From 4162e9b5eb0785211e77db487fe3041eb8fa63f6 Mon Sep 17 00:00:00 2001 From: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com> Date: Tue, 24 May 2022 15:00:09 -0700 Subject: [PATCH] Filter was missing any and all detections which started with s and a. Fixed it, and fixed the order of these detections. Now it should be easier to pre-merge changes from develop. --- ...mber_of_cloud_infrastructure_api_calls.yml | 20 +++++------ ...mber_of_cloud_security_group_api_calls.yml | 20 +++++------ ...azon_eks_kubernetes_activity_by_src_ip.yml | 22 ++++++------ ..._policy_version_to_allow_all_resources.yml | 30 ++++++++-------- detections/cloud/aws_createaccesskey.yml | 26 +++++++------- detections/cloud/aws_createloginprofile.yml | 26 +++++++------- ...ctivity_from_previously_unseen_account.yml | 32 ++++++++--------- ...g_keys_with_encrypt_policy_without_mfa.yml | 26 +++++++------- ...with_kms_keys_performing_encryption_s3.yml | 26 +++++++------- ...s_ecr_container_scanning_findings_high.yml | 22 ++++++------ ...ing_findings_low_informational_unknown.yml | 22 ++++++------ ...ecr_container_scanning_findings_medium.yml | 22 ++++++------ ...ontainer_upload_outside_business_hours.yml | 24 ++++++------- .../aws_ecr_container_upload_unknown_user.yml | 22 ++++++------ .../cloud/aws_excessive_security_scanning.yml | 22 ++++++------ .../aws_iam_accessdenied_discovery_events.yml | 26 +++++++------- ...aws_iam_assume_role_policy_brute_force.yml | 32 ++++++++--------- detections/cloud/aws_iam_delete_policy.yml | 32 ++++++++--------- .../cloud/aws_iam_failure_group_deletion.yml | 30 ++++++++-------- .../aws_iam_successful_group_deletion.yml | 30 ++++++++-------- ...nvestigate_security_hub_alerts_by_dest.yml | 22 ++++++------ ...stigate_user_activities_by_accesskeyid.yml | 22 ++++++------ ...aws_investigate_user_activities_by_arn.yml | 16 ++++----- ...ntrol_list_created_with_all_open_ports.yml | 26 +++++++------- ...ws_network_access_control_list_deleted.yml | 24 ++++++------- .../cloud/aws_network_acl_details_from_id.yml | 16 ++++----- ...twork_interface_details_via_resourceid.yml | 22 ++++++------ .../aws_s3_bucket_details_via_bucketname.yml | 16 ++++----- ..._access_by_provider_user_and_principal.yml | 22 ++++++------ .../aws_saml_update_identity_provider.yml | 30 ++++++++-------- .../cloud/aws_setdefaultpolicyversion.yml | 30 ++++++++-------- detections/cloud/aws_updateloginprofile.yml | 26 +++++++------- .../account_discovery_with_net_app.yml | 30 ++++++++-------- .../active_setup_registry_autostart.yml | 30 ++++++++-------- ...d_defaultuser_and_password_in_registry.yml | 24 ++++++------- .../add_or_set_windows_defender_exclusion.yml | 26 +++++++------- .../adsisearcher_account_discovery.yml | 28 +++++++-------- .../endpoint/all_backup_logs_for_host.yml | 14 ++++---- ..._file_and_printing_sharing_in_firewall.yml | 30 ++++++++-------- ...ound_traffic_by_firewall_rule_registry.yml | 26 +++++++------- ...allow_inbound_traffic_in_firewall_rule.yml | 26 +++++++------- .../allow_network_discovery_in_firewall.yml | 30 ++++++++-------- .../allow_operation_with_consent_admin.yml | 30 ++++++++-------- .../endpoint/anomalous_usage_of_7zip.yml | 28 +++++++-------- .../endpoint/any_powershell_downloadfile.yml | 34 +++++++++--------- .../any_powershell_downloadstring.yml | 34 +++++++++--------- .../endpoint/attacker_tools_on_endpoint.yml | 28 +++++++-------- ..._to_add_certificate_to_untrusted_store.yml | 30 ++++++++-------- .../attempt_to_stop_security_service.yml | 28 +++++++-------- ...dential_dump_from_registry_via_reg_exe.yml | 26 +++++++------- .../auto_admin_logon_registry_entry.yml | 24 ++++++------- .../sam_database_file_access_attempt.yml | 18 +++++----- .../endpoint/samsam_test_file_write.yml | 22 ++++++------ .../sc_exe_manipulating_windows_services.yml | 24 ++++++------- ..._by_app_connect_and_create_adsi_object.yml | 30 ++++++++-------- ...edule_task_with_http_command_arguments.yml | 24 ++++++------- ...ule_task_with_rundll32_command_trigger.yml | 26 +++++++------- ...k_creation_on_remote_endpoint_using_at.yml | 26 +++++++------- ...eduled_task_deleted_or_created_via_cmd.yml | 24 ++++++------- ...led_task_initiation_on_remote_endpoint.yml | 26 +++++++------- .../endpoint/schtasks_run_task_on_demand.yml | 26 +++++++------- ...htasks_scheduling_job_on_remote_system.yml | 28 +++++++-------- .../schtasks_used_for_forcing_a_reboot.yml | 26 +++++++------- .../screensaver_event_trigger_execution.yml | 20 +++++------ .../endpoint/script_execution_via_wmi.yml | 26 +++++++------- detections/endpoint/sdclt_uac_bypass.yml | 26 +++++++------- .../sdelete_application_execution.yml | 26 +++++++------- ...host_with_no_command_line_with_network.yml | 24 ++++++------- .../secretdumps_offline_ntds_dumping_tool.yml | 24 ++++++------- ...incipalnames_discovery_with_powershell.yml | 20 +++++------ ...ceprincipalnames_discovery_with_setspn.yml | 24 ++++++------- detections/endpoint/services_escalate_exe.yml | 26 +++++++------- ...ces_exe_lolbas_execution_process_spawn.yml | 28 +++++++-------- ...ution_policy_to_unrestricted_or_bypass.yml | 28 +++++++-------- .../endpoint/shim_database_file_creation.yml | 26 +++++++------- ...nstallation_with_suspicious_parameters.yml | 24 ++++++------- .../endpoint/short_lived_scheduled_task.yml | 28 +++++++-------- .../endpoint/short_lived_windows_accounts.yml | 22 ++++++------ .../endpoint/silentcleanup_uac_bypass.yml | 26 +++++++------- .../single_letter_process_on_endpoint.yml | 26 +++++++------- detections/endpoint/slui_runas_elevated.yml | 32 ++++++++--------- .../endpoint/slui_spawning_a_process.yml | 28 +++++++-------- .../endpoint/spoolsv_spawning_rundll32.yml | 32 ++++++++--------- .../spoolsv_suspicious_loaded_modules.yml | 24 ++++++------- .../spoolsv_suspicious_process_access.yml | 32 ++++++++--------- detections/endpoint/spoolsv_writing_a_dll.yml | 28 +++++++-------- .../spoolsv_writing_a_dll___sysmon.yml | 20 +++++------ .../endpoint/sqlite_module_in_temp_folder.yml | 26 +++++++------- .../start_up_during_safe_mode_boot.yml | 20 +++++------ ...uspicious_computer_account_name_change.yml | 18 +++++----- .../endpoint/suspicious_copy_on_system32.yml | 26 +++++++------- ...ious_dllhost_no_command_line_arguments.yml | 30 ++++++++-------- .../suspicious_driver_loaded_path.yml | 28 +++++++-------- ...ous_gpupdate_no_command_line_arguments.yml | 28 +++++++-------- .../suspicious_icedid_rundll32_cmdline.yml | 28 +++++++-------- ...cious_image_creation_in_appdata_folder.yml | 26 +++++++------- ...icious_kerberos_service_ticket_request.yml | 20 +++++------ ...ous_microsoft_workflow_compiler_rename.yml | 30 ++++++++-------- ...ious_microsoft_workflow_compiler_usage.yml | 30 ++++++++-------- .../endpoint/suspicious_msbuild_path.yml | 34 +++++++++--------- .../endpoint/suspicious_msbuild_rename.yml | 32 ++++++++--------- .../endpoint/suspicious_msbuild_spawn.yml | 30 ++++++++-------- .../suspicious_mshta_child_process.yml | 28 +++++++-------- .../endpoint/suspicious_mshta_spawn.yml | 32 ++++++++--------- ...ess_dns_query_known_abuse_web_services.yml | 26 +++++++------- .../endpoint/suspicious_process_file_path.yml | 24 ++++++------- .../endpoint/suspicious_reg_exe_process.yml | 30 ++++++++-------- ...ious_regsvr32_register_suspicious_path.yml | 24 ++++++------- .../suspicious_rundll32_dllregisterserver.yml | 22 ++++++------ .../suspicious_rundll32_plugininit.yml | 28 +++++++-------- .../endpoint/suspicious_rundll32_rename.yml | 32 ++++++++--------- .../endpoint/suspicious_rundll32_startw.yml | 36 +++++++++---------- ...undll32_with_no_command_line_arguments.yml | 34 +++++++++--------- ...s_scheduled_task_from_public_directory.yml | 24 ++++++------- ...protocolhost_no_command_line_arguments.yml | 28 +++++++-------- ...picious_ticket_granting_ticket_request.yml | 32 ++++++++--------- .../suspicious_wav_file_in_appdata_folder.yml | 26 +++++++------- .../endpoint/suspicious_wevtutil_usage.yml | 28 +++++++-------- ...spicious_writes_to_windows_recycle_bin.yml | 24 ++++++------- ...ost_exe_lolbas_execution_process_spawn.yml | 28 +++++++-------- ...nfo_gathering_using_dxdiag_application.yml | 28 +++++++-------- ...system_information_discovery_detection.yml | 22 ++++++------ ...rocesses_run_from_unexpected_locations.yml | 26 +++++++------- .../system_user_discovery_with_query.yml | 22 ++++++------ .../system_user_discovery_with_whoami.yml | 22 ++++++------ ...ady_for_spectre_meltdown_windows_patch.yml | 20 +++++------ 126 files changed, 1641 insertions(+), 1641 deletions(-) diff --git a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml index 587684b2eb..038df98daf 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml @@ -1,16 +1,13 @@ +name: Abnormally High Number Of Cloud Infrastructure API Calls +id: 0840ddf1-8c89-46ff-b730-c8d6722478c0 +version: 1 +date: '2020-09-07' author: David Dorsey, Splunk +type: Anomaly datamodel: - Change -date: '2020-09-07' description: This search will detect a spike in the number of API calls made to your cloud infrastructure environment by a user. -how_to_implement: You must be ingesting your cloud infrastructure logs. You also must - run the baseline search `Baseline Of Cloud Infrastructure API Calls Per User` to - create the probability density function. -id: 0840ddf1-8c89-46ff-b730-c8d6722478c0 -known_false_positives: '' -name: Abnormally High Number Of Cloud Infrastructure API Calls -references: [] search: '| tstats count as api_calls values(All_Changes.command) as command from datamodel=Change.All_Changes where All_Changes.user!=unknown All_Changes.status=success by All_Changes.user _time span=1h | `drop_dm_object_name("All_Changes")` | eval HourOfDay=strftime(_time, @@ -22,6 +19,11 @@ search: '| tstats count as api_calls values(All_Changes.command) as command from -1), ":"), 0) | where api_calls > expected_upper_threshold | eval distance_from_threshold = api_calls - expected_upper_threshold | table _time, user, command, api_calls, expected_upper_threshold, distance_from_threshold | `abnormally_high_number_of_cloud_infrastructure_api_calls_filter`' +how_to_implement: You must be ingesting your cloud infrastructure logs. You also must + run the baseline search `Baseline Of Cloud Infrastructure API Calls Per User` to + create the probability density function. +known_false_positives: '' +references: [] tags: analytic_story: - Suspicious Cloud User Activities @@ -64,5 +66,3 @@ tags: - _time risk_score: 15 security_domain: network -type: Anomaly -version: 1 diff --git a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml index e79bb7a3c1..6809d84c81 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml @@ -1,16 +1,13 @@ +name: Abnormally High Number Of Cloud Security Group API Calls +id: d4dfb7f3-7a37-498a-b5df-f19334e871af +version: 1 +date: '2020-09-07' author: David Dorsey, Splunk +type: Anomaly datamodel: - Change -date: '2020-09-07' description: This search will detect a spike in the number of API calls made to your cloud infrastructure environment about security groups by a user. -how_to_implement: You must be ingesting your cloud infrastructure logs. You also must - run the baseline search `Baseline Of Cloud Security Group API Calls Per User` to - create the probability density function model. -id: d4dfb7f3-7a37-498a-b5df-f19334e871af -known_false_positives: '' -name: Abnormally High Number Of Cloud Security Group API Calls -references: [] search: '| tstats count as security_group_api_calls values(All_Changes.command) as command from datamodel=Change.All_Changes where All_Changes.object_category=firewall AND All_Changes.status=success by All_Changes.user _time span=1h | `drop_dm_object_name("All_Changes")` @@ -23,6 +20,11 @@ search: '| tstats count as security_group_api_calls values(All_Changes.command) 0) | where security_group_api_calls > expected_upper_threshold | eval distance_from_threshold = security_group_api_calls - expected_upper_threshold | table _time, user, command, security_group_api_calls, expected_upper_threshold, distance_from_threshold | `abnormally_high_number_of_cloud_security_group_api_calls_filter`' +how_to_implement: You must be ingesting your cloud infrastructure logs. You also must + run the baseline search `Baseline Of Cloud Security Group API Calls Per User` to + create the probability density function model. +known_false_positives: '' +references: [] tags: analytic_story: - Suspicious Cloud User Activities @@ -70,5 +72,3 @@ tags: - _time risk_score: 15 security_domain: network -type: Anomaly -version: 1 diff --git a/detections/cloud/amazon_eks_kubernetes_activity_by_src_ip.yml b/detections/cloud/amazon_eks_kubernetes_activity_by_src_ip.yml index 5eed63deaa..60afb539e8 100644 --- a/detections/cloud/amazon_eks_kubernetes_activity_by_src_ip.yml +++ b/detections/cloud/amazon_eks_kubernetes_activity_by_src_ip.yml @@ -1,20 +1,22 @@ -author: Rod Soto, Splunk -datamodel: [] +name: Amazon EKS Kubernetes activity by src ip +id: a636cca4-7434-4a15-a278-c70734938e39 +version: 1 date: '2020-04-13' +author: Rod Soto, Splunk +type: Investigation +datamodel: [] description: This search provides investigation data about requests via user agent, authentication request URI, verb and cluster name data against Kubernetes cluster from a specific IP address -how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) - and Splunk Add-on for AWS (version 4.4.0 or later), then configure your Cloud Watch - EKS inputs. -id: a636cca4-7434-4a15-a278-c70734938e39 -known_false_positives: '' -name: Amazon EKS Kubernetes activity by src ip -references: [] search: '`aws_cloudwatchlogs_eks` |rename sourceIPs{} as src_ip |search src_ip=$src_ip$ | stats count min(_time) as firstTime max(_time) as lastTime values(user.username) values(requestURI) values(verb) values(userAgent) by source annotations.authorization.k8s.io/decision src_ip' +how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) + and Splunk Add-on for AWS (version 4.4.0 or later), then configure your Cloud Watch + EKS inputs. +known_false_positives: '' +references: [] tags: analytic_story: - Kubernetes Scanning Activity @@ -28,5 +30,3 @@ tags: - userAgent - verb security_domain: network -type: Investigation -version: 1 diff --git a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml index 949232aca8..722ff3e830 100644 --- a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml +++ b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml @@ -1,19 +1,12 @@ -author: Bhavin Patel, Splunk -datamodel: [] +name: AWS Create Policy Version to allow all resources +id: 2a9b80d3-6340-4345-b5ad-212bf3d0dac4 +version: 2 date: '2021-02-22' +author: Bhavin Patel, Splunk +type: TTP +datamodel: [] description: This search looks for AWS CloudTrail events where a user created a policy version that allows them to access any resource in their account -how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This - search works with AWS CloudTrail logs. -id: 2a9b80d3-6340-4345-b5ad-212bf3d0dac4 -known_false_positives: While this search has no known false positives, it is possible - that an AWS admin has legitimately created a policy to allow a user to access all - resources. That said, AWS strongly advises against granting full control to all - AWS resources -name: AWS Create Policy Version to allow all resources -references: -- https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws -- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ search: '`cloudtrail` eventName=CreatePolicyVersion eventSource = iam.amazonaws.com errorCode = success | spath input=requestParameters.policyDocument output=key_policy_statements path=Statement{} | mvexpand key_policy_statements | spath input=key_policy_statements @@ -22,6 +15,15 @@ search: '`cloudtrail` eventName=CreatePolicyVersion eventSource = iam.amazonaws. as policy_added by eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`aws_create_policy_version_to_allow_all_resources_filter`' +how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This + search works with AWS CloudTrail logs. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has legitimately created a policy to allow a user to access all + resources. That said, AWS strongly advises against granting full control to all + AWS resources +references: +- https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws +- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ tags: analytic_story: - AWS IAM Privilege Escalation @@ -66,5 +68,3 @@ tags: - userAgent risk_score: 49 security_domain: network -type: TTP -version: 2 diff --git a/detections/cloud/aws_createaccesskey.yml b/detections/cloud/aws_createaccesskey.yml index 2843390ad9..312fb3f184 100644 --- a/detections/cloud/aws_createaccesskey.yml +++ b/detections/cloud/aws_createaccesskey.yml @@ -1,24 +1,26 @@ -author: Bhavin Patel, Splunk -datamodel: [] +name: AWS CreateAccessKey +id: 2a9b80d3-6340-4345-11ad-212bf3d0d111 +version: 2 date: '2021-07-19' +author: Bhavin Patel, Splunk +type: Hunting +datamodel: [] description: This search looks for AWS CloudTrail events where a user A who has already permission to create access keys, makes an API call to create access keys for another user B. Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) -how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This - search works with AWS CloudTrail logs. -id: 2a9b80d3-6340-4345-11ad-212bf3d0d111 -known_false_positives: While this search has no known false positives, it is possible - that an AWS admin has legitimately created keys for another user. -name: AWS CreateAccessKey -references: -- https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws -- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ search: '`cloudtrail` eventName = CreateAccessKey userAgent !=console.amazonaws.com errorCode = success| search userIdentity.userName!=requestParameters.userName | stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`aws_createaccesskey_filter`' +how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This + search works with AWS CloudTrail logs. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has legitimately created keys for another user. +references: +- https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws +- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ tags: analytic_story: - AWS IAM Privilege Escalation @@ -67,5 +69,3 @@ tags: - userAgent risk_score: 63 security_domain: network -type: Hunting -version: 2 diff --git a/detections/cloud/aws_createloginprofile.yml b/detections/cloud/aws_createloginprofile.yml index 90df0ad1e5..e1c73ecd13 100644 --- a/detections/cloud/aws_createloginprofile.yml +++ b/detections/cloud/aws_createloginprofile.yml @@ -1,19 +1,14 @@ -author: Bhavin Patel, Splunk -datamodel: [] +name: AWS CreateLoginProfile +id: 2a9b80d3-6340-4345-11ad-212bf444d111 +version: 2 date: '2021-07-19' +author: Bhavin Patel, Splunk +type: TTP +datamodel: [] description: This search looks for AWS CloudTrail events where a user A(victim A) creates a login profile for user B, followed by a AWS Console login event from user B from the same src_ip as user B. This correlated event can be indicative of privilege escalation since both events happened from the same src_ip -how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This - search works with AWS CloudTrail logs. -id: 2a9b80d3-6340-4345-11ad-212bf444d111 -known_false_positives: While this search has no known false positives, it is possible - that an AWS admin has legitimately created a login profile for another user. -name: AWS CreateLoginProfile -references: -- https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws -- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ search: '`cloudtrail` eventName = CreateLoginProfile | rename requestParameters.userName as new_login_profile | table src_ip eventName new_login_profile userIdentity.userName | join new_login_profile src_ip [| search `cloudtrail` eventName = ConsoleLogin | @@ -22,6 +17,13 @@ search: '`cloudtrail` eventName = CreateLoginProfile | rename requestParameters. userAgent eventID awsRegion userIdentity.principalId user_arn new_login_profile src_ip | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`] | `aws_createloginprofile_filter`' +how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This + search works with AWS CloudTrail logs. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has legitimately created a login profile for another user. +references: +- https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws +- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ tags: analytic_story: - AWS IAM Privilege Escalation @@ -70,5 +72,3 @@ tags: - userAgent risk_score: 72 security_domain: network -type: TTP -version: 2 diff --git a/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml b/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml index 86d0665ab6..a8770af04f 100644 --- a/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml +++ b/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml @@ -1,22 +1,13 @@ +name: AWS Cross Account Activity From Previously Unseen Account +id: 21193641-cb96-4a2c-a707-d9b9a7f7792b +version: 1 +date: '2020-05-28' author: Rico Valdez, Splunk +type: Anomaly datamodel: - Authentication -date: '2020-05-28' description: This search looks for AssumeRole events where an IAM role in a different account is requested for the first time. -how_to_implement: You must be ingesting your cloud infrastructure logs from your cloud - provider. You should run the baseline search `Previously Seen AWS Cross Account - Activity - Initial` to build the initial table of source IP address, geographic - locations, and times. You must also enable the second baseline search `Previously - Seen AWS Cross Account Activity - Update` to keep this table up to date and to age - out old data. You can also provide additional filtering for this search by customizing - the `aws_cross_account_activity_from_previously_unseen_account_filter` macro. -id: 21193641-cb96-4a2c-a707-d9b9a7f7792b -known_false_positives: Using multiple AWS accounts and roles is perfectly valid behavior. - It's suspicious when an account requests privileges of an account it hasn't before. - You should validate with the account owner that this is a legitimate request. -name: AWS Cross Account Activity From Previously Unseen Account -references: [] search: '| tstats min(_time) as firstTime max(_time) as lastTime from datamodel=Authentication.Authentication where Authentication.signature=AssumeRole by Authentication.vendor_account Authentication.user Authentication.src Authentication.user_role | `drop_dm_object_name(Authentication)` @@ -27,6 +18,17 @@ search: '| tstats min(_time) as firstTime max(_time) as lastTime from datamodel= Cross Account Activity","Previously Seen") | where status = "New Cross Account Activity" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `aws_cross_account_activity_from_previously_unseen_account_filter`' +how_to_implement: You must be ingesting your cloud infrastructure logs from your cloud + provider. You should run the baseline search `Previously Seen AWS Cross Account + Activity - Initial` to build the initial table of source IP address, geographic + locations, and times. You must also enable the second baseline search `Previously + Seen AWS Cross Account Activity - Update` to keep this table up to date and to age + out old data. You can also provide additional filtering for this search by customizing + the `aws_cross_account_activity_from_previously_unseen_account_filter` macro. +known_false_positives: Using multiple AWS accounts and roles is perfectly valid behavior. + It's suspicious when an account requests privileges of an account it hasn't before. + You should validate with the account owner that this is a legitimate request. +references: [] tags: analytic_story: - Suspicious Cloud Authentication Activities @@ -74,5 +76,3 @@ tags: - _time risk_score: 15 security_domain: network -type: Anomaly -version: 1 diff --git a/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml b/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml index 013682a76b..89d4120e98 100644 --- a/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml +++ b/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml @@ -1,19 +1,14 @@ -author: Rod Soto, Patrick Bareiss Splunk -datamodel: [] +name: AWS Detect Users creating keys with encrypt policy without MFA +id: c79c164f-4b21-4847-98f9-cf6a9f49179e +version: 1 date: '2021-01-11' +author: Rod Soto, Patrick Bareiss Splunk +type: TTP +datamodel: [] description: This search provides detection of KMS keys where action kms:Encrypt is accessible for everyone (also outside of your organization). This is an indicator that your account is compromised and the attacker uses the encryption key to compromise another company. -how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This - search works with AWS CloudTrail logs -id: c79c164f-4b21-4847-98f9-cf6a9f49179e -known_false_positives: unknown -name: AWS Detect Users creating keys with encrypt policy without MFA -references: -- https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/ -- https://github.com/d1vious/git-wild-hunt -- https://www.youtube.com/watch?v=PgzNib37g0M search: '`cloudtrail` eventName=CreateKey OR eventName=PutKeyPolicy | spath input=requestParameters.policy output=key_policy_statements path=Statement{} | mvexpand key_policy_statements | spath input=key_policy_statements output=key_policy_action_1 path=Action | spath @@ -23,6 +18,13 @@ search: '`cloudtrail` eventName=CreateKey OR eventName=PutKeyPolicy | spath inpu | stats count min(_time) as firstTime max(_time) as lastTime by eventName eventSource eventID awsRegion userIdentity.principalId | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` |`aws_detect_users_creating_keys_with_encrypt_policy_without_mfa_filter`' +how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This + search works with AWS CloudTrail logs +known_false_positives: unknown +references: +- https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/ +- https://github.com/d1vious/git-wild-hunt +- https://www.youtube.com/watch?v=PgzNib37g0M tags: analytic_story: - Ransomware Cloud @@ -59,5 +61,3 @@ tags: - eventSource risk_score: 25 security_domain: threat -type: TTP -version: 1 diff --git a/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml b/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml index 6a71bdd854..20ec2a78f6 100644 --- a/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml +++ b/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml @@ -1,23 +1,25 @@ -author: Rod Soto, Patrick Bareiss Splunk -datamodel: [] +name: AWS Detect Users with KMS keys performing encryption S3 +id: 884a5f59-eec7-4f4a-948b-dbde18225fdc +version: 1 date: '2021-01-11' +author: Rod Soto, Patrick Bareiss Splunk +type: Anomaly +datamodel: [] description: This search provides detection of users with KMS keys performing encryption specifically against S3 buckets. -how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This - search works with AWS CloudTrail logs -id: 884a5f59-eec7-4f4a-948b-dbde18225fdc -known_false_positives: bucket with S3 encryption -name: AWS Detect Users with KMS keys performing encryption S3 -references: -- https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/ -- https://github.com/d1vious/git-wild-hunt -- https://www.youtube.com/watch?v=PgzNib37g0M search: '`cloudtrail` eventName=CopyObject requestParameters.x-amz-server-side-encryption="aws:kms" | rename requestParameters.bucketName AS bucket_name, requestParameters.x-amz-copy-source AS src_file, requestParameters.key AS dest_file | stats count min(_time) as firstTime max(_time) as lastTime values(src_file) AS src_file values(dest_file) AS dest_file values(userAgent) AS userAgent values(region) AS region values(src) AS src by user | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` |`aws_detect_users_with_kms_keys_performing_encryption_s3_filter`' +how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This + search works with AWS CloudTrail logs +known_false_positives: bucket with S3 encryption +references: +- https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/ +- https://github.com/d1vious/git-wild-hunt +- https://www.youtube.com/watch?v=PgzNib37g0M tags: analytic_story: - Ransomware Cloud @@ -57,5 +59,3 @@ tags: - userAgent risk_score: 15 security_domain: threat -type: Anomaly -version: 1 diff --git a/detections/cloud/aws_ecr_container_scanning_findings_high.yml b/detections/cloud/aws_ecr_container_scanning_findings_high.yml index dcdf5187a3..8f8f19729b 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_high.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_high.yml @@ -1,16 +1,13 @@ -author: Patrick Bareiss, Splunk -datamodel: [] +name: AWS ECR Container Scanning Findings High +id: 62721bd2-1d82-4623-b6e6-aac170014423 +version: 1 date: '2021-08-17' +author: Patrick Bareiss, Splunk +type: TTP +datamodel: [] description: This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings with the results. -how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This - search works with AWS CloudTrail logs. -id: 62721bd2-1d82-4623-b6e6-aac170014423 -known_false_positives: unknown -name: AWS ECR Container Scanning Findings High -references: -- https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings | spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand findings | spath input=findings| search severity=HIGH | rename name as finding_name, @@ -20,6 +17,11 @@ search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanF as lastTime by awsRegion, eventName, eventSource, imageDigest, image, user, userName, src_ip, finding, phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_high_filter`' +how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This + search works with AWS CloudTrail logs. +known_false_positives: unknown +references: +- https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html tags: analytic_story: - Dev Sec Ops @@ -59,5 +61,3 @@ tags: - userName risk_score: 70 security_domain: network -type: TTP -version: 1 diff --git a/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml b/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml index 44cea87c54..968236e569 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml @@ -1,16 +1,13 @@ -author: Patrick Bareiss, Splunk -datamodel: [] +name: AWS ECR Container Scanning Findings Low Informational Unknown +id: cbc95e44-7c22-443f-88fd-0424478f5589 +version: 1 date: '2021-08-17' +author: Patrick Bareiss, Splunk +type: Hunting +datamodel: [] description: This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings with the results. -how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This - search works with AWS CloudTrail logs. -id: cbc95e44-7c22-443f-88fd-0424478f5589 -known_false_positives: unknown -name: AWS ECR Container Scanning Findings Low Informational Unknown -references: -- https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings | spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand findings | spath input=findings| search severity IN (LOW, INFORMATIONAL, UNKNWON) @@ -21,6 +18,11 @@ search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanF eventSource, imageDigest, repositoryName, user, userName, src_ip, finding, phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_low_informational_unknown_filter`' +how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This + search works with AWS CloudTrail logs. +known_false_positives: unknown +references: +- https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html tags: analytic_story: - Dev Sec Ops @@ -58,5 +60,3 @@ tags: - userName risk_score: 7 security_domain: network -type: Hunting -version: 1 diff --git a/detections/cloud/aws_ecr_container_scanning_findings_medium.yml b/detections/cloud/aws_ecr_container_scanning_findings_medium.yml index ebd61ff82f..7fd6fe93cb 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_medium.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_medium.yml @@ -1,16 +1,13 @@ -author: Patrick Bareiss, Splunk -datamodel: [] +name: AWS ECR Container Scanning Findings Medium +id: 0b80e2c8-c746-4ddb-89eb-9efd892220cf +version: 1 date: '2021-08-17' +author: Patrick Bareiss, Splunk +type: Anomaly +datamodel: [] description: This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings with the results. -how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This - search works with AWS CloudTrail logs. -id: 0b80e2c8-c746-4ddb-89eb-9efd892220cf -known_false_positives: unknown -name: AWS ECR Container Scanning Findings Medium -references: -- https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings | spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand findings | spath input=findings| search severity=MEDIUM | rename name as finding_name, @@ -20,6 +17,11 @@ search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanF max(_time) as lastTime by awsRegion, eventName, eventSource, imageDigest, image, user, userName, src_ip, finding, phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_medium_filter`' +how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This + search works with AWS CloudTrail logs. +known_false_positives: unknown +references: +- https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html tags: analytic_story: - Dev Sec Ops @@ -57,5 +59,3 @@ tags: - userName risk_score: 21 security_domain: network -type: Anomaly -version: 1 diff --git a/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml b/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml index 40ff14d272..9dc3b9764a 100644 --- a/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml +++ b/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml @@ -1,23 +1,25 @@ -author: Patrick Bareiss, Splunk -datamodel: [] +name: AWS ECR Container Upload Outside Business Hours +id: d4c4d4eb-3994-41ca-a25e-a82d64e125bb +version: 1 date: '2021-08-19' +author: Patrick Bareiss, Splunk +type: Anomaly +datamodel: [] description: This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). A upload of a new container is normally done during business hours. When done outside business hours, we want to take a look into it. -how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This - search works with AWS CloudTrail logs. -id: d4c4d4eb-3994-41ca-a25e-a82d64e125bb -known_false_positives: When your development is spreaded in different time zones, - applying this rule can be difficult. -name: AWS ECR Container Upload Outside Business Hours -references: -- https://attack.mitre.org/techniques/T1204/003/ search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=PutImage date_hour>=20 OR date_hour<8 NOT (date_wday=saturday OR date_wday=sunday) | rename requestParameters.* as * | rename repositoryName AS image | eval phase="release" | eval severity="medium" | stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, user, userName, src_ip, imageTag, registryId, image, phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_upload_outside_business_hours_filter`' +how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This + search works with AWS CloudTrail logs. +known_false_positives: When your development is spreaded in different time zones, + applying this rule can be difficult. +references: +- https://attack.mitre.org/techniques/T1204/003/ tags: analytic_story: - Dev Sec Ops @@ -59,5 +61,3 @@ tags: - userName risk_score: 49 security_domain: network -type: Anomaly -version: 1 diff --git a/detections/cloud/aws_ecr_container_upload_unknown_user.yml b/detections/cloud/aws_ecr_container_upload_unknown_user.yml index 44e2a77738..f9761a5145 100644 --- a/detections/cloud/aws_ecr_container_upload_unknown_user.yml +++ b/detections/cloud/aws_ecr_container_upload_unknown_user.yml @@ -1,23 +1,25 @@ -author: Patrick Bareiss, Splunk -datamodel: [] +name: AWS ECR Container Upload Unknown User +id: 300688e4-365c-4486-a065-7c884462b31d +version: 1 date: '2021-08-19' +author: Patrick Bareiss, Splunk +type: Anomaly +datamodel: [] description: This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). A upload of a new container is normally done from only a few known users. When the user was never seen before, we should have a closer look into the event. -how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This - search works with AWS CloudTrail logs. -id: 300688e4-365c-4486-a065-7c884462b31d -known_false_positives: unknown -name: AWS ECR Container Upload Unknown User -references: -- https://attack.mitre.org/techniques/T1204/003/ search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=PutImage NOT `aws_ecr_users` | rename requestParameters.* as * | rename repositoryName AS image | eval phase="release" | eval severity="high" | stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, user, userName, src_ip, imageTag, registryId, image, phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_upload_unknown_user_filter`' +how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This + search works with AWS CloudTrail logs. +known_false_positives: unknown +references: +- https://attack.mitre.org/techniques/T1204/003/ tags: analytic_story: - Dev Sec Ops @@ -59,5 +61,3 @@ tags: - userName risk_score: 49 security_domain: network -type: Anomaly -version: 1 diff --git a/detections/cloud/aws_excessive_security_scanning.yml b/detections/cloud/aws_excessive_security_scanning.yml index 06513b56b2..97cd12e6fc 100644 --- a/detections/cloud/aws_excessive_security_scanning.yml +++ b/detections/cloud/aws_excessive_security_scanning.yml @@ -1,21 +1,23 @@ -author: Patrick Bareiss, Splunk -datamodel: [] +name: AWS Excessive Security Scanning +id: 1fdd164a-def8-4762-83a9-9ffe24e74d5a +version: 1 date: '2021-04-13' +author: Patrick Bareiss, Splunk +type: TTP +datamodel: [] description: This search looks for AWS CloudTrail events and analyse the amount of eventNames which starts with Describe by a single user. This indicates that this user scans the configuration of your AWS cloud environment. -how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This - search works with AWS CloudTrail logs. -id: 1fdd164a-def8-4762-83a9-9ffe24e74d5a -known_false_positives: While this search has no known false positives. -name: AWS Excessive Security Scanning -references: -- https://github.com/aquasecurity/cloudsploit search: '`cloudtrail` eventName=Describe* OR eventName=List* OR eventName=Get* | stats dc(eventName) as dc_events min(_time) as firstTime max(_time) as lastTime values(eventName) as eventName values(src) as src values(userAgent) as userAgent by user userIdentity.arn | where dc_events > 50 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`aws_excessive_security_scanning_filter`' +how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This + search works with AWS CloudTrail logs. +known_false_positives: While this search has no known false positives. +references: +- https://github.com/aquasecurity/cloudsploit tags: analytic_story: - AWS User Monitoring @@ -66,5 +68,3 @@ tags: risk_object_type: system risk_score: 18 security_domain: network -type: TTP -version: 1 diff --git a/detections/cloud/aws_iam_accessdenied_discovery_events.yml b/detections/cloud/aws_iam_accessdenied_discovery_events.yml index 21803db498..83affe8abb 100644 --- a/detections/cloud/aws_iam_accessdenied_discovery_events.yml +++ b/detections/cloud/aws_iam_accessdenied_discovery_events.yml @@ -1,24 +1,26 @@ -author: Michael Haag, Splunk -datamodel: [] +name: AWS IAM AccessDenied Discovery Events +id: 3e1f1568-9633-11eb-a69c-acde48001122 +version: 2 date: '2021-11-12' +author: Michael Haag, Splunk +type: Anomaly +datamodel: [] description: The following detection identifies excessive AccessDenied events within an hour timeframe. It is possible that an access key to AWS may have been stolen and is being misused to perform discovery events. In these instances, the access is not available with the key stolen therefore these events will be generated. -how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize - this data. The search requires AWS Cloudtrail logs. -id: 3e1f1568-9633-11eb-a69c-acde48001122 -known_false_positives: It is possible to start this detection will need to be tuned - by source IP or user. In addition, change the count values to an upper threshold - to restrict false positives. -name: AWS IAM AccessDenied Discovery Events -references: -- https://aws.amazon.com/premiumsupport/knowledge-center/troubleshoot-iam-permission-errors/ search: '`cloudtrail` (errorCode = "AccessDenied") user_type=IAMUser (userAgent!=*.amazonaws.com) | bucket _time span=1h | stats count as failures min(_time) as firstTime max(_time) as lastTime, dc(eventName) as methods, dc(eventSource) as sources by src_ip, userIdentity.arn, _time | where failures >= 5 and methods >= 1 and sources >= 1 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_accessdenied_discovery_events_filter`' +how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize + this data. The search requires AWS Cloudtrail logs. +known_false_positives: It is possible to start this detection will need to be tuned + by source IP or user. In addition, change the count values to an upper threshold + to restrict false positives. +references: +- https://aws.amazon.com/premiumsupport/knowledge-center/troubleshoot-iam-permission-errors/ tags: analytic_story: - Suspicious Cloud User Activities @@ -62,5 +64,3 @@ tags: risk_object_type: system risk_score: 10 security_domain: access -type: Anomaly -version: 2 diff --git a/detections/cloud/aws_iam_assume_role_policy_brute_force.yml b/detections/cloud/aws_iam_assume_role_policy_brute_force.yml index 69d5f6ed49..b5ea965bb8 100644 --- a/detections/cloud/aws_iam_assume_role_policy_brute_force.yml +++ b/detections/cloud/aws_iam_assume_role_policy_brute_force.yml @@ -1,30 +1,32 @@ -author: Michael Haag, Splunk -datamodel: [] +name: AWS IAM Assume Role Policy Brute Force +id: f19e09b0-9308-11eb-b7ec-acde48001122 +version: 1 date: '2021-04-01' +author: Michael Haag, Splunk +type: TTP +datamodel: [] description: The following detection identifies any malformed policy document exceptions with a status of `failure`. A malformed policy document exception occurs in instances where roles are attempted to be assumed, or brute forced. In a brute force attempt, using a tool like CloudSploit or Pacu, an attempt will look like `arn:aws:iam::111111111111:role/aws-service-role/rds.amazonaws.com/AWSServiceRoleForRDS`. Meaning, when an adversary is attempting to identify a role name, multiple failures will occur. This detection focuses on the errors of a remote attempt that is failing. -how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize - this data. The search requires AWS Cloudtrail logs. Set the `where count` greater - than a value to identify suspicious activity in your environment. -id: f19e09b0-9308-11eb-b7ec-acde48001122 -known_false_positives: This detection will require tuning to provide high fidelity - detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) - or by groups of users. -name: AWS IAM Assume Role Policy Brute Force -references: -- https://www.praetorian.com/blog/aws-iam-assume-role-vulnerabilities -- https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/ -- https://www.elastic.co/guide/en/security/current/aws-iam-brute-force-of-assume-role-policy.html search: '`cloudtrail` (errorCode=MalformedPolicyDocumentException) status=failure (userAgent!=*.amazonaws.com) | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyName) as policy_name by src eventName eventSource aws_account_id errorCode requestParameters.policyDocument userAgent eventID awsRegion userIdentity.principalId user_arn | where count >= 2 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_assume_role_policy_brute_force_filter`' +how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize + this data. The search requires AWS Cloudtrail logs. Set the `where count` greater + than a value to identify suspicious activity in your environment. +known_false_positives: This detection will require tuning to provide high fidelity + detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) + or by groups of users. +references: +- https://www.praetorian.com/blog/aws-iam-assume-role-vulnerabilities +- https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/ +- https://www.elastic.co/guide/en/security/current/aws-iam-brute-force-of-assume-role-policy.html tags: analytic_story: - AWS IAM Privilege Escalation @@ -66,5 +68,3 @@ tags: - userAgent risk_score: 28 security_domain: access -type: TTP -version: 1 diff --git a/detections/cloud/aws_iam_delete_policy.yml b/detections/cloud/aws_iam_delete_policy.yml index 29a170718a..412177827f 100644 --- a/detections/cloud/aws_iam_delete_policy.yml +++ b/detections/cloud/aws_iam_delete_policy.yml @@ -1,28 +1,30 @@ -author: Michael Haag, Splunk -datamodel: [] +name: AWS IAM Delete Policy +id: ec3a9362-92fe-11eb-99d0-acde48001122 +version: 1 date: '2021-04-01' +author: Michael Haag, Splunk +type: Hunting +datamodel: [] description: The following detection identifes when a policy is deleted on AWS. This does not identify whether successful or failed, but the error messages tell a story of suspicious attempts. There is a specific process to follow when deleting a policy. First, detach the policy from all users, groups, and roles that the policy is attached to, using DetachUserPolicy , DetachGroupPolicy , or DetachRolePolicy. -how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize - this data. The search requires AWS Cloudtrail logs. -id: ec3a9362-92fe-11eb-99d0-acde48001122 -known_false_positives: This detection will require tuning to provide high fidelity - detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) - or by groups of users. Not every user with AWS access should have permission to - delete policies (least privilege). In addition, this may be saved seperately and - tuned for failed or success attempts only. -name: AWS IAM Delete Policy -references: -- https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeletePolicy.html -- https://docs.aws.amazon.com/cli/latest/reference/iam/delete-policy.html search: '`cloudtrail` eventName=DeletePolicy (userAgent!=*.amazonaws.com) | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyArn) as policyArn by src eventName eventSource aws_account_id errorCode errorMessage userAgent eventID awsRegion userIdentity.principalId userIdentity.arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_delete_policy_filter`' +how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize + this data. The search requires AWS Cloudtrail logs. +known_false_positives: This detection will require tuning to provide high fidelity + detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) + or by groups of users. Not every user with AWS access should have permission to + delete policies (least privilege). In addition, this may be saved seperately and + tuned for failed or success attempts only. +references: +- https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeletePolicy.html +- https://docs.aws.amazon.com/cli/latest/reference/iam/delete-policy.html tags: analytic_story: - AWS IAM Privilege Escalation @@ -63,5 +65,3 @@ tags: - userAgent risk_score: 10 security_domain: access -type: Hunting -version: 1 diff --git a/detections/cloud/aws_iam_failure_group_deletion.yml b/detections/cloud/aws_iam_failure_group_deletion.yml index b2ecef992b..4936c0ee68 100644 --- a/detections/cloud/aws_iam_failure_group_deletion.yml +++ b/detections/cloud/aws_iam_failure_group_deletion.yml @@ -1,28 +1,30 @@ -author: Michael Haag, Splunk -datamodel: [] +name: AWS IAM Failure Group Deletion +id: 723b861a-92eb-11eb-93b8-acde48001122 +version: 1 date: '2021-04-01' +author: Michael Haag, Splunk +type: Anomaly +datamodel: [] description: This detection identifies failure attempts to delete groups. We want to identify when a group is attempting to be deleted, but either access is denied, there is a conflict or there is no group. This is indicative of administrators performing an action, but also could be suspicious behavior occurring. Review parallel IAM events - recently added users, new groups and so forth. -how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize - this data. The search requires AWS Cloudtrail logs. -id: 723b861a-92eb-11eb-93b8-acde48001122 -known_false_positives: This detection will require tuning to provide high fidelity - detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) - or by groups of users. Not every user with AWS access should have permission to - delete groups (least privilege). -name: AWS IAM Failure Group Deletion -references: -- https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html -- https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html search: '`cloudtrail` eventSource=iam.amazonaws.com eventName=DeleteGroup errorCode IN (NoSuchEntityException,DeleteConflictException, AccessDenied) (userAgent!=*.amazonaws.com) | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.groupName) as group_name by src eventName eventSource aws_account_id errorCode errorMessage userAgent eventID awsRegion userIdentity.principalId user_arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_failure_group_deletion_filter`' +how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize + this data. The search requires AWS Cloudtrail logs. +known_false_positives: This detection will require tuning to provide high fidelity + detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) + or by groups of users. Not every user with AWS access should have permission to + delete groups (least privilege). +references: +- https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html +- https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html tags: analytic_story: - AWS IAM Privilege Escalation @@ -66,5 +68,3 @@ tags: - userAgent risk_score: 5 security_domain: cloud -type: Anomaly -version: 1 diff --git a/detections/cloud/aws_iam_successful_group_deletion.yml b/detections/cloud/aws_iam_successful_group_deletion.yml index 7316610ce9..ec9f71e9f1 100644 --- a/detections/cloud/aws_iam_successful_group_deletion.yml +++ b/detections/cloud/aws_iam_successful_group_deletion.yml @@ -1,26 +1,28 @@ -author: Michael Haag, Splunk -datamodel: [] +name: AWS IAM Successful Group Deletion +id: e776d06c-9267-11eb-819b-acde48001122 +version: 1 date: '2021-03-31' +author: Michael Haag, Splunk +type: Hunting +datamodel: [] description: The following query uses IAM events to track the success of a group being deleted on AWS. This is typically not indicative of malicious behavior, but a precurser to additional events thay may unfold. Review parallel IAM events - recently added users, new groups and so forth. Inversely, review failed attempts in a similar manner. -how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize - this data. The search requires AWS Cloudtrail logs. -id: e776d06c-9267-11eb-819b-acde48001122 -known_false_positives: This detection will require tuning to provide high fidelity - detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) - or by groups of users. Not every user with AWS access should have permission to - delete groups (least privilege). -name: AWS IAM Successful Group Deletion -references: -- https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html -- https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html search: '`cloudtrail` eventSource=iam.amazonaws.com eventName=DeleteGroup errorCode=success (userAgent!=*.amazonaws.com) | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.groupName) as group_deleted by src eventName eventSource errorCode user_agent awsRegion userIdentity.principalId user_arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_iam_successful_group_deletion_filter`' +how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize + this data. The search requires AWS Cloudtrail logs. +known_false_positives: This detection will require tuning to provide high fidelity + detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) + or by groups of users. Not every user with AWS access should have permission to + delete groups (least privilege). +references: +- https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html +- https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html tags: analytic_story: - AWS IAM Privilege Escalation @@ -66,5 +68,3 @@ tags: - userAgent risk_score: 5 security_domain: cloud -type: Hunting -version: 1 diff --git a/detections/cloud/aws_investigate_security_hub_alerts_by_dest.yml b/detections/cloud/aws_investigate_security_hub_alerts_by_dest.yml index 4578d20f76..31334f6b3d 100644 --- a/detections/cloud/aws_investigate_security_hub_alerts_by_dest.yml +++ b/detections/cloud/aws_investigate_security_hub_alerts_by_dest.yml @@ -1,20 +1,22 @@ -author: Bhavin Patel, Splunk -datamodel: [] +name: AWS Investigate Security Hub alerts by dest +id: b0d2e6a8-75fa-4b1b-9486-3d32acadf822 +version: 1 date: '2020-06-08' +author: Bhavin Patel, Splunk +type: Investigation +datamodel: [] description: This search retrieves the all the alerts created by AWS Security Hub for a specific dest(instance_id). -how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) - and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail - inputs. -id: b0d2e6a8-75fa-4b1b-9486-3d32acadf822 -known_false_positives: '' -name: AWS Investigate Security Hub alerts by dest -references: [] search: '`aws_securityhub_firehose` "findings{}.Resources{}.Type"=AWSEC2Instance | rex field=findings{}.Resources{}.Id .*instance/(?.*)| rename instance as dest| search dest = $dest$ |rename findings{}.* as * | rename Remediation.Recommendation.Text as Remediation | table dest Title ProductArn Description FirstObservedAt RecordState Remediation' +how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) + and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail + inputs. +known_false_positives: '' +references: [] tags: analytic_story: - Cloud Compute Instance @@ -32,5 +34,3 @@ tags: - Title - instance security_domain: network -type: Investigation -version: 1 diff --git a/detections/cloud/aws_investigate_user_activities_by_accesskeyid.yml b/detections/cloud/aws_investigate_user_activities_by_accesskeyid.yml index ba3e0fdb68..d8c67a3fc2 100644 --- a/detections/cloud/aws_investigate_user_activities_by_accesskeyid.yml +++ b/detections/cloud/aws_investigate_user_activities_by_accesskeyid.yml @@ -1,18 +1,20 @@ -author: David Dorsey, Splunk -datamodel: [] +name: AWS Investigate User Activities By AccessKeyId +id: 703b65a4-a0ae-4171-965d-45507506c64f +version: 1 date: '2018-06-08' +author: David Dorsey, Splunk +type: Investigation +datamodel: [] description: This search retrieves the times, ARN, source IPs, AWS regions, event names, and the result of the event for specific credentials. -how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) - and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail - inputs. -id: 703b65a4-a0ae-4171-965d-45507506c64f -known_false_positives: '' -name: AWS Investigate User Activities By AccessKeyId -references: [] search: '`cloudtrail` | rename userIdentity.accessKeyId as accessKeyId| search accessKeyId=$accessKeyId$ | spath output=user path=userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, awsRegion, eventName, errorCode, errorMessage' +how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) + and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail + inputs. +known_false_positives: '' +references: [] tags: analytic_story: - AWS Cross Account Activity @@ -28,5 +30,3 @@ tags: - eventName - sourceIPAddress security_domain: network -type: Investigation -version: 1 diff --git a/detections/cloud/aws_investigate_user_activities_by_arn.yml b/detections/cloud/aws_investigate_user_activities_by_arn.yml index e22de9bf63..898716b64b 100644 --- a/detections/cloud/aws_investigate_user_activities_by_arn.yml +++ b/detections/cloud/aws_investigate_user_activities_by_arn.yml @@ -1,19 +1,21 @@ -author: Bhavin Patel, Splunk -datamodel: [] +name: AWS Investigate User Activities By ARN +id: bc91a8cd-35e7-4bb2-6140-e756cc46fd72 +version: 2 date: '2019-04-30' +author: Bhavin Patel, Splunk +type: Investigation +datamodel: [] description: This search lists all the logged CloudTrail activities by a specific user ARN and will create a table containing the source of the user, the region of the activity, the name and type of the event, the action taken, and all the user's identity information. +search: '`cloudtrail` | search user=$user$| table _time userIdentity.type userIdentity.userName + userIdentity.arn aws_account_id src awsRegion eventName eventType' how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. -id: bc91a8cd-35e7-4bb2-6140-e756cc46fd72 known_false_positives: '' -name: AWS Investigate User Activities By ARN references: [] -search: '`cloudtrail` | search user=$user$| table _time userIdentity.type userIdentity.userName - userIdentity.arn aws_account_id src awsRegion eventName eventType' tags: analytic_story: - AWS Cryptomining @@ -41,5 +43,3 @@ tags: - src - user security_domain: network -type: Investigation -version: 2 diff --git a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml index e0572a02a2..ca3f143997 100644 --- a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml +++ b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml @@ -1,17 +1,12 @@ -author: Bhavin Patel, Patrick Bareiss, Splunk -datamodel: [] +name: AWS Network Access Control List Created with All Open Ports +id: ada0f478-84a8-4641-a3f1-d82362d6bd75 +version: 2 date: '2021-01-11' +author: Bhavin Patel, Patrick Bareiss, Splunk +type: TTP +datamodel: [] description: The search looks for AWS CloudTrail events to detect if any network ACLs were created with all the ports open to a specified CIDR. -how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) - and Splunk Add-on for AWS, version 4.4.0 or later, and configure your AWS CloudTrail - inputs. -id: ada0f478-84a8-4641-a3f1-d82362d6bd75 -known_false_positives: It's possible that an admin has created this ACL with all ports - open for some legitimate purpose however, this should be scoped and not allowed - in production environment. -name: AWS Network Access Control List Created with All Open Ports -references: [] search: '`cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetworkAclEntry requestParameters.ruleAction=allow requestParameters.egress=false requestParameters.aclProtocol=-1 | append [search `cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetworkAclEntry @@ -22,6 +17,13 @@ search: '`cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetwor requestParameters.egress requestParameters.aclProtocol requestParameters.portRange.to requestParameters.portRange.from src userAgent requestParameters.cidrBlock | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `aws_network_access_control_list_created_with_all_open_ports_filter`' +how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) + and Splunk Add-on for AWS, version 4.4.0 or later, and configure your AWS CloudTrail + inputs. +known_false_positives: It's possible that an admin has created this ACL with all ports + open for some legitimate purpose however, this should be scoped and not allowed + in production environment. +references: [] tags: analytic_story: - AWS Network ACL Activity @@ -73,5 +75,3 @@ tags: - userName risk_score: 48 security_domain: network -type: TTP -version: 2 diff --git a/detections/cloud/aws_network_access_control_list_deleted.yml b/detections/cloud/aws_network_access_control_list_deleted.yml index 9eee751050..bb06b96bb5 100644 --- a/detections/cloud/aws_network_access_control_list_deleted.yml +++ b/detections/cloud/aws_network_access_control_list_deleted.yml @@ -1,23 +1,25 @@ -author: Bhavin Patel, Patrick Bareiss, Splunk -datamodel: [] +name: AWS Network Access Control List Deleted +id: ada0f478-84a8-4641-a3f1-d82362d6fd75 +version: 2 date: '2021-01-12' +author: Bhavin Patel, Patrick Bareiss, Splunk +type: Anomaly +datamodel: [] description: Enforcing network-access controls is one of the defensive mechanisms used by cloud administrators to restrict access to a cloud instance. After the attacker has gained control of the AWS console by compromising an admin account, they can delete a network ACL and gain access to the instance from anywhere. This search will query the AWS CloudTrail logs to detect users deleting network ACLs. -how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) - and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail - inputs. -id: ada0f478-84a8-4641-a3f1-d82362d6fd75 -known_false_positives: It's possible that a user has legitimately deleted a network - ACL. -name: AWS Network Access Control List Deleted -references: [] search: '`cloudtrail` eventName=DeleteNetworkAclEntry requestParameters.egress=false | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by userName userIdentity.principalId eventName requestParameters.egress src userAgent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `aws_network_access_control_list_deleted_filter`' +how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later) + and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail + inputs. +known_false_positives: It's possible that a user has legitimately deleted a network + ACL. +references: [] tags: analytic_story: - AWS Network ACL Activity @@ -65,5 +67,3 @@ tags: - userName risk_score: 5 security_domain: network -type: Anomaly -version: 2 diff --git a/detections/cloud/aws_network_acl_details_from_id.yml b/detections/cloud/aws_network_acl_details_from_id.yml index c56f48fc4a..e5a5950271 100644 --- a/detections/cloud/aws_network_acl_details_from_id.yml +++ b/detections/cloud/aws_network_acl_details_from_id.yml @@ -1,17 +1,19 @@ -author: Bhavin Patel, Splunk -datamodel: [] +name: AWS Network ACL Details from ID +id: f3fb4d1b-5f33-4b01-b541-c7ah9534c242 +version: 1 date: '2017-01-22' +author: Bhavin Patel, Splunk +type: Investigation +datamodel: [] description: This search queries AWS description logs and returns all the information about a specific network ACL via network ACL ID +search: '`aws_description` | rename id as networkAclId | search networkAclId=$networkAclId$ + | table id account_id vpc_id network_acl_entries{}.*' how_to_implement: In order to implement this search, you must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS(version 4.4.0 or later) and configure your AWS description inputs. -id: f3fb4d1b-5f33-4b01-b541-c7ah9534c242 known_false_positives: '' -name: AWS Network ACL Details from ID references: [] -search: '`aws_description` | rename id as networkAclId | search networkAclId=$networkAclId$ - | table id account_id vpc_id network_acl_entries{}.*' tags: analytic_story: - AWS Network ACL Activity @@ -25,5 +27,3 @@ tags: - id - vpc_id security_domain: network -type: Investigation -version: 1 diff --git a/detections/cloud/aws_network_interface_details_via_resourceid.yml b/detections/cloud/aws_network_interface_details_via_resourceid.yml index e539505c40..24260be301 100644 --- a/detections/cloud/aws_network_interface_details_via_resourceid.yml +++ b/detections/cloud/aws_network_interface_details_via_resourceid.yml @@ -1,20 +1,22 @@ -author: Bhavin Patel, Splunk -datamodel: [] +name: AWS Network Interface details via resourceId +id: f3fb4d1c-5f33-4b01-b541-c3ah9534c241 +version: 1 date: '2018-05-07' +author: Bhavin Patel, Splunk +type: Investigation +datamodel: [] description: This search queries AWS configuration logs and returns the information about a specific network interface via network interface ID. The information will include the ARN of the network interface, its relationships with other AWS resources, the public and the private IP associated with the network interface. -how_to_implement: In order to implement this search, you must install the AWS App - for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS(version 4.4.0 or later) - and configure your AWS configuration inputs -id: f3fb4d1c-5f33-4b01-b541-c3ah9534c241 -known_false_positives: '' -name: AWS Network Interface details via resourceId -references: [] search: '`aws_config` resourceId=$resourceId$ | table _time ARN relationships{}.resourceType relationships{}.name relationships{}.resourceId configuration.privateIpAddresses{}.privateIpAddress configuration.privateIpAddresses{}.association.publicIp' +how_to_implement: In order to implement this search, you must install the AWS App + for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS(version 4.4.0 or later) + and configure your AWS configuration inputs +known_false_positives: '' +references: [] tags: analytic_story: - AWS Network ACL Activity @@ -28,5 +30,3 @@ tags: - _time - resourceId security_domain: network -type: Investigation -version: 1 diff --git a/detections/cloud/aws_s3_bucket_details_via_bucketname.yml b/detections/cloud/aws_s3_bucket_details_via_bucketname.yml index e7103ce987..d0a530604b 100644 --- a/detections/cloud/aws_s3_bucket_details_via_bucketname.yml +++ b/detections/cloud/aws_s3_bucket_details_via_bucketname.yml @@ -1,20 +1,22 @@ -author: Bhavin Patel, Splunk -datamodel: [] +name: AWS S3 Bucket details via bucketName +id: f3fb2q1c-5f33-4b01-b541-c2ah9534c242 +version: 1 date: '2018-06-26' +author: Bhavin Patel, Splunk +type: Investigation +datamodel: [] description: This search queries AWS configuration logs and returns the information about a specific S3 bucket. The information returned includes the time the S3 bucket was created, the resource ID, the region it belongs to, the value of action performed, AWS account ID, and configuration values of the access-control lists associated with the bucket. +search: '`aws_config` | rename resourceId as bucketName |search bucketName=$bucketName$ + | table resourceCreationTime bucketName vendor_region action aws_account_id supplementaryConfiguration.AccessControlList' how_to_implement: To implement this search, you must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later) and configure your AWS inputs. -id: f3fb2q1c-5f33-4b01-b541-c2ah9534c242 known_false_positives: '' -name: AWS S3 Bucket details via bucketName references: [] -search: '`aws_config` | rename resourceId as bucketName |search bucketName=$bucketName$ - | table resourceCreationTime bucketName vendor_region action aws_account_id supplementaryConfiguration.AccessControlList' tags: analytic_story: - Suspicious AWS S3 Activities @@ -29,5 +31,3 @@ tags: - resourceId - vendor_region security_domain: network -type: Investigation -version: 1 diff --git a/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml b/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml index 0ea4f43f2d..bd01434348 100644 --- a/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml +++ b/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml @@ -1,30 +1,32 @@ -author: Rod Soto, Splunk -datamodel: [] +name: AWS SAML Access by Provider User and Principal +id: bbe23980-6019-11eb-ae93-0242ac130002 +version: 1 date: '2021-01-26' +author: Rod Soto, Splunk +type: Anomaly +datamodel: [] description: This search provides specific SAML access from specific Service Provider, user and targeted principal at AWS. This search provides specific information to detect abnormal access or potential credential hijack or forgery, specially in federated environments using SAML protocol inside the perimeter or cloud provider. +search: '`cloudtrail` eventName=Assumerolewithsaml | stats count min(_time) as firstTime + max(_time) as lastTime by requestParameters.principalArn requestParameters.roleArn + requestParameters.roleSessionName recipientAccountId responseElements.issuer sourceIPAddress + userAgent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` + |`aws_saml_access_by_provider_user_and_principal_filter`' how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs -id: bbe23980-6019-11eb-ae93-0242ac130002 known_false_positives: Attacks using a Golden SAML or SAML assertion hijacks or forgeries are very difficult to detect as accessing cloud providers with these assertions looks exactly like normal access, however things such as source IP sourceIPAddress user, and principal targeted at receiving cloud provider along with endpoint credential access and abuse detection searches can provide the necessary context to detect these attacks. -name: AWS SAML Access by Provider User and Principal references: - https://us-cert.cisa.gov/ncas/alerts/aa21-008a - https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html - https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf - https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps -search: '`cloudtrail` eventName=Assumerolewithsaml | stats count min(_time) as firstTime - max(_time) as lastTime by requestParameters.principalArn requestParameters.roleArn - requestParameters.roleSessionName recipientAccountId responseElements.issuer sourceIPAddress - userAgent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` - |`aws_saml_access_by_provider_user_and_principal_filter`' tags: analytic_story: - Cloud Federated Credential Abuse @@ -66,5 +68,3 @@ tags: - userAgent risk_score: 64 security_domain: threat -type: Anomaly -version: 1 diff --git a/detections/cloud/aws_saml_update_identity_provider.yml b/detections/cloud/aws_saml_update_identity_provider.yml index 858cceedfe..ef4d5e2425 100644 --- a/detections/cloud/aws_saml_update_identity_provider.yml +++ b/detections/cloud/aws_saml_update_identity_provider.yml @@ -1,26 +1,28 @@ -author: Rod Soto, Splunk -datamodel: [] +name: AWS SAML Update identity provider +id: 2f0604c6-6030-11eb-ae93-0242ac130002 +version: 1 date: '2021-01-26' +author: Rod Soto, Splunk +type: TTP +datamodel: [] description: This search provides detection of updates to SAML provider in AWS. Updates to SAML provider need to be monitored closely as they may indicate possible perimeter compromise of federated credentials, or backdoor access from another cloud provider set by attacker. -how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This - search works with AWS CloudTrail logs. -id: 2f0604c6-6030-11eb-ae93-0242ac130002 -known_false_positives: Updating a SAML provider or creating a new one may not necessarily - be malicious however it needs to be closely monitored. -name: AWS SAML Update identity provider -references: -- https://us-cert.cisa.gov/ncas/alerts/aa21-008a -- https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html -- https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf -- https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps search: '`cloudtrail` eventName=UpdateSAMLProvider | stats count min(_time) as firstTime max(_time) as lastTime by eventType eventName requestParameters.sAMLProviderArn userIdentity.sessionContext.sessionIssuer.arn sourceIPAddress userIdentity.accessKeyId userIdentity.principalId | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` |`aws_saml_update_identity_provider_filter`' +how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This + search works with AWS CloudTrail logs. +known_false_positives: Updating a SAML provider or creating a new one may not necessarily + be malicious however it needs to be closely monitored. +references: +- https://us-cert.cisa.gov/ncas/alerts/aa21-008a +- https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html +- https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf +- https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps tags: analytic_story: - Cloud Federated Credential Abuse @@ -60,5 +62,3 @@ tags: - sourceIPAddress risk_score: 64 security_domain: threat -type: TTP -version: 1 diff --git a/detections/cloud/aws_setdefaultpolicyversion.yml b/detections/cloud/aws_setdefaultpolicyversion.yml index da636d6b05..3e2a48bc9a 100644 --- a/detections/cloud/aws_setdefaultpolicyversion.yml +++ b/detections/cloud/aws_setdefaultpolicyversion.yml @@ -1,26 +1,28 @@ -author: Bhavin Patel, Splunk -datamodel: [] +name: AWS SetDefaultPolicyVersion +id: 2a9b80d3-6340-4345-11ad-212bf3d0dac4 +version: 1 date: '2021-03-02' +author: Bhavin Patel, Splunk +type: TTP +datamodel: [] description: This search looks for AWS CloudTrail events where a user has set a default policy versions. Attackers have been know to use this technique for Privilege Escalation in case the previous versions of the policy had permissions to access more resources than the current version of the policy -how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This - search works with AWS CloudTrail logs. -id: 2a9b80d3-6340-4345-11ad-212bf3d0dac4 -known_false_positives: While this search has no known false positives, it is possible - that an AWS admin has legitimately set a default policy to allow a user to access - all resources. That said, AWS strongly advises against granting full control to - all AWS resources -name: AWS SetDefaultPolicyVersion -references: -- https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws -- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ search: '`cloudtrail` eventName=SetDefaultPolicyVersion eventSource = iam.amazonaws.com | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyArn) as policy_arn by src requestParameters.versionId eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_setdefaultpolicyversion_filter`' +how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This + search works with AWS CloudTrail logs. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has legitimately set a default policy to allow a user to access + all resources. That said, AWS strongly advises against granting full control to + all AWS resources +references: +- https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws +- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ tags: analytic_story: - AWS IAM Privilege Escalation @@ -70,5 +72,3 @@ tags: - userAgent risk_score: 30 security_domain: threat -type: TTP -version: 1 diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml index 2d0e23b07f..a71ca2525e 100644 --- a/detections/cloud/aws_updateloginprofile.yml +++ b/detections/cloud/aws_updateloginprofile.yml @@ -1,24 +1,26 @@ -author: Bhavin Patel, Splunk -datamodel: [] +name: AWS UpdateLoginProfile +id: 2a9b80d3-6a40-4115-11ad-212bf3d0d111 +version: 2 date: '2021-07-19' +author: Bhavin Patel, Splunk +type: TTP +datamodel: [] description: This search looks for AWS CloudTrail events where a user A who has already permission to update login profile, makes an API call to update login profile for another user B . Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) -how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This - search works with AWS CloudTrail logs. -id: 2a9b80d3-6a40-4115-11ad-212bf3d0d111 -known_false_positives: While this search has no known false positives, it is possible - that an AWS admin has legitimately created keys for another user. -name: AWS UpdateLoginProfile -references: -- https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws -- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ search: '`cloudtrail` eventName = UpdateLoginProfile userAgent !=console.amazonaws.com errorCode = success| search userIdentity.userName!=requestParameters.userName | stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.userName user_arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`aws_updateloginprofile_filter`' +how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This + search works with AWS CloudTrail logs. +known_false_positives: While this search has no known false positives, it is possible + that an AWS admin has legitimately created keys for another user. +references: +- https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws +- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ tags: analytic_story: - AWS IAM Privilege Escalation @@ -63,5 +65,3 @@ tags: - userAgent risk_score: 30 security_domain: threat -type: TTP -version: 2 diff --git a/detections/endpoint/account_discovery_with_net_app.yml b/detections/endpoint/account_discovery_with_net_app.yml index a35a4b31bf..71a4f6e08a 100644 --- a/detections/endpoint/account_discovery_with_net_app.yml +++ b/detections/endpoint/account_discovery_with_net_app.yml @@ -1,7 +1,11 @@ +name: Account Discovery With Net App +id: 339805ce-ac30-11eb-b87d-acde48001122 +version: 3 +date: '2021-09-16' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-09-16' description: this search is to detect a potential account discovery series of command used by several malware or attack to recon the target machine. This technique is also seen in some note worthy malware like trickbot where it runs a cmd process, @@ -9,18 +13,6 @@ description: this search is to detect a potential account discovery series of co of command are good correlation search and indicator of attacker recon if seen in the machines within a none technical user or department (HR, finance, ceo and etc) network. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product.. -id: 339805ce-ac30-11eb-b87d-acde48001122 -known_false_positives: admin or power user may used this series of command. -name: Account Discovery With Net App -references: -- https://labs.vipre.com/trickbot-and-its-modules/ -- https://blog.whitehat.eu/2019/05/incident-trickbot-ryuk-2.html -- https://app.any.run/tasks/48414a33-3d66-4a46-afe5-c2003bb55ccf/ search: '| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes @@ -28,6 +20,16 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as OR Processes.process="*view /all*") by Processes.process_name Processes.dest Processes.user Processes.parent_process_name | where count >=5 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `account_discovery_with_net_app_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product.. +known_false_positives: admin or power user may used this series of command. +references: +- https://labs.vipre.com/trickbot-and-its-modules/ +- https://blog.whitehat.eu/2019/05/incident-trickbot-ryuk-2.html +- https://app.any.run/tasks/48414a33-3d66-4a46-afe5-c2003bb55ccf/ tags: analytic_story: - Trickbot @@ -74,5 +76,3 @@ tags: - _time risk_score: 5 security_domain: endpoint -type: TTP -version: 3 diff --git a/detections/endpoint/active_setup_registry_autostart.yml b/detections/endpoint/active_setup_registry_autostart.yml index 3465e5a81d..c7aecfb032 100644 --- a/detections/endpoint/active_setup_registry_autostart.yml +++ b/detections/endpoint/active_setup_registry_autostart.yml @@ -1,7 +1,11 @@ +name: Active Setup Registry Autostart +id: f64579c0-203f-11ec-abcc-acde48001122 +version: 1 +date: '2021-09-28' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-09-28' description: This analytic is to detect a suspicious modification of the active setup registry for persistence and privilege escalation. This technique was seen in several malware (poisonIvy), adware and APT to gain persistence to the compromised machine @@ -9,24 +13,22 @@ description: This analytic is to detect a suspicious modification of the active do the modification since modification of this registry is not commonly done. check the legitimacy of the file and process involve in this rules to check if it is a valid setup installer that creating or modifying this registry. -how_to_implement: To successfully implement this search, you must be ingesting data - that records registry activity from your hosts to populate the endpoint data model - in the registry node. This is typically populated via endpoint detection-and-response - product, such as Carbon Black or endpoint data sources, such as Sysmon. The data - used for this search is typically generated via logs that report reads and writes - to the registry. -id: f64579c0-203f-11ec-abcc-acde48001122 -known_false_positives: Active setup installer may add or modify this registry. -name: Active Setup Registry Autostart -references: -- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor%3aWin32%2fPoisonivy.E -- https://attack.mitre.org/techniques/T1547/014/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_value_name = "StubPath" Registry.registry_key_name = "*\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `active_setup_registry_autostart_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: Active setup installer may add or modify this registry. +references: +- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor%3aWin32%2fPoisonivy.E +- https://attack.mitre.org/techniques/T1547/014/ tags: analytic_story: - Windows Persistence Techniques @@ -67,5 +69,3 @@ tags: - _time risk_score: 64 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/add_defaultuser_and_password_in_registry.yml b/detections/endpoint/add_defaultuser_and_password_in_registry.yml index 4a75b458b1..ba36845872 100644 --- a/detections/endpoint/add_defaultuser_and_password_in_registry.yml +++ b/detections/endpoint/add_defaultuser_and_password_in_registry.yml @@ -1,28 +1,30 @@ +name: Add DefaultUser And Password In Registry +id: d4a3eb62-0f1e-11ec-a971-acde48001122 +version: 1 +date: '2021-09-06' author: Teoderick Contreras, Splunk +type: Anomaly datamodel: - Endpoint -date: '2021-09-06' description: this search is to detect a suspicious registry modification to implement auto admin logon to a host. This technique was seen in BlackMatter ransomware to automatically logon to the compromise host after triggering a safemode boot to continue encrypting the whole network. This behavior is not a common practice and really a suspicious TTP or alert need to be consider if found within then network premise. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure - that this registry was included in your config files ex. sysmon config to be monitored. -id: d4a3eb62-0f1e-11ec-a971-acde48001122 -known_false_positives: unknown -name: Add DefaultUser And Password In Registry -references: -- https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*" AND Registry.registry_value_name= DefaultPassword OR Registry.registry_value_name= DefaultUserName by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `add_defaultuser_and_password_in_registry_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure + that this registry was included in your config files ex. sysmon config to be monitored. +known_false_positives: unknown +references: +- https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/ tags: analytic_story: - BlackMatter Ransomware @@ -58,5 +60,3 @@ tags: - _time risk_score: 25 security_domain: endpoint -type: Anomaly -version: 1 diff --git a/detections/endpoint/add_or_set_windows_defender_exclusion.yml b/detections/endpoint/add_or_set_windows_defender_exclusion.yml index 8dd72bf835..8db7eb2ea7 100644 --- a/detections/endpoint/add_or_set_windows_defender_exclusion.yml +++ b/detections/endpoint/add_or_set_windows_defender_exclusion.yml @@ -1,23 +1,17 @@ +name: Add or Set Windows Defender Exclusion +id: 773b66fe-4dd9-11ec-8289-acde48001122 +version: 1 +date: '2021-11-25' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-11-25' description: This analytic will detect a suspicious process commandline related to windows defender exclusion feature. This command is abused by adversaries, malware author and red teams to bypassed Windows Defender Anti-Virus product by excluding folder path, file path, process, extensions and etc. from its real time or schedule scan to execute their malicious code. This is a good indicator for defense evasion and to look further for events after this behavior. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure - that this registry was included in your config files ex. sysmon config to be monitored. -id: 773b66fe-4dd9-11ec-8289-acde48001122 -known_false_positives: admin or user may choose to use this windows features. -name: Add or Set Windows Defender Exclusion -references: -- https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html -- https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process = "*Add-MpPreference *" OR Processes.process = "*Set-MpPreference *") AND Processes.process="*-exclusion*" @@ -25,6 +19,14 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `add_or_set_windows_defender_exclusion_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure + that this registry was included in your config files ex. sysmon config to be monitored. +known_false_positives: admin or user may choose to use this windows features. +references: +- https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html +- https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/ tags: analytic_story: - Remcos @@ -69,5 +71,3 @@ tags: - _time risk_score: 64 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/adsisearcher_account_discovery.yml b/detections/endpoint/adsisearcher_account_discovery.yml index 404862909d..36ff577ea8 100644 --- a/detections/endpoint/adsisearcher_account_discovery.yml +++ b/detections/endpoint/adsisearcher_account_discovery.yml @@ -1,24 +1,26 @@ -author: Teoderick Contreras, Mauricio Velazco, Splunk -datamodel: [] +name: AdsiSearcher Account Discovery +id: de7fcadc-04f3-11ec-a241-acde48001122 +version: 1 date: '2021-08-24' +author: Teoderick Contreras, Mauricio Velazco, Splunk +type: TTP +datamodel: [] description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the `[Adsisearcher]` type accelerator being used to query Active Directory for domain groups. Red Teams and adversaries may leverage `[Adsisearcher]` to enumerate domain users for situational awareness and Active Directory Discovery. -how_to_implement: The following Hunting analytic requires PowerShell operational logs - to be imported. Modify the powershell macro as needed to match the sourcetype or - add index. This analytic is specific to 4104, or PowerShell Script Block Logging. -id: de7fcadc-04f3-11ec-a241-acde48001122 -known_false_positives: Administrators or power users may use this command for troubleshooting. -name: AdsiSearcher Account Discovery -references: -- https://attack.mitre.org/techniques/T1087/002/ -- https://www.blackhillsinfosec.com/red-blue-purple/ -- https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/ search: '`powershell` EventCode=4104 Message = "*[adsisearcher]*" Message = "*objectcategory=user*" Message = "*.findAll()*" | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `adsisearcher_account_discovery_filter`' +how_to_implement: The following Hunting analytic requires PowerShell operational logs + to be imported. Modify the powershell macro as needed to match the sourcetype or + add index. This analytic is specific to 4104, or PowerShell Script Block Logging. +known_false_positives: Administrators or power users may use this command for troubleshooting. +references: +- https://attack.mitre.org/techniques/T1087/002/ +- https://www.blackhillsinfosec.com/red-blue-purple/ +- https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/ tags: analytic_story: - Active Directory Discovery @@ -57,5 +59,3 @@ tags: - User risk_score: 25 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/all_backup_logs_for_host.yml b/detections/endpoint/all_backup_logs_for_host.yml index 2c9ef2e525..bc918e9dc1 100644 --- a/detections/endpoint/all_backup_logs_for_host.yml +++ b/detections/endpoint/all_backup_logs_for_host.yml @@ -1,15 +1,17 @@ -author: Rico Valdez, Splunk -datamodel: [] +name: All backup logs for host +id: bc91a8cf-aaaa-4bb2-8140-e756cc06fd72 +version: 1 date: '2017-09-12' +author: Rico Valdez, Splunk +type: Investigation +datamodel: [] description: Retrieve the backup logs for the last 2 weeks for a specific host in order to investigate why backups are not completing successfully. +search: '| search `netbackup` dest=$dest$' how_to_implement: The successfully implement this search you must first send your backup logs to Splunk. -id: bc91a8cf-aaaa-4bb2-8140-e756cc06fd72 known_false_positives: none -name: All backup logs for host references: [] -search: '| search `netbackup` dest=$dest$' tags: analytic_story: - Monitor Backup Solution @@ -18,5 +20,3 @@ tags: required_fields: - dest security_domain: endpoint -type: Investigation -version: 1 diff --git a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml index fef5cd4280..2dcb4055ad 100644 --- a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml +++ b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml @@ -1,22 +1,14 @@ +name: Allow File And Printing Sharing In Firewall +id: ce27646e-d411-11eb-8a00-acde48001122 +version: 2 +date: '2021-06-23' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-06-23' description: This search is to detect a suspicious modification of firewall to allow file and printer sharing. This technique was seen in ransomware to be able to discover more machine connected to the compromised host to encrypt more files -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: ce27646e-d411-11eb-8a00-acde48001122 -known_false_positives: network admin may modify this firewall feature that may cause - this rule to be triggered. -name: Allow File And Printing Sharing In Firewall -references: -- https://kb.fortinet.com/kb/documentLink.do?externalID=FD52469 -- https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_netsh` Processes.process= "*firewall*" Processes.process= "*group=\"File and Printer Sharing\"*" Processes.process="*enable=Yes*" @@ -24,6 +16,16 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `allow_file_and_printing_sharing_in_firewall_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: network admin may modify this firewall feature that may cause + this rule to be triggered. +references: +- https://kb.fortinet.com/kb/documentLink.do?externalID=FD52469 +- https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ tags: analytic_story: - Ransomware @@ -51,5 +53,3 @@ tags: - Endpoint.Processes.user - _time security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml index 2a4b619d2c..2105cfa163 100644 --- a/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml +++ b/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml @@ -1,21 +1,15 @@ +name: Allow Inbound Traffic By Firewall Rule Registry +id: 0a46537c-be02-11eb-92ca-acde48001122 +version: 1 +date: '2021-05-26' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-05-26' description: This analytic detects a potential suspicious modification of firewall rule registry allowing inbound traffic in specific port with public profile. This technique was identified when an adversary wants to grant remote access to a machine by allowing the traffic in a firewall rule. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure - that this registry was included in your config files ex. sysmon config to be monitored. -id: 0a46537c-be02-11eb-92ca-acde48001122 -known_false_positives: network admin may add/remove/modify public inbound firewall - rule that may cause this rule to be triggered. -name: Allow Inbound Traffic By Firewall Rule Registry -references: -- https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*" Registry.registry_value_name = "*|Action=Allow|*" Registry.registry_value_name = @@ -23,6 +17,14 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime = "*|LPort=*" by Registry.registry_path Registry.registry_key_name Registry.user Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `allow_inbound_traffic_by_firewall_rule_registry_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure + that this registry was included in your config files ex. sysmon config to be monitored. +known_false_positives: network admin may add/remove/modify public inbound firewall + rule that may cause this rule to be triggered. +references: +- https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps tags: analytic_story: - Prohibited Traffic Allowed or Protocol Mismatch @@ -63,5 +65,3 @@ tags: - _time risk_score: 3 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml index 2452068297..81f5d65149 100644 --- a/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml +++ b/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml @@ -1,23 +1,25 @@ -author: Teoderick Contreras, Splunk -datamodel: [] +name: Allow Inbound Traffic In Firewall Rule +id: a5d85486-b89c-11eb-8267-acde48001122 +version: 1 date: '2021-05-19' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: [] description: The following analytic identifies suspicious PowerShell command to allow inbound traffic inbound to a specific local port within the public profile. This technique was seen in some attacker want to have a remote access to a machine by allowing the traffic in firewall rule. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the powershell logs from your endpoints. make sure you enable needed - registry to monitor this event. -id: a5d85486-b89c-11eb-8267-acde48001122 -known_false_positives: administrator may allow inbound traffic in certain network - or machine. -name: Allow Inbound Traffic In Firewall Rule -references: -- https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps search: '`powershell` EventCode=4104 Message = "*firewall*" Message = "*Inbound*" Message = "*Allow*" Message = "*-LocalPort*" | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `allow_inbound_traffic_in_firewall_rule_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the powershell logs from your endpoints. make sure you enable needed + registry to monitor this event. +known_false_positives: administrator may allow inbound traffic in certain network + or machine. +references: +- https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps tags: analytic_story: - Prohibited Traffic Allowed or Protocol Mismatch @@ -57,5 +59,3 @@ tags: - User risk_score: 3 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/allow_network_discovery_in_firewall.yml b/detections/endpoint/allow_network_discovery_in_firewall.yml index 03c6ebe6c8..9ffc43f5f4 100644 --- a/detections/endpoint/allow_network_discovery_in_firewall.yml +++ b/detections/endpoint/allow_network_discovery_in_firewall.yml @@ -1,23 +1,15 @@ +name: Allow Network Discovery In Firewall +id: ccd6a38c-d40b-11eb-85a5-acde48001122 +version: 2 +date: '2021-06-23' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-06-23' description: This search is to detect a suspicious modification to the firewall to allow network discovery on a machine. This technique was seen in couple of ransomware (revil, reddot) to discover other machine connected to the compromised host to encrypt more files. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: ccd6a38c-d40b-11eb-85a5-acde48001122 -known_false_positives: network admin may modify this firewall feature that may cause - this rule to be triggered. -name: Allow Network Discovery In Firewall -references: -- https://kb.fortinet.com/kb/documentLink.do?externalID=FD52469 -- https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_netsh` Processes.process= "*firewall*" Processes.process= "*group=\"Network Discovery\"*" Processes.process="*enable*" @@ -25,6 +17,16 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `allow_network_discovery_in_firewall_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: network admin may modify this firewall feature that may cause + this rule to be triggered. +references: +- https://kb.fortinet.com/kb/documentLink.do?externalID=FD52469 +- https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ tags: analytic_story: - Ransomware @@ -53,5 +55,3 @@ tags: - Endpoint.Processes.user - _time security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/allow_operation_with_consent_admin.yml b/detections/endpoint/allow_operation_with_consent_admin.yml index d243ec2de0..28e6be4061 100644 --- a/detections/endpoint/allow_operation_with_consent_admin.yml +++ b/detections/endpoint/allow_operation_with_consent_admin.yml @@ -1,30 +1,32 @@ +name: Allow Operation with Consent Admin +id: 7de17d7a-c9d8-11eb-a812-acde48001122 +version: 1 +date: '2021-06-10' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-06-10' description: This analytic identifies a potential privilege escalation attempt to perform malicious task. This registry modification is designed to allow the `Consent Admin` to perform an operation that requires elevation without consent or credentials. We also found this in some attacker to gain privilege escalation to the compromise machine. -how_to_implement: To successfully implement this search, you must be ingesting data - that records registry activity from your hosts to populate the endpoint data model - in the registry node. This is typically populated via endpoint detection-and-response - product, such as Carbon Black or endpoint data sources, such as Sysmon. The data - used for this search is typically generated via logs that report reads and writes - to the registry. -id: 7de17d7a-c9d8-11eb-a812-acde48001122 -known_false_positives: unknown -name: Allow Operation with Consent Admin -references: -- https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-gpsb/341747f5-6b5d-4d30-85fc-fa1cc04038d4 -- https://www.trendmicro.com/vinfo/no/threat-encyclopedia/malware/Ransom.Win32.MRDEC.MRA/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\Microsoft\\Windows\\CurrentVersion\\Policies\\System*" Registry.registry_value_name = ConsentPromptBehaviorAdmin Registry.registry_value_data = "0x00000000" by Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `allow_operation_with_consent_admin_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: unknown +references: +- https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-gpsb/341747f5-6b5d-4d30-85fc-fa1cc04038d4 +- https://www.trendmicro.com/vinfo/no/threat-encyclopedia/malware/Ransom.Win32.MRDEC.MRA/ tags: analytic_story: - Ransomware @@ -64,5 +66,3 @@ tags: - _time risk_score: 25 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/anomalous_usage_of_7zip.yml b/detections/endpoint/anomalous_usage_of_7zip.yml index 5c7a448e11..c8b1aea55e 100644 --- a/detections/endpoint/anomalous_usage_of_7zip.yml +++ b/detections/endpoint/anomalous_usage_of_7zip.yml @@ -1,7 +1,11 @@ +name: Anomalous usage of 7zip +id: 9364ee8e-a39a-11eb-8f1d-acde48001122 +version: 1 +date: '2021-04-22' author: Michael Haag, Teoderick Contreras, Splunk +type: Anomaly datamodel: - Endpoint -date: '2021-04-22' description: The following detection identifies a 7z.exe spawned from `Rundll32.exe` or `Dllhost.exe`. It is assumed that the adversary has brought in `7z.exe` and `7z.dll`. It has been observed where an adversary will rename `7z.exe`. Additional coverage @@ -9,23 +13,21 @@ description: The following detection identifies a 7z.exe spawned from `Rundll32. triage, identify the source of injection into `Rundll32.exe` or `Dllhost.exe`. Capture any files written to disk and analyze as needed. Review parallel processes for additional behaviors. Typically, archiving files will result in exfiltration. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. -id: 9364ee8e-a39a-11eb-8f1d-acde48001122 -known_false_positives: False positives should be limited as this behavior is not normal - for `rundll32.exe` or `dllhost.exe` to spawn and run 7zip. -name: Anomalous usage of 7zip -references: -- https://attack.mitre.org/techniques/T1560/001/ -- https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/ -- https://thedfirreport.com/2021/01/31/bazar-no-ryuk/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN ("rundll32.exe", "dllhost.exe") Processes.process_name=*7z* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `anomalous_usage_of_7zip_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +known_false_positives: False positives should be limited as this behavior is not normal + for `rundll32.exe` or `dllhost.exe` to spawn and run 7zip. +references: +- https://attack.mitre.org/techniques/T1560/001/ +- https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/ +- https://thedfirreport.com/2021/01/31/bazar-no-ryuk/ tags: analytic_story: - Cobalt Strike @@ -79,5 +81,3 @@ tags: - _time risk_score: 64 security_domain: endpoint -type: Anomaly -version: 1 diff --git a/detections/endpoint/any_powershell_downloadfile.yml b/detections/endpoint/any_powershell_downloadfile.yml index 1c2b7b7688..d5b78d073c 100644 --- a/detections/endpoint/any_powershell_downloadfile.yml +++ b/detections/endpoint/any_powershell_downloadfile.yml @@ -1,32 +1,34 @@ +name: Any Powershell DownloadFile +id: 1a93b7ea-7af7-11eb-adb5-acde48001122 +version: 2 +date: '2021-03-01' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-03-01' description: The following analytic identifies the use of PowerShell downloading a file using `DownloadFile` method. This particular method is utilized in many different PowerShell frameworks to download files and output to disk. Identify the source (IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell transaction logs are available, review for further details of the implant. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: 1a93b7ea-7af7-11eb-adb5-acde48001122 -known_false_positives: False positives may be present and filtering will need to occur - by parent process or command line argument. It may be required to modify this query - to an EDR product for more granular coverage. -name: Any Powershell DownloadFile -references: -- https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadfile?view=net-5.0 -- https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process=*DownloadFile* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `any_powershell_downloadfile_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: False positives may be present and filtering will need to occur + by parent process or command line argument. It may be required to modify this query + to an EDR product for more granular coverage. +references: +- https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadfile?view=net-5.0 +- https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md tags: analytic_story: - Malicious PowerShell @@ -83,5 +85,3 @@ tags: - _time risk_score: 56 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/endpoint/any_powershell_downloadstring.yml index 69a8f40bd6..ccfbcf87c2 100644 --- a/detections/endpoint/any_powershell_downloadstring.yml +++ b/detections/endpoint/any_powershell_downloadstring.yml @@ -1,31 +1,33 @@ +name: Any Powershell DownloadString +id: 4d015ef2-7adf-11eb-95da-acde48001122 +version: 2 +date: '2021-03-01' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-03-01' description: The following analytic identifies the use of PowerShell downloading a file using `DownloadString` method. This particular method is utilized in many different PowerShell frameworks to download files and output to disk. Identify the source (IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell transaction logs are available, review for further details of the implant. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: 4d015ef2-7adf-11eb-95da-acde48001122 -known_false_positives: False positives may be present and filtering will need to occur - by parent process or command line argument. It may be required to modify this query - to an EDR product for more granular coverage. -name: Any Powershell DownloadString -references: -- https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadstring?view=net-5.0 -- https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_powershell` Processes.process=*.DownloadString* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `any_powershell_downloadstring_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: False positives may be present and filtering will need to occur + by parent process or command line argument. It may be required to modify this query + to an EDR product for more granular coverage. +references: +- https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadstring?view=net-5.0 +- https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md tags: analytic_story: - Malicious PowerShell @@ -77,5 +79,3 @@ tags: - _time risk_score: 56 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 222cd7c973..07eabc9cf3 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -1,20 +1,13 @@ +name: Attacker Tools On Endpoint +id: a51bfe1a-94f0-48cc-b4e4-16a110145893 +version: 2 +date: '2021-11-04' author: Bhavin Patel, Splunk +type: TTP datamodel: - Endpoint -date: '2021-11-04' description: This search looks for execution of commonly used attacker tools on an endpoint. -how_to_implement: To successfully implement this search, you must be ingesting data - that records process activity from your hosts to populate the endpoint data model - in the processes node. This is typically populated via endpoint detection-and-response - product, such as Carbon Black or endpoint data sources, such as Sysmon. The data - used for this search is usually generated via logs that report process tracking - in your Windows audit settings. -id: a51bfe1a-94f0-48cc-b4e4-16a110145893 -known_false_positives: Some administrator activity can be potentially triggered, please - add those users to the filter macro. -name: Attacker Tools On Endpoint -references: [] search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process) as process values(Processes.parent_process) as parent_process from datamodel=Endpoint.Processes where Processes.dest!=unknown @@ -22,6 +15,15 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.process | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name(Processes)` | lookup attacker_tools attacker_tool_names AS process_name OUTPUT description | search description !=false| `attacker_tools_on_endpoint_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records process activity from your hosts to populate the endpoint data model + in the processes node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is usually generated via logs that report process tracking + in your Windows audit settings. +known_false_positives: Some administrator activity can be potentially triggered, please + add those users to the filter macro. +references: [] tags: analytic_story: - Monitor for Unauthorized Software @@ -85,5 +87,3 @@ tags: - Endpoint.Processes.user risk_score: 64 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index 138dc23f49..a2462b4abc 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -1,26 +1,28 @@ +name: Attempt To Add Certificate To Untrusted Store +id: 6bc5243e-ef36-45dc-9b12-f4a6be131159 +version: 7 +date: '2021-09-16' author: Patrick Bareiss, Rico Valdez, Splunk +type: TTP datamodel: - Endpoint -date: '2021-09-16' description: Attempt To Add Certificate To Untrusted Store -how_to_implement: You must be ingesting data that records process activity from your - hosts to populate the Endpoint data model in the Processes node. You must also be - ingesting logs with both the process name and command line from your endpoints. - The command-line arguments are mapped to the "process" field in the Endpoint data - model. -id: 6bc5243e-ef36-45dc-9b12-f4a6be131159 -known_false_positives: There may be legitimate reasons for administrators to add a - certificate to the untrusted certificate store. In such cases, this will typically - be done on a large number of systems. -name: Attempt To Add Certificate To Untrusted Store -references: -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1553.004/T1553.004.md search: '| tstats `security_content_summariesonly` count min(_time) as firstTime values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where `process_certutil` (Processes.process=*-addstore*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `attempt_to_add_certificate_to_untrusted_store_filter`' +how_to_implement: You must be ingesting data that records process activity from your + hosts to populate the Endpoint data model in the Processes node. You must also be + ingesting logs with both the process name and command line from your endpoints. + The command-line arguments are mapped to the "process" field in the Endpoint data + model. +known_false_positives: There may be legitimate reasons for administrators to add a + certificate to the untrusted certificate store. In such cases, this will typically + be done on a large number of systems. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1553.004/T1553.004.md tags: analytic_story: - Disabling Security Tools @@ -81,5 +83,3 @@ tags: - _time risk_score: 35 security_domain: endpoint -type: TTP -version: 7 diff --git a/detections/endpoint/attempt_to_stop_security_service.yml b/detections/endpoint/attempt_to_stop_security_service.yml index e4e76ed360..29356aa451 100644 --- a/detections/endpoint/attempt_to_stop_security_service.yml +++ b/detections/endpoint/attempt_to_stop_security_service.yml @@ -1,20 +1,13 @@ +name: Attempt To Stop Security Service +id: c8e349c6-b97c-486e-8949-bd7bcd1f3910 +version: 4 +date: '2020-07-21' author: Rico Valdez, Splunk +type: TTP datamodel: - Endpoint -date: '2020-07-21' description: This search looks for attempts to stop security-related services on the endpoint. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: c8e349c6-b97c-486e-8949-bd7bcd1f3910 -known_false_positives: None identified. Attempts to disable security-related services - should be identified and understood. -name: Attempt To Stop Security Service -references: -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_net` OR Processes.process_name = sc.exe Processes.process="* stop @@ -23,6 +16,15 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |lookup security_services_lookup service as process OUTPUTNEW category, description | search category=security | `attempt_to_stop_security_service_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: None identified. Attempts to disable security-related services + should be identified and understood. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service tags: analytic_story: - Disabling Security Tools @@ -85,5 +87,3 @@ tags: - _time risk_score: 20 security_domain: endpoint -type: TTP -version: 4 diff --git a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml index c2671eb597..f9ca479d1e 100644 --- a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -1,19 +1,13 @@ +name: Attempted Credential Dump From Registry via Reg exe +id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911 +version: 6 +date: '2021-09-16' author: Patrick Bareiss, Splunk +type: TTP datamodel: - Endpoint -date: '2021-09-16' description: Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911 -known_false_positives: None identified. -name: Attempted Credential Dump From Registry via Reg exe -references: -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_reg` OR `process_cmd` Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\SAM* @@ -22,6 +16,14 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: None identified. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets tags: analytic_story: - Credential Dumping @@ -81,5 +83,3 @@ tags: - _time risk_score: 90 security_domain: endpoint -type: TTP -version: 6 diff --git a/detections/endpoint/auto_admin_logon_registry_entry.yml b/detections/endpoint/auto_admin_logon_registry_entry.yml index 9c3438a75b..6455c1614c 100644 --- a/detections/endpoint/auto_admin_logon_registry_entry.yml +++ b/detections/endpoint/auto_admin_logon_registry_entry.yml @@ -1,28 +1,30 @@ +name: Auto Admin Logon Registry Entry +id: 1379d2b8-0f18-11ec-8ca3-acde48001122 +version: 1 +date: '2021-09-06' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-09-06' description: this search is to detect a suspicious registry modification to implement auto admin logon to a host. This technique was seen in BlackMatter ransomware to automatically logon to the compromise host after triggering a safemode boot to continue encrypting the whole network. This behavior is not a common practice and really a suspicious TTP or alert need to be consider if found within then network premise. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure - that this registry was included in your config files ex. sysmon config to be monitored. -id: 1379d2b8-0f18-11ec-8ca3-acde48001122 -known_false_positives: unknown -name: Auto Admin Logon Registry Entry -references: -- https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*" AND Registry.registry_key_name=AutoAdminLogon AND Registry.registry_value_name=1 by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `auto_admin_logon_registry_entry_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure + that this registry was included in your config files ex. sysmon config to be monitored. +known_false_positives: unknown +references: +- https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/ tags: analytic_story: - BlackMatter Ransomware @@ -58,5 +60,3 @@ tags: - _time risk_score: 63 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/sam_database_file_access_attempt.yml b/detections/endpoint/sam_database_file_access_attempt.yml index 1a24204b3a..e349b41da5 100644 --- a/detections/endpoint/sam_database_file_access_attempt.yml +++ b/detections/endpoint/sam_database_file_access_attempt.yml @@ -1,20 +1,25 @@ -author: Michael Haag, Mauricio Velazco, Splunk -datamodel: [] +name: SAM Database File Access Attempt +id: 57551656-ebdb-11eb-afdf-acde48001122 +version: 1 date: '2021-07-23' +author: Michael Haag, Mauricio Velazco, Splunk +type: Hunting +datamodel: [] description: The following analytic identifies access to SAM, SYSTEM or SECURITY databases' within the file path of `windows\system32\config` using Windows Security EventCode 4663. This particular behavior is related to credential access, an attempt to either use a Shadow Copy or recent CVE-2021-36934 to access the SAM database. The Security Account Manager (SAM) is a database file in Windows XP, Windows Vista, Windows 7, 8.1 and 10 that stores users' passwords. +search: '`wineventlog_security` (EventCode=4663) process_name!=*\\dllhost.exe Object_Name + IN ("*\\Windows\\System32\\config\\SAM*","*\\Windows\\System32\\config\\SYSTEM*","*\\Windows\\System32\\config\\SECURITY*") + | stats values(Accesses) count by process_name Object_Name dest user | `sam_database_file_access_attempt_filter`' how_to_implement: To successfully implement this search, you must ingest Windows Security Event logs and track event code 4663. For 4663, enable "Audit Object Access" in Group Policy. Then check the two boxes listed for both "Success" and "Failure." -id: 57551656-ebdb-11eb-afdf-acde48001122 known_false_positives: Natively, `dllhost.exe` will access the files. Every environment will have additional native processes that do as well. Filter by process_name. As an aside, one can remove process_name entirely and add `Object_Name=*ShadowCopy*`. -name: SAM Database File Access Attempt references: - https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4663 - https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4663 @@ -22,9 +27,6 @@ references: - https://github.com/GossiTheDog/HiveNightmare - https://github.com/JumpsecLabs/Guidance-Advice/tree/main/SAM_Permissions - https://en.wikipedia.org/wiki/Security_Account_Manager -search: '`wineventlog_security` (EventCode=4663) process_name!=*\\dllhost.exe Object_Name - IN ("*\\Windows\\System32\\config\\SAM*","*\\Windows\\System32\\config\\SYSTEM*","*\\Windows\\System32\\config\\SECURITY*") - | stats values(Accesses) count by process_name Object_Name dest user | `sam_database_file_access_attempt_filter`' tags: analytic_story: - Credential Dumping @@ -70,5 +72,3 @@ tags: - user risk_score: 80 security_domain: endpoint -type: Hunting -version: 1 diff --git a/detections/endpoint/samsam_test_file_write.yml b/detections/endpoint/samsam_test_file_write.yml index ae43efd995..6ee689025a 100644 --- a/detections/endpoint/samsam_test_file_write.yml +++ b/detections/endpoint/samsam_test_file_write.yml @@ -1,22 +1,24 @@ +name: Samsam Test File Write +id: 493a879d-519d-428f-8f57-a06a0fdc107e +version: 1 +date: '2018-12-14' author: Rico Valdez, Splunk +type: TTP datamodel: - Endpoint -date: '2018-12-14' description: The search looks for a file named "test.txt" written to the windows system directory tree, which is consistent with Samsam propagation. -how_to_implement: You must be ingesting data that records the file-system activity - from your hosts to populate the Endpoint file-system data-model node. If you are - using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which - you want to collect data. -id: 493a879d-519d-428f-8f57-a06a0fdc107e -known_false_positives: No false positives have been identified. -name: Samsam Test File Write -references: [] search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_name) as file_name from datamodel=Endpoint.Filesystem where Filesystem.file_path=*\\windows\\system32\\test.txt by Filesystem.file_path | `drop_dm_object_name(Filesystem)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `samsam_test_file_write_filter`' +how_to_implement: You must be ingesting data that records the file-system activity + from your hosts to populate the Endpoint file-system data-model node. If you are + using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which + you want to collect data. +known_false_positives: No false positives have been identified. +references: [] tags: analytic_story: - SamSam Ransomware @@ -60,5 +62,3 @@ tags: - _time risk_score: 12 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index 03b39ad3b9..988d7613c6 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -1,24 +1,26 @@ +name: Sc exe Manipulating Windows Services +id: f0c693d8-2a89-4ce7-80b4-98fea4c3ea6d +version: 4 +date: '2020-07-21' author: Rico Valdez, Splunk +type: TTP datamodel: - Endpoint -date: '2020-07-21' description: This search looks for arguments to sc.exe indicating the creation or modification of a Windows service. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. -id: f0c693d8-2a89-4ce7-80b4-98fea4c3ea6d -known_false_positives: Using sc.exe to manipulate Windows services is uncommon. However, - there may be legitimate instances of this behavior. It is important to validate - and investigate as appropriate. -name: Sc exe Manipulating Windows Services -references: [] search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = sc.exe (Processes.process="* create *" OR Processes.process="* config *") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `sc_exe_manipulating_windows_services_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +known_false_positives: Using sc.exe to manipulate Windows services is uncommon. However, + there may be legitimate instances of this behavior. It is important to validate + and investigate as appropriate. +references: [] tags: analytic_story: - Windows Service Abuse @@ -76,5 +78,3 @@ tags: - _time risk_score: 56 security_domain: endpoint -type: TTP -version: 4 diff --git a/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml b/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml index 0c6b82af9f..668ce295d9 100644 --- a/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml +++ b/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml @@ -1,6 +1,10 @@ -author: Teoderick Contreras, Splunk -datamodel: [] +name: SchCache Change By App Connect And Create ADSI Object +id: 991eb510-0fc6-11ec-82d3-acde48001122 +version: 1 date: '2021-09-07' +author: Teoderick Contreras, Splunk +type: Anomaly +datamodel: [] description: This analytic is to detect an application try to connect and create ADSI Object to do LDAP query. Every time an application connects to the directory and attempts to create an ADSI object, the Active Directory Schema is checked for changes. @@ -10,22 +14,20 @@ description: This analytic is to detect an application try to connect and create application like blackmatter ransomware that use ADS object api to execute ldap query. having a good list of ldap or normal AD query tool used within the network is a good start to reduce the noise. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 991eb510-0fc6-11ec-82d3-acde48001122 -known_false_positives: normal application like mmc.exe and other ldap query tool may - trigger this detections. -name: SchCache Change By App Connect And Create ADSI Object -references: -- https://docs.microsoft.com/en-us/windows/win32/adsi/adsi-and-uac -- https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/ search: '`sysmon` EventCode=11 TargetFilename = "*\\Windows\\SchCache\\*" TargetFilename = "*.sch*" NOT (Image IN ("*\\Windows\\system32\\mmc.exe")) |stats count min(_time) as firstTime max(_time) as lastTime by Image TargetFilename EventCode process_id process_name Computer | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `schcache_change_by_app_connect_and_create_adsi_object_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: normal application like mmc.exe and other ldap query tool may + trigger this detections. +references: +- https://docs.microsoft.com/en-us/windows/win32/adsi/adsi-and-uac +- https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/ tags: analytic_story: - blackMatter ransomware @@ -62,5 +64,3 @@ tags: - Computer risk_score: 25 security_domain: endpoint -type: Anomaly -version: 1 diff --git a/detections/endpoint/schedule_task_with_http_command_arguments.yml b/detections/endpoint/schedule_task_with_http_command_arguments.yml index 5883380127..c055f32ec4 100644 --- a/detections/endpoint/schedule_task_with_http_command_arguments.yml +++ b/detections/endpoint/schedule_task_with_http_command_arguments.yml @@ -1,6 +1,10 @@ -author: Teoderick Contreras, Splunk -datamodel: [] +name: Schedule Task with HTTP Command Arguments +id: 523c2684-a101-11eb-916b-acde48001122 +version: 1 date: '2021-04-19' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: [] description: The following query utilizes Windows Security EventCode 4698, `A scheduled task was created`, to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with an arguments "HTTP" string that are unique entry @@ -15,18 +19,16 @@ description: The following query utilizes Windows Security EventCode 4698, `A sc Review the job created and the Command to be executed. Capture any artifacts on disk and review. Identify any parallel processes within the same timeframe to identify source.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the task schedule (Exa. Security Log EventCode 4698) endpoints. Tune and - filter known instances of Task schedule used in your environment. -id: 523c2684-a101-11eb-916b-acde48001122 -known_false_positives: unknown -name: Schedule Task with HTTP Command Arguments -references: -- https://app.any.run/tasks/92d7ef61-bfd7-4c92-bc15-322172b4ebec/ search: '`wineventlog_security` EventCode=4698 | xmlkv Message| search Arguments IN ("*http*") | stats count min(_time) as firstTime max(_time) as lastTime by dest, Task_Name, Command, Author, Enabled, Hidden, Arguments | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `schedule_task_with_http_command_arguments_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the task schedule (Exa. Security Log EventCode 4698) endpoints. Tune and + filter known instances of Task schedule used in your environment. +known_false_positives: unknown +references: +- https://app.any.run/tasks/92d7ef61-bfd7-4c92-bc15-322172b4ebec/ tags: analytic_story: - Windows Persistence Techniques @@ -70,5 +72,3 @@ tags: - Arguments risk_score: 63 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/schedule_task_with_rundll32_command_trigger.yml b/detections/endpoint/schedule_task_with_rundll32_command_trigger.yml index ad425e3f0e..e50b3d0773 100644 --- a/detections/endpoint/schedule_task_with_rundll32_command_trigger.yml +++ b/detections/endpoint/schedule_task_with_rundll32_command_trigger.yml @@ -1,6 +1,10 @@ -author: Teoderick Contreras, Splunk -datamodel: [] +name: Schedule Task with Rundll32 Command Trigger +id: 75b00fd8-a0ff-11eb-8b31-acde48001122 +version: 1 date: '2021-04-19' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: [] description: The following query utilizes Windows Security EventCode 4698, `A scheduled task was created`, to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with a command to be executed with a Rundll32. This @@ -15,19 +19,17 @@ description: The following query utilizes Windows Security EventCode 4698, `A sc Review the job created and the Command to be executed. Capture any artifacts on disk and review. Identify any parallel processes within the same timeframe to identify source.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the task schedule (Exa. Security Log EventCode 4698) endpoints. Tune and - filter known instances of Task schedule used in your environment. -id: 75b00fd8-a0ff-11eb-8b31-acde48001122 -known_false_positives: unknown -name: Schedule Task with Rundll32 Command Trigger -references: -- https://labs.vipre.com/trickbot-and-its-modules/ -- https://blog.whitehat.eu/2019/05/incident-trickbot-ryuk-2.html search: '`wineventlog_security` EventCode=4698 | xmlkv Message | search Command IN ("*rundll32*") | stats count min(_time) as firstTime max(_time) as lastTime by dest, Task_Name, Command, Author, Enabled, Hidden, Arguments | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `schedule_task_with_rundll32_command_trigger_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the task schedule (Exa. Security Log EventCode 4698) endpoints. Tune and + filter known instances of Task schedule used in your environment. +known_false_positives: unknown +references: +- https://labs.vipre.com/trickbot-and-its-modules/ +- https://blog.whitehat.eu/2019/05/incident-trickbot-ryuk-2.html tags: analytic_story: - Windows Persistence Techniques @@ -71,5 +73,3 @@ tags: - Arguments risk_score: 70 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml b/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml index 68555070de..a4e1edde53 100644 --- a/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml +++ b/detections/endpoint/scheduled_task_creation_on_remote_endpoint_using_at.yml @@ -1,7 +1,11 @@ +name: Scheduled Task Creation on Remote Endpoint using At +id: 4be54858-432f-11ec-8209-3e22fbd008af +version: 1 +date: '2021-11-11' author: Mauricio Velazco, Splunk +type: TTP datamodel: - Endpoint -date: '2021-11-11' description: This analytic looks for the execution of `at.exe` with command-line arguments utilized to create a Scheduled Task on a remote endpoint. Red Teams and adversaries alike may abuse the Task Scheduler for lateral movement and remote code execution. @@ -9,22 +13,20 @@ description: This analytic looks for the execution of `at.exe` with command-line with Windows 8 and Windows Server 2012 but may still work on previous versions of Windows. Furthermore, attackers may enable this protocol on demand by changing a sytem registry key. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. -id: 4be54858-432f-11ec-8209-3e22fbd008af -known_false_positives: Administrators may create scheduled tasks on remote systems, - but this activity is usually limited to a small set of hosts or users. -name: Scheduled Task Creation on Remote Endpoint using At -references: -- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/at -- https://docs.microsoft.com/en-us/windows/win32/cimwin32prov/win32-scheduledjob?redirectedfrom=MSDN search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=at.exe OR Processes.original_file_name=at.exe) (Processes.process=*\\\\*) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `scheduled_task_creation_on_remote_endpoint_using_at_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. +known_false_positives: Administrators may create scheduled tasks on remote systems, + but this activity is usually limited to a small set of hosts or users. +references: +- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/at +- https://docs.microsoft.com/en-us/windows/win32/cimwin32prov/win32-scheduledjob?redirectedfrom=MSDN tags: analytic_story: - Active Directory Lateral Movement @@ -63,5 +65,3 @@ tags: - _time risk_score: 54 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml index c12a473f8c..da73e5449a 100644 --- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml +++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml @@ -1,25 +1,27 @@ +name: Scheduled Task Deleted Or Created via CMD +id: d5af132c-7c17-439c-9d31-13d55340f36c +version: 5 +date: '2020-12-17' author: Bhavin Patel, Splunk +type: TTP datamodel: - Endpoint -date: '2020-12-17' description: This search looks for flags passed to schtasks.exe on the command-line that indicate a task was created via command like. This has been associated with the Dragonfly threat actor, and the SUNBURST attack against Solarwinds. -how_to_implement: You must be ingesting endpoint data that tracks process activity, - including parent-child relationships from your endpoints to populate the Endpoint - data model in the Processes node. The command-line arguments are mapped to the "process" - field in the Endpoint data model. -id: d5af132c-7c17-439c-9d31-13d55340f36c -known_false_positives: Tasks should not be manually created via CLI, this is rarely - done by admins as well -name: Scheduled Task Deleted Or Created via CMD -references: [] search: '| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process=*delete* OR Processes.process=*create*) by Processes.user Processes.process_name Processes.parent_process_name Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `scheduled_task_deleted_or_created_via_cmd_filter` ' +how_to_implement: You must be ingesting endpoint data that tracks process activity, + including parent-child relationships from your endpoints to populate the Endpoint + data model in the Processes node. The command-line arguments are mapped to the "process" + field in the Endpoint data model. +known_false_positives: Tasks should not be manually created via CLI, this is rarely + done by admins as well +references: [] tags: analytic_story: - DHS Report TA18-074A @@ -69,5 +71,3 @@ tags: - _time risk_score: 56 security_domain: endpoint -type: TTP -version: 5 diff --git a/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml b/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml index 4114b23271..3f48ec67b3 100644 --- a/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml +++ b/detections/endpoint/scheduled_task_initiation_on_remote_endpoint.yml @@ -1,27 +1,29 @@ +name: Scheduled Task Initiation on Remote Endpoint +id: 95cf4608-4302-11ec-8194-3e22fbd008af +version: 1 +date: '2021-11-11' author: Mauricio Velazco, Splunk +type: TTP datamodel: - Endpoint -date: '2021-11-11' description: This analytic looks for the execution of `schtasks.exe` with command-line arguments utilized to start a Scheduled Task on a remote endpoint. Red Teams and adversaries alike may abuse the Task Scheduler for lateral movement and remote code execution. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. -id: 95cf4608-4302-11ec-8194-3e22fbd008af -known_false_positives: Administrators may start scheduled tasks on remote systems, - but this activity is usually limited to a small set of hosts or users. -name: Scheduled Task Initiation on Remote Endpoint -references: -- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/schtasks -- https://attack.mitre.org/techniques/T1053/005/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=schtasks.exe OR Processes.original_file_name=schtasks.exe) (Processes.process=*/s* AND Processes.process=*/run*) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `scheduled_task_initiation_on_remote_endpoint_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. +known_false_positives: Administrators may start scheduled tasks on remote systems, + but this activity is usually limited to a small set of hosts or users. +references: +- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/schtasks +- https://attack.mitre.org/techniques/T1053/005/ tags: analytic_story: - Active Directory Lateral Movement @@ -60,5 +62,3 @@ tags: - _time risk_score: 54 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/schtasks_run_task_on_demand.yml b/detections/endpoint/schtasks_run_task_on_demand.yml index 07b8a078c3..f757d5d8ed 100644 --- a/detections/endpoint/schtasks_run_task_on_demand.yml +++ b/detections/endpoint/schtasks_run_task_on_demand.yml @@ -1,27 +1,29 @@ +name: Schtasks Run Task On Demand +id: bb37061e-af1f-11eb-a159-acde48001122 +version: 1 +date: '2021-05-07' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-05-07' description: This analytic identifies an on demand run of a Windows Schedule Task through shell or command-line. This technique has been used by adversaries that force to run their created Schedule Task as their persistence mechanism or for lateral movement as part of their malicious attack to the compromised machine. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed schtasks.exe may be used. -id: bb37061e-af1f-11eb-a159-acde48001122 -known_false_positives: Administrators may use to debug Schedule Task entries. Filter - as needed. -name: Schtasks Run Task On Demand -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ search: '| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "schtasks.exe" Processes.process = "*/run*" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `schtasks_run_task_on_demand_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed schtasks.exe may be used. +known_false_positives: Administrators may use to debug Schedule Task entries. Filter + as needed. +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ tags: analytic_story: - XMRig @@ -64,5 +66,3 @@ tags: - _time risk_score: 48 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml index d0362eb7a3..f40b4d24b4 100644 --- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml +++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml @@ -1,28 +1,30 @@ +name: Schtasks scheduling job on remote system +id: 1297fb80-f42a-4b4a-9c8a-88c066237cf6 +version: 5 +date: '2021-11-11' author: David Dorsey, Mauricio Velazco, Splunk +type: TTP datamodel: - Endpoint -date: '2021-11-11' description: This analytic looks for the execution of `schtasks.exe` with command-line arguments utilized to create a Scheduled Task on a remote endpoint. Red Teams and adversaries alike may abuse the Task Scheduler for lateral movement and remote code execution. -how_to_implement: You must be ingesting data that records process activity from your - hosts to populate the Endpoint data model in the Processes node. You must also be - ingesting logs with both the process name and command line from your endpoints. - The command-line arguments are mapped to the "process" field in the Endpoint data - model. -id: 1297fb80-f42a-4b4a-9c8a-88c066237cf6 -known_false_positives: Administrators may create scheduled tasks on remote systems, - but this activity is usually limited to a small set of hosts or users. It is important - to validate and investigate as appropriate. -name: Schtasks scheduling job on remote system -references: [] search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = schtasks.exe OR Processes.original_file_name=schtasks.exe) (Processes.process="*/create*" AND Processes.process="*/s*") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `schtasks_scheduling_job_on_remote_system_filter`' +how_to_implement: You must be ingesting data that records process activity from your + hosts to populate the Endpoint data model in the Processes node. You must also be + ingesting logs with both the process name and command line from your endpoints. + The command-line arguments are mapped to the "process" field in the Endpoint data + model. +known_false_positives: Administrators may create scheduled tasks on remote systems, + but this activity is usually limited to a small set of hosts or users. It is important + to validate and investigate as appropriate. +references: [] tags: analytic_story: - Active Directory Lateral Movement @@ -72,5 +74,3 @@ tags: - _time risk_score: 63 security_domain: endpoint -type: TTP -version: 5 diff --git a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml index 079524f1d9..a38328c3b2 100644 --- a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml +++ b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml @@ -1,25 +1,27 @@ +name: Schtasks used for forcing a reboot +id: 1297fb80-f42a-4b4a-9c8a-88c066437cf6 +version: 4 +date: '2020-12-07' author: Bhavin Patel, Splunk +type: TTP datamodel: - Endpoint -date: '2020-12-07' description: This search looks for flags passed to schtasks.exe on the command-line that indicate that a forced reboot of system is scheduled. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: 1297fb80-f42a-4b4a-9c8a-88c066437cf6 -known_false_positives: Administrators may create jobs on systems forcing reboots to - perform updates, maintenance, etc. -name: Schtasks used for forcing a reboot -references: [] search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe Processes.process="*shutdown*" Processes.process="*/create *" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `schtasks_used_for_forcing_a_reboot_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Administrators may create jobs on systems forcing reboots to + perform updates, maintenance, etc. +references: [] tags: analytic_story: - Windows Persistence Techniques @@ -68,5 +70,3 @@ tags: - _time risk_score: 56 security_domain: endpoint -type: TTP -version: 4 diff --git a/detections/endpoint/screensaver_event_trigger_execution.yml b/detections/endpoint/screensaver_event_trigger_execution.yml index 8fa9658065..d5d094aa91 100644 --- a/detections/endpoint/screensaver_event_trigger_execution.yml +++ b/detections/endpoint/screensaver_event_trigger_execution.yml @@ -1,30 +1,32 @@ +name: Screensaver Event Trigger Execution +id: 58cea3ec-1f6d-11ec-8560-acde48001122 +version: 1 +date: '2021-09-27' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-09-27' description: This analytic is developed to detect possible event trigger execution through screensaver registry entry modification for persistence or privilege escalation. This technique was seen in several APT and malware where they put the malicious payload path to the SCRNSAVE.EXE registry key to redirect the execution to their malicious payload path. This TTP is a good indicator that some attacker may modify this entry for their persistence and privilege escalation. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\Control + Panel\\Desktop\\SCRNSAVE.EXE*") by Registry.dest Registry.user Registry.registry_path + Registry.registry_key_name Registry.registry_value_name | `security_content_ctime(lastTime)` + | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `screensaver_event_trigger_execution_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. -id: 58cea3ec-1f6d-11ec-8560-acde48001122 known_false_positives: unknown -name: Screensaver Event Trigger Execution references: - https://attack.mitre.org/techniques/T1546/002/ - https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/screensaver -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime - max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\Control - Panel\\Desktop\\SCRNSAVE.EXE*") by Registry.dest Registry.user Registry.registry_path - Registry.registry_key_name Registry.registry_value_name | `security_content_ctime(lastTime)` - | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `screensaver_event_trigger_execution_filter`' tags: analytic_story: - Windows Persistence Techniques @@ -65,5 +67,3 @@ tags: - _time risk_score: 72 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/script_execution_via_wmi.yml b/detections/endpoint/script_execution_via_wmi.yml index aa57aa03ee..ae0818f95d 100644 --- a/detections/endpoint/script_execution_via_wmi.yml +++ b/detections/endpoint/script_execution_via_wmi.yml @@ -1,23 +1,25 @@ +name: Script Execution via WMI +id: aa73f80d-d728-4077-b226-81ea0c8be589 +version: 4 +date: '2020-03-16' author: Rico Valdez, Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2020-03-16' description: This search looks for scripts launched via WMI. -how_to_implement: You must be ingesting endpoint data that tracks process activity, - including parent-child relationships from your endpoints to populate the Endpoint - data model in the Processes node. The command-line arguments are mapped to the "process" - field in the Endpoint data model. -id: aa73f80d-d728-4077-b226-81ea0c8be589 -known_false_positives: Although unlikely, administrators may use wmi to launch scripts - for legitimate purposes. Filter as needed. -name: Script Execution via WMI -references: -- https://redcanary.com/blog/child-processes/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=scrcons.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `script_execution_via_wmi_filter` ' +how_to_implement: You must be ingesting endpoint data that tracks process activity, + including parent-child relationships from your endpoints to populate the Endpoint + data model in the Processes node. The command-line arguments are mapped to the "process" + field in the Endpoint data model. +known_false_positives: Although unlikely, administrators may use wmi to launch scripts + for legitimate purposes. Filter as needed. +references: +- https://redcanary.com/blog/child-processes/ tags: analytic_story: - Suspicious WMI Use @@ -67,5 +69,3 @@ tags: - _time risk_score: 36 security_domain: endpoint -type: TTP -version: 4 diff --git a/detections/endpoint/sdclt_uac_bypass.yml b/detections/endpoint/sdclt_uac_bypass.yml index 21be37b047..57c8124656 100644 --- a/detections/endpoint/sdclt_uac_bypass.yml +++ b/detections/endpoint/sdclt_uac_bypass.yml @@ -1,21 +1,15 @@ +name: Sdclt UAC Bypass +id: d71efbf6-da63-11eb-8c6e-acde48001122 +version: 1 +date: '2021-07-01' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-07-01' description: This search is to detect a suspicious sdclt.exe registry modification. This technique is commonly seen when attacker try to bypassed UAC by using sdclt.exe application by modifying some registry that sdclt.exe tries to open or query with payload file path on it to be executed. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. -id: d71efbf6-da63-11eb-8c6e-acde48001122 -known_false_positives: Limited to no false positives are expected. -name: Sdclt UAC Bypass -references: -- https://enigma0x3.net/2017/03/17/fileless-uac-bypass-using-sdclt-exe/ -- https://github.com/hfiref0x/UACME -- https://www.cyborgsecurity.com/cyborg_labs/threat-hunt-deep-dives-user-account-control-bypass-via-registry-modification/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where (Registry.registry_path= "*\\Windows\\CurrentVersion\\App Paths\\control.exe*" OR Registry.registry_path= "*\\exefile\\shell\\runas\\command\\*") @@ -23,6 +17,14 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `sdclt_uac_bypass_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +known_false_positives: Limited to no false positives are expected. +references: +- https://enigma0x3.net/2017/03/17/fileless-uac-bypass-using-sdclt-exe/ +- https://github.com/hfiref0x/UACME +- https://www.cyborgsecurity.com/cyborg_labs/threat-hunt-deep-dives-user-account-control-bypass-via-registry-modification/ tags: analytic_story: - Windows Defense Evasion Tactics @@ -60,5 +62,3 @@ tags: - _time risk_score: 63 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/sdelete_application_execution.yml b/detections/endpoint/sdelete_application_execution.yml index f50623b4d2..da5472c2e9 100644 --- a/detections/endpoint/sdelete_application_execution.yml +++ b/detections/endpoint/sdelete_application_execution.yml @@ -1,23 +1,17 @@ +name: Sdelete Application Execution +id: 31702fc0-2682-11ec-85c3-acde48001122 +version: 1 +date: '2021-10-06' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-10-06' description: This analytic is to detect the execution of sdelete.exe application sysinternal tools. This tool is one of the most use tool of malware and adversaries to remove or clear their tracks and artifact in the targetted host. This tool is designed to delete securely a file in file system that remove the forensic evidence on the machine. A good TTP query to check why user execute this application which is not a common practice. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: 31702fc0-2682-11ec-85c3-acde48001122 -known_false_positives: user may execute and use this application -name: Sdelete Application Execution -references: -- https://app.any.run/tasks/956f50be-2c13-465a-ac00-6224c14c5f89/ search: '| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes @@ -25,6 +19,14 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as Processes.dest Processes.user Processes.parent_process_name Processes.parent_process | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `sdelete_application_execution_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: user may execute and use this application +references: +- https://app.any.run/tasks/956f50be-2c13-465a-ac00-6224c14c5f89/ tags: analytic_story: - Masquerading - Rename System Utilities @@ -68,5 +70,3 @@ tags: - _time risk_score: 49 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml b/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml index 79a6e24b4c..0ccf87d670 100644 --- a/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml +++ b/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml @@ -1,7 +1,11 @@ +name: SearchProtocolHost with no Command Line with Network +id: b690df8c-a145-11eb-a38b-acde48001122 +version: 2 +date: '2021-10-13' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-10-13' description: The following analytic identifies searchprotocolhost.exe with no command line arguments and with a network connection. It is unusual for searchprotocolhost.exe to execute with no command line arguments present. This particular behavior is common @@ -9,15 +13,6 @@ description: The following analytic identifies searchprotocolhost.exe with no co any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. searchprotocolhost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` and `ports` node. -id: b690df8c-a145-11eb-a38b-acde48001122 -known_false_positives: Limited false positives may be present in small environments. - Tuning may be required based on parent process. -name: SearchProtocolHost with no Command Line with Network -references: -- https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=searchprotocolhost.exe by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name @@ -27,6 +22,13 @@ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint !="0" by Ports.process_guid Ports.dest Ports.dest_port | `drop_dm_object_name(Ports)` | rename dest as connection_to_CNC] | table _time dest parent_process_name process_name process_path process process_guid connection_to_CNC dest_port | `searchprotocolhost_with_no_command_line_with_network_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` and `ports` node. +known_false_positives: Limited false positives may be present in small environments. + Tuning may be required based on parent process. +references: +- https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc tags: analytic_story: - Cobalt Strike @@ -75,5 +77,3 @@ tags: - process_path risk_score: 70 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml index ec2bb47697..54763357c1 100644 --- a/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml +++ b/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml @@ -1,20 +1,15 @@ +name: SecretDumps Offline NTDS Dumping Tool +id: 5672819c-be09-11eb-bbfb-acde48001122 +version: 1 +date: '2021-05-26' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-05-26' description: This analytic detects a potential usage of secretsdump.py tool for dumping credentials (ntlm hash) from a copy of ntds.dit and SAM.Security,SYSTEM registrry hive. This technique was seen in some attacker that dump ntlm hashes offline after having a copy of ntds.dit and SAM/SYSTEM/SECURITY registry hive. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 5672819c-be09-11eb-bbfb-acde48001122 -known_false_positives: unknown -name: SecretDumps Offline NTDS Dumping Tool -references: -- https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "python*.exe" Processes.process = "*.py*" Processes.process = "*-ntds*" (Processes.process = "*-system*" @@ -23,6 +18,13 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.parent_process Processes.dest Processes.user Processes.process_id Processes.process_guid | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `secretdumps_offline_ntds_dumping_tool_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: unknown +references: +- https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py tags: analytic_story: - Credential Dumping @@ -66,5 +68,3 @@ tags: - _time risk_score: 80 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/serviceprincipalnames_discovery_with_powershell.yml b/detections/endpoint/serviceprincipalnames_discovery_with_powershell.yml index a3a353d20a..2d44f0b3e0 100644 --- a/detections/endpoint/serviceprincipalnames_discovery_with_powershell.yml +++ b/detections/endpoint/serviceprincipalnames_discovery_with_powershell.yml @@ -1,6 +1,10 @@ -author: Michael Haag, Splunk -datamodel: [] +name: ServicePrincipalNames Discovery with PowerShell +id: 13243068-2d38-11ec-8908-acde48001122 +version: 1 date: '2021-10-14' +author: Michael Haag, Splunk +type: TTP +datamodel: [] description: 'The following analytic identifies `powershell.exe` usage, using Script Block Logging EventCode 4104, related to querying the domain for Service Principle Names. typically, this is a precursor activity related to kerberoasting or the silver @@ -18,12 +22,14 @@ description: 'The following analytic identifies `powershell.exe` usage, using Sc class in PowerShell is the equivelant of using setspn.exe. \ During triage, review parallel processes for further suspicious activity.' +search: '`powershell` EventCode=4104 Message="*KerberosRequestorSecurityToken*" | + stats count min(_time) as firstTime max(_time) as lastTime by Message OpCode ComputerName + User EventCode | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `serviceprincipalnames_discovery_with_powershell_filter`' how_to_implement: To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. -id: 13243068-2d38-11ec-8908-acde48001122 known_false_positives: False positives should be limited, however filter as needed. -name: ServicePrincipalNames Discovery with PowerShell references: - https://docs.microsoft.com/en-us/windows/win32/ad/service-principal-names - https://docs.microsoft.com/en-us/dotnet/api/system.identitymodel.tokens.kerberosrequestorsecuritytoken?view=netframework-4.8 @@ -39,10 +45,6 @@ references: - https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63 - https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf - https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ -search: '`powershell` EventCode=4104 Message="*KerberosRequestorSecurityToken*" | - stats count min(_time) as firstTime max(_time) as lastTime by Message OpCode ComputerName - User EventCode | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `serviceprincipalnames_discovery_with_powershell_filter`' tags: analytic_story: - Active Directory Discovery @@ -85,5 +87,3 @@ tags: - _time risk_score: 80 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml index 5f092bfa38..805fc6029e 100644 --- a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml +++ b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml @@ -1,7 +1,11 @@ +name: ServicePrincipalNames Discovery with SetSPN +id: ae8b3efc-2d2e-11ec-8b57-acde48001122 +version: 1 +date: '2021-10-14' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-10-14' description: 'The following analytic identifies `setspn.exe` usage related to querying the domain for Service Principle Names. typically, this is a precursor activity related to kerberoasting or the silver ticket attack. \ @@ -25,15 +29,20 @@ description: 'The following analytic identifies `setspn.exe` usage related to qu existence of SPN \ During triage, review parallel processes for further suspicious activity.' +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_setspn` (Processes.process="*-t*" + AND Processes.process="*-f*") OR (Processes.process="*-q*" AND Processes.process="**/**") + OR (Processes.process="*-q*") OR (Processes.process="*-s*") by Processes.dest Processes.user + Processes.parent_process_name Processes.process_name Processes.original_file_name + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `serviceprincipalnames_discovery_with_setspn_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. -id: ae8b3efc-2d2e-11ec-8b57-acde48001122 known_false_positives: False positives may be caused by Administrators resetting SPNs or querying for SPNs. Filter as needed. -name: ServicePrincipalNames Discovery with SetSPN references: - https://docs.microsoft.com/en-us/windows/win32/ad/service-principal-names - https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting @@ -44,13 +53,6 @@ references: - https://blog.zsec.uk/paving-2-da-wholeset/ - https://msitpros.com/?p=3113 - https://adsecurity.org/?p=3466 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_setspn` (Processes.process="*-t*" - AND Processes.process="*-f*") OR (Processes.process="*-q*" AND Processes.process="**/**") - OR (Processes.process="*-q*") OR (Processes.process="*-s*") by Processes.dest Processes.user - Processes.parent_process_name Processes.process_name Processes.original_file_name - Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `serviceprincipalnames_discovery_with_setspn_filter`' tags: analytic_story: - Active Directory Discovery @@ -101,5 +103,3 @@ tags: - _time risk_score: 80 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/services_escalate_exe.yml b/detections/endpoint/services_escalate_exe.yml index d11cb2f963..d2614b8cac 100644 --- a/detections/endpoint/services_escalate_exe.yml +++ b/detections/endpoint/services_escalate_exe.yml @@ -1,7 +1,11 @@ +name: Services Escalate Exe +id: c448488c-b7ec-11eb-8253-acde48001122 +version: 1 +date: '2021-05-18' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-05-18' description: The following analytic identifies the use of `svc-exe` with Cobalt Strike. The behavior typically follows after an adversary has already gained initial access and is escalating privileges. Using `svc-exe`, a randomly named binary will be downloaded @@ -14,22 +18,20 @@ description: The following analytic identifies the use of `svc-exe` with Cobalt and may be any process on disk (typically system32/syswow64 binary). The `spawnto_` process will also contain a network connection. During triage, review parallel procesess and identify any additional file modifications. -how_to_implement: To successfully implement this search, you will need to ensure that - DNS data is populating the Network_Resolution data model. -id: c448488c-b7ec-11eb-8253-acde48001122 -known_false_positives: False positives should be limited as `services.exe` should - never spawn a process from `ADMIN$`. Filter as needed. -name: Services Escalate Exe -references: -- https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ -- https://attack.mitre.org/techniques/T1548/ -- https://www.cobaltstrike.com/help-beacon search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=services.exe Processes.process_path=*admin$* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `services_escalate_exe_filter`' +how_to_implement: To successfully implement this search, you will need to ensure that + DNS data is populating the Network_Resolution data model. +known_false_positives: False positives should be limited as `services.exe` should + never spawn a process from `ADMIN$`. Filter as needed. +references: +- https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ +- https://attack.mitre.org/techniques/T1548/ +- https://www.cobaltstrike.com/help-beacon tags: analytic_story: - Cobalt Strike @@ -75,5 +77,3 @@ tags: - _time risk_score: 76 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml index 540e644985..9c0d5f2a65 100644 --- a/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/services_exe_lolbas_execution_process_spawn.yml @@ -1,7 +1,11 @@ +name: Services LOLBAS Execution Process Spawn +id: ba9e1954-4c04-11ec-8b74-3e22fbd008af +version: 1 +date: '2021-11-22' author: Mauricio Velazco, Splunk +type: TTP datamodel: - Endpoint -date: '2021-11-22' description: The following analytic identifies `services.exe` spawning a LOLBAS execution process. When adversaries execute code on remote endpoints abusing the Service Control Manager and creating a remote malicious service, the executed command is spawned @@ -9,17 +13,6 @@ description: The following analytic identifies `services.exe` spawning a LOLBAS binaries that can be abused by threat actors to perform tasks like executing malicious code. Looking for child processes of services.exe that are part of the LOLBAS project can help defenders identify lateral movement activity. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. -id: ba9e1954-4c04-11ec-8b74-3e22fbd008af -known_false_positives: Legitimate applications may trigger this behavior, filter as - needed. -name: Services LOLBAS Execution Process Spawn -references: -- https://attack.mitre.org/techniques/T1543/003/ -- https://pentestlab.blog/2020/07/21/lateral-movement-services/ -- https://lolbas-project.github.io/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=services.exe) (Processes.process_name IN ("Regsvcs.exe", "Ftp.exe", "OfflineScannerShell.exe", @@ -36,6 +29,15 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `services_lolbas_execution_process_spawn_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. +known_false_positives: Legitimate applications may trigger this behavior, filter as + needed. +references: +- https://attack.mitre.org/techniques/T1543/003/ +- https://pentestlab.blog/2020/07/21/lateral-movement-services/ +- https://lolbas-project.github.io/ tags: analytic_story: - Active Directory Lateral Movement @@ -74,5 +76,3 @@ tags: - _time risk_score: 54 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index 66f75388ac..dd38d47d9a 100644 --- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -1,26 +1,28 @@ +name: Set Default PowerShell Execution Policy To Unrestricted or Bypass +id: c2590137-0b08-4985-9ec5-6ae23d92f63d +version: 6 +date: '2020-11-06' author: Patrick Bareiss, Splunk +type: TTP datamodel: - Endpoint -date: '2020-11-06' description: Monitor for changes of the ExecutionPolicy in the registry to the values "unrestricted" or "bypass," which allows the execution of malicious scripts. -how_to_implement: You must be ingesting data that records process activity from your - hosts to populate the Endpoint data model in the Registry node. You must also be - ingesting logs with the fields registry_path, registry_key_name, and registry_value_name - from your endpoints. -id: c2590137-0b08-4985-9ec5-6ae23d92f63d -known_false_positives: Administrators may attempt to change the default execution - policy on a system for a variety of reasons. However, setting the policy to "unrestricted" - or "bypass" as this search is designed to identify, would be unusual. Hits should - be reviewed and investigated as appropriate. -name: Set Default PowerShell Execution Policy To Unrestricted or Bypass -references: [] search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path=*Software\\Microsoft\\Powershell\\1\\ShellIds\\Microsoft.PowerShell* Registry.registry_key_name=ExecutionPolicy (Registry.registry_value_name=Unrestricted OR Registry.registry_value_name=Bypass) by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)` | `set_default_powershell_execution_policy_to_unrestricted_or_bypass_filter`' +how_to_implement: You must be ingesting data that records process activity from your + hosts to populate the Endpoint data model in the Registry node. You must also be + ingesting logs with the fields registry_path, registry_key_name, and registry_value_name + from your endpoints. +known_false_positives: Administrators may attempt to change the default execution + policy on a system for a variety of reasons. However, setting the policy to "unrestricted" + or "bypass" as this search is designed to identify, would be unusual. Hits should + be reviewed and investigated as appropriate. +references: [] tags: analytic_story: - Malicious PowerShell @@ -69,5 +71,3 @@ tags: - _time risk_score: 48 security_domain: endpoint -type: TTP -version: 6 diff --git a/detections/endpoint/shim_database_file_creation.yml b/detections/endpoint/shim_database_file_creation.yml index a29e620cc0..e60ee78d5b 100644 --- a/detections/endpoint/shim_database_file_creation.yml +++ b/detections/endpoint/shim_database_file_creation.yml @@ -1,27 +1,29 @@ +name: Shim Database File Creation +id: 6e4c4588-ba2f-42fa-97e6-9f6f548eaa33 +version: 3 +date: '2020-12-08' author: David Dorsey, Splunk +type: TTP datamodel: - Endpoint -date: '2020-12-08' description: This search looks for shim database files being written to default directories. The sdbinst.exe application is used to install shim database files (.sdb). According to Microsoft, a shim is a small library that transparently intercepts an API, changes the parameters passed, handles the operation itself, or redirects the operation elsewhere. -how_to_implement: You must be ingesting data that records the filesystem activity - from your hosts to populate the Endpoint file-system data model node. If you are - using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which - you want to collect data. -id: 6e4c4588-ba2f-42fa-97e6-9f6f548eaa33 -known_false_positives: Because legitimate shim files are created and used all the - time, this event, in itself, is not suspicious. However, if there are other correlating - events, it may warrant further investigation. -name: Shim Database File Creation -references: [] search: '| tstats `security_content_summariesonly` count values(Filesystem.action) values(Filesystem.file_hash) as file_hash values(Filesystem.file_path) as file_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path=*Windows\\AppPatch\\Custom* by Filesystem.file_name Filesystem.dest | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` |`drop_dm_object_name(Filesystem)` | `shim_database_file_creation_filter`' +how_to_implement: You must be ingesting data that records the filesystem activity + from your hosts to populate the Endpoint file-system data model node. If you are + using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which + you want to collect data. +known_false_positives: Because legitimate shim files are created and used all the + time, this event, in itself, is not suspicious. However, if there are other correlating + events, it may warrant further investigation. +references: [] tags: analytic_story: - Windows Persistence Techniques @@ -67,5 +69,3 @@ tags: - _time risk_score: 56 security_domain: endpoint -type: TTP -version: 3 diff --git a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml index 6ef4ecc930..132614939e 100644 --- a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml +++ b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml @@ -1,26 +1,28 @@ +name: Shim Database Installation With Suspicious Parameters +id: 404620de-46d8-48b6-90cc-8a8d7b0876a3 +version: 4 +date: '2020-11-23' author: David Dorsey, Splunk +type: TTP datamodel: - Endpoint -date: '2020-11-23' description: This search detects the process execution and arguments required to silently create a shim database. The sdbinst.exe application is used to install shim database files (.sdb). A shim is a small library which transparently intercepts an API, changes the parameters passed, handles the operation itself, or redirects the operation elsewhere. -how_to_implement: You must be ingesting data that records process activity from your - hosts to populate the Endpoint data model in the Processes node. You must also be - ingesting logs with both the process name and command line from your endpoints. - The command-line arguments are mapped to the "process" field in the Endpoint data - model. -id: 404620de-46d8-48b6-90cc-8a8d7b0876a3 -known_false_positives: None identified -name: Shim Database Installation With Suspicious Parameters -references: [] search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = sdbinst.exe by Processes.process_name Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `shim_database_installation_with_suspicious_parameters_filter`' +how_to_implement: You must be ingesting data that records process activity from your + hosts to populate the Endpoint data model in the Processes node. You must also be + ingesting logs with both the process name and command line from your endpoints. + The command-line arguments are mapped to the "process" field in the Endpoint data + model. +known_false_positives: None identified +references: [] tags: analytic_story: - Windows Persistence Techniques @@ -67,5 +69,3 @@ tags: - _time risk_score: 63 security_domain: endpoint -type: TTP -version: 4 diff --git a/detections/endpoint/short_lived_scheduled_task.yml b/detections/endpoint/short_lived_scheduled_task.yml index f3b81b2e7d..6c5179ec35 100644 --- a/detections/endpoint/short_lived_scheduled_task.yml +++ b/detections/endpoint/short_lived_scheduled_task.yml @@ -1,26 +1,28 @@ -author: Mauricio Velazco, Splunk -datamodel: [] +name: Short Lived Scheduled Task +id: 6fa31414-546e-11ec-adfa-acde48001122 +version: 1 date: '2021-12-03' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] description: The following analytic leverages Windows Security EventCode 4698, `A scheduled task was created` and Windows Security EventCode 4699, `A scheduled task was deleted` to identify scheduled tasks created and deleted in less than 30 seconds. This behavior may represent a lateral movement attack abusing the Task Scheduler to obtain code execution. Red Teams and adversaries alike may abuse the Task Scheduler for lateral movement and remote code execution. -how_to_implement: To successfully implement this search, you need to be ingesting - Windows Security Event Logs with 4698 EventCode enabled. The Windows TA is also - required. -id: 6fa31414-546e-11ec-adfa-acde48001122 -known_false_positives: Although uncommon, legitimate applications may create and delete - a Scheduled Task within 30 seconds. Filter as needed. -name: Short Lived Scheduled Task -references: -- https://attack.mitre.org/techniques/T1053/005/ -- https://docs.microsoft.com/en-us/windows/win32/taskschd/about-the-task-scheduler search: ' `wineventlog_security` EventCode=4698 OR EventCode=4699 | xmlkv Message | transaction Task_Name startswith=(EventCode=4698) endswith=(EventCode=4699) | eval short_lived=case((duration<30),"TRUE") | search short_lived = TRUE | table _time, ComputerName, Account_Name, Command, Task_Name, short_lived | `short_lived_scheduled_task_filter` ' +how_to_implement: To successfully implement this search, you need to be ingesting + Windows Security Event Logs with 4698 EventCode enabled. The Windows TA is also + required. +known_false_positives: Although uncommon, legitimate applications may create and delete + a Scheduled Task within 30 seconds. Filter as needed. +references: +- https://attack.mitre.org/techniques/T1053/005/ +- https://docs.microsoft.com/en-us/windows/win32/taskschd/about-the-task-scheduler tags: analytic_story: - Active Directory Lateral Movement @@ -61,5 +63,3 @@ tags: - _time risk_score: 81 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/short_lived_windows_accounts.yml b/detections/endpoint/short_lived_windows_accounts.yml index c009f92ef2..562ed15730 100644 --- a/detections/endpoint/short_lived_windows_accounts.yml +++ b/detections/endpoint/short_lived_windows_accounts.yml @@ -1,17 +1,13 @@ +name: Short Lived Windows Accounts +id: b25f6f62-0782-43c1-b403-083231ffd97d +version: 2 +date: '2020-07-06' author: David Dorsey, Splunk +type: TTP datamodel: - Change -date: '2020-07-06' description: This search detects accounts that were created and deleted in a short time period. -how_to_implement: 'This search requires you to have enabled your Group Management - Audit Logs in your Local Windows Security Policy and be ingesting those logs. More - information on how to enable them can be found here: http://whatevernetworks.com/auditing-group-membership-changes-in-active-directory/' -id: b25f6f62-0782-43c1-b403-083231ffd97d -known_false_positives: It is possible that an administrator created and deleted an - account in a short time period. Verifying activity with an administrator is advised. -name: Short Lived Windows Accounts -references: [] search: '| tstats `security_content_summariesonly` values(All_Changes.result_id) as result_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Change.All_Changes where All_Changes.result_id=4720 OR All_Changes.result_id=4726 by _time span=4h @@ -19,6 +15,12 @@ search: '| tstats `security_content_summariesonly` values(All_Changes.result_id) | `drop_dm_object_name("All_Changes")` | search result_id = 4720 result_id=4726 | transaction user connected=false maxspan=240m | table firstTime lastTime count user dest result_id | `short_lived_windows_accounts_filter`' +how_to_implement: 'This search requires you to have enabled your Group Management + Audit Logs in your Local Windows Security Policy and be ingesting those logs. More + information on how to enable them can be found here: http://whatevernetworks.com/auditing-group-membership-changes-in-active-directory/' +known_false_positives: It is possible that an administrator created and deleted an + account in a short time period. Verifying activity with an administrator is advised. +references: [] tags: analytic_story: - Account Monitoring and Controls @@ -61,5 +63,3 @@ tags: - _time risk_score: 63 security_domain: access -type: TTP -version: 2 diff --git a/detections/endpoint/silentcleanup_uac_bypass.yml b/detections/endpoint/silentcleanup_uac_bypass.yml index dc66062686..d2989385fc 100644 --- a/detections/endpoint/silentcleanup_uac_bypass.yml +++ b/detections/endpoint/silentcleanup_uac_bypass.yml @@ -1,26 +1,28 @@ +name: SilentCleanup UAC Bypass +id: 56d7cfcc-da63-11eb-92d4-acde48001122 +version: 1 +date: '2021-07-01' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-07-01' description: This search is to detect a suspicious modification of registry that may related to UAC bypassed. This registry will be trigger once the attacker abuse the silentcleanup task schedule to gain high privilege execution that will bypass User control account. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure - that this registry was included in your config files ex. sysmon config to be monitored. -id: 56d7cfcc-da63-11eb-92d4-acde48001122 -known_false_positives: unknown -name: SilentCleanup UAC Bypass -references: -- https://github.com/hfiref0x/UACME -- https://www.intezer.com/blog/malware-analysis/klingon-rat-holding-on-for-dear-life/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\Environment\\windir" Registry.registry_value_name = "*.exe*" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `silentcleanup_uac_bypass_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure + that this registry was included in your config files ex. sysmon config to be monitored. +known_false_positives: unknown +references: +- https://github.com/hfiref0x/UACME +- https://www.intezer.com/blog/malware-analysis/klingon-rat-holding-on-for-dear-life/ tags: analytic_story: - Windows Defense Evasion Tactics @@ -58,5 +60,3 @@ tags: - _time risk_score: 63 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/single_letter_process_on_endpoint.yml b/detections/endpoint/single_letter_process_on_endpoint.yml index ca41c2f098..c27f6c01b1 100644 --- a/detections/endpoint/single_letter_process_on_endpoint.yml +++ b/detections/endpoint/single_letter_process_on_endpoint.yml @@ -1,18 +1,12 @@ +name: Single Letter Process On Endpoint +id: a4214f0b-e01c-41bc-8cc4-d2b71e3056b4 +version: 3 +date: '2020-12-08' author: David Dorsey, Splunk +type: TTP datamodel: - Endpoint -date: '2020-12-08' description: This search looks for process names that consist only of a single letter. -how_to_implement: You must be ingesting data that records process activity from your - hosts to populate the Endpoint data model in the Processes node. You must also be - ingesting logs with both the process name and command line from your endpoints. - The command-line arguments are mapped to the "process" field in the Endpoint data - model. -id: a4214f0b-e01c-41bc-8cc4-d2b71e3056b4 -known_false_positives: Single-letter executables are not always malicious. Investigate - this activity with your normal incident-response process. -name: Single Letter Process On Endpoint -references: [] search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.dest, Processes.user, Processes.process, Processes.process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(lastTime)` @@ -20,6 +14,14 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime endExe = if(substr(process_name, -4) == ".exe", 1, 0) | search process_name_length=5 AND endExe=1 | table count, firstTime, lastTime, dest, user, process, process_name | `single_letter_process_on_endpoint_filter`' +how_to_implement: You must be ingesting data that records process activity from your + hosts to populate the Endpoint data model in the Processes node. You must also be + ingesting logs with both the process name and command line from your endpoints. + The command-line arguments are mapped to the "process" field in the Endpoint data + model. +known_false_positives: Single-letter executables are not always malicious. Investigate + this activity with your normal incident-response process. +references: [] tags: analytic_story: - DHS Report TA18-074A @@ -64,5 +66,3 @@ tags: - _time risk_score: 63 security_domain: endpoint -type: TTP -version: 3 diff --git a/detections/endpoint/slui_runas_elevated.yml b/detections/endpoint/slui_runas_elevated.yml index a463db9533..ba9411f1a1 100644 --- a/detections/endpoint/slui_runas_elevated.yml +++ b/detections/endpoint/slui_runas_elevated.yml @@ -1,32 +1,34 @@ +name: SLUI RunAs Elevated +id: 8d124810-b3e4-11eb-96c7-acde48001122 +version: 1 +date: '2021-05-13' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-05-13' description: The following analytic identifies the Microsoft Software Licensing User Interface Tool, `slui.exe`, elevating access using the `-verb runas` function. This particular bypass utilizes a registry key/value. Identified by two sources, the registry keys are `HKCU\Software\Classes\exefile\shell` and `HKCU\Software\Classes\launcher.Systemsettings\Shell\open\command`. To simulate this behavior, multiple POC are available. The analytic identifies the use of `runas` by `slui.exe`. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. -id: 8d124810-b3e4-11eb-96c7-acde48001122 -known_false_positives: Limited false positives should be present as this is not commonly - used by legitimate applications. -name: SLUI RunAs Elevated -references: -- https://www.exploit-db.com/exploits/46998 -- https://medium.com/@mattharr0ey/privilege-escalation-uac-bypass-in-changepk-c40b92818d1b -- https://gist.github.com/r00t-3xp10it/0c92cd554d3156fd74f6c25660ccc466 -- https://www.rapid7.com/db/modules/exploit/windows/local/bypassuac_sluihijack/ -- https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=slui.exe (Processes.process=*-verb* Processes.process=*runas*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `slui_runas_elevated_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +known_false_positives: Limited false positives should be present as this is not commonly + used by legitimate applications. +references: +- https://www.exploit-db.com/exploits/46998 +- https://medium.com/@mattharr0ey/privilege-escalation-uac-bypass-in-changepk-c40b92818d1b +- https://gist.github.com/r00t-3xp10it/0c92cd554d3156fd74f6c25660ccc466 +- https://www.rapid7.com/db/modules/exploit/windows/local/bypassuac_sluihijack/ +- https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html tags: analytic_story: - DarkSide Ransomware @@ -70,5 +72,3 @@ tags: - _time risk_score: 63 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/slui_spawning_a_process.yml b/detections/endpoint/slui_spawning_a_process.yml index 0f2992b1b9..aa068cd0b8 100644 --- a/detections/endpoint/slui_spawning_a_process.yml +++ b/detections/endpoint/slui_spawning_a_process.yml @@ -1,7 +1,11 @@ +name: SLUI Spawning a Process +id: 879c4330-b3e0-11eb-b1b1-acde48001122 +version: 1 +date: '2021-05-13' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-05-13' description: The following analytic identifies the Microsoft Software Licensing User Interface Tool, `slui.exe`, spawning a child process. This behavior is associated with publicly known UAC bypass. `slui.exe` is commonly associated with software @@ -9,22 +13,20 @@ description: The following analytic identifies the Microsoft Software Licensing not have child processes, and any processes spawning from it will be running with elevated privileges. During triage, review the child process and additional parallel processes. Identify any file modifications that may have lead to the bypass. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. -id: 879c4330-b3e0-11eb-b1b1-acde48001122 -known_false_positives: Certain applications may spawn from `slui.exe` that are legitimate. - Filtering will be needed to ensure proper monitoring. -name: SLUI Spawning a Process -references: -- https://www.exploit-db.com/exploits/46998 -- https://www.rapid7.com/db/modules/exploit/windows/local/bypassuac_sluihijack/ -- https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=slui.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `slui_spawning_a_process_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +known_false_positives: Certain applications may spawn from `slui.exe` that are legitimate. + Filtering will be needed to ensure proper monitoring. +references: +- https://www.exploit-db.com/exploits/46998 +- https://www.rapid7.com/db/modules/exploit/windows/local/bypassuac_sluihijack/ +- https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html tags: analytic_story: - DarkSide Ransomware @@ -69,5 +71,3 @@ tags: - _time risk_score: 63 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/spoolsv_spawning_rundll32.yml b/detections/endpoint/spoolsv_spawning_rundll32.yml index 929aa70a98..611d25a7c3 100644 --- a/detections/endpoint/spoolsv_spawning_rundll32.yml +++ b/detections/endpoint/spoolsv_spawning_rundll32.yml @@ -1,32 +1,34 @@ +name: Spoolsv Spawning Rundll32 +id: 15d905f6-da6b-11eb-ab82-acde48001122 +version: 2 +date: '2021-07-01' author: Mauricio Velazco, Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-07-01' description: The following analytic identifies a suspicious child process, `rundll32.exe`, with no command-line arguments being spawned from `spoolsv.exe`. This was identified during our testing of CVE-2021-34527 previously (CVE-2021-1675) or PrintNightmare. Typically, this is not normal behavior for `spoolsv.exe` to spawn a process. During triage, isolate the endpoint and review for source of exploitation. Capture any additional file modification events. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: 15d905f6-da6b-11eb-ab82-acde48001122 -known_false_positives: Limited false positives have been identified. There are limited - instances where `rundll32.exe` may be spawned by a legitimate print driver. -name: Spoolsv Spawning Rundll32 -references: -- https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/ -- https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/ -- https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=spoolsv.exe `process_rundll32` by Processes.dest Processes.user Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `spoolsv_spawning_rundll32_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Limited false positives have been identified. There are limited + instances where `rundll32.exe` may be spawned by a legitimate print driver. +references: +- https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/ +- https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/ +- https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes tags: analytic_story: - PrintNightmare CVE-2021-34527 @@ -80,5 +82,3 @@ tags: - _time risk_score: 72 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml index e14f11daaf..574fcb3d73 100644 --- a/detections/endpoint/spoolsv_suspicious_loaded_modules.yml +++ b/detections/endpoint/spoolsv_suspicious_loaded_modules.yml @@ -1,22 +1,24 @@ -author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk -datamodel: [] +name: Spoolsv Suspicious Loaded Modules +id: a5e451f8-da81-11eb-b245-acde48001122 +version: 1 date: '2021-07-01' +author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk +type: TTP +datamodel: [] description: This search is to detect suspicious loading of dll in specific path relative to printnightmare exploitation. In this search we try to detect the loaded modules made by spoolsv.exe after the exploitation. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name and imageloaded executions from your endpoints. If you - are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -id: a5e451f8-da81-11eb-b245-acde48001122 -known_false_positives: unknown -name: Spoolsv Suspicious Loaded Modules -references: -- https://raw.githubusercontent.com/hieuttmmo/sigma/dceb13fe3f1821b119ae495b41e24438bd97e3d0/rules/windows/image_load/sysmon_cve_2021_1675_print_nightmare.yml search: '`sysmon` EventCode=7 Image ="*\\spoolsv.exe" ImageLoaded="*\\Windows\\System32\\spool\\drivers\\x64\\*" ImageLoaded = "*.dll" | stats dc(ImageLoaded) as countImgloaded values(ImageLoaded) as ImgLoaded count min(_time) as firstTime max(_time) as lastTime by Image Computer process_id EventCode | where countImgloaded >= 3 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `spoolsv_suspicious_loaded_modules_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name and imageloaded executions from your endpoints. If you + are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +known_false_positives: unknown +references: +- https://raw.githubusercontent.com/hieuttmmo/sigma/dceb13fe3f1821b119ae495b41e24438bd97e3d0/rules/windows/image_load/sysmon_cve_2021_1675_print_nightmare.yml tags: analytic_story: - PrintNightmare CVE-2021-34527 @@ -65,5 +67,3 @@ tags: - ImageLoaded risk_score: 72 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/spoolsv_suspicious_process_access.yml b/detections/endpoint/spoolsv_suspicious_process_access.yml index ec41cdd329..9e135a222e 100644 --- a/detections/endpoint/spoolsv_suspicious_process_access.yml +++ b/detections/endpoint/spoolsv_suspicious_process_access.yml @@ -1,28 +1,30 @@ -author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk -datamodel: [] +name: Spoolsv Suspicious Process Access +id: 799b606e-da81-11eb-93f8-acde48001122 +version: 1 date: '2021-07-01' +author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk +type: TTP +datamodel: [] description: This analytic identifies a suspicious behavior related to PrintNightmare, or CVE-2021-34527 previously (CVE-2021-1675), to gain privilege escalation on the vulnerable machine. This exploit attacks a critical Windows Print Spooler Vulnerability to elevate privilege. This detection is to look for suspicious process access made by the spoolsv.exe that may related to the attack. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with process access event where SourceImage, TargetImage, GrantedAccess and - CallTrace executions from your endpoints. If you are using Sysmon, you must have - at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of spoolsv.exe. -id: 799b606e-da81-11eb-93f8-acde48001122 -known_false_positives: Unknown. Filter as needed. -name: Spoolsv Suspicious Process Access -references: -- https://github.com/cube0x0/impacket/commit/73b9466c17761384ece11e1028ec6689abad6818 -- https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/ -- https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/ -- https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes search: '`sysmon` EventCode=10 SourceImage = "*\\spoolsv.exe" CallTrace = "*\\Windows\\system32\\spool\\DRIVERS\\x64\\*" TargetImage IN ("*\\rundll32.exe", "*\\spoolsv.exe") GrantedAccess = 0x1fffff | stats count min(_time) as firstTime max(_time) as lastTime by Computer SourceImage TargetImage GrantedAccess CallTrace EventCode ProcessID| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `spoolsv_suspicious_process_access_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with process access event where SourceImage, TargetImage, GrantedAccess and + CallTrace executions from your endpoints. If you are using Sysmon, you must have + at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of spoolsv.exe. +known_false_positives: Unknown. Filter as needed. +references: +- https://github.com/cube0x0/impacket/commit/73b9466c17761384ece11e1028ec6689abad6818 +- https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/ +- https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/ +- https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes tags: analytic_story: - PrintNightmare CVE-2021-34527 @@ -70,5 +72,3 @@ tags: - EventCode risk_score: 72 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/spoolsv_writing_a_dll.yml b/detections/endpoint/spoolsv_writing_a_dll.yml index d26e01a667..a14afb5b06 100644 --- a/detections/endpoint/spoolsv_writing_a_dll.yml +++ b/detections/endpoint/spoolsv_writing_a_dll.yml @@ -1,24 +1,17 @@ +name: Spoolsv Writing a DLL +id: d5bf5cf2-da71-11eb-92c2-acde48001122 +version: 1 +date: '2021-07-01' author: Mauricio Velazco, Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-07-01' description: The following analytic identifies a `.dll` being written by `spoolsv.exe`. This was identified during our testing of CVE-2021-34527 previously (CVE-2021-1675) or PrintNightmare. Typically, this is not normal behavior for `spoolsv.exe` to write a `.dll`. Current POC code used will write the suspicious DLL to disk within a path of `\spool\drivers\x64\`. During triage, isolate the endpoint and review for source of exploitation. Capture any additional file modification events. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` - node. -id: d5bf5cf2-da71-11eb-92c2-acde48001122 -known_false_positives: Unknown. -name: Spoolsv Writing a DLL -references: -- https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/ -- https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/ -- https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=spoolsv.exe by _time Processes.process_id Processes.process_name Processes.dest | `drop_dm_object_name(Processes)` | join process_guid, _time [| @@ -29,6 +22,15 @@ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint fields _time dest file_create_time file_name file_path process_name process_path process] | dedup file_create_time | table dest file_create_time, file_name, file_path, process_name | `spoolsv_writing_a_dll_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` + node. +known_false_positives: Unknown. +references: +- https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/ +- https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/ +- https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes tags: analytic_story: - PrintNightmare CVE-2021-34527 @@ -78,5 +80,3 @@ tags: - _time risk_score: 72 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml index 23766f5e50..044466f512 100644 --- a/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml +++ b/detections/endpoint/spoolsv_writing_a_dll___sysmon.yml @@ -1,28 +1,30 @@ -author: Mauricio Velazco, Michael Haag, Splunk -datamodel: [] +name: Spoolsv Writing a DLL - Sysmon +id: 347fd388-da87-11eb-836d-acde48001122 +version: 1 date: '2021-07-01' +author: Mauricio Velazco, Michael Haag, Splunk +type: TTP +datamodel: [] description: The following analytic identifies a `.dll` being written by `spoolsv.exe`. This was identified during our testing of CVE-2021-34527 previously(CVE-2021-1675) or PrintNightmare. Typically, this is not normal behavior for `spoolsv.exe` to write a `.dll`. Current POC code used will write the suspicious DLL to disk within a path of `\spool\drivers\x64\`. During triage, isolate the endpoint and review for source of exploitation. Capture any additional file modification events. +search: '`sysmon` EventID=11 process_name=spoolsv.exe file_path="*\\spool\\drivers\\x64\\*" + file_name=*.dll | stats count min(_time) as firstTime max(_time) as lastTime by + dest, UserID, process_name, file_path, file_name, TargetFilename, process_id | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `spoolsv_writing_a_dll___sysmon_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used. -id: 347fd388-da87-11eb-836d-acde48001122 known_false_positives: Limited false positives. Filter as needed. -name: Spoolsv Writing a DLL - Sysmon references: - https://github.com/cube0x0/impacket/commit/73b9466c17761384ece11e1028ec6689abad6818 - https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/ - https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/ - https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes -search: '`sysmon` EventID=11 process_name=spoolsv.exe file_path="*\\spool\\drivers\\x64\\*" - file_name=*.dll | stats count min(_time) as firstTime max(_time) as lastTime by - dest, UserID, process_name, file_path, file_name, TargetFilename, process_id | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` | `spoolsv_writing_a_dll___sysmon_filter`' tags: analytic_story: - PrintNightmare CVE-2021-34527 @@ -72,5 +74,3 @@ tags: - TargetFilename risk_score: 72 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/sqlite_module_in_temp_folder.yml b/detections/endpoint/sqlite_module_in_temp_folder.yml index 5a38685668..090d7b48c0 100644 --- a/detections/endpoint/sqlite_module_in_temp_folder.yml +++ b/detections/endpoint/sqlite_module_in_temp_folder.yml @@ -1,24 +1,26 @@ -author: Teoderick Contreras, Splunk -datamodel: [] +name: Sqlite Module In Temp Folder +id: 0f216a38-f45f-11eb-b09c-acde48001122 +version: 1 date: '2021-08-03' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: [] description: This search is to detect a suspicious file creation of sqlite3.dll in %temp% folder. This behavior was seen in IcedID malware where it download sqlite module to parse browser database like for chrome or firefox to stole browser information related to bank, credit card or credentials. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 0f216a38-f45f-11eb-b09c-acde48001122 -known_false_positives: unknown -name: Sqlite Module In Temp Folder -references: -- https://www.cisecurity.org/white-papers/security-primer-icedid/ search: '`sysmon` EventCode=11 (TargetFilename = "*\\sqlite32.dll" OR TargetFilename = "*\\sqlite64.dll") (TargetFilename = "*\\temp\\*") |stats count min(_time) as firstTime max(_time) as lastTime by process_name TargetFilename EventCode ProcessId Image | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `sqlite_module_in_temp_folder_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: unknown +references: +- https://www.cisecurity.org/white-papers/security-primer-icedid/ tags: analytic_story: - IcedID @@ -57,5 +59,3 @@ tags: - Image risk_score: 9 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/start_up_during_safe_mode_boot.yml b/detections/endpoint/start_up_during_safe_mode_boot.yml index 27086aaa01..aff8da54d3 100644 --- a/detections/endpoint/start_up_during_safe_mode_boot.yml +++ b/detections/endpoint/start_up_during_safe_mode_boot.yml @@ -1,27 +1,29 @@ +name: Start Up During Safe Mode Boot +id: c6149154-c9d8-11eb-9da7-acde48001122 +version: 1 +date: '2021-06-10' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-06-10' description: This search is to detect a modification or registry add to the safeboot registry as an autostart mechanism. This technique was seen in some ransomware to automatically execute its code upon a safe mode boot. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SafeBoot\\Minimal\*" + by Registry.registry_path Registry.registry_key_name Registry.registry_value_name + Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` + |`security_content_ctime(lastTime)` | `start_up_during_safe_mode_boot_filter`' how_to_implement: To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response product, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. -id: c6149154-c9d8-11eb-9da7-acde48001122 known_false_positives: updated windows application needed in safe boot may used this registry -name: Start Up During Safe Mode Boot references: - https://malware.news/t/threat-analysis-unit-tau-threat-intelligence-notification-snatch-ransomware/36365 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SafeBoot\\Minimal\*" - by Registry.registry_path Registry.registry_key_name Registry.registry_value_name - Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` - |`security_content_ctime(lastTime)` | `start_up_during_safe_mode_boot_filter`' tags: analytic_story: - Ransomware @@ -57,5 +59,3 @@ tags: - _time risk_score: 42 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/suspicious_computer_account_name_change.yml b/detections/endpoint/suspicious_computer_account_name_change.yml index c8332c861b..15b99b7eed 100644 --- a/detections/endpoint/suspicious_computer_account_name_change.yml +++ b/detections/endpoint/suspicious_computer_account_name_change.yml @@ -1,6 +1,10 @@ -author: Mauricio Velazco, Splunk -datamodel: [] +name: Suspicious Computer Account Name Change +id: 35a61ed8-61c4-11ec-bc1e-acde48001122 +version: 1 date: '2021-12-20' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] description: As part of the sAMAccountName Spoofing (CVE-2021-42278) and Domain Controller Impersonation (CVE-2021-42287) exploitation chain, adversaries need to create a new computer account name and rename it to match the name of a domain controller @@ -9,19 +13,17 @@ description: As part of the sAMAccountName Spoofing (CVE-2021-42278) and Domain of an account was changed`, to identify a computer account rename event with a suspicious name that does not terminate with `$`. This behavior could represent an exploitation attempt of CVE-2021-42278 and CVE-2021-42287 for privilege escalation. +search: '`wineventlog_security` EventCode=4781 Old_Account_Name="*$" New_Account_Name!="*$" + | table _time, ComputerName, Account_Name, Old_Account_Name, New_Account_Name | + `suspicious_computer_account_name_change_filter`' how_to_implement: To successfully implement this search, you need to be ingesting Windows event logs from your hosts. In addition, the Splunk Windows TA is needed. -id: 35a61ed8-61c4-11ec-bc1e-acde48001122 known_false_positives: Renaming a computer account name to a name that not end with '$' is highly unsual and may not have any legitimate scenarios. -name: Suspicious Computer Account Name Change references: - https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278 - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287 -search: '`wineventlog_security` EventCode=4781 Old_Account_Name="*$" New_Account_Name!="*$" - | table _time, ComputerName, Account_Name, Old_Account_Name, New_Account_Name | - `suspicious_computer_account_name_change_filter`' tags: analytic_story: - sAMAccountName Spoofing and Domain Controller Impersonation @@ -61,5 +63,3 @@ tags: - New_Account_Name risk_score: 70 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/suspicious_copy_on_system32.yml b/detections/endpoint/suspicious_copy_on_system32.yml index e9a59c2256..3740dc4117 100644 --- a/detections/endpoint/suspicious_copy_on_system32.yml +++ b/detections/endpoint/suspicious_copy_on_system32.yml @@ -1,22 +1,16 @@ +name: Suspicious Copy on System32 +id: ce633e56-25b2-11ec-9e76-acde48001122 +version: 1 +date: '2021-10-05' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-10-05' description: This analytic is to detect a suspicious copy of file from systemroot folder of the windows OS. This technique is commonly used by APT or other malware as part of execution (LOLBIN) to run its malicious code using the available legitimate tool in OS. this type of event may seen or may execute of normal user in some instance but this is really a anomaly that needs to be check within the network. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: ce633e56-25b2-11ec-9e76-acde48001122 -known_false_positives: every user may do this event but very un-ussual. -name: Suspicious Copy on System32 -references: -- https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120 search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name IN("cmd.exe", "powershell*","pwsh.exe", "sqlps.exe", "sqltoolsps.exe", "powershell_ise.exe") @@ -25,6 +19,14 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `suspicious_copy_on_system32_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: every user may do this event but very un-ussual. +references: +- https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120 tags: analytic_story: - Unusual Processes @@ -66,5 +68,3 @@ tags: - _time risk_score: 63 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml b/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml index 253355fc54..432c29cf7c 100644 --- a/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml @@ -1,30 +1,32 @@ +name: Suspicious DLLHost no Command Line Arguments +id: ff61e98c-0337-4593-a78f-72a676c56f26 +version: 2 +date: '2021-09-20' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-09-20' description: The following analytic identifies DLLHost.exe with no command line arguments. It is unusual for DLLHost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. DLLHost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: ff61e98c-0337-4593-a78f-72a676c56f26 -known_false_positives: Limited false positives may be present in small environments. - Tuning may be required based on parent process. -name: Suspicious DLLHost no Command Line Arguments -references: -- https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile -- https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_dllhost` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | regex process="(dllhost\.exe.{0,4}$)" | `suspicious_dllhost_no_command_line_arguments_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Limited false positives may be present in small environments. + Tuning may be required based on parent process. +references: +- https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile +- https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ tags: analytic_story: - Cobalt Strike @@ -67,5 +69,3 @@ tags: - _time risk_score: 49 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/suspicious_driver_loaded_path.yml b/detections/endpoint/suspicious_driver_loaded_path.yml index 50bee627d0..05acf88799 100644 --- a/detections/endpoint/suspicious_driver_loaded_path.yml +++ b/detections/endpoint/suspicious_driver_loaded_path.yml @@ -1,6 +1,10 @@ -author: Teoderick Contreras, Splunk -datamodel: [] +name: Suspicious Driver Loaded Path +id: f880acd4-a8f1-11eb-a53b-acde48001122 +version: 1 date: '2021-04-29' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: [] description: This analytic will detect suspicious driver loaded paths. This technique is commonly used by malicious software like coin miners (xmrig) to register its malicious driver from notable directories where executable or drivers do not commonly @@ -9,21 +13,19 @@ description: This analytic will detect suspicious driver loaded paths. This tech is not normal, but occurs. In addition, review driver loads into `ntoskrnl.exe` for possible other drivers of interest. Long tail analyze drivers by path (outside of default, and in default) for further review. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the driver loaded and Signature from your endpoints. If you are using - Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -id: f880acd4-a8f1-11eb-a53b-acde48001122 -known_false_positives: Limited false positives will be present. Some applications - do load drivers -name: Suspicious Driver Loaded Path -references: -- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ -- https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/ search: '`sysmon` EventCode=6 ImageLoaded = "*.sys" NOT (ImageLoaded IN("*\\WINDOWS\\inf","*\\WINDOWS\\System32\\drivers\\*", "*\\WINDOWS\\System32\\DriverStore\\FileRepository\\*")) | stats min(_time) as firstTime max(_time) as lastTime count by Computer ImageLoaded Hashes IMPHASH Signature Signed | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_driver_loaded_path_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the driver loaded and Signature from your endpoints. If you are using + Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +known_false_positives: Limited false positives will be present. Some applications + do load drivers +references: +- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ +- https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/ tags: analytic_story: - XMRig @@ -65,5 +67,3 @@ tags: - Signed risk_score: 63 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml b/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml index 9baa0a3d93..520395e1be 100644 --- a/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml @@ -1,29 +1,31 @@ +name: Suspicious GPUpdate no Command Line Arguments +id: f308490a-473a-40ef-ae64-dd7a6eba284a +version: 2 +date: '2021-09-20' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-09-20' description: The following analytic identifies gpupdate.exe with no command line arguments. It is unusual for gpupdate.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. gpupdate.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: f308490a-473a-40ef-ae64-dd7a6eba284a -known_false_positives: Limited false positives may be present in small environments. - Tuning may be required based on parent process. -name: Suspicious GPUpdate no Command Line Arguments -references: -- https://raw.githubusercontent.com/xx0hcd/Malleable-C2-Profiles/0ef8cf4556e26f6d4190c56ba697c2159faa5822/crimeware/trick_ryuk.profile -- https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_gpupdate` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | regex process="(gpupdate\.exe.{0,4}$)" | `suspicious_gpupdate_no_command_line_arguments_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: Limited false positives may be present in small environments. + Tuning may be required based on parent process. +references: +- https://raw.githubusercontent.com/xx0hcd/Malleable-C2-Profiles/0ef8cf4556e26f6d4190c56ba697c2159faa5822/crimeware/trick_ryuk.profile +- https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ tags: analytic_story: - Cobalt Strike @@ -66,5 +68,3 @@ tags: - _time risk_score: 49 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml index b925ff0751..8a0416901a 100644 --- a/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml +++ b/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml @@ -1,27 +1,29 @@ +name: Suspicious IcedID Rundll32 Cmdline +id: bed761f8-ee29-11eb-8bf3-acde48001122 +version: 2 +date: '2021-07-26' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-07-26' description: This search is to detect a suspicious rundll32.exe commandline to execute dll file. This technique was seen in IcedID malware to load its payload dll with the following parameter to load encrypted dll payload which is the license.dat. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: bed761f8-ee29-11eb-8bf3-acde48001122 -known_false_positives: limitted. this parameter is not commonly used by windows application - but can be used by the network operator. -name: Suspicious IcedID Rundll32 Cmdline -references: -- https://threatpost.com/icedid-banking-trojan-surges-emotet/165314/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*/i:* by Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.process_id Processes.parent_process_id Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_icedid_rundll32_cmdline_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: limitted. this parameter is not commonly used by windows application + but can be used by the network operator. +references: +- https://threatpost.com/icedid-banking-trojan-surges-emotet/165314/ tags: analytic_story: - IcedID @@ -64,5 +66,3 @@ tags: - _time risk_score: 56 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml b/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml index e53fd98af9..bda0298696 100644 --- a/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml +++ b/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml @@ -1,23 +1,17 @@ +name: Suspicious Image Creation In Appdata Folder +id: f6f904c4-1ac0-11ec-806b-acde48001122 +version: 1 +date: '2021-09-21' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-09-21' description: This search is to detect a suspicious creation of image in appdata folder made by process that also has a file reference in appdata folder. This technique was seen in remcos rat that capture screenshot of the compromised machine and place it in the appdata and will be send to its C2 server. This TTP is really a good indicator to check that process because it is in suspicious folder path and image files are not commonly created by user in this folder path. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: f6f904c4-1ac0-11ec-806b-acde48001122 -known_false_positives: unknown -name: Suspicious Image Creation In Appdata Folder -references: -- https://success.trendmicro.com/solution/1123281-remcos-malware-information -- https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=*.exe Processes.process_path="*\\appdata\\Roaming\\*" by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest @@ -28,6 +22,14 @@ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint Filesystem.file_name Filesystem.file_path | `drop_dm_object_name(Filesystem)` | fields _time dest file_create_time file_name file_path process_name process_path process] | `suspicious_image_creation_in_appdata_folder_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: unknown +references: +- https://success.trendmicro.com/solution/1123281-remcos-malware-information +- https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/ tags: analytic_story: - Remcos @@ -77,5 +79,3 @@ tags: - process_path risk_score: 49 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/suspicious_kerberos_service_ticket_request.yml b/detections/endpoint/suspicious_kerberos_service_ticket_request.yml index e27771f62a..da789f228c 100644 --- a/detections/endpoint/suspicious_kerberos_service_ticket_request.yml +++ b/detections/endpoint/suspicious_kerberos_service_ticket_request.yml @@ -1,6 +1,10 @@ -author: Mauricio Velazco, Splunk -datamodel: [] +name: Suspicious Kerberos Service Ticket Request +id: 8b1297bc-6204-11ec-b7c4-acde48001122 +version: 1 date: '2021-12-20' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] description: As part of the sAMAccountName Spoofing (CVE-2021-42278) and Domain Controller Impersonation (CVE-2021-42287) exploitation chain, adversaries will request and obtain a Kerberos Service Ticket (TGS) with a domain controller computer account @@ -10,23 +14,21 @@ description: As part of the sAMAccountName Spoofing (CVE-2021-42278) and Domain where the Account_Name requesting the ticket matches the Service_Name field. This behavior could represent an exploitation attempt of CVE-2021-42278 and CVE-2021-42287 for privilege escalation. +search: ' `wineventlog_security` EventCode=4769 | eval isSuspicious = if(lower(Service_Name) + = lower(mvindex(split(Account_Name,"@"),0)+"$"),1,0) | where isSuspicious = 1 | + table _time, Client_Address, Account_Name, Service_Name, Failure_Code, isSuspicious + | `suspicious_kerberos_service_ticket_request_filter`' how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. -id: 8b1297bc-6204-11ec-b7c4-acde48001122 known_false_positives: We have tested this detection logic with ~2 million 4769 events and did not identify false positives. However, they may be possible in certain environments. Filter as needed. -name: Suspicious Kerberos Service Ticket Request references: - https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278 - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287 - https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-sfu/02636893-7a1f-4357-af9a-b672e3e3de13 -search: ' `wineventlog_security` EventCode=4769 | eval isSuspicious = if(lower(Service_Name) - = lower(mvindex(split(Account_Name,"@"),0)+"$"),1,0) | where isSuspicious = 1 | - table _time, Client_Address, Account_Name, Service_Name, Failure_Code, isSuspicious - | `suspicious_kerberos_service_ticket_request_filter`' tags: analytic_story: - sAMAccountName Spoofing and Domain Controller Impersonation @@ -65,5 +67,3 @@ tags: - Failure_Code risk_score: 60 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml index 114b9b95d5..937b90d5f9 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml @@ -1,31 +1,33 @@ +name: Suspicious microsoft workflow compiler rename +id: f0db4464-55d9-11eb-ae93-0242ac130002 +version: 3 +date: '2021-09-20' author: Michael Haag, Splunk +type: Hunting datamodel: - Endpoint -date: '2021-09-20' description: The following analytic identifies a renamed instance of microsoft.workflow.compiler.exe. Microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and is rarely utilized. When investigating, identify the executed code on disk and review. A spawned child process from microsoft.workflow.compiler.exe is uncommon. In any instance, microsoft.workflow.compiler.exe spawning from an Office product or any living off the land binary is highly suspect. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: f0db4464-55d9-11eb-ae93-0242ac130002 -known_false_positives: Although unlikely, some legitimate applications may use a moved - copy of microsoft.workflow.compiler.exe, triggering a false positive. -name: Suspicious microsoft workflow compiler rename -references: -- https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_microsoftworkflowcompiler` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_microsoft_workflow_compiler_rename_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Although unlikely, some legitimate applications may use a moved + copy of microsoft.workflow.compiler.exe, triggering a false positive. +references: +- https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution tags: analytic_story: - Trusted Developer Utilities Proxy Execution @@ -80,5 +82,3 @@ tags: - _time risk_score: 63 security_domain: endpoint -type: Hunting -version: 3 diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml index c0c47a1f10..50a4932709 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml @@ -1,28 +1,30 @@ +name: Suspicious microsoft workflow compiler usage +id: 9bbc62e8-55d8-11eb-ae93-0242ac130002 +version: 2 +date: '2021-01-12' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-01-12' description: The following analytic identifies microsoft.workflow.compiler.exe usage. microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and is rarely utilized. When investigating, identify the executed code on disk and review. It is not a commonly used process by many applications. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: 9bbc62e8-55d8-11eb-ae93-0242ac130002 -known_false_positives: Although unlikely, limited instances have been identified coming - from native Microsoft utilities similar to SCCM. -name: Suspicious microsoft workflow compiler usage -references: -- https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_microsoftworkflowcompiler` by Processes.dest Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_microsoft_workflow_compiler_usage_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Although unlikely, limited instances have been identified coming + from native Microsoft utilities similar to SCCM. +references: +- https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution tags: analytic_story: - Trusted Developer Utilities Proxy Execution @@ -68,5 +70,3 @@ tags: - _time risk_score: 35 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/suspicious_msbuild_path.yml b/detections/endpoint/suspicious_msbuild_path.yml index 194b5e5edb..2511f9b91e 100644 --- a/detections/endpoint/suspicious_msbuild_path.yml +++ b/detections/endpoint/suspicious_msbuild_path.yml @@ -1,32 +1,34 @@ +name: Suspicious msbuild path +id: f5198224-551c-11eb-ae93-0242ac130002 +version: 2 +date: '2021-01-12' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-01-12' description: The following analytic identifies msbuild.exe executing from a non-standard path. Msbuild.exe is natively found in C:\Windows\Microsoft.NET\Framework\v4.0.30319 and C:\Windows\Microsoft.NET\Framework64\v4.0.30319. Instances of Visual Studio will run a copy of msbuild.exe. A moved instance of MSBuild is suspicious, however there are instances of build applications that will move or use a copy of MSBuild. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: f5198224-551c-11eb-ae93-0242ac130002 -known_false_positives: Some legitimate applications may use a moved copy of msbuild.exe, - triggering a false positive. Baselining of MSBuild.exe usage is recommended to better - understand it's path usage. Visual Studio runs an instance out of a path that will - need to be filtered on. -name: Suspicious msbuild path -references: -- https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md search: '| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_msbuild` AND (Processes.process_path!=c:\\windows\\microsoft.net\\framework*\\v*\\*) by Processes.dest Processes.original_file_name Processes.parent_process Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `suspicious_msbuild_path_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Some legitimate applications may use a moved copy of msbuild.exe, + triggering a false positive. Baselining of MSBuild.exe usage is recommended to better + understand it's path usage. Visual Studio runs an instance out of a path that will + need to be filtered on. +references: +- https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md tags: analytic_story: - Trusted Developer Utilities Proxy Execution MSBuild @@ -80,5 +82,3 @@ tags: - _time risk_score: 49 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/suspicious_msbuild_rename.yml b/detections/endpoint/suspicious_msbuild_rename.yml index b4bfdc05b6..b89616ff49 100644 --- a/detections/endpoint/suspicious_msbuild_rename.yml +++ b/detections/endpoint/suspicious_msbuild_rename.yml @@ -1,30 +1,32 @@ +name: Suspicious MSBuild Rename +id: 4006adac-5937-11eb-ae93-0242ac130002 +version: 2 +date: '2021-01-12' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-01-12' description: The following analytic identifies renamed instances of msbuild.exe executing. Msbuild.exe is natively found in C:\Windows\Microsoft.NET\Framework\v4.0.30319 and C:\Windows\Microsoft.NET\Framework64\v4.0.30319. During investigation, identify the code executed and what is executing a renamed instance of MSBuild. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: 4006adac-5937-11eb-ae93-0242ac130002 -known_false_positives: Although unlikely, some legitimate applications may use a moved - copy of msbuild, triggering a false positive. -name: Suspicious MSBuild Rename -references: -- https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md -- https://github.com/infosecn1nja/MaliciousMacroMSBuild/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_msbuild` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_msbuild_rename_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Although unlikely, some legitimate applications may use a moved + copy of msbuild, triggering a false positive. +references: +- https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md +- https://github.com/infosecn1nja/MaliciousMacroMSBuild/ tags: analytic_story: - Trusted Developer Utilities Proxy Execution MSBuild @@ -79,5 +81,3 @@ tags: - _time risk_score: 63 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/suspicious_msbuild_spawn.yml b/detections/endpoint/suspicious_msbuild_spawn.yml index 1250c97154..49f90934c9 100644 --- a/detections/endpoint/suspicious_msbuild_spawn.yml +++ b/detections/endpoint/suspicious_msbuild_spawn.yml @@ -1,7 +1,11 @@ +name: Suspicious MSBuild Spawn +id: a115fba6-5514-11eb-ae93-0242ac130002 +version: 2 +date: '2021-01-12' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-01-12' description: The following analytic identifies wmiprvse.exe spawning msbuild.exe. This behavior is indicative of a COM object being utilized to spawn msbuild from wmiprvse.exe. It is common for MSBuild.exe to be spawned from devenv.exe while using @@ -9,24 +13,22 @@ description: The following analytic identifies wmiprvse.exe spawning msbuild.exe In a malicious instance, MSBuild.exe will spawn from non-standard processes and have no command line arguments. For example, MSBuild.exe spawning from explorer.exe, powershell.exe is far less common and should be investigated. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: a115fba6-5514-11eb-ae93-0242ac130002 -known_false_positives: Although unlikely, some legitimate applications may exhibit - this behavior, triggering a false positive. -name: Suspicious MSBuild Spawn -references: -- https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md search: '| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=wmiprvse.exe AND `process_msbuild` by Processes.dest Processes.parent_process Processes.original_file_name Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_msbuild_spawn_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Although unlikely, some legitimate applications may exhibit + this behavior, triggering a false positive. +references: +- https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md tags: analytic_story: - Trusted Developer Utilities Proxy Execution MSBuild @@ -75,5 +77,3 @@ tags: - _time risk_score: 42 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/suspicious_mshta_child_process.yml b/detections/endpoint/suspicious_mshta_child_process.yml index e94c2ffe6f..35dccdd5bb 100644 --- a/detections/endpoint/suspicious_mshta_child_process.yml +++ b/detections/endpoint/suspicious_mshta_child_process.yml @@ -1,22 +1,15 @@ +name: Suspicious mshta child process +id: 60023bb6-5500-11eb-ae93-0242ac130002 +version: 1 +date: '2021-01-12' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-01-12' description: The following analytic identifies child processes spawning from "mshta.exe". The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, parent process "mshta.exe" and its child process. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 60023bb6-5500-11eb-ae93-0242ac130002 -known_false_positives: Although unlikely, some legitimate applications may exhibit - this behavior, triggering a false positive. -name: Suspicious mshta child process -references: -- https://github.com/redcanaryco/AtomicTestHarnesses -- https://redcanary.com/blog/introducing-atomictestharnesses/ search: '| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=mshta.exe @@ -27,6 +20,15 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces OR Processes.process_name=cmd.exe) by Processes.dest Processes.parent_process Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_mshta_child_process_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: Although unlikely, some legitimate applications may exhibit + this behavior, triggering a false positive. +references: +- https://github.com/redcanaryco/AtomicTestHarnesses +- https://redcanary.com/blog/introducing-atomictestharnesses/ tags: analytic_story: - Suspicious MSHTA Activity @@ -77,5 +79,3 @@ tags: - _time risk_score: 40 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/suspicious_mshta_spawn.yml b/detections/endpoint/suspicious_mshta_spawn.yml index e041fa0e08..43a22fda38 100644 --- a/detections/endpoint/suspicious_mshta_spawn.yml +++ b/detections/endpoint/suspicious_mshta_spawn.yml @@ -1,30 +1,32 @@ +name: Suspicious mshta spawn +id: 4d33a488-5b5f-11eb-ae93-0242ac130002 +version: 2 +date: '2021-01-20' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-01-20' description: The following analytic identifies wmiprvse.exe spawning mshta.exe. This behavior is indicative of a DCOM object being utilized to spawn mshta from wmiprvse.exe or svchost.exe. In this instance, adversaries may use LethalHTA that will spawn mshta.exe from svchost.exe. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: 4d33a488-5b5f-11eb-ae93-0242ac130002 -known_false_positives: Although unlikely, some legitimate applications may exhibit - this behavior, triggering a false positive. -name: Suspicious mshta spawn -references: -- https://codewhitesec.blogspot.com/2018/07/lethalhta.html -- https://github.com/redcanaryco/AtomicTestHarnesses -- https://redcanary.com/blog/introducing-atomictestharnesses/ search: '| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=svchost.exe OR Processes.parent_process_name=wmiprvse.exe) AND `process_mshta` by Processes.dest Processes.parent_process Processes.user Processes.original_file_name| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_mshta_spawn_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Although unlikely, some legitimate applications may exhibit + this behavior, triggering a false positive. +references: +- https://codewhitesec.blogspot.com/2018/07/lethalhta.html +- https://github.com/redcanaryco/AtomicTestHarnesses +- https://redcanary.com/blog/introducing-atomictestharnesses/ tags: analytic_story: - Suspicious MSHTA Activity @@ -69,5 +71,3 @@ tags: - _time risk_score: 42 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml b/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml index 9f652a3585..c3f5dcbc11 100644 --- a/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml +++ b/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml @@ -1,6 +1,10 @@ -author: Teoderick Contreras, Splunk -datamodel: [] +name: Suspicious Process DNS Query Known Abuse Web Services +id: 3cf0dc36-484d-11ec-a6bc-acde48001122 +version: 1 date: '2021-11-18' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: [] description: This analytic detects a suspicious process making a DNS query via known, abused text-paste web services, VoIP, instant messaging, and digital distribution platforms used to download external files. This technique is abused by adversaries, @@ -8,20 +12,18 @@ description: This analytic detects a suspicious process making a DNS query via k is a good TTP indicator for possible initial access techniques. A user will experience false positives if the following instant messaging is allowed or common applications like telegram or discord are allowed in the corporate network. -how_to_implement: This detection relies on sysmon logs with the Event ID 22, DNS Query. - We suggest you run this detection at least once a day over the last 14 days. -id: 3cf0dc36-484d-11ec-a6bc-acde48001122 -known_false_positives: Noise and false positive can be seen if the following instant - messaging is allowed to use within corporate network. In this case, a filter is - needed. -name: Suspicious Process DNS Query Known Abuse Web Services -references: -- https://urlhaus.abuse.ch/url/1798923/ search: '`sysmon` EventCode=22 QueryName IN ("*pastebin*", "*discord*", "*telegram*", "*t.me*") process_name IN ("cmd.exe", "*powershell*", "pwsh.exe", "wscript.exe", "cscript.exe") | stats count min(_time) as firstTime max(_time) as lastTime by Image QueryName QueryStatus process_name QueryResults Computer | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_process_dns_query_known_abuse_web_services_filter`' +how_to_implement: This detection relies on sysmon logs with the Event ID 22, DNS Query. + We suggest you run this detection at least once a day over the last 14 days. +known_false_positives: Noise and false positive can be seen if the following instant + messaging is allowed to use within corporate network. In this case, a filter is + needed. +references: +- https://urlhaus.abuse.ch/url/1798923/ tags: analytic_story: - Remcos @@ -62,5 +64,3 @@ tags: - Computer risk_score: 64 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/endpoint/suspicious_process_file_path.yml index 47a48cc8d5..4007a45a00 100644 --- a/detections/endpoint/suspicious_process_file_path.yml +++ b/detections/endpoint/suspicious_process_file_path.yml @@ -1,20 +1,15 @@ +name: Suspicious Process File Path +id: 9be25988-ad82-11eb-a14f-acde48001122 +version: 1 +date: '2021-05-05' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-05-05' description: The following analytic will detect a suspicious process running in a file path where a process is not commonly seen and is most commonly used by malicious softtware. This behavior has been used by adversaries where they drop and run an exe in a path that is accessible without admin privileges. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. -id: 9be25988-ad82-11eb-a14f-acde48001122 -known_false_positives: Administrators may allow execution of specific binaries in - non-standard paths. Filter as needed. -name: Suspicious Process File Path -references: -- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ search: '| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_path = "*\\windows\\fonts\\*" @@ -27,6 +22,13 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.parent_process Processes.process_path Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_process_file_path_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +known_false_positives: Administrators may allow execution of specific binaries in + non-standard paths. Filter as needed. +references: +- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ tags: analytic_story: - XMRig @@ -70,5 +72,3 @@ tags: - _time risk_score: 35 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index c1ce40ccc8..156a75f65a 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -1,22 +1,14 @@ +name: Suspicious Reg exe Process +id: a6b3ab4e-dd77-4213-95fa-fc94701995e0 +version: 4 +date: '2020-07-22' author: David Dorsey, Splunk +type: TTP datamodel: - Endpoint -date: '2020-07-22' description: This search looks for reg.exe being launched from a command prompt not started by the user. When a user launches cmd.exe, the parent process is usually explorer.exe. This search filters out those instances. -how_to_implement: You must be ingesting data that records process activity from your - hosts to populate the Endpoint data model in the Processes node. You must also be - ingesting logs with both the process name and command line from your endpoints. - The command-line arguments are mapped to the "process" field in the Endpoint data - model. -id: a6b3ab4e-dd77-4213-95fa-fc94701995e0 -known_false_positives: It's possible for system administrators to write scripts that - exhibit this behavior. If this is the case, the search will need to be modified - to filter them out. -name: Suspicious Reg exe Process -references: -- https://car.mitre.org/wiki/CAR-2013-03-001 search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.parent_process_name != explorer.exe Processes.process_name =cmd.exe by Processes.user Processes.process_name @@ -27,6 +19,16 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.dest Processes.process_name | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | rename parent_process_id as process_id |dedup process_id| table process_id dest] | `suspicious_reg_exe_process_filter` ' +how_to_implement: You must be ingesting data that records process activity from your + hosts to populate the Endpoint data model in the Processes node. You must also be + ingesting logs with both the process name and command line from your endpoints. + The command-line arguments are mapped to the "process" field in the Endpoint data + model. +known_false_positives: It's possible for system administrators to write scripts that + exhibit this behavior. If this is the case, the search will need to be modified + to filter them out. +references: +- https://car.mitre.org/wiki/CAR-2013-03-001 tags: analytic_story: - Windows Defense Evasion Tactics @@ -75,5 +77,3 @@ tags: - _time risk_score: 35 security_domain: endpoint -type: TTP -version: 4 diff --git a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml index 76a8b56720..2bbb2787ba 100644 --- a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml +++ b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml @@ -1,11 +1,22 @@ +name: Suspicious Regsvr32 Register Suspicious Path +id: 62732736-6250-11eb-ae93-0242ac130002 +version: 2 +date: '2021-01-28' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-01-28' description: Adversaries may abuse Regsvr32.exe to proxy execution of malicious code by using non-standard file extensions to load malciious DLLs. Upon investigating, look for network connections to remote destinations (internal or external). Review additional parrallel processes and child processes for additional activity. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` (Processes.process=*appdata* + OR Processes.process=*programdata* OR Processes.process=*windows\temp*) (Processes.process!=*.dll + Processes.process!=*.ax Processes.process!=*.ocx) by Processes.dest Processes.user + Processes.parent_process Processes.process_name Processes.process Processes.original_file_name + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `suspicious_regsvr32_register_suspicious_path_filter`' how_to_implement: You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" @@ -15,23 +26,14 @@ how_to_implement: You must be ingesting endpoint data that tracks process activi responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. -id: 62732736-6250-11eb-ae93-0242ac130002 known_false_positives: Limited false positives with the query restricted to specified paths. Add more world writeable paths as tuning continues. -name: Suspicious Regsvr32 Register Suspicious Path references: - https://attack.mitre.org/techniques/T1218/010/ - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md - https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/ - https://support.microsoft.com/en-us/topic/how-to-use-the-regsvr32-tool-and-troubleshoot-regsvr32-error-messages-a98d960a-7392-e6fe-d90a-3f4e0cb543e5 - https://any.run/report/f29a7d2ecd3585e1e4208e44bcc7156ab5388725f1d29d03e7699da0d4598e7c/0826458b-5367-45cf-b841-c95a33a01718 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` (Processes.process=*appdata* - OR Processes.process=*programdata* OR Processes.process=*windows\temp*) (Processes.process!=*.dll - Processes.process!=*.ax Processes.process!=*.ocx) by Processes.dest Processes.user - Processes.parent_process Processes.process_name Processes.process Processes.original_file_name - Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `suspicious_regsvr32_register_suspicious_path_filter`' tags: analytic_story: - Suspicious Regsvr32 Activity @@ -83,5 +85,3 @@ tags: - _time risk_score: 35 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml index e300194585..c3bb588821 100644 --- a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml +++ b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml @@ -1,7 +1,11 @@ +name: Suspicious Rundll32 dllregisterserver +id: 8c00a385-9b86-4ac0-8932-c9ec3713b159 +version: 2 +date: '2021-02-09' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-02-09' description: The following analytic identifies rundll32.exe using dllregisterserver on the command line to load a DLL. When a DLL is registered, the DllRegisterServer method entry point in the DLL is invoked. This is typically seen when a DLL is being @@ -9,16 +13,20 @@ description: The following analytic identifies rundll32.exe using dllregisterser capture malicious use of it. During investigation, review the parent process and parrellel processes executing. Capture the DLL being loaded and inspect further. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*dllregisterserver* + by Processes.dest Processes.user Processes.parent_process Processes.original_file_name + Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `suspicious_rundll32_dllregisterserver_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. -id: 8c00a385-9b86-4ac0-8932-c9ec3713b159 known_false_positives: This is likely to produce false positives and will require some filtering. Tune the query by adding command line paths to known good DLLs, or filtering based on parent process names. -name: Suspicious Rundll32 dllregisterserver references: - https://attack.mitre.org/techniques/T1218/011/ - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md @@ -27,12 +35,6 @@ references: - https://github.com/pan-unit42/tweets/blob/master/2020-12-10-IOCs-from-Ursnif-infection-with-Delf-variant.txt - https://www.crowdstrike.com/blog/duck-hunting-with-falcon-complete-qakbot-zip-based-campaign/ - https://msdn.microsoft.com/en-us/library/windows/desktop/ms682162(v=vs.85).aspx -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*dllregisterserver* - by Processes.dest Processes.user Processes.parent_process Processes.original_file_name - Processes.process_name Processes.process Processes.process_id Processes.parent_process_id - | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `suspicious_rundll32_dllregisterserver_filter`' tags: analytic_story: - Suspicious Rundll32 Activity @@ -83,5 +85,3 @@ tags: - _time risk_score: 35 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/suspicious_rundll32_plugininit.yml b/detections/endpoint/suspicious_rundll32_plugininit.yml index afb9e79d41..218288e282 100644 --- a/detections/endpoint/suspicious_rundll32_plugininit.yml +++ b/detections/endpoint/suspicious_rundll32_plugininit.yml @@ -1,27 +1,29 @@ +name: Suspicious Rundll32 PluginInit +id: 92d51712-ee29-11eb-b1ae-acde48001122 +version: 2 +date: '2021-07-26' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-07-26' description: This search is to detect a suspicious rundll32.exe process with plugininit parameter. This technique is commonly seen in IceID malware to execute its initial dll stager to download another payload to the compromised machine. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: 92d51712-ee29-11eb-b1ae-acde48001122 -known_false_positives: third party application may used this dll export name to execute - function. -name: Suspicious Rundll32 PluginInit -references: -- https://threatpost.com/icedid-banking-trojan-surges-emotet/165314/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*PluginInit* by Processes.process_name Processes.process Processes.parent_process_name Processes.original_file_name Processes.parent_process Processes.process_id Processes.parent_process_id Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_rundll32_plugininit_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: third party application may used this dll export name to execute + function. +references: +- https://threatpost.com/icedid-banking-trojan-surges-emotet/165314/ tags: analytic_story: - IcedID @@ -65,5 +67,3 @@ tags: - _time risk_score: 42 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/suspicious_rundll32_rename.yml b/detections/endpoint/suspicious_rundll32_rename.yml index 9b870f81aa..663230d89f 100644 --- a/detections/endpoint/suspicious_rundll32_rename.yml +++ b/detections/endpoint/suspicious_rundll32_rename.yml @@ -1,32 +1,34 @@ +name: Suspicious Rundll32 Rename +id: 7360137f-abad-473e-8189-acbdaa34d114 +version: 3 +date: '2021-02-04' author: Michael Haag, Splunk +type: Hunting datamodel: - Endpoint -date: '2021-02-04' description: The following analytic identifies renamed instances of rundll32.exe executing. rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During investigation, validate it is the legitimate rundll32.exe executing and what script content it is loading. This query relies on the original filename or internal name from the PE meta data. Expand the query as needed by looking for specific command line arguments outlined in other analytics. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: 7360137f-abad-473e-8189-acbdaa34d114 -known_false_positives: Although unlikely, some legitimate applications may use a moved - copy of rundll32, triggering a false positive. -name: Suspicious Rundll32 Rename -references: -- https://attack.mitre.org/techniques/T1218/011/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md -- https://lolbas-project.github.io/lolbas/Binaries/Rundll32 search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_rundll32_rename_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Although unlikely, some legitimate applications may use a moved + copy of rundll32, triggering a false positive. +references: +- https://attack.mitre.org/techniques/T1218/011/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md +- https://lolbas-project.github.io/lolbas/Binaries/Rundll32 tags: analytic_story: - Suspicious Rundll32 Activity @@ -80,5 +82,3 @@ tags: - _time risk_score: 63 security_domain: endpoint -type: Hunting -version: 3 diff --git a/detections/endpoint/suspicious_rundll32_startw.yml b/detections/endpoint/suspicious_rundll32_startw.yml index d723ad3f03..dce331a3f8 100644 --- a/detections/endpoint/suspicious_rundll32_startw.yml +++ b/detections/endpoint/suspicious_rundll32_startw.yml @@ -1,7 +1,11 @@ +name: Suspicious Rundll32 StartW +id: 9319dda5-73f2-4d43-a85a-67ce961bddb7 +version: 3 +date: '2021-02-04' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-02-04' description: The following analytic identifies rundll32.exe executing a DLL function name, Start and StartW, on the command line that is commonly observed with Cobalt Strike x86 and x64 DLL payloads. Rundll32.exe is natively found in C:\Windows\system32 @@ -11,27 +15,25 @@ description: The following analytic identifies rundll32.exe executing a DLL func execution. Capture and triage the DLL in question. In the instance of Cobalt Strike, rundll32.exe is the default process it opens and injects shellcode into. This default process can be changed, but typically is not. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: 9319dda5-73f2-4d43-a85a-67ce961bddb7 -known_false_positives: Although unlikely, some legitimate applications may use Start - as a function and call it via the command line. Filter as needed. -name: Suspicious Rundll32 StartW -references: -- https://attack.mitre.org/techniques/T1218/011/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md -- https://www.cobaltstrike.com/help-windows-executable -- https://lolbas-project.github.io/lolbas/Binaries/Rundll32 -- https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*start* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_rundll32_startw_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Although unlikely, some legitimate applications may use Start + as a function and call it via the command line. Filter as needed. +references: +- https://attack.mitre.org/techniques/T1218/011/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md +- https://www.cobaltstrike.com/help-windows-executable +- https://lolbas-project.github.io/lolbas/Binaries/Rundll32 +- https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ tags: analytic_story: - Suspicious Rundll32 Activity @@ -84,5 +86,3 @@ tags: - _time risk_score: 35 security_domain: endpoint -type: TTP -version: 3 diff --git a/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml b/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml index 0df19aa1b5..75adeb031e 100644 --- a/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml @@ -1,32 +1,34 @@ +name: Suspicious Rundll32 no Command Line Arguments +id: e451bd16-e4c5-4109-8eb1-c4c6ecf048b4 +version: 2 +date: '2021-09-20' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-09-20' description: The following analytic identifies rundll32.exe with no command line arguments. It is unusual for rundll32.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: e451bd16-e4c5-4109-8eb1-c4c6ecf048b4 -known_false_positives: Although unlikely, some legitimate applications may use a moved - copy of rundll32, triggering a false positive. -name: Suspicious Rundll32 no Command Line Arguments -references: -- https://attack.mitre.org/techniques/T1218/011/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md -- https://lolbas-project.github.io/lolbas/Binaries/Rundll32 -- https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_rundll32` by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | regex process="(rundll32\.exe.{0,4}$)" | `suspicious_rundll32_no_command_line_arguments_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Although unlikely, some legitimate applications may use a moved + copy of rundll32, triggering a false positive. +references: +- https://attack.mitre.org/techniques/T1218/011/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md +- https://lolbas-project.github.io/lolbas/Binaries/Rundll32 +- https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ tags: analytic_story: - Suspicious Rundll32 Activity @@ -80,5 +82,3 @@ tags: - _time risk_score: 49 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml index 83957edc0c..d8f5df1db5 100644 --- a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml +++ b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml @@ -1,22 +1,17 @@ +name: Suspicious Scheduled Task from Public Directory +id: 7feb7972-7ac3-11eb-bac8-acde48001122 +version: 1 +date: '2021-03-01' author: Michael Haag, Splunk +type: Anomaly datamodel: - Endpoint -date: '2021-03-01' description: The following detection identifies Scheduled Tasks registering (creating a new task) a binary or script to run from a public directory which includes users\public, \programdata\ and \windows\temp. Upon triage, review the binary or script in the command line for legitimacy, whether an approved binary/script or not. In addition, capture the binary or script in question and analyze for further behaviors. Identify the source and contain the endpoint. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. -id: 7feb7972-7ac3-11eb-bac8-acde48001122 -known_false_positives: Limited false positives may be present. Filter as needed by - parent process or command line argument. -name: Suspicious Scheduled Task from Public Directory -references: -- https://attack.mitre.org/techniques/T1053/005/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process=*\\users\\public\\* OR Processes.process=*\\programdata\\* OR @@ -24,6 +19,13 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `suspicious_scheduled_task_from_public_directory_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +known_false_positives: Limited false positives may be present. Filter as needed by + parent process or command line argument. +references: +- https://attack.mitre.org/techniques/T1053/005/ tags: analytic_story: - Ransomware @@ -70,5 +72,3 @@ tags: - _time risk_score: 35 security_domain: endpoint -type: Anomaly -version: 1 diff --git a/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml b/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml index 48eb070fd9..db7ac9d13d 100644 --- a/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml @@ -1,7 +1,11 @@ +name: Suspicious SearchProtocolHost no Command Line Arguments +id: f52d2db8-31f9-4aa7-a176-25779effe55c +version: 2 +date: '2021-09-20' author: Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-09-20' description: The following analytic identifies searchprotocolhost.exe with no command line arguments. It is unusual for searchprotocolhost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, @@ -9,22 +13,20 @@ description: The following analytic identifies searchprotocolhost.exe with no co and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. searchprotocolhost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: f52d2db8-31f9-4aa7-a176-25779effe55c -known_false_positives: Limited false positives may be present in small environments. - Tuning may be required based on parent process. -name: Suspicious SearchProtocolHost no Command Line Arguments -references: -- https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=searchprotocolhost.exe by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | regex process="(searchprotocolhost\.exe.{0,4}$)" | `suspicious_searchprotocolhost_no_command_line_arguments_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Limited false positives may be present in small environments. + Tuning may be required based on parent process. +references: +- https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc tags: analytic_story: - Cobalt Strike @@ -67,5 +69,3 @@ tags: - _time risk_score: 49 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/suspicious_ticket_granting_ticket_request.yml b/detections/endpoint/suspicious_ticket_granting_ticket_request.yml index 8854aa6726..5f3199e334 100644 --- a/detections/endpoint/suspicious_ticket_granting_ticket_request.yml +++ b/detections/endpoint/suspicious_ticket_granting_ticket_request.yml @@ -1,6 +1,10 @@ -author: Mauricio Velazco, Splunk -datamodel: [] +name: Suspicious Ticket Granting Ticket Request +id: d77d349e-6269-11ec-9cfe-acde48001122 +version: 1 date: '2021-12-21' +author: Mauricio Velazco, Splunk +type: Hunting +datamodel: [] description: As part of the sAMAccountName Spoofing (CVE-2021-42278) and Domain Controller Impersonation (CVE-2021-42287) exploitation chain, adversaries will need to request a Kerberos Ticket Granting Ticket (TGT) on behalf of the newly created and renamed @@ -10,24 +14,22 @@ description: As part of the sAMAccountName Spoofing (CVE-2021-42278) and Domain a sequence of events where the new computer account on event id 4781 matches the request account on event id 4768. This behavior could represent an exploitation attempt of CVE-2021-42278 and CVE-2021-42287 for privilege escalation. -how_to_implement: To successfully implement this search, you need to be ingesting - Domain Controller and Kerberos events. The Advanced Security Audit policy setting - `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. -id: d77d349e-6269-11ec-9cfe-acde48001122 -known_false_positives: A computer account name change event inmediately followed by - a kerberos TGT request with matching fields is unsual. However, legitimate behavior - may trigger it. Filter as needed. -name: Suspicious Ticket Granting Ticket Request -references: -- https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html -- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278 -- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287 search: ' `wineventlog_security` (EventCode=4781 Old_Account_Name="*$" New_Account_Name!="*$") OR (EventCode=4768 Account_Name!="*$") | eval RenamedComputerAccount = coalesce(New_Account_Name, mvindex(Account_Name,0)) | transaction RenamedComputerAccount startswith=(EventCode=4781) endswith=(EventCode=4768) | eval short_lived=case((duration<2),"TRUE") | search short_lived = TRUE | table _time, ComputerName, EventCode, Account_Name,RenamedComputerAccount, short_lived |`suspicious_ticket_granting_ticket_request_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + Domain Controller and Kerberos events. The Advanced Security Audit policy setting + `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. +known_false_positives: A computer account name change event inmediately followed by + a kerberos TGT request with matching fields is unsual. However, legitimate behavior + may trigger it. Filter as needed. +references: +- https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html +- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278 +- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287 tags: analytic_story: - sAMAccountName Spoofing and Domain Controller Impersonation @@ -63,5 +65,3 @@ tags: - ComputerName risk_score: 60 security_domain: endpoint -type: Hunting -version: 1 diff --git a/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml b/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml index 63fd56cbd8..9e8fed9ee4 100644 --- a/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml +++ b/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml @@ -1,23 +1,17 @@ +name: Suspicious WAV file in Appdata Folder +id: 5be109e6-1ac5-11ec-b421-acde48001122 +version: 1 +date: '2021-09-21' author: Teoderick Contreras, Splunk +type: TTP datamodel: - Endpoint -date: '2021-09-21' description: This analytic is to detect a suspicious creation of .wav file in appdata folder. This behavior was seen in Remcos RAT malware where it put the audio recording in the appdata\audio folde as part of data collection. this recording can be send to its C2 server as part of its exfiltration to the compromised machine. creation of wav files in this folder path is not a ussual disk place used by user to save audio format file. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, file_name, file_path and command-line - executions from your endpoints. If you are using Sysmon, you must have at least - version 6.0.4 of the Sysmon TA. -id: 5be109e6-1ac5-11ec-b421-acde48001122 -known_false_positives: unknown -name: Suspicious WAV file in Appdata Folder -references: -- https://success.trendmicro.com/solution/1123281-remcos-malware-information -- https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=*.exe Processes.process_path="*\\appdata\\Roaming\\*" by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest @@ -27,6 +21,14 @@ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path | `drop_dm_object_name(Filesystem)` | fields file_name file_path process_name process_path process dest file_create_time _time ] | `suspicious_wav_file_in_appdata_folder_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, file_name, file_path and command-line + executions from your endpoints. If you are using Sysmon, you must have at least + version 6.0.4 of the Sysmon TA. +known_false_positives: unknown +references: +- https://success.trendmicro.com/solution/1123281-remcos-malware-information +- https://blog.malwarebytes.com/threat-intelligence/2021/07/remcos-rat-delivered-via-visual-basic/ tags: analytic_story: - Remcos @@ -76,5 +78,3 @@ tags: - process_path risk_score: 49 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/suspicious_wevtutil_usage.yml b/detections/endpoint/suspicious_wevtutil_usage.yml index a922cf274d..940a706a13 100644 --- a/detections/endpoint/suspicious_wevtutil_usage.yml +++ b/detections/endpoint/suspicious_wevtutil_usage.yml @@ -1,21 +1,14 @@ +name: Suspicious wevtutil Usage +id: 2827c0fd-e1be-4868-ae25-59d28e0f9d4f +version: 4 +date: '2021-10-11' author: David Dorsey, Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2021-10-11' description: The wevtutil.exe application is the windows event log utility. This searches for wevtutil.exe with parameters for clearing the application, security, setup, trace or system event logs. -how_to_implement: You must be ingesting data that records process activity from your - hosts to populate the Endpoint data model in the Processes node. You must also be - ingesting logs with both the process name and command line from your endpoints. - The command-line arguments are mapped to the "process" field in the Endpoint data - model. -id: 2827c0fd-e1be-4868-ae25-59d28e0f9d4f -known_false_positives: The wevtutil.exe application is a legitimate Windows event - log utility. Administrators may use it to manage Windows event logs. -name: Suspicious wevtutil Usage -references: -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wevtutil.exe Processes.process IN ("* cl *", "*clear-log*") @@ -23,6 +16,15 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as OR Processes.process="*Application*" OR Processes.process="*trace*") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `suspicious_wevtutil_usage_filter`' +how_to_implement: You must be ingesting data that records process activity from your + hosts to populate the Endpoint data model in the Processes node. You must also be + ingesting logs with both the process name and command line from your endpoints. + The command-line arguments are mapped to the "process" field in the Endpoint data + model. +known_false_positives: The wevtutil.exe application is a legitimate Windows event + log utility. Administrators may use it to manage Windows event logs. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md tags: analytic_story: - Windows Log Manipulation @@ -75,5 +77,3 @@ tags: - _time risk_score: 28 security_domain: endpoint -type: TTP -version: 4 diff --git a/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml b/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml index f9a2a7b8bf..6938868dd6 100644 --- a/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml +++ b/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml @@ -1,19 +1,14 @@ +name: Suspicious writes to windows Recycle Bin +id: b5541828-8ffd-4070-9d95-b3da4de924cb +version: 4 +date: '2020-07-22' author: Rico Valdez, Splunk +type: TTP datamodel: - Endpoint - Endpoint -date: '2020-07-22' description: This search detects writes to the recycle bin by a process other than explorer.exe. -how_to_implement: To successfully implement this search you need to be ingesting information - on filesystem and process logs responsible for the changes from your endpoints into - the `Endpoint` datamodel in the `Processes` and `Filesystem` nodes. -id: b5541828-8ffd-4070-9d95-b3da4de924cb -known_false_positives: Because the Recycle Bin is a hidden folder in modern versions - of Windows, it would be unusual for a process other than explorer.exe to write to - it. Incidents should be investigated as appropriate. -name: Suspicious writes to windows Recycle Bin -references: [] search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.file_path) as file_path values(Filesystem.file_name) as file_name FROM datamodel=Endpoint.Filesystem where Filesystem.file_path = "*$Recycle.Bin*" @@ -23,6 +18,13 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime as parent_process_name FROM datamodel=Endpoint.Processes where Processes.process_name != "explorer.exe" by Processes.process_id Processes.dest| `drop_dm_object_name("Processes")` | table process_id dest] | `suspicious_writes_to_windows_recycle_bin_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on filesystem and process logs responsible for the changes from your endpoints into + the `Endpoint` datamodel in the `Processes` and `Filesystem` nodes. +known_false_positives: Because the Recycle Bin is a hidden folder in modern versions + of Windows, it would be unusual for a process other than explorer.exe to write to + it. Incidents should be investigated as appropriate. +references: [] tags: analytic_story: - Collection and Staging @@ -68,5 +70,3 @@ tags: - _time risk_score: 28 security_domain: endpoint -type: TTP -version: 4 diff --git a/detections/endpoint/svchost_exe_lolbas_execution_process_spawn.yml b/detections/endpoint/svchost_exe_lolbas_execution_process_spawn.yml index ec169265ce..89de4ba8b5 100644 --- a/detections/endpoint/svchost_exe_lolbas_execution_process_spawn.yml +++ b/detections/endpoint/svchost_exe_lolbas_execution_process_spawn.yml @@ -1,7 +1,11 @@ +name: Svchost LOLBAS Execution Process Spawn +id: 09e5c72a-4c0d-11ec-aa29-3e22fbd008af +version: 1 +date: '2021-11-22' author: Mauricio Velazco, Splunk +type: TTP datamodel: - Endpoint -date: '2021-11-22' description: The following analytic identifies `svchost.exe` spawning a LOLBAS execution process. When adversaries execute code on remote endpoints abusing the Task Scheduler and creating a malicious remote scheduled task, the executed command is spawned @@ -9,17 +13,6 @@ description: The following analytic identifies `svchost.exe` spawning a LOLBAS e binaries that can be abused by threat actors to perform tasks like executing malicious code. Looking for child processes of svchost.exe that are part of the LOLBAS project can help defenders identify lateral movement activity. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. -id: 09e5c72a-4c0d-11ec-aa29-3e22fbd008af -known_false_positives: Legitimate applications may trigger this behavior, filter as - needed. -name: Svchost LOLBAS Execution Process Spawn -references: -- https://attack.mitre.org/techniques/T1053/005/ -- https://www.ired.team/offensive-security/persistence/t1053-schtask -- https://lolbas-project.github.io/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=svchost.exe) (Processes.process_name IN ("Regsvcs.exe", "Ftp.exe", "OfflineScannerShell.exe", @@ -35,6 +28,15 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime "Msconfig.exe")) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `svchost_lolbas_execution_process_spawn_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. +known_false_positives: Legitimate applications may trigger this behavior, filter as + needed. +references: +- https://attack.mitre.org/techniques/T1053/005/ +- https://www.ired.team/offensive-security/persistence/t1053-schtask +- https://lolbas-project.github.io/ tags: analytic_story: - Active Directory Lateral Movement @@ -73,5 +75,3 @@ tags: - _time risk_score: 54 security_domain: endpoint -type: TTP -version: 1 diff --git a/detections/endpoint/system_info_gathering_using_dxdiag_application.yml b/detections/endpoint/system_info_gathering_using_dxdiag_application.yml index 7c45b42145..d5862a4ee1 100644 --- a/detections/endpoint/system_info_gathering_using_dxdiag_application.yml +++ b/detections/endpoint/system_info_gathering_using_dxdiag_application.yml @@ -1,7 +1,11 @@ +name: System Info Gathering Using Dxdiag Application +id: f92d74f2-4921-11ec-b685-acde48001122 +version: 1 +date: '2021-11-19' author: Teoderick Contreras, Splunk +type: Hunting datamodel: - Endpoint -date: '2021-11-19' description: This analytic is to detect a suspicious dxdiag.exe process command-line execution. Dxdiag is used to collect the system info of the target host. This technique has been used by Remcos RATS, various actors, and other malware to collect information @@ -10,23 +14,21 @@ description: This analytic is to detect a suspicious dxdiag.exe process command- to audit host machine specifications. Thus in some rare cases, this detection will contain false positives in its results. To triage further, analyze what commands were passed after it pipes out the result to a file for further processing. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` - node. In addition, confirm the latest CIM App 4.20 or higher is installed and the - latest TA for the endpoint product. -id: f92d74f2-4921-11ec-b685-acde48001122 -known_false_positives: This commandline can be used by a network administrator to - audit host machine specifications. Thus, a filter is needed. -name: System Info Gathering Using Dxdiag Application -references: -- https://app.any.run/tasks/df0baf9f-8baf-4c32-a452-16562ecb19be/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_dxdiag` AND Processes.process = "* /t *" by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `system_info_gathering_using_dxdiag_application_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` + node. In addition, confirm the latest CIM App 4.20 or higher is installed and the + latest TA for the endpoint product. +known_false_positives: This commandline can be used by a network administrator to + audit host machine specifications. Thus, a filter is needed. +references: +- https://app.any.run/tasks/df0baf9f-8baf-4c32-a452-16562ecb19be/ tags: analytic_story: - Remcos @@ -68,5 +70,3 @@ tags: - _time risk_score: 25 security_domain: endpoint -type: Hunting -version: 1 diff --git a/detections/endpoint/system_information_discovery_detection.yml b/detections/endpoint/system_information_discovery_detection.yml index 44074f8752..fb65bf6561 100644 --- a/detections/endpoint/system_information_discovery_detection.yml +++ b/detections/endpoint/system_information_discovery_detection.yml @@ -1,17 +1,13 @@ +name: System Information Discovery Detection +id: 8e99f89e-ae58-4ebc-bf52-ae0b1a277e72 +version: 2 +date: '2021-09-07' author: Patrick Bareiss, Splunk +type: TTP datamodel: - Endpoint -date: '2021-09-07' description: Detect system information discovery techniques used by attackers to understand configurations of the system to further exploit it. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. -id: 8e99f89e-ae58-4ebc-bf52-ae0b1a277e72 -known_false_positives: Administrators debugging servers -name: System Information Discovery Detection -references: -- https://oscp.infosecsanyam.in/priv-escalation/windows-priv-escalation search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process="*wmic* qfe*" OR Processes.process=*systeminfo* OR Processes.process=*hostname*) by Processes.user @@ -20,6 +16,12 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime by dest | where dc_processes_by_dest > 2 | stats values(process) as processes min(firstTime) as firstTime max(lastTime) as lastTime by user, dest parent_process_name | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `system_information_discovery_detection_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +known_false_positives: Administrators debugging servers +references: +- https://oscp.infosecsanyam.in/priv-escalation/windows-priv-escalation tags: analytic_story: - Discovery Techniques @@ -65,5 +67,3 @@ tags: - _time risk_score: 15 security_domain: endpoint -type: TTP -version: 2 diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml index 246358ebc0..371b2eac16 100644 --- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml +++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml @@ -1,7 +1,11 @@ +name: System Processes Run From Unexpected Locations +id: a34aae96-ccf8-4aef-952c-3ea21444444d +version: 6 +date: '2020-12-08' author: David Dorsey, Michael Haag, Splunk +type: TTP datamodel: - Endpoint -date: '2020-12-08' description: 'This search looks for system processes that typically execute from `C:\Windows\System32\` or `C:\Windows\SysWOW64`. This may indicate a malicious process that is trying to hide as a legitimate process.\ @@ -12,16 +16,6 @@ description: 'This search looks for system processes that typically execute from During triage, review the parallel processes - what process moved the native Windows binary? identify any artifacts on disk and review. If a remote destination is contacted, what is the reputation?' -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. -id: a34aae96-ccf8-4aef-952c-3ea21444444d -known_false_positives: This detection may require tuning based on third party applications - utilizing native Windows binaries in non-standard paths. -name: System Processes Run From Unexpected Locations -references: -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml -- https://attack.mitre.org/techniques/T1036/003/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process_path !="C:\\Windows\\System32*" Processes.process_path !="C:\\Windows\\SysWOW64*" by Processes.dest Processes.user @@ -29,6 +23,14 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.parent_process_id Processes.process_hash | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `is_windows_system_file` | `system_processes_run_from_unexpected_locations_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +known_false_positives: This detection may require tuning based on third party applications + utilizing native Windows binaries in non-standard paths. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ tags: analytic_story: - Suspicious Command-Line Executions @@ -82,5 +84,3 @@ tags: - _time risk_score: 49 security_domain: endpoint -type: TTP -version: 6 diff --git a/detections/endpoint/system_user_discovery_with_query.yml b/detections/endpoint/system_user_discovery_with_query.yml index 1b029216bf..ad3842dc70 100644 --- a/detections/endpoint/system_user_discovery_with_query.yml +++ b/detections/endpoint/system_user_discovery_with_query.yml @@ -1,25 +1,27 @@ +name: System User Discovery With Query +id: ad03bfcf-8a91-4bc2-a500-112993deba87 +version: 1 +date: '2021-09-13' author: Mauricio Velazco, Splunk +type: Hunting datamodel: - Endpoint -date: '2021-09-13' description: This analytic looks for the execution of `query.exe` with command-line arguments utilized to discover the logged user. Red Teams and adversaries alike may leverage `query.exe` to identify system users on a compromised endpoint for situational awareness and Active Directory Discovery. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. -id: ad03bfcf-8a91-4bc2-a500-112993deba87 -known_false_positives: Administrators or power users may use this command for troubleshooting. -name: System User Discovery With Query -references: -- https://attack.mitre.org/techniques/T1033/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="query.exe") (Processes.process=*user*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `system_user_discovery_with_query_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +known_false_positives: Administrators or power users may use this command for troubleshooting. +references: +- https://attack.mitre.org/techniques/T1033/ tags: analytic_story: - Active Directory Discovery @@ -57,5 +59,3 @@ tags: - _time risk_score: 15 security_domain: endpoint -type: Hunting -version: 1 diff --git a/detections/endpoint/system_user_discovery_with_whoami.yml b/detections/endpoint/system_user_discovery_with_whoami.yml index 7299966e8e..7a5f404eed 100644 --- a/detections/endpoint/system_user_discovery_with_whoami.yml +++ b/detections/endpoint/system_user_discovery_with_whoami.yml @@ -1,24 +1,26 @@ +name: System User Discovery With Whoami +id: 894fc43e-6f50-47d5-a68b-ee9ee23e18f4 +version: 1 +date: '2021-09-13' author: Mauricio Velazco, Splunk +type: Hunting datamodel: - Endpoint -date: '2021-09-13' description: This analytic looks for the execution of `whoami.exe` without any arguments. This windows native binary prints out the current logged user. Red Teams and adversaries alike may leverage `whoami.exe` to identify system users on a compromised endpoint for situational awareness and Active Directory Discovery. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. -id: 894fc43e-6f50-47d5-a68b-ee9ee23e18f4 -known_false_positives: Administrators or power users may use this command for troubleshooting. -name: System User Discovery With Whoami -references: -- https://attack.mitre.org/techniques/T1033/ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="whoami.exe") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `system_user_discovery_with_whoami_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +known_false_positives: Administrators or power users may use this command for troubleshooting. +references: +- https://attack.mitre.org/techniques/T1033/ tags: analytic_story: - Active Directory Discovery @@ -56,5 +58,3 @@ tags: - _time risk_score: 15 security_domain: endpoint -type: Hunting -version: 1 diff --git a/detections/endpoint/systems_ready_for_spectre_meltdown_windows_patch.yml b/detections/endpoint/systems_ready_for_spectre_meltdown_windows_patch.yml index 9e1ca37ff2..b36694138d 100644 --- a/detections/endpoint/systems_ready_for_spectre_meltdown_windows_patch.yml +++ b/detections/endpoint/systems_ready_for_spectre_meltdown_windows_patch.yml @@ -1,24 +1,26 @@ +name: Systems Ready for Spectre-Meltdown Windows Patch +id: fc0edc95-ff2b-48b0-9f6f-63da3789fd61 +version: 1 +date: '2018-01-08' author: David Dorsey, Splunk +type: Baseline datamodel: - Change_Analysis -date: '2018-01-08' description: Some AV applications can cause the Spectre/Meltdown patch for Windows not to install successfully. This registry key is supposed to be created by the AV engine when it has been patched to be able to handle the Windows patch. If this key has been written, the system can then be patched for Spectre and Meltdown. -how_to_implement: You need to be ingesting logs with both the process name and command-line - from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 - of the Sysmon TA. -id: fc0edc95-ff2b-48b0-9f6f-63da3789fd61 -known_false_positives: none -name: Systems Ready for Spectre-Meltdown Windows Patch -references: [] search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Change_Analysis.All_Changes where All_Changes.object_category=registry AND (All_Changes.object_path="HKLM\Software\Microsoft\Windows\CurrentVersion\QualityCompat*") by All_Changes.dest, All_Changes.command, All_Changes.user, All_Changes.object, All_Changes.object_path | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name("All_Changes")`' +how_to_implement: You need to be ingesting logs with both the process name and command-line + from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 + of the Sysmon TA. +known_false_positives: none +references: [] tags: analytic_story: - Spectre And Meltdown Vulnerabilities @@ -39,5 +41,3 @@ tags: - Change_Analysis.All_Changes.user - _time security_domain: endpoint -type: Baseline -version: 1