From 6ba42f6a9e392365aa99466e249445ebf1d14573 Mon Sep 17 00:00:00 2001 From: tccontre Date: Tue, 13 Jun 2023 16:34:18 +0200 Subject: [PATCH 1/2] graceful_wipe_out --- .../endpoint/anomalous_usage_of_7zip.yml | 3 +- .../attempt_to_stop_security_service.yml | 9 ++-- .../endpoint/cmd_echo_pipe___escalation.yml | 3 +- .../endpoint/cobalt_strike_named_pipes.yml | 9 ++-- detections/endpoint/deleting_of_net_users.yml | 3 +- ...ct_regsvr32_application_control_bypass.yml | 5 +- ...no_command_line_arguments_with_network.yml | 3 +- .../domain_account_discovery_with_net_app.yml | 3 +- .../domain_group_discovery_with_net.yml | 5 +- .../endpoint/excessive_usage_of_net_app.yml | 11 ++-- ...le_written_in_administrative_smb_share.yml | 11 ++-- ..._or_script_creation_in_suspicious_path.yml | 31 +++++------ ...no_command_line_arguments_with_network.yml | 3 +- ...ateral_movement_commandline_parameters.yml | 9 ++-- ...ovement_smbexec_commandline_parameters.yml | 54 ++++++++++++------- ...ovement_wmiexec_commandline_parameters.yml | 40 ++++++++------ .../endpoint/net_localgroup_discovery.yml | 11 ++-- .../endpoint/remote_wmi_command_attempt.yml | 7 +-- ...no_command_line_arguments_with_network.yml | 5 +- .../sam_database_file_access_attempt.yml | 3 +- ...host_with_no_command_line_with_network.yml | 3 +- .../secretdumps_offline_ntds_dumping_tool.yml | 3 +- detections/endpoint/services_escalate_exe.yml | 3 +- ...ious_dllhost_no_command_line_arguments.yml | 3 +- ...ous_gpupdate_no_command_line_arguments.yml | 3 +- ...ous_microsoft_workflow_compiler_rename.yml | 7 +-- .../endpoint/suspicious_msbuild_path.yml | 7 +-- .../endpoint/suspicious_msbuild_rename.yml | 7 +-- .../endpoint/suspicious_process_file_path.yml | 33 ++++++------ ...ous_rundll32_no_command_line_arguments.yml | 5 +- .../endpoint/suspicious_rundll32_startw.yml | 5 +- ...protocolhost_no_command_line_arguments.yml | 3 +- detections/endpoint/windows_adfind_exe.yml | 19 ++++--- ...indows_process_injection_remote_thread.yml | 6 ++- ...ws_raw_access_to_disk_volume_partition.yml | 5 +- ...raw_access_to_master_boot_record_drive.yml | 9 ++-- .../windows_service_stop_by_deletion.yml | 3 +- ...rvice_stop_via_net__and_sc_application.yml | 3 +- stories/graceful_wipe_out_attack.yml | 25 +++++++++ 39 files changed, 237 insertions(+), 143 deletions(-) create mode 100644 stories/graceful_wipe_out_attack.yml diff --git a/detections/endpoint/anomalous_usage_of_7zip.yml b/detections/endpoint/anomalous_usage_of_7zip.yml index 9d000c6f2a..8d411a6c1b 100644 --- a/detections/endpoint/anomalous_usage_of_7zip.yml +++ b/detections/endpoint/anomalous_usage_of_7zip.yml @@ -1,7 +1,7 @@ name: Anomalous usage of 7zip id: 9364ee8e-a39a-11eb-8f1d-acde48001122 version: 1 -date: '2021-04-22' +date: '2023-06-13' author: Michael Haag, Teoderick Contreras, Splunk status: production type: Anomaly @@ -33,6 +33,7 @@ tags: analytic_story: - Cobalt Strike - NOBELIUM Group + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 80 impact: 80 diff --git a/detections/endpoint/attempt_to_stop_security_service.yml b/detections/endpoint/attempt_to_stop_security_service.yml index c5aa104ec5..4b7b425388 100644 --- a/detections/endpoint/attempt_to_stop_security_service.yml +++ b/detections/endpoint/attempt_to_stop_security_service.yml @@ -1,7 +1,7 @@ name: Attempt To Stop Security Service id: c8e349c6-b97c-486e-8949-bd7bcd1f3910 version: 4 -date: '2023-04-14' +date: '2023-06-13' author: Rico Valdez, Splunk status: production type: TTP @@ -29,11 +29,12 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - - Azorult - - Trickbot + - WhisperGate + - Graceful Wipe Out Attack - Disabling Security Tools - Data Destruction - - WhisperGate + - Azorult + - Trickbot asset_type: Endpoint confidence: 50 impact: 40 diff --git a/detections/endpoint/cmd_echo_pipe___escalation.yml b/detections/endpoint/cmd_echo_pipe___escalation.yml index 20dc4424dd..93f66d6b34 100644 --- a/detections/endpoint/cmd_echo_pipe___escalation.yml +++ b/detections/endpoint/cmd_echo_pipe___escalation.yml @@ -1,7 +1,7 @@ name: CMD Echo Pipe - Escalation id: eb277ba0-b96b-11eb-b00e-acde48001122 version: 2 -date: '2021-05-20' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: TTP @@ -30,6 +30,7 @@ references: tags: analytic_story: - Cobalt Strike + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 80 impact: 80 diff --git a/detections/endpoint/cobalt_strike_named_pipes.yml b/detections/endpoint/cobalt_strike_named_pipes.yml index 22624c11e7..7cdf14cf0b 100644 --- a/detections/endpoint/cobalt_strike_named_pipes.yml +++ b/detections/endpoint/cobalt_strike_named_pipes.yml @@ -1,7 +1,7 @@ name: Cobalt Strike Named Pipes id: 5876d429-0240-4709-8b93-ea8330b411b5 version: 2 -date: '2022-05-16' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: TTP @@ -41,10 +41,11 @@ references: - https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations tags: analytic_story: - - Cobalt Strike - - Trickbot - - DarkSide Ransomware - LockBit Ransomware + - Graceful Wipe Out Attack + - Cobalt Strike + - DarkSide Ransomware + - Trickbot asset_type: Endpoint confidence: 90 impact: 