Merge branch 'develop' into medusa_ransomware

This commit is contained in:
Bhavin Patel
2025-04-02 14:28:10 -07:00
committed by GitHub
49 changed files with 469 additions and 451 deletions
@@ -74,18 +74,18 @@ rba:
type: process_name
tags:
analytic_story:
- Ingress Tool Transfer
- Data Destruction
- Malicious PowerShell
- China-Nexus Threat Activity
- Crypto Stealer
- Hermetic Wiper
- DarkCrystal RAT
- Malicious PowerShell
- Earth Estries
- Phemedrone Stealer
- Braodo Stealer
- PXA Stealer
- Data Destruction
- Log4Shell CVE-2021-44228
- Salt Typhoon
- Braodo Stealer
- Crypto Stealer
- Ingress Tool Transfer
- PHP-CGI RCE Attack on Japanese Organizations
asset_type: Endpoint
cve:
@@ -68,12 +68,12 @@ rba:
threat_objects: []
tags:
analytic_story:
- SnappyBee
- Rhysida Ransomware
- China-Nexus Threat Activity
- Crypto Stealer
- Earth Estries
- Unusual Processes
- SnappyBee
- Salt Typhoon
- Rhysida Ransomware
- Crypto Stealer
asset_type: Endpoint
mitre_attack_id:
- T1204
+11 -10
View File
@@ -42,19 +42,20 @@ references:
- https://redcanary.com/blog/threat-hunting-psexec-lateral-movement/
tags:
analytic_story:
- DHS Report TA18-074A
- Active Directory Lateral Movement
- BlackByte Ransomware
- HAFNIUM Group
- Rhysida Ransomware
- Medusa Ransomware
- DarkSide Ransomware
- Earth Estries
- SamSam Ransomware
- DarkGate Malware
- CISA AA22-320A
- Sandworm Tools
- China-Nexus Threat Activity
- CISA AA22-320A
- DarkGate Malware
- DarkSide Ransomware
- DHS Report TA18-074A
- Earth Estries
- HAFNIUM Group
- Medusa Ransomware
- Rhysida Ransomware
- Salt Typhoon
- SamSam Ransomware
- Sandworm Tools
- VanHelsing Ransomware
asset_type: Endpoint
mitre_attack_id:
@@ -42,9 +42,9 @@ references:
tags:
analytic_story:
- China-Nexus Threat Activity
- CISA AA22-277A
- Collection and Staging
- Earth Estries
- CISA AA22-277A
- Salt Typhoon
asset_type: Endpoint
mitre_attack_id:
- T1560.001
@@ -63,48 +63,48 @@ rba:
type: file_name
tags:
analytic_story:
- BlackByte Ransomware
- Brute Ratel C4
- Trickbot
- Snake Keylogger
- Graceful Wipe Out Attack
- PlugX
- Handala Wiper
- Earth Estries
- Warzone RAT
- ValleyRAT
- NjRAT
- LockBit Ransomware
- Double Zero Destructor
- Swift Slicer
- DarkCrystal RAT
- AsyncRAT
- Volt Typhoon
- Chaos Ransomware
- Hermetic Wiper
- Derusbi
- XMRig
- AgentTesla
- WinDealer RAT
- RedLine Stealer
- Remcos
- Rhysida Ransomware
- China-Nexus Threat Activity
- Crypto Stealer
- Qakbot
- IcedID
- Meduza Stealer
- AcidPour
- MoonPeak
- CISA AA23-347A
- DarkGate Malware
- Industroyer2
- Azorult
- Data Destruction
- Amadey
- SnappyBee
- WhisperGate
- SystemBC
- Snake Keylogger
- China-Nexus Threat Activity
- Remcos
- LockBit Ransomware
- AsyncRAT
- DarkCrystal RAT
- Derusbi
- WinDealer RAT
- DarkGate Malware
- Crypto Stealer
- ValleyRAT
- AcidPour
- PlugX
- Data Destruction
- Qakbot
- CISA AA23-347A
- Hermetic Wiper
- Volt Typhoon
- Double Zero Destructor
- NjRAT
- Trickbot
- AgentTesla
- Meduza Stealer
- SnappyBee
- Azorult
- WhisperGate
- Warzone RAT
- Swift Slicer
- Rhysida Ransomware
- Brute Ratel C4
- BlackByte Ransomware
- Graceful Wipe Out Attack
- Chaos Ransomware
- Handala Wiper
- RedLine Stealer
- Salt Typhoon
- XMRig
- MoonPeak
- Industroyer2
- Amadey
- IcedID
asset_type: Endpoint
mitre_attack_id:
- T1036
@@ -60,47 +60,47 @@ rba:
type: file_name
tags:
analytic_story:
- Chaos Ransomware
- Trickbot
- Snake Keylogger
- CISA AA23-347A
- Industroyer2
- WinDealer RAT
- Qakbot
- Warzone RAT
- IcedID
- ValleyRAT
- Azorult
- Handala Wiper
- LockBit Ransomware
- Meduza Stealer
- Brute Ratel C4
- AsyncRAT
- AcidPour
- Derusbi
- DarkGate Malware
- Graceful Wipe Out Attack
- NjRAT
- WhisperGate
- Data Destruction
- BlackByte Ransomware
- AgentTesla
- Swift Slicer
- Crypto Stealer
- Hermetic Wiper
- MoonPeak
- Double Zero Destructor
- XMRig
- PlugX
- Amadey
- DarkCrystal RAT
- Remcos
- China-Nexus Threat Activity
- Earth Estries
- Rhysida Ransomware
- RedLine Stealer
- Remcos
- LockBit Ransomware
- AsyncRAT
- DarkCrystal RAT
- Derusbi
- WinDealer RAT
- DarkGate Malware
- AcidPour
- ValleyRAT
- Crypto Stealer
- PlugX
- Data Destruction
- Qakbot
- CISA AA23-347A
- Hermetic Wiper
- Volt Typhoon
- Double Zero Destructor
- NjRAT
- Trickbot
- Meduza Stealer
- AgentTesla
- SnappyBee
- Azorult
- WhisperGate
- Warzone RAT
- Swift Slicer
- Rhysida Ransomware
- Brute Ratel C4
- BlackByte Ransomware
- Graceful Wipe Out Attack
- Chaos Ransomware
- Handala Wiper
- RedLine Stealer
- Salt Typhoon
- XMRig
- MoonPeak
- Industroyer2
- Amadey
- IcedID
asset_type: Endpoint
mitre_attack_id:
- T1036
@@ -1,8 +1,8 @@
name: Linux Auditd File Permission Modification Via Chmod
id: 5f1d2ea7-eec0-4790-8b24-6875312ad492
version: 9
date: '2025-02-24'
author: Teoderick Contreras, Splunk, Ivar Nygård
version: '10'
date: '2025-03-19'
author: "Teoderick Contreras, Splunk, Ivar Nyg\xE5rd"
status: production
type: Anomaly
description: The following analytic detects suspicious file permission modifications
@@ -15,12 +15,10 @@ description: The following analytic detects suspicious file permission modificat
actions on the system.
data_source:
- Linux Auditd Proctitle
search: '`linux_auditd` proctitle="*chmod*" AND proctitle IN ("* 777 *", "* 755 *", "*+*x*", "* 754 *")
| rename host as dest
| stats count min(_time) as firstTime max(_time) as lastTime by proctitle dest
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `linux_auditd_file_permission_modification_via_chmod_filter`'
search: '`linux_auditd` proctitle="*chmod*" AND proctitle IN ("* 777 *", "* 755 *",
"*+*x*", "* 754 *") | rename host as dest | stats count min(_time) as firstTime
max(_time) as lastTime by proctitle dest | `security_content_ctime(firstTime)` |
`security_content_ctime(lastTime)` | `linux_auditd_file_permission_modification_via_chmod_filter`'
how_to_implement: To implement this detection, the process begins by ingesting auditd
data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
command-line executions and process details on Unix/Linux systems. These logs should
@@ -58,13 +56,13 @@ rba:
threat_objects: []
tags:
analytic_story:
- China-Nexus Threat Activity
- Linux Persistence Techniques
- XorDDos
- Linux Privilege Escalation
- Compromised Linux Host
- China-Nexus Threat Activity
- Linux Living Off The Land
- Earth Estries
- XorDDos
- Salt Typhoon
- Linux Privilege Escalation
asset_type: Endpoint
mitre_attack_id:
- T1222.002
@@ -76,8 +74,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chmod_exec_attrib/auditd_proctitle_chmod.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chmod_exec_attrib/auditd_proctitle_chmod.log
source: auditd
sourcetype: auditd
@@ -1,7 +1,7 @@
name: Linux Auditd Nopasswd Entry In Sudoers File
id: 651df959-ad17-4b73-a323-90cb96d5fa1b
version: 6
date: '2025-02-24'
version: '7'
date: '2025-03-19'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -14,11 +14,9 @@ description: The following analytic detects the addition of NOPASSWD entries to
and potential compromise of sensitive data and system integrity.
data_source:
- Linux Auditd Proctitle
search: '`linux_auditd` proctitle = "*NOPASSWD*"
| rename host as dest
| stats count min(_time) as firstTime max(_time) as lastTime by proctitle dest
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
| `linux_auditd_nopasswd_entry_in_sudoers_file_filter`'
search: '`linux_auditd` proctitle = "*NOPASSWD*" | rename host as dest | stats count
min(_time) as firstTime max(_time) as lastTime by proctitle dest | `security_content_ctime(firstTime)`|
`security_content_ctime(lastTime)` | `linux_auditd_nopasswd_entry_in_sudoers_file_filter`'
how_to_implement: To implement this detection, the process begins by ingesting auditd
data, that consist SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line
executions and process details on Unix/Linux systems. These logs should be ingested
@@ -57,11 +55,11 @@ rba:
threat_objects: []
tags:
analytic_story:
- China-Nexus Threat Activity
- Linux Persistence Techniques
- Linux Privilege Escalation
- Compromised Linux Host
- Earth Estries
- China-Nexus Threat Activity
- Salt Typhoon
- Linux Privilege Escalation
asset_type: Endpoint
mitre_attack_id:
- T1548.003
@@ -73,8 +71,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_nopasswd/linux_auditd_nopasswd2.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_nopasswd/linux_auditd_nopasswd2.log
source: auditd
sourcetype: auditd
@@ -1,7 +1,7 @@
name: Linux Auditd Possible Access To Credential Files
id: 0419cb7a-57ea-467b-974f-77c303dfe2a3
version: 7
date: '2025-02-24'
version: '8'
date: '2025-03-19'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -14,11 +14,10 @@ description: The following analytic detects attempts to access or dump the conte
offline cracking, leading to unauthorized access and potential system compromise.
data_source:
- Linux Auditd Proctitle
search: '`linux_auditd` proctitle IN ("*shadow*", "*passwd*") AND proctitle IN ("*cat *", "*nano *", "*vim *", "*vi *")
| rename host as dest
| stats count min(_time) as firstTime max(_time) as lastTime by proctitle dest
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `linux_auditd_possible_access_to_credential_files_filter`'
search: '`linux_auditd` proctitle IN ("*shadow*", "*passwd*") AND proctitle IN ("*cat
*", "*nano *", "*vim *", "*vi *") | rename host as dest | stats count min(_time)
as firstTime max(_time) as lastTime by proctitle dest | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `linux_auditd_possible_access_to_credential_files_filter`'
how_to_implement: To implement this detection, the process begins by ingesting auditd
data, that consist SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line
executions and process details on Unix/Linux systems. These logs should be ingested
@@ -48,8 +47,8 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: A [$proctitle$] event occurred on host - [$dest$] to access or dump
the contents of /etc/passwd and /etc/shadow files.
message: A [$proctitle$] event occurred on host - [$dest$] to access or dump the
contents of /etc/passwd and /etc/shadow files.
risk_objects:
- field: dest
type: system
@@ -57,11 +56,11 @@ rba:
threat_objects: []
tags:
analytic_story:
- China-Nexus Threat Activity
- Linux Persistence Techniques
- Linux Privilege Escalation
- Compromised Linux Host
- Earth Estries
- China-Nexus Threat Activity
- Salt Typhoon
- Linux Privilege Escalation
asset_type: Endpoint
mitre_attack_id:
- T1003.008
@@ -73,7 +72,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/linux_auditd_access_credential/auditd_proctitle_access_cred.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/linux_auditd_access_credential/auditd_proctitle_access_cred.log
source: auditd
sourcetype: auditd
@@ -1,7 +1,7 @@
name: Linux Auditd Possible Access To Sudoers File
id: 8be88f46-f7e8-4ae6-b15e-cf1b13392834
version: 7
date: '2025-02-24'
version: '8'
date: '2025-03-19'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -56,11 +56,11 @@ rba:
threat_objects: []
tags:
analytic_story:
- China-Nexus Threat Activity
- Linux Persistence Techniques
- Linux Privilege Escalation
- Compromised Linux Host
- Earth Estries
- China-Nexus Threat Activity
- Salt Typhoon
- Linux Privilege Escalation
asset_type: Endpoint
mitre_attack_id:
- T1548.003
@@ -72,8 +72,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudoers_access/linux_auditd_sudoers_access.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudoers_access/linux_auditd_sudoers_access.log
source: auditd
sourcetype: auditd
@@ -1,7 +1,7 @@
name: Linux Auditd Preload Hijack Library Calls
id: 35c50572-a70b-452f-afa9-bebdf3c3ce36
version: 7
date: '2025-02-24'
version: '8'
date: '2025-03-19'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -15,13 +15,10 @@ description: The following analytic detects the use of the LD_PRELOAD environmen
access to the system.
data_source:
- Linux Auditd Execve
search: '`linux_auditd` execve_command = "*LD_PRELOAD*"
| rename host as dest
| rename comm as process_name
| rename exe as process
| stats count min(_time) as firstTime max(_time) as lastTime by argc execve_command dest
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
| `linux_auditd_preload_hijack_library_calls_filter`'
search: '`linux_auditd` execve_command = "*LD_PRELOAD*" | rename host as dest | rename
comm as process_name | rename exe as process | stats count min(_time) as firstTime
max(_time) as lastTime by argc execve_command dest | `security_content_ctime(firstTime)`|
`security_content_ctime(lastTime)` | `linux_auditd_preload_hijack_library_calls_filter`'
how_to_implement: To implement this detection, the process begins by ingesting auditd
data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
command-line executions and process details on Unix/Linux systems. These logs should
@@ -59,11 +56,11 @@ rba:
threat_objects: []
tags:
analytic_story:
- China-Nexus Threat Activity
- Linux Persistence Techniques
- Linux Privilege Escalation
- Compromised Linux Host
- Earth Estries
- China-Nexus Threat Activity
- Salt Typhoon
- Linux Privilege Escalation
asset_type: Endpoint
mitre_attack_id:
- T1574.006
@@ -75,8 +72,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/linux_auditd_ldpreload/auditd_execve_ldpreload.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/linux_auditd_ldpreload/auditd_execve_ldpreload.log
source: auditd
sourcetype: auditd
@@ -48,11 +48,11 @@ references:
- https://github.com/microsoft/MSTIC-Sysmon/blob/main/linux/configs/attack-based/privilege_escalation/T1548.001_ElevationControl_CommonProcesses.xml
tags:
analytic_story:
- China-Nexus Threat Activity
- Linux Persistence Techniques
- Linux Privilege Escalation
- China-Nexus Threat Activity
- Linux Living Off The Land
- Earth Estries
- Salt Typhoon
- Linux Privilege Escalation
asset_type: Endpoint
mitre_attack_id:
- T1548.001
@@ -61,10 +61,10 @@ rba:
threat_objects: []
tags:
analytic_story:
- China-Nexus Threat Activity
- Linux Persistence Techniques
- China-Nexus Threat Activity
- Salt Typhoon
- Linux Privilege Escalation
- Earth Estries
asset_type: Endpoint
mitre_attack_id:
- T1548.003
@@ -61,11 +61,11 @@ rba:
threat_objects: []
tags:
analytic_story:
- China-Nexus Threat Activity
- Linux Persistence Techniques
- China-Nexus Threat Activity
- XorDDos
- Salt Typhoon
- Linux Privilege Escalation
- Earth Estries
asset_type: Endpoint
mitre_attack_id:
- T1003.008
@@ -61,10 +61,10 @@ rba:
threat_objects: []
tags:
analytic_story:
- China-Nexus Threat Activity
- Linux Persistence Techniques
- China-Nexus Threat Activity
- Salt Typhoon
- Linux Privilege Escalation
- Earth Estries
asset_type: Endpoint
mitre_attack_id:
- T1548.003
@@ -60,10 +60,10 @@ rba:
threat_objects: []
tags:
analytic_story:
- China-Nexus Threat Activity
- Linux Persistence Techniques
- China-Nexus Threat Activity
- Salt Typhoon
- Linux Privilege Escalation
- Earth Estries
asset_type: Endpoint
mitre_attack_id:
- T1574.006
@@ -53,10 +53,10 @@ rba:
threat_objects: []
tags:
analytic_story:
- China-Nexus Threat Activity
- Linux Persistence Techniques
- China-Nexus Threat Activity
- Salt Typhoon
- Linux Privilege Escalation
- Earth Estries
asset_type: Endpoint
mitre_attack_id:
- T1548.003
@@ -67,12 +67,12 @@ rba:
tags:
analytic_story:
- China-Nexus Threat Activity
- AsyncRAT
- DarkCrystal RAT
- Volt Typhoon
- Salt Typhoon
- HAFNIUM Group
- DHS Report TA18-074A
- DarkCrystal RAT
- AsyncRAT
- Earth Estries
- Volt Typhoon
asset_type: Endpoint
mitre_attack_id:
- T1059.001
@@ -1,7 +1,7 @@
name: Non Chrome Process Accessing Chrome Default Dir
id: 81263de4-160a-11ec-944f-acde48001122
version: '8'
date: '2025-02-24'
version: '9'
date: '2025-03-19'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -49,20 +49,20 @@ rba:
threat_objects: []
tags:
analytic_story:
- SnappyBee
- Phemedrone Stealer
- Snake Keylogger
- NjRAT
- CISA AA23-347A
- 3CX Supply Chain Attack
- FIN7
- Earth Estries
- Warzone RAT
- China-Nexus Threat Activity
- DarