Branch was auto-updated.

This commit is contained in:
srv-rr-gh-researchbt
2023-06-23 07:26:59 -07:00
committed by GitHub
39 changed files with 237 additions and 143 deletions
@@ -1,7 +1,7 @@
name: Anomalous usage of 7zip
id: 9364ee8e-a39a-11eb-8f1d-acde48001122
version: 1
date: '2021-04-22'
date: '2023-06-13'
author: Michael Haag, Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -33,6 +33,7 @@ tags:
analytic_story:
- Cobalt Strike
- NOBELIUM Group
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 80
impact: 80
@@ -1,7 +1,7 @@
name: Attempt To Stop Security Service
id: c8e349c6-b97c-486e-8949-bd7bcd1f3910
version: 4
date: '2023-04-14'
date: '2023-06-13'
author: Rico Valdez, Splunk
status: production
type: TTP
@@ -29,11 +29,12 @@ references:
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
tags:
analytic_story:
- Azorult
- Trickbot
- WhisperGate
- Graceful Wipe Out Attack
- Disabling Security Tools
- Data Destruction
- WhisperGate
- Azorult
- Trickbot
asset_type: Endpoint
confidence: 50
impact: 40
@@ -1,7 +1,7 @@
name: CMD Echo Pipe - Escalation
id: eb277ba0-b96b-11eb-b00e-acde48001122
version: 2
date: '2021-05-20'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -30,6 +30,7 @@ references:
tags:
analytic_story:
- Cobalt Strike
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 80
impact: 80
@@ -1,7 +1,7 @@
name: Cobalt Strike Named Pipes
id: 5876d429-0240-4709-8b93-ea8330b411b5
version: 2
date: '2022-05-16'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -41,10 +41,11 @@ references:
- https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations
tags:
analytic_story:
- Cobalt Strike
- Trickbot
- DarkSide Ransomware
- LockBit Ransomware
- Graceful Wipe Out Attack
- Cobalt Strike
- DarkSide Ransomware
- Trickbot
asset_type: Endpoint
confidence: 90
impact: 80
@@ -1,7 +1,7 @@
name: Deleting Of Net Users
id: 1c8c6f66-acce-11eb-aafb-acde48001122
version: 2
date: '2021-05-04'
date: '2023-06-13'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -32,6 +32,7 @@ references:
tags:
analytic_story:
- XMRig
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 50
impact: 50
@@ -1,7 +1,7 @@
name: Detect Regsvr32 Application Control Bypass
id: 070e9b80-6252-11eb-ae93-0242ac130002
version: 2
date: '2021-01-28'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -37,9 +37,10 @@ references:
- https://support.microsoft.com/en-us/topic/how-to-use-the-regsvr32-tool-and-troubleshoot-regsvr32-error-messages-a98d960a-7392-e6fe-d90a-3f4e0cb543e5
tags:
analytic_story:
- Suspicious Regsvr32 Activity
- Cobalt Strike
- Living Off The Land
- Suspicious Regsvr32 Activity
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 100
impact: 80
@@ -1,7 +1,7 @@
name: DLLHost with no Command Line Arguments with Network
id: f1c07594-a141-11eb-8407-acde48001122
version: 4
date: '2022-03-15'
date: '2023-06-13'
author: Steven Dick, Michael Haag, Splunk
status: experimental
type: TTP
@@ -34,6 +34,7 @@ references:
tags:
analytic_story:
- Cobalt Strike
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 70
impact: 70
@@ -1,7 +1,7 @@
name: Domain Account Discovery With Net App
id: 98f6a534-04c2-11ec-96b2-acde48001122
version: 1
date: '2021-08-24'
date: '2023-06-13'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -28,6 +28,7 @@ references:
tags:
analytic_story:
- Active Directory Discovery
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 50
impact: 50
@@ -1,7 +1,7 @@
name: Domain Group Discovery With Net
id: f2f14ac7-fa81-471a-80d5-7eb65c3c7349
version: 1
date: '2021-08-25'
date: '2023-06-13'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -25,9 +25,10 @@ references:
- https://attack.mitre.org/techniques/T1069/002/
tags:
analytic_story:
- Active Directory Discovery
- Windows Post-Exploitation
- Active Directory Discovery
- Prestige Ransomware
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 50
impact: 30
@@ -1,7 +1,7 @@
name: Excessive Usage Of Net App
id: 45e52536-ae42-11eb-b5c6-acde48001122
version: 2
date: '2021-05-06'