80 diff --git a/detections/endpoint/deleting_of_net_users.yml b/detections/endpoint/deleting_of_net_users.yml index 7b70210da6..d4326f981c 100644 --- a/detections/endpoint/deleting_of_net_users.yml +++ b/detections/endpoint/deleting_of_net_users.yml @@ -1,7 +1,7 @@ name: Deleting Of Net Users id: 1c8c6f66-acce-11eb-aafb-acde48001122 version: 2 -date: '2021-05-04' +date: '2023-06-13' author: Teoderick Contreras, Splunk status: production type: TTP @@ -32,6 +32,7 @@ references: tags: analytic_story: - XMRig + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/detect_regsvr32_application_control_bypass.yml b/detections/endpoint/detect_regsvr32_application_control_bypass.yml index b42e31c258..751f1e6bf7 100644 --- a/detections/endpoint/detect_regsvr32_application_control_bypass.yml +++ b/detections/endpoint/detect_regsvr32_application_control_bypass.yml @@ -1,7 +1,7 @@ name: Detect Regsvr32 Application Control Bypass id: 070e9b80-6252-11eb-ae93-0242ac130002 version: 2 -date: '2021-01-28' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: TTP @@ -37,9 +37,10 @@ references: - https://support.microsoft.com/en-us/topic/how-to-use-the-regsvr32-tool-and-troubleshoot-regsvr32-error-messages-a98d960a-7392-e6fe-d90a-3f4e0cb543e5 tags: analytic_story: - - Suspicious Regsvr32 Activity - Cobalt Strike - Living Off The Land + - Suspicious Regsvr32 Activity + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 100 impact: 80 diff --git a/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml b/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml index a353619621..a9f50d7c33 100644 --- a/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml @@ -1,7 +1,7 @@ name: DLLHost with no Command Line Arguments with Network id: f1c07594-a141-11eb-8407-acde48001122 version: 4 -date: '2022-03-15' +date: '2023-06-13' author: Steven Dick, Michael Haag, Splunk status: experimental type: TTP @@ -34,6 +34,7 @@ references: tags: analytic_story: - Cobalt Strike + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/domain_account_discovery_with_net_app.yml b/detections/endpoint/domain_account_discovery_with_net_app.yml index 93eed15475..03f5d9e2de 100644 --- a/detections/endpoint/domain_account_discovery_with_net_app.yml +++ b/detections/endpoint/domain_account_discovery_with_net_app.yml @@ -1,7 +1,7 @@ name: Domain Account Discovery With Net App id: 98f6a534-04c2-11ec-96b2-acde48001122 version: 1 -date: '2021-08-24' +date: '2023-06-13' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -28,6 +28,7 @@ references: tags: analytic_story: - Active Directory Discovery + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/domain_group_discovery_with_net.yml b/detections/endpoint/domain_group_discovery_with_net.yml index 84afd3fa34..b7ac8da53b 100644 --- a/detections/endpoint/domain_group_discovery_with_net.yml +++ b/detections/endpoint/domain_group_discovery_with_net.yml @@ -1,7 +1,7 @@ name: Domain Group Discovery With Net id: f2f14ac7-fa81-471a-80d5-7eb65c3c7349 version: 1 -date: '2021-08-25' +date: '2023-06-13' author: Mauricio Velazco, Splunk status: production type: Hunting @@ -25,9 +25,10 @@ references: - https://attack.mitre.org/techniques/T1069/002/ tags: analytic_story: - - Active Directory Discovery - Windows Post-Exploitation + - Active Directory Discovery - Prestige Ransomware + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 50 impact: 30 diff --git a/detections/endpoint/excessive_usage_of_net_app.yml b/detections/endpoint/excessive_usage_of_net_app.yml index 2475a9f6fd..83246f8a75 100644 --- a/detections/endpoint/excessive_usage_of_net_app.yml +++ b/detections/endpoint/excessive_usage_of_net_app.yml @@ -1,7 +1,7 @@ name: Excessive Usage Of Net App id: 45e52536-ae42-11eb-b5c6-acde48001122 version: 2 -date: '2021-05-06' +date: '2023-06-13' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -27,11 +27,12 @@ references: - https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ tags: analytic_story: - - XMRig - - Ransomware - - Azorult - - Windows Post-Exploitation - Prestige Ransomware + - Graceful Wipe Out Attack + - XMRig + - Windows Post-Exploitation + - Azorult + - Ransomware asset_type: Endpoint confidence: 70 impact: 40 diff --git a/detections/endpoint/executable_file_written_in_administrative_smb_share.yml b/detections/endpoint/executable_file_written_in_administrative_smb_share.yml index 5a001336d5..2d3c3e93d3 100644 --- a/detections/endpoint/executable_file_written_in_administrative_smb_share.yml +++ b/detections/endpoint/executable_file_written_in_administrative_smb_share.yml @@ -1,7 +1,7 @@ name: Executable File Written in Administrative SMB Share id: f63c34fe-a435-11eb-935a-acde48001122 version: 2 -date: '2023-04-14' +date: '2023-06-13' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -33,13 +33,14 @@ references: - https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/ tags: analytic_story: - - Industroyer2 - Active Directory Lateral Movement + - Prestige Ransomware + - Graceful Wipe Out Attack + - Industroyer2 + - IcedID + - Data Destruction - Hermetic Wiper - Trickbot - - Prestige Ransomware - - Data Destruction - - IcedID asset_type: Endpoint confidence: 100 impact: 70 diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml index df154d2328..b86981b426 100644 --- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml @@ -1,7 +1,7 @@ name: Executables Or Script Creation In Suspicious Path id: a7e3f0f0-ae42-11eb-b245-acde48001122 version: 1 -date: '2023-04-25' +date: '2023-06-13' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -38,26 +38,27 @@ references: - https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - - Azorult - - AsyncRAT + - WhisperGate - XMRig - - Swift Slicer - - DarkCrystal RAT - - Double Zero Destructor - - Trickbot - - Data Destruction - - LockBit Ransomware - Industroyer2 - Remcos - - RedLine Stealer - - WhisperGate - - IcedID + - Data Destruction - Hermetic Wiper - - AgentTesla - - Brute Ratel C4 + - Azorult + - DarkCrystal RAT + - Graceful Wipe Out Attack + - IcedID + - Swift Slicer - Qakbot - - Chaos Ransomware + - RedLine Stealer + - Brute Ratel C4 + - AsyncRAT + - LockBit Ransomware + - AgentTesla + - Double Zero Destructor - Volt Typhoon + - Chaos Ransomware + - Trickbot asset_type: Endpoint confidence: 50 impact: 40 diff --git a/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml b/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml index d1c012595f..608c640c5a 100644 --- a/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml @@ -1,7 +1,7 @@ name: GPUpdate with no Command Line Arguments with Network id: 2c853856-a140-11eb-a5b5-acde48001122 version: 2 -date: '2022-03-15' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: TTP @@ -34,6 +34,7 @@ references: tags: analytic_story: - Cobalt Strike + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 90 impact: 90 diff --git a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml index 7dec17d390..d1509ccfed 100644 --- a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml @@ -1,7 +1,7 @@ name: Impacket Lateral Movement Commandline Parameters id: 8ce07472-496f-11ec-ab3b-3e22fbd008af version: 3 -date: '2023-04-14' +date: '2023-06-13' author: Mauricio Velazco, Splunk status: production type: TTP @@ -39,13 +39,14 @@ references: - https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - - Industroyer2 - Active Directory Lateral Movement - - Prestige Ransomware - CISA AA22-277A - - Data Destruction - WhisperGate + - Prestige Ransomware - Volt Typhoon + - Graceful Wipe Out Attack + - Industroyer2 + - Data Destruction asset_type: Endpoint confidence: 70 impact: 90 diff --git a/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml index 0b850fd266..a8cc6c1b7b 100644 --- a/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_smbexec_commandline_parameters.yml @@ -1,20 +1,36 @@ name: Impacket Lateral Movement smbexec CommandLine Parameters id: bb3c1bac-6bdf-4aa0-8dc9-068b8b712a76 version: 1 -date: '2023-04-25' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: TTP data_source: - Sysmon Event ID 1 - Windows Security 4688 -description: This analytic focuses on identifying suspicious command-line parameters commonly associated with the use of Impacket wmiexec.py. Impacket is a set of Python classes designed for working with Microsoft network protocols, and it includes several scripts like wmiexec.py, smbexec.py, dcomexec.py, and atexec.py that enable command execution on remote endpoints. These scripts typically utilize administrative shares and hardcoded parameters, which can serve as signatures to detect their usage. Both Red Teams and adversaries may employ Impacket tools for lateral movement and remote code execution purposes. By monitoring for these specific command-line indicators, the analytic aims to detect potentially malicious activities related to Impacket tool usage. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id - | `drop_dm_object_name(Processes)` - | where match(process, "(?i)cmd\.exe\s+\/Q\s+\/c") AND match(process,"(?i)echo\s+cd") AND match(process, "(?i)\\__output") AND match(process, "(?i)C:\\\\Windows\\\\[a-zA-Z]{1,8}\\.bat") AND match(process, "\\\\127\.0\.0\.1\\.*") - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` | `impacket_lateral_movement_smbexec_commandline_parameters_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +description: This analytic focuses on identifying suspicious command-line parameters + commonly associated with the use of Impacket wmiexec.py. Impacket is a set of Python + classes designed for working with Microsoft network protocols, and it includes several + scripts like wmiexec.py, smbexec.py, dcomexec.py, and atexec.py that enable command + execution on remote endpoints. These scripts typically utilize administrative shares + and hardcoded parameters, which can serve as signatures to detect their usage. Both + Red Teams and adversaries may employ Impacket tools for lateral movement and remote + code execution purposes. By monitoring for these specific command-line indicators, + the analytic aims to detect potentially malicious activities related to Impacket + tool usage. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe + by Processes.dest Processes.user Processes.parent_process_name Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | where match(process, "(?i)cmd\.exe\s+\/Q\s+\/c") AND match(process,"(?i)echo\s+cd") + AND match(process, "(?i)\\__output") AND match(process, "(?i)C:\\\\Windows\\\\[a-zA-Z]{1,8}\\.bat") AND + match(process, "\\\\127\.0\.0\.1\\.*") | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `impacket_lateral_movement_smbexec_commandline_parameters_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. known_false_positives: Although uncommon, Administrators may leverage Impackets tools to start a process on remote systems for system administration or automation use cases. @@ -30,18 +46,20 @@ references: - https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - - Industroyer2 - Active Directory Lateral Movement - - Prestige Ransomware - CISA AA22-277A - - Data Destruction - WhisperGate + - Prestige Ransomware - Volt Typhoon + - Graceful Wipe Out Attack + - Industroyer2 + - Data Destruction asset_type: Endpoint atomic_guid: [] confidence: 70 impact: 90 - message: Suspicious command-line parameters on $dest$ may represent lateral movement using smbexec. + message: Suspicious command-line parameters on $dest$ may represent lateral movement + using smbexec. mitre_attack_id: - T1021 - T1021.002 @@ -59,11 +77,11 @@ tags: - Splunk Cloud required_fields: - Processes.process_name - - Processes.dest - - Processes.user - - Processes.parent_process_name - - Processes.process - - Processes.process_id + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.process + - Processes.process_id - Processes.parent_process_id risk_score: 63 security_domain: endpoint @@ -72,4 +90,4 @@ tests: attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.002/atomic_red_team/smbexec_windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog \ No newline at end of file + sourcetype: xmlwineventlog diff --git a/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml index 8ce04734b9..454dbc77b0 100644 --- a/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_wmiexec_commandline_parameters.yml @@ -1,7 +1,7 @@ name: Impacket Lateral Movement WMIExec Commandline Parameters id: d6e464e4-5c6a-474e-82d2-aed616a3a492 version: 1 -date: '2023-04-21' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: TTP @@ -16,12 +16,18 @@ description: This analytic looks for the presence of suspicious commandline para scripts leverage administrative shares and hardcoded parameters that can be used as a signature to detect its use. Red Teams and adversaries alike may leverage Impackets tools for lateral movement and remote code execution. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=wmiprvse.exe by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id - | `drop_dm_object_name(Processes)` - | where match(process, "(?i)cmd\.exe\s+\/Q\s+\/c") AND match(process, "\\\\127\.0\.0\.1\\.*") AND match(process, "__\\d{1,10}\\.\\d{1,10}") - | `security_content_ctime(firstTime)` +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=wmiprvse.exe + by Processes.dest Processes.user Processes.parent_process_name Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | where match(process, "(?i)cmd\.exe\s+\/Q\s+\/c") AND match(process, "\\\\127\.0\.0\.1\\.*") + AND match(process, "__\\d{1,10}\\.\\d{1,10}") | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `impacket_lateral_movement_wmiexec_commandline_parameters_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. known_false_positives: Although uncommon, Administrators may leverage Impackets tools to start a process on remote systems for system administration or automation use cases. @@ -37,18 +43,20 @@ references: - https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - - Industroyer2 - Active Directory Lateral Movement - - Prestige Ransomware - CISA AA22-277A - - Data Destruction - WhisperGate + - Prestige Ransomware - Volt Typhoon + - Graceful Wipe Out Attack + - Industroyer2 + - Data Destruction asset_type: Endpoint atomic_guid: [] confidence: 70 impact: 90 - message: Suspicious command-line parameters on $dest$ may represent lateral movement using wmiexec. + message: Suspicious command-line parameters on $dest$ may represent lateral movement + using wmiexec. mitre_attack_id: - T1021 - T1021.002 @@ -66,11 +74,11 @@ tags: - Splunk Cloud required_fields: - Processes.process_name - - Processes.dest - - Processes.user - - Processes.parent_process_name - - Processes.process - - Processes.process_id + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.process + - Processes.process_id - Processes.parent_process_id risk_score: 63 security_domain: endpoint @@ -79,4 +87,4 @@ tests: attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.002/atomic_red_team/wmiexec_windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog \ No newline at end of file + sourcetype: xmlwineventlog diff --git a/detections/endpoint/net_localgroup_discovery.yml b/detections/endpoint/net_localgroup_discovery.yml index 1fc086ef52..2c64bd8956 100644 --- a/detections/endpoint/net_localgroup_discovery.yml +++ b/detections/endpoint/net_localgroup_discovery.yml @@ -1,7 +1,7 @@ name: Net Localgroup Discovery id: 54f5201e-155b-11ec-a6e2-acde48001122 version: 1 -date: '2021-09-14' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: Hunting @@ -30,13 +30,14 @@ references: - https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/ tags: analytic_story: - - Active Directory Discovery - - Windows Discovery Techniques - - Azorult - - Windows Post-Exploitation - Prestige Ransomware - Volt Typhoon + - Graceful Wipe Out Attack - IcedID + - Windows Discovery Techniques + - Windows Post-Exploitation + - Azorult + - Active Directory Discovery asset_type: Endpoint confidence: 50 impact: 30 diff --git a/detections/endpoint/remote_wmi_command_attempt.yml b/detections/endpoint/remote_wmi_command_attempt.yml index 55c13d3dc2..8c50722c7f 100644 --- a/detections/endpoint/remote_wmi_command_attempt.yml +++ b/detections/endpoint/remote_wmi_command_attempt.yml @@ -1,7 +1,7 @@ name: Remote WMI Command Attempt id: 272df6de-61f1-4784-877c-1fbc3e2d0838 version: 4 -date: '2018-12-03' +date: '2023-06-13' author: Rico Valdez, Michael Haag, Splunk status: production type: TTP @@ -31,10 +31,11 @@ references: - https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/ tags: analytic_story: + - Volt Typhoon + - Graceful Wipe Out Attack + - IcedID - Suspicious WMI Use - Living Off The Land - - Volt Typhoon - - IcedID asset_type: Endpoint confidence: 60 impact: 60 diff --git a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml index 092923616d..6f2ff8fb7f 100644 --- a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml @@ -1,7 +1,7 @@ name: Rundll32 with no Command Line Arguments with Network id: 35307032-a12d-11eb-835f-acde48001122 version: 4 -date: '2022-03-15' +date: '2023-06-13' author: Steven Dick, Michael Haag, Splunk status: production type: TTP @@ -40,9 +40,10 @@ references: - https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ tags: analytic_story: - - Suspicious Rundll32 Activity - Cobalt Strike - PrintNightmare CVE-2021-34527 + - Suspicious Rundll32 Activity + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 100 cve: diff --git a/detections/endpoint/sam_database_file_access_attempt.yml b/detections/endpoint/sam_database_file_access_attempt.yml index 2e29986294..a83a0609f5 100644 --- a/detections/endpoint/sam_database_file_access_attempt.yml +++ b/detections/endpoint/sam_database_file_access_attempt.yml @@ -1,7 +1,7 @@ name: SAM Database File Access Attempt id: 57551656-ebdb-11eb-afdf-acde48001122 version: 1 -date: '2021-07-23' +date: '2023-06-13' author: Michael Haag, Mauricio Velazco, Splunk status: production type: Hunting @@ -32,6 +32,7 @@ references: tags: analytic_story: - Credential Dumping + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 100 cve: diff --git a/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml b/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml index 692cc09245..c5225623e9 100644 --- a/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml +++ b/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml @@ -1,7 +1,7 @@ name: SearchProtocolHost with no Command Line with Network id: b690df8c-a145-11eb-a38b-acde48001122 version: 3 -date: '2022-03-15' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: TTP @@ -33,6 +33,7 @@ references: tags: analytic_story: - Cobalt Strike + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 100 impact: 70 diff --git a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml index f8087c035f..23317fc878 100644 --- a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml +++ b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml @@ -1,7 +1,7 @@ name: SecretDumps Offline NTDS Dumping Tool id: 5672819c-be09-11eb-bbfb-acde48001122 version: 1 -date: '2021-05-26' +date: '2023-06-13' author: Teoderick Contreras, Splunk status: production type: TTP @@ -29,6 +29,7 @@ references: tags: analytic_story: - Credential Dumping + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 100 impact: 80 diff --git a/detections/endpoint/services_escalate_exe.yml b/detections/endpoint/services_escalate_exe.yml index 0fbb910192..76028dd4b5 100644 --- a/detections/endpoint/services_escalate_exe.yml +++ b/detections/endpoint/services_escalate_exe.yml @@ -1,7 +1,7 @@ name: Services Escalate Exe id: c448488c-b7ec-11eb-8253-acde48001122 version: 1 -date: '2021-05-18' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: TTP @@ -36,6 +36,7 @@ references: tags: analytic_story: - Cobalt Strike + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 95 impact: 80 diff --git a/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml b/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml index 062941a1f8..291bbba2dc 100644 --- a/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Suspicious DLLHost no Command Line Arguments id: ff61e98c-0337-4593-a78f-72a676c56f26 version: 4 -date: '2023-03-08' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: TTP @@ -31,6 +31,7 @@ references: tags: analytic_story: - Cobalt Strike + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml b/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml index e9c958fc8c..a965271e52 100644 --- a/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Suspicious GPUpdate no Command Line Arguments id: f308490a-473a-40ef-ae64-dd7a6eba284a version: 3 -date: '2022-03-15' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: TTP @@ -30,6 +30,7 @@ references: tags: analytic_story: - Cobalt Strike + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml index 3fbbf85426..2b39dd5277 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml @@ -1,7 +1,7 @@ name: Suspicious microsoft workflow compiler rename id: f0db4464-55d9-11eb-ae93-0242ac130002 version: 4 -date: '2022-04-07' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: Hunting @@ -32,10 +32,11 @@ references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution tags: analytic_story: - - Trusted Developer Utilities Proxy Execution - - Cobalt Strike - Masquerading - Rename System Utilities + - Trusted Developer Utilities Proxy Execution + - Graceful Wipe Out Attack - Living Off The Land + - Cobalt Strike asset_type: Endpoint confidence: 90 impact: 70 diff --git a/detections/endpoint/suspicious_msbuild_path.yml b/detections/endpoint/suspicious_msbuild_path.yml index 39369573e4..5cf8df0b33 100644 --- a/detections/endpoint/suspicious_msbuild_path.yml +++ b/detections/endpoint/suspicious_msbuild_path.yml @@ -1,7 +1,7 @@ name: Suspicious msbuild path id: f5198224-551c-11eb-ae93-0242ac130002 version: 3 -date: '2022-03-08' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: TTP @@ -32,10 +32,11 @@ references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md tags: analytic_story: + - Masquerading - Rename System Utilities + - Graceful Wipe Out Attack + - Living Off The Land - Trusted Developer Utilities Proxy Execution MSBuild - Cobalt Strike - - Masquerading - Rename System Utilities - - Living Off The Land asset_type: Endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/suspicious_msbuild_rename.yml b/detections/endpoint/suspicious_msbuild_rename.yml index 9c489d4e5b..5f0503e8e2 100644 --- a/detections/endpoint/suspicious_msbuild_rename.yml +++ b/detections/endpoint/suspicious_msbuild_rename.yml @@ -1,7 +1,7 @@ name: Suspicious MSBuild Rename id: 4006adac-5937-11eb-ae93-0242ac130002 version: 3 -date: '2022-04-07' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: Hunting @@ -30,10 +30,11 @@ references: - https://github.com/infosecn1nja/MaliciousMacroMSBuild/ tags: analytic_story: + - Masquerading - Rename System Utilities + - Graceful Wipe Out Attack + - Living Off The Land - Trusted Developer Utilities Proxy Execution MSBuild - Cobalt Strike - - Masquerading - Rename System Utilities - - Living Off The Land asset_type: Endpoint confidence: 90 impact: 70 diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/endpoint/suspicious_process_file_path.yml index 23a65c16e3..85282b8bae 100644 --- a/detections/endpoint/suspicious_process_file_path.yml +++ b/detections/endpoint/suspicious_process_file_path.yml @@ -1,7 +1,7 @@ name: Suspicious Process File Path id: 9be25988-ad82-11eb-a14f-acde48001122 version: 1 -date: '2023-04-25' +date: '2023-06-13' author: Teoderick Contreras, Splunk status: production type: TTP @@ -36,27 +36,28 @@ references: - https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ tags: analytic_story: - - Azorult - - AsyncRAT + - WhisperGate - XMRig - - Swift Slicer - - DarkCrystal RAT - - Double Zero Destructor - - Trickbot - - Data Destruction - - LockBit Ransomware - - Prestige Ransomware - Industroyer2 - Remcos - - RedLine Stealer - - WhisperGate - - IcedID + - Data Destruction - Hermetic Wiper - - AgentTesla - - Brute Ratel C4 + - Azorult + - DarkCrystal RAT + - Graceful Wipe Out Attack + - IcedID + - Swift Slicer - Qakbot - - Chaos Ransomware + - RedLine Stealer + - Brute Ratel C4 + - Prestige Ransomware + - AsyncRAT + - LockBit Ransomware + - AgentTesla + - Double Zero Destructor - Volt Typhoon + - Chaos Ransomware + - Trickbot asset_type: Endpoint confidence: 50 impact: 70 diff --git a/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml b/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml index 204b36609a..e5c0fbd983 100644 --- a/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 no Command Line Arguments id: e451bd16-e4c5-4109-8eb1-c4c6ecf048b4 version: 3 -date: '2022-03-15' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: TTP @@ -32,9 +32,10 @@ references: - https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ tags: analytic_story: - - Suspicious Rundll32 Activity - Cobalt Strike - PrintNightmare CVE-2021-34527 + - Suspicious Rundll32 Activity + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 70 cve: diff --git a/detections/endpoint/suspicious_rundll32_startw.yml b/detections/endpoint/suspicious_rundll32_startw.yml index 117c76585c..192ee5efa8 100644 --- a/detections/endpoint/suspicious_rundll32_startw.yml +++ b/detections/endpoint/suspicious_rundll32_startw.