||||
role:
|
||||
|
||||
@@ -14,8 +14,7 @@ data_source:
|
||||
- Sysmon Event ID 9
|
||||
search: '`sysmon` EventCode=9 Device = \\Device\\HarddiskVolume* NOT (Image IN("*\\Windows\\System32\\*",
|
||||
"*\\Windows\\SysWOW64\\*")) | stats count min(_time) as firstTime max(_time) as
|
||||
lastTime by dest user Image Device ProcessGuid ProcessId EventDescription EventCode
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_raw_access_to_disk_volume_partition_filter`'
|
||||
lastTime by dest signature signature_id process_guid process_name process_path Device | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_raw_access_to_disk_volume_partition_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the raw access read event (like sysmon eventcode 9), process name and
|
||||
process guid from your endpoints. If you are using Sysmon, you must have at least
|
||||
@@ -51,13 +50,15 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- Computer
|
||||
- Image
|
||||
- dest
|
||||
- signature
|
||||
- signature_id
|
||||
- process_guid
|
||||
- process_name
|
||||
- process_path
|
||||
- Device
|
||||
- ProcessGuid
|
||||
- ProcessId
|
||||
- EventDescription
|
||||
- EventCode
|
||||
- Image
|
||||
risk_score: 90
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
|
||||
Reference in New Issue
Block a user