date: '2023-06-13'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -27,11 +27,12 @@ references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
- Ransomware
- Azorult
- Windows Post-Exploitation
- Prestige Ransomware
- Graceful Wipe Out Attack
- XMRig
- Windows Post-Exploitation
- Azorult
- Ransomware
asset_type: Endpoint
confidence: 70
impact: 40
@@ -1,7 +1,7 @@
name: Executable File Written in Administrative SMB Share
id: f63c34fe-a435-11eb-935a-acde48001122
version: 2
date: '2023-04-14'
date: '2023-06-13'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -33,13 +33,14 @@ references:
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
tags:
analytic_story:
- Industroyer2
- Active Directory Lateral Movement
- Prestige Ransomware
- Graceful Wipe Out Attack
- Industroyer2
- IcedID
- Data Destruction
- Hermetic Wiper
- Trickbot
- Prestige Ransomware
- Data Destruction
- IcedID
asset_type: Endpoint
confidence: 100
impact: 70
@@ -1,7 +1,7 @@
name: Executables Or Script Creation In Suspicious Path
id: a7e3f0f0-ae42-11eb-b245-acde48001122
version: 1
date: '2023-04-25'
date: '2023-06-13'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -38,26 +38,27 @@ references:
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Azorult
- AsyncRAT
- WhisperGate
- XMRig
- Swift Slicer
- DarkCrystal RAT
- Double Zero Destructor
- Trickbot
- Data Destruction
- LockBit Ransomware
- Industroyer2
- Remcos
- RedLine Stealer
- WhisperGate
- IcedID
- Data Destruction
- Hermetic Wiper
- AgentTesla
- Brute Ratel C4
- Azorult
- DarkCrystal RAT
- Graceful Wipe Out Attack
- IcedID
- Swift Slicer
- Qakbot
- Chaos Ransomware
- RedLine Stealer
- Brute Ratel C4
- AsyncRAT
- LockBit Ransomware
- AgentTesla
- Double Zero Destructor
- Volt Typhoon
- Chaos Ransomware
- Trickbot
asset_type: Endpoint
confidence: 50
impact: 40
@@ -1,7 +1,7 @@
name: GPUpdate with no Command Line Arguments with Network
id: 2c853856-a140-11eb-a5b5-acde48001122
version: 2
date: '2022-03-15'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -34,6 +34,7 @@ references:
tags:
analytic_story:
- Cobalt Strike
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 90
impact: 90
@@ -1,7 +1,7 @@
name: Impacket Lateral Movement Commandline Parameters
id: 8ce07472-496f-11ec-ab3b-3e22fbd008af
version: 3
date: '2023-04-14'
date: '2023-06-13'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -39,13 +39,14 @@ references:
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Industroyer2
- Active Directory Lateral Movement
- Prestige Ransomware
- CISA AA22-277A
- Data Destruction
- WhisperGate
- Prestige Ransomware
- Volt Typhoon
- Graceful Wipe Out Attack
- Industroyer2
- Data Destruction
asset_type: Endpoint
confidence: 70
impact: 90
@@ -1,20 +1,36 @@
name: Impacket Lateral Movement smbexec CommandLine Parameters
id: bb3c1bac-6bdf-4aa0-8dc9-068b8b712a76
version: 1
date: '2023-04-25'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: TTP
data_source:
- Sysmon Event ID 1
- Windows Security 4688
description: This analytic focuses on identifying suspicious command-line parameters commonly associated with the use of Impacket wmiexec.py. Impacket is a set of Python classes designed for working with Microsoft network protocols, and it includes several scripts like wmiexec.py, smbexec.py, dcomexec.py, and atexec.py that enable command execution on remote endpoints. These scripts typically utilize administrative shares and hardcoded parameters, which can serve as signatures to detect their usage. Both Red Teams and adversaries may employ Impacket tools for lateral movement and remote code execution purposes. By monitoring for these specific command-line indicators, the analytic aims to detect potentially malicious activities related to Impacket tool usage.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| where match(process, "(?i)cmd\.exe\s+\/Q\s+\/c") AND match(process,"(?i)echo\s+cd") AND match(process, "(?i)\\__output") AND match(process, "(?i)C:\\\\Windows\\\\[a-zA-Z]{1,8}\\.bat") AND match(process, "\\\\127\.0\.0\.1\\.*")