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 StartW id: 9319dda5-73f2-4d43-a85a-67ce961bddb7 version: 3 -date: '2021-02-04' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: TTP @@ -37,8 +37,9 @@ references: - https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ tags: analytic_story: - - Suspicious Rundll32 Activity - Cobalt Strike + - Suspicious Rundll32 Activity + - Graceful Wipe Out Attack - Trickbot asset_type: Endpoint confidence: 50 diff --git a/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml b/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml index af6249d069..9c1cd51772 100644 --- a/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Suspicious SearchProtocolHost no Command Line Arguments id: f52d2db8-31f9-4aa7-a176-25779effe55c version: 3 -date: '2022-03-15' +date: '2023-06-13' author: Michael Haag, Splunk status: production type: TTP @@ -31,6 +31,7 @@ references: tags: analytic_story: - Cobalt Strike + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/windows_adfind_exe.yml b/detections/endpoint/windows_adfind_exe.yml index 0354123c20..b37616845e 100644 --- a/detections/endpoint/windows_adfind_exe.yml +++ b/detections/endpoint/windows_adfind_exe.yml @@ -1,14 +1,18 @@ name: Windows AdFind Exe id: bd3b0187-189b-46c0-be45-f52da2bae67f version: 3 -date: '2023-05-15' +date: '2023-06-13' author: Jose Hernandez, Bhavin Patel, Splunk status: production type: TTP description: 'This search looks for the execution of `adfind.exe` with command-line - arguments that it uses by default specifically the filter or search functions. - It also considers the arguments necessary like objectcategory, see readme for more - details: https://www.joeware.net/freetools/tools/adfind/usage.htm. AdFind.exe is a powerful tool that is commonly used for querying and retrieving information from Active Directory (AD). While it is primarily designed for AD administration and management, it has been seen used before by Wizard Spider, FIN6 and actors whom also launched SUNBURST.' + arguments that it uses by default specifically the filter or search functions. It + also considers the arguments necessary like objectcategory, see readme for more + details: https://www.joeware.net/freetools/tools/adfind/usage.htm. AdFind.exe is + a powerful tool that is commonly used for querying and retrieving information from + Active Directory (AD). While it is primarily designed for AD administration and + management, it has been seen used before by Wizard Spider, FIN6 and actors whom + also launched SUNBURST.' data_source: - Sysmon Event ID 1 search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) @@ -21,7 +25,9 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -known_false_positives: ADfind is a command-line tool for AD administration and management that is seen to be leveraged by various adversaries. Filter out legitimate administrator usage using the filter macro. +known_false_positives: ADfind is a command-line tool for AD administration and management + that is seen to be leveraged by various adversaries. Filter out legitimate administrator + usage using the filter macro. references: - https://www.volexity.com/blog/2020/12/14/dark-halo-leverages-solarwinds-compromise-to-breach-organizations/ - https://www.mandiant.com/resources/a-nasty-trick-from-credential-theft-malware-to-business-disruption @@ -29,9 +35,10 @@ references: - https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/ tags: analytic_story: - - NOBELIUM Group - Domain Trust Discovery - IcedID + - NOBELIUM Group + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/windows_process_injection_remote_thread.yml b/detections/endpoint/windows_process_injection_remote_thread.yml index 04963aa49e..f5eb4114dc 100644 --- a/detections/endpoint/windows_process_injection_remote_thread.yml +++ b/detections/endpoint/windows_process_injection_remote_thread.yml @@ -1,7 +1,7 @@ name: Windows Process Injection Remote Thread id: 8a618ade-ca8f-4d04-b972-2d526ba59924 version: 1 -date: '2022-11-10' +date: '2023-06-15' author: Teoderick Contreras, Splunk status: production type: TTP @@ -16,7 +16,7 @@ data_source: - Sysmon Event ID 8 search: '`sysmon` EventCode=8 TargetImage IN ("*\\Taskmgr.exe", "*\\calc.exe", "*\\notepad.exe", "*\\rdpclip.exe", "*\\explorer.exe", "*\\wermgr.exe", "*\\ping.exe", "*\\OneDriveSetup.exe", - "*\\dxdiag.exe", "*\\mobsync.exe", "*\\msra.exe", "*\\xwizard.exe") | stats count + "*\\dxdiag.exe", "*\\mobsync.exe", "*\\msra.exe", "*\\xwizard.exe","*\\cmd.exe", "*\\powershell.exe") | stats count min(_time) as firstTime max(_time) as lastTime by TargetImage TargetProcessId SourceProcessId EventCode StartAddress SourceImage Computer | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_process_injection_remote_thread_filter`' @@ -27,9 +27,11 @@ how_to_implement: To successfully implement this search, you must be ingesting d known_false_positives: unknown references: - https://twitter.com/pr0xylife/status/1585612370441031680?s=46&t=Dc3CJi4AnM-8rNoacLbScg +- https://thedfirreport.com/2023/06/12/a-truly-graceful-wipe-out/ tags: analytic_story: - Qakbot + - Graceful Wipe Out Attack asset_type: 80 confidence: 80 impact: 80 diff --git a/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml b/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml index 44ef4bf36e..0a52ba3dda 100644 --- a/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml +++ b/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml @@ -1,7 +1,7 @@ name: Windows Raw Access To Disk Volume Partition id: a85aa37e-9647-11ec-90c5-acde48001122 version: 1 -date: '2023-04-14' +date: '2023-06-13' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -28,9 +28,10 @@ references: tags: analytic_story: - CISA AA22-264A + - Graceful Wipe Out Attack - Data Destruction - - Caddy Wiper - Hermetic Wiper + - Caddy Wiper asset_type: Endpoint confidence: 100 impact: 90 diff --git a/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml b/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml index 4ed481b408..613c5628dc 100644 --- a/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml +++ b/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml @@ -1,7 +1,7 @@ name: Windows Raw Access To Master Boot Record Drive id: 7b83f666-900c-11ec-a2d9-acde48001122 version: 1 -date: '2023-04-14' +date: '2023-06-13' author: Teoderick Contreras, Splunk status: production type: TTP @@ -29,11 +29,12 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - - Caddy Wiper - CISA AA22-264A - - Hermetic Wiper - - Data Destruction - WhisperGate + - Graceful Wipe Out Attack + - Data Destruction + - Hermetic Wiper + - Caddy Wiper asset_type: Endpoint confidence: 100 impact: 90 diff --git a/detections/endpoint/windows_service_stop_by_deletion.yml b/detections/endpoint/windows_service_stop_by_deletion.yml index d6873d7b23..20ec8ac144 100644 --- a/detections/endpoint/windows_service_stop_by_deletion.yml +++ b/detections/endpoint/windows_service_stop_by_deletion.yml @@ -1,7 +1,7 @@ name: Windows Service Stop By Deletion id: 196ff536-58d9-4d1b-9686-b176b04e430b version: 1 -date: '2022-06-21' +date: '2023-06-13' author: Teoderick Contreras, Splunk status: production type: TTP @@ -32,6 +32,7 @@ references: tags: analytic_story: - Azorult + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/windows_service_stop_via_net__and_sc_application.yml b/detections/endpoint/windows_service_stop_via_net__and_sc_application.yml index 2d389cb003..a09c91a2f5 100644 --- a/detections/endpoint/windows_service_stop_via_net__and_sc_application.yml +++ b/detections/endpoint/windows_service_stop_via_net__and_sc_application.yml @@ -1,7 +1,7 @@ name: Windows Service Stop Via Net and SC Application id: 827af04b-0d08-479b-9b84-b7d4644e4b80 version: 1 -date: '2022-11-30' +date: '2023-06-13' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -31,6 +31,7 @@ references: tags: analytic_story: - Prestige Ransomware + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 70 impact: 70 diff --git a/stories/graceful_wipe_out_attack.yml b/stories/graceful_wipe_out_attack.yml new file mode 100644 index 0000000000..c4f839846b --- /dev/null +++ b/stories/graceful_wipe_out_attack.yml @@ -0,0 +1,25 @@ +name: Graceful Wipe Out Attack +id: 83b15b3c-6bda-45aa-a3b6-b05c52443f44 +version: 1 +date: '20223-06-15' +author: Teoderick Contreras, Splunk +description: This analytic story contains detections that allow security analysts to detect and investigate unusual activities + that might relate to the destructive attack or campaign found by "THE DFIR Report" that uses Truebot, FlawedGrace and MBR killer malware. + This analytic story looks for suspicious dropped files, cobalt strike execution, im-packet execution, registry modification, scripts, + persistence, lateral movement, impact, exfiltration and recon. +narrative: Graceful Wipe Out Attack is a destructive malware campaign found by "The DFIR Report" targeting + multiple organizations to collect, exfiltrate and wipe the data of targeted networks. + This malicious payload corrupts or wipes Master Boot Records by using an NSIS script after the exfiltration of sensitive information from the targeted host or system. +references: +- https://thedfirreport.com/2023/06/12/a-truly-graceful-wipe-out/ +tags: + analytic_story: Graceful Wipe Out Attack + category: + - Data Destruction + - Malware + - Adversary Tactics + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection From 1656ff3f38ad77954fbaf025361492c47b7f8e5d Mon Sep 17 00:00:00 2001 From: tccontre <26181693+tccontre@users.noreply.github.com> Date: Tue, 13 Jun 2023 16:36:53 +0200 Subject: [PATCH 2/2] Update graceful_wipe_out_attack.yml --- stories/graceful_wipe_out_attack.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/stories/graceful_wipe_out_attack.yml b/stories/graceful_wipe_out_attack.yml index c4f839846b..a19c260379 100644 --- a/stories/graceful_wipe_out_attack.yml +++ b/stories/graceful_wipe_out_attack.yml @@ -1,7 +1,7 @@ name: Graceful Wipe Out Attack id: 83b15b3c-6bda-45aa-a3b6-b05c52443f44 version: 1 -date: '20223-06-15' +date: '2023-06-15' author: Teoderick Contreras, Splunk description: This analytic story contains detections that allow security analysts to detect and investigate unusual activities that might relate to the destructive attack or campaign found by "THE DFIR Report" that uses Truebot, FlawedGrace and MBR killer malware.