Added detection testing service results inServices.exe LOLBAS Execution Process Spawn

This commit is contained in:
root
2021-11-23 22:39:17 +00:00
parent c2fd0a4b29
commit 37f4a32647
@@ -6,30 +6,34 @@ author: Mauricio Velazco, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies `services.exe` spawning a LOLBAS execution process.
When adversaries execute code on remote endpoints abusing the Service Control Manager and
creating a remote malicious service, the executed command is spawned as a child processs of `services.exe`.
The LOLBAS project documents Windows native binaries that can be abused by threat actors to
perform tasks like executing malicious code. Looking for child processes of services.exe
that are part of the LOLBAS project can help defenders identify lateral movement activity.
description: The following analytic identifies `services.exe` spawning a LOLBAS execution
process. When adversaries execute code on remote endpoints abusing the Service Control
Manager and creating a remote malicious service, the executed command is spawned
as a child processs of `services.exe`. The LOLBAS project documents Windows native
binaries that can be abused by threat actors to perform tasks like executing malicious
code. Looking for child processes of services.exe that are part of the LOLBAS project
can help defenders identify lateral movement activity.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=services.exe)
(Processes.process_name IN ("Regsvcs.exe", "Ftp.exe", "OfflineScannerShell.exe", "Rasautou.exe", "Schtasks.exe",
"Xwizard.exe", "Dllhost.exe", "Pnputil.exe", "Atbroker.exe", "Pcwrun.exe", "Ttdinject.exe","Mshta.exe", "Bitsadmin.exe",
"Certoc.exe", "Ieexec.exe", "Microsoft.Workflow.Compiler.exe", "Runscripthelper.exe", "Forfiles.exe", "Msbuild.exe",
"Register-cimprovider.exe", "Tttracer.exe", "Ie4uinit.exe", "Bash.exe", "Hh.exe", "SettingSyncHost.exe", "Cmstp.exe",
"Mmc.exe", "Stordiag.exe", "Scriptrunner.exe", "Odbcconf.exe", "Extexport.exe", "Msdt.exe", "WorkFolders.exe",
"Diskshadow.exe", "Mavinject.exe", "Regasm.exe", "Gpscript.exe", "Rundll32.exe", "Regsvr32.exe", "Msiexec.exe",
"Wuauclt.exe", "Presentationhost.exe", "Wmic.exe", "Runonce.exe", "Syncappvpublishingserver.exe", "Verclsid.exe",
"Infdefaultinstall.exe", "Explorer.exe", "Installutil.exe", "Netsh.exe", "Wab.exe", "Dnscmd.exe", "At.exe",
"Pcalua.exe", "Msconfig.exe"))
by Processes.dest Processes.user Processes.parent_process Processes.process_name
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
(Processes.process_name IN ("Regsvcs.exe", "Ftp.exe", "OfflineScannerShell.exe",
"Rasautou.exe", "Schtasks.exe", "Xwizard.exe", "Dllhost.exe", "Pnputil.exe", "Atbroker.exe",
"Pcwrun.exe", "Ttdinject.exe","Mshta.exe", "Bitsadmin.exe", "Certoc.exe", "Ieexec.exe",
"Microsoft.Workflow.Compiler.exe", "Runscripthelper.exe", "Forfiles.exe", "Msbuild.exe",
"Register-cimprovider.exe", "Tttracer.exe", "Ie4uinit.exe", "Bash.exe", "Hh.exe",
"SettingSyncHost.exe", "Cmstp.exe", "Mmc.exe", "Stordiag.exe", "Scriptrunner.exe",
"Odbcconf.exe", "Extexport.exe", "Msdt.exe", "WorkFolders.exe", "Diskshadow.exe",
"Mavinject.exe", "Regasm.exe", "Gpscript.exe", "Rundll32.exe", "Regsvr32.exe", "Msiexec.exe",
"Wuauclt.exe", "Presentationhost.exe", "Wmic.exe", "Runonce.exe", "Syncappvpublishingserver.exe",
"Verclsid.exe", "Infdefaultinstall.exe", "Explorer.exe", "Installutil.exe", "Netsh.exe",
"Wab.exe", "Dnscmd.exe", "At.exe", "Pcalua.exe", "Msconfig.exe")) by Processes.dest
Processes.user Processes.parent_process Processes.process_name Processes.process
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `services_lolbas_execution_process_spawn_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints.
known_false_positives: Legitimate applications may trigger this behavior, filter as needed.
known_false_positives: Legitimate applications may trigger this behavior, filter as
needed.
references:
- https://attack.mitre.org/techniques/T1543/003/
- https://pentestlab.blog/2020/07/21/lateral-movement-services/
@@ -73,4 +77,5 @@ tags:
- name: dest
type: Endpoint
role:
- Victim
- Victim
automated_detection_testing: passed