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `impacket_lateral_movement_smbexec_commandline_parameters_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
description: This analytic focuses on identifying suspicious command-line parameters
commonly associated with the use of Impacket wmiexec.py. Impacket is a set of Python
classes designed for working with Microsoft network protocols, and it includes several
scripts like wmiexec.py, smbexec.py, dcomexec.py, and atexec.py that enable command
execution on remote endpoints. These scripts typically utilize administrative shares
and hardcoded parameters, which can serve as signatures to detect their usage. Both
Red Teams and adversaries may employ Impacket tools for lateral movement and remote
code execution purposes. By monitoring for these specific command-line indicators,
the analytic aims to detect potentially malicious activities related to Impacket
tool usage.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
| where match(process, "(?i)cmd\.exe\s+\/Q\s+\/c") AND match(process,"(?i)echo\s+cd")
AND match(process, "(?i)\\__output") AND match(process, "(?i)C:\\\\Windows\\\\[a-zA-Z]{1,8}\\.bat") AND
match(process, "\\\\127\.0\.0\.1\\.*") | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `impacket_lateral_movement_smbexec_commandline_parameters_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: Although uncommon, Administrators may leverage Impackets tools
to start a process on remote systems for system administration or automation use
cases.
@@ -30,18 +46,20 @@ references:
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Industroyer2
- Active Directory Lateral Movement
- Prestige Ransomware
- CISA AA22-277A
- Data Destruction
- WhisperGate
- Prestige Ransomware
- Volt Typhoon
- Graceful Wipe Out Attack
- Industroyer2
- Data Destruction
asset_type: Endpoint
atomic_guid: []
confidence: 70
impact: 90
message: Suspicious command-line parameters on $dest$ may represent lateral movement using smbexec.
message: Suspicious command-line parameters on $dest$ may represent lateral movement
using smbexec.
mitre_attack_id:
- T1021
- T1021.002
@@ -59,11 +77,11 @@ tags:
- Splunk Cloud
required_fields:
- Processes.process_name
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.process
- Processes.process_id
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_id
risk_score: 63
security_domain: endpoint
@@ -72,4 +90,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.002/atomic_red_team/smbexec_windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: xmlwineventlog
@@ -1,7 +1,7 @@
name: Impacket Lateral Movement WMIExec Commandline Parameters
id: d6e464e4-5c6a-474e-82d2-aed616a3a492
version: 1
date: '2023-04-21'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -16,12 +16,18 @@ description: This analytic looks for the presence of suspicious commandline para
scripts leverage administrative shares and hardcoded parameters that can be used
as a signature to detect its use. Red Teams and adversaries alike may leverage Impackets
tools for lateral movement and remote code execution.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=wmiprvse.exe by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| where match(process, "(?i)cmd\.exe\s+\/Q\s+\/c") AND match(process, "\\\\127\.0\.0\.1\\.*") AND match(process, "__\\d{1,10}\\.\\d{1,10}")
| `security_content_ctime(firstTime)`
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=wmiprvse.exe
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
| where match(process, "(?i)cmd\.exe\s+\/Q\s+\/c") AND match(process, "\\\\127\.0\.0\.1\\.*")
AND match(process, "__\\d{1,10}\\.\\d{1,10}") | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`| `impacket_lateral_movement_wmiexec_commandline_parameters_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: Although uncommon, Administrators may leverage Impackets tools
to start a process on remote systems for system administration or automation use
cases.
@@ -37,18 +43,20 @@ references:
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Industroyer2
- Active Directory Lateral Movement
- Prestige Ransomware
- CISA AA22-277A
- Data Destruction
- WhisperGate
- Prestige Ransomware
- Volt Typhoon
- Graceful Wipe Out Attack
- Industroyer2
- Data Destruction
asset_type: Endpoint
atomic_guid: []
confidence: 70
impact: 90
message: Suspicious command-line parameters on $dest$ may represent lateral movement using wmiexec.
message: Suspicious command-line parameters on $dest$ may represent lateral movement
using wmiexec.
mitre_attack_id:
- T1021
- T1021.002
@@ -66,11 +74,11 @@ tags:
- Splunk Cloud
required_fields:
- Processes.process_name
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.process
- Processes.process_id
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_id
risk_score: 63
security_domain: endpoint
@@ -79,4 +87,4 @@ tests:
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.002/atomic_red_team/wmiexec_windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
sourcetype: xmlwineventlog
@@ -1,7 +1,7 @@
name: Net Localgroup Discovery
id: 54f5201e-155b-11ec-a6e2-acde48001122
version: 1
date: '2021-09-14'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -30,13 +30,14 @@ references:
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
tags:
analytic_story:
- Active Directory Discovery
- Windows Discovery Techniques
- Azorult
- Windows Post-Exploitation
- Prestige Ransomware
- Volt Typhoon
- Graceful Wipe Out Attack
- IcedID
- Windows Discovery Techniques
- Windows Post-Exploitation
- Azorult
- Active Directory Discovery
asset_type: Endpoint
confidence: 50
impact: 30
@@ -1,7 +1,7 @@
name: Remote WMI Command Attempt
id: 272df6de-61f1-4784-877c-1fbc3e2d0838
version: 4
date: '2018-12-03'
date: '2023-06-13'
author: Rico Valdez, Michael Haag, Splunk
status: production
type: TTP
@@ -31,10 +31,11 @@ references:
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
tags:
analytic_story:
- Volt Typhoon
- Graceful Wipe Out Attack
- IcedID
- Suspicious WMI Use
- Living Off The Land
- Volt Typhoon
- IcedID
asset_type: Endpoint
confidence: 60
impact: 60
@@ -1,7 +1,7 @@
name: Rundll32 with no Command Line Arguments with Network
id: 35307032-a12d-11eb-835f-acde48001122
version: 4
date: '2022-03-15'
date: '2023-06-13'
author: Steven Dick, Michael Haag, Splunk
status: production
type: TTP
@@ -40,9 +40,10 @@ references:
- https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/
tags:
analytic_story:
- Suspicious Rundll32 Activity
- Cobalt Strike
- PrintNightmare CVE-2021-34527
- Suspicious Rundll32 Activity
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 100
cve:
@@ -1,7 +1,7 @@
name: SAM Database File Access Attempt
id: 57551656-ebdb-11eb-afdf-acde48001122
version: 1
date: '2021-07-23'
date: '2023-06-13'
author: Michael Haag, Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -32,6 +32,7 @@ references:
tags:
analytic_story:
- Credential Dumping
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 100
cve:
@@ -1,7 +1,7 @@
name: SearchProtocolHost with no Command Line with Network
id: b690df8c-a145-11eb-a38b-acde48001122
version: 3
date: '2022-03-15'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -33,6 +33,7 @@ references:
tags:
analytic_story:
- Cobalt Strike
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 100
impact: 70
@@ -1,7 +1,7 @@
name: SecretDumps Offline NTDS Dumping Tool
id: 5672819c-be09-11eb-bbfb-acde48001122
version: 1
date: '2021-05-26'
date: '2023-06-13'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -29,6 +29,7 @@ references:
tags:
analytic_story:
- Credential Dumping
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 100
impact: 80
@@ -1,7 +1,7 @@
name: Services Escalate Exe
id: c448488c-b7ec-11eb-8253-acde48001122
version: 1
date: '2021-05-18'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -36,6 +36,7 @@ references:
tags:
analytic_story:
- Cobalt Strike
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 95
impact: 80
@@ -1,7 +1,7 @@
name: Suspicious DLLHost no Command Line Arguments
id: ff61e98c-0337-4593-a78f-72a676c56f26
version: 4
date: '2023-03-08'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -31,6 +31,7 @@ references:
tags:
analytic_story:
- Cobalt Strike
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 70
impact: 70
@@ -1,7 +1,7 @@
name: Suspicious GPUpdate no Command Line Arguments
id: f308490a-473a-40ef-ae64-dd7a6eba284a
version: 3
date: '2022-03-15'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -30,6 +30,7 @@ references:
tags:
analytic_story:
- Cobalt Strike
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 70
impact: 70
@@ -1,7 +1,7 @@
name: Suspicious microsoft workflow compiler rename
id: f0db4464-55d9-11eb-ae93-0242ac130002
version: 4
date: '2022-04-07'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -32,10 +32,11 @@ references:
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution
tags:
analytic_story:
- Trusted Developer Utilities Proxy Execution
- Cobalt Strike
- Masquerading - Rename System Utilities
- Trusted Developer Utilities Proxy Execution
- Graceful Wipe Out Attack
- Living Off The Land
- Cobalt Strike
asset_type: Endpoint
confidence: 90
impact: 70
@@ -1,7 +1,7 @@
name: Suspicious msbuild path
id: f5198224-551c-11eb-ae93-0242ac130002
version: 3
date: '2022-03-08'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -32,10 +32,11 @@ references:
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md
tags:
analytic_story:
- Masquerading - Rename System Utilities
- Graceful Wipe Out Attack
- Living Off The Land
- Trusted Developer Utilities Proxy Execution MSBuild
- Cobalt Strike
- Masquerading - Rename System Utilities
- Living Off The Land
asset_type: Endpoint
confidence: 70
impact: 70
@@ -1,7 +1,7 @@
name: Suspicious MSBuild Rename
id: 4006adac-5937-11eb-ae93-0242ac130002
version: 3
date: '2022-04-07'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -30,10 +30,11 @@ references:
- https://github.com/infosecn1nja/MaliciousMacroMSBuild/
tags:
analytic_story:
- Masquerading - Rename System Utilities
- Graceful Wipe Out Attack
- Living Off The Land
- Trusted Developer Utilities Proxy Execution MSBuild
- Cobalt Strike
- Masquerading - Rename System Utilities
- Living Off The Land
asset_type: Endpoint
confidence: 90
impact: 70
@@ -1,7 +1,7 @@
name: Suspicious Process File Path
id: 9be25988-ad82-11eb-a14f-acde48001122
version: 1
date: '2023-04-25'
date: '2023-06-13'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -36,27 +36,28 @@ references:
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Azorult
- AsyncRAT
- WhisperGate
- XMRig
- Swift Slicer
- DarkCrystal RAT
- Double Zero Destructor
- Trickbot
- Data Destruction
- LockBit Ransomware
- Prestige Ransomware
- Industroyer2
- Remcos
- RedLine Stealer
- WhisperGate
- IcedID
- Data Destruction
- Hermetic Wiper
- AgentTesla
- Brute Ratel C4
- Azorult
- DarkCrystal RAT
- Graceful Wipe Out Attack
- IcedID
- Swift Slicer
- Qakbot
- Chaos Ransomware
- RedLine Stealer
- Brute Ratel C4
- Prestige Ransomware
- AsyncRAT
- LockBit Ransomware
- AgentTesla
- Double Zero Destructor
- Volt Typhoon
- Chaos Ransomware
- Trickbot
asset_type: Endpoint
confidence: 50
impact: 70
@@ -1,7 +1,7 @@
name: Suspicious Rundll32 no Command Line Arguments
id: e451bd16-e4c5-4109-8eb1-c4c6ecf048b4
version: 3
date: '2022-03-15'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -32,9 +32,10 @@ references:
- https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/
tags:
analytic_story:
- Suspicious Rundll32 Activity
- Cobalt Strike
- PrintNightmare CVE-2021-34527
- Suspicious Rundll32 Activity
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 70
cve:
@@ -1,7 +1,7 @@
name: Suspicious Rundll32 StartW
id: 9319dda5-73f2-4d43-a85a-67ce961bddb7
version: 3
date: '2021-02-04'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -37,8 +37,9 @@ references:
- https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/
tags:
analytic_story:
- Suspicious Rundll32 Activity
- Cobalt Strike
- Suspicious Rundll32 Activity
- Graceful Wipe Out Attack
- Trickbot
asset_type: Endpoint
confidence: 50
@@ -1,7 +1,7 @@
name: Suspicious SearchProtocolHost no Command Line Arguments
id: f52d2db8-31f9-4aa7-a176-25779effe55c
version: 3
date: '2022-03-15'
date: '2023-06-13'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -31,6 +31,7 @@ references:
tags:
analytic_story:
- Cobalt Strike
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 70
impact: 70
+13 -6
View File
@@ -1,14 +1,18 @@
name: Windows AdFind Exe
id: bd3b0187-189b-46c0-be45-f52da2bae67f
version: 3
date: '2023-05-15'
date: '2023-06-13'
author: Jose Hernandez, Bhavin Patel, Splunk
status: production
type: TTP
description: 'This search looks for the execution of `adfind.exe` with command-line
arguments that it uses by default specifically the filter or search functions.
It also considers the arguments necessary like objectcategory, see readme for more
details: https://www.joeware.net/freetools/tools/adfind/usage.htm. AdFind.exe is a powerful tool that is commonly used for querying and retrieving information from Active Directory (AD). While it is primarily designed for AD administration and management, it has been seen used before by Wizard Spider, FIN6 and actors whom also launched SUNBURST.'
arguments that it uses by default specifically the filter or search functions. It
also considers the arguments necessary like objectcategory, see readme for more
details: https://www.joeware.net/freetools/tools/adfind/usage.htm. AdFind.exe is
a powerful tool that is commonly used for querying and retrieving information from
Active Directory (AD). While it is primarily designed for AD administration and
management, it has been seen used before by Wizard Spider, FIN6 and actors whom
also launched SUNBURST.'
data_source:
- Sysmon Event ID 1
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
@@ -21,7 +25,9 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, and command-line executions from your endpoints. If
you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
known_false_positives: ADfind is a command-line tool for AD administration and management that is seen to be leveraged by various adversaries. Filter out legitimate administrator usage using the filter macro.
known_false_positives: ADfind is a command-line tool for AD administration and management
that is seen to be leveraged by various adversaries. Filter out legitimate administrator
usage using the filter macro.
references:
- https://www.volexity.com/blog/2020/12/14/dark-halo-leverages-solarwinds-compromise-to-breach-organizations/
- https://www.mandiant.com/resources/a-nasty-trick-from-credential-theft-malware-to-business-disruption
@@ -29,9 +35,10 @@ references:
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
tags:
analytic_story:
- NOBELIUM Group
- Domain Trust Discovery
- IcedID
- NOBELIUM Group
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 50
impact: 50
@@ -1,7 +1,7 @@
name: Windows Process Injection Remote Thread
id: 8a618ade-ca8f-4d04-b972-2d526ba59924
version: 1
date: '2022-11-10'
date: '2023-06-15'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -16,7 +16,7 @@ data_source:
- Sysmon Event ID 8
search: '`sysmon` EventCode=8 TargetImage IN ("*\\Taskmgr.exe", "*\\calc.exe", "*\\notepad.exe",
"*\\rdpclip.exe", "*\\explorer.exe", "*\\wermgr.exe", "*\\ping.exe", "*\\OneDriveSetup.exe",
"*\\dxdiag.exe", "*\\mobsync.exe", "*\\msra.exe", "*\\xwizard.exe") | stats count
"*\\dxdiag.exe", "*\\mobsync.exe", "*\\msra.exe", "*\\xwizard.exe","*\\cmd.exe", "*\\powershell.exe") | stats count
min(_time) as firstTime max(_time) as lastTime by TargetImage TargetProcessId SourceProcessId EventCode
StartAddress SourceImage Computer | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `windows_process_injection_remote_thread_filter`'
@@ -27,9 +27,11 @@ how_to_implement: To successfully implement this search, you must be ingesting d
known_false_positives: unknown
references:
- https://twitter.com/pr0xylife/status/1585612370441031680?s=46&t=Dc3CJi4AnM-8rNoacLbScg
- https://thedfirreport.com/2023/06/12/a-truly-graceful-wipe-out/
tags:
analytic_story:
- Qakbot
- Graceful Wipe Out Attack
asset_type: 80
confidence: 80
impact: 80
@@ -1,7 +1,7 @@
name: Windows Raw Access To Disk Volume Partition
id: a85aa37e-9647-11ec-90c5-acde48001122
version: 1
date: '2023-04-14'
date: '2023-06-13'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -28,9 +28,10 @@ references:
tags:
analytic_story:
- CISA AA22-264A
- Graceful Wipe Out Attack
- Data Destruction
- Caddy Wiper
- Hermetic Wiper
- Caddy Wiper
asset_type: Endpoint
confidence: 100
impact: 90
@@ -1,7 +1,7 @@
name: Windows Raw Access To Master Boot Record Drive
id: 7b83f666-900c-11ec-a2d9-acde48001122
version: 1
date: '2023-04-14'
date: '2023-06-13'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -29,11 +29,12 @@ references:
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
tags:
analytic_story:
- Caddy Wiper
- CISA AA22-264A
- Hermetic Wiper
- Data Destruction
- WhisperGate
- Graceful Wipe Out Attack
- Data Destruction
- Hermetic Wiper
- Caddy Wiper
asset_type: Endpoint
confidence: 100
impact: 90
@@ -1,7 +1,7 @@
name: Windows Service Stop By Deletion
id: 196ff536-58d9-4d1b-9686-b176b04e430b
version: 1
date: '2022-06-21'
date: '2023-06-13'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -32,6 +32,7 @@ references:
tags:
analytic_story:
- Azorult
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 70
impact: 70
@@ -1,7 +1,7 @@
name: Windows Service Stop Via Net and SC Application
id: 827af04b-0d08-479b-9b84-b7d4644e4b80
version: 1
date: '2022-11-30'
date: '2023-06-13'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -31,6 +31,7 @@ references:
tags:
analytic_story:
- Prestige Ransomware
- Graceful Wipe Out Attack
asset_type: Endpoint
confidence: 70
impact: 70
+25
View File
@@ -0,0 +1,25 @@
name: Graceful Wipe Out Attack
id: 83b15b3c-6bda-45aa-a3b6-b05c52443f44
version: 1
date: '2023-06-15'
author: Teoderick Contreras, Splunk
description: This analytic story contains detections that allow security analysts to detect and investigate unusual activities
that might relate to the destructive attack or campaign found by "THE DFIR Report" that uses Truebot, FlawedGrace and MBR killer malware.
This analytic story looks for suspicious dropped files, cobalt strike execution, im-packet execution, registry modification, scripts,
persistence, lateral movement, impact, exfiltration and recon.
narrative: Graceful Wipe Out Attack is a destructive malware campaign found by "The DFIR Report" targeting
multiple organizations to collect, exfiltrate and wipe the data of targeted networks.
This malicious payload corrupts or wipes Master Boot Records by using an NSIS script after the exfiltration of sensitive information from the targeted host or system.
references:
- https://thedfirreport.com/2023/06/12/a-truly-graceful-wipe-out/
tags:
analytic_story: Graceful Wipe Out Attack
category:
- Data Destruction
- Malware
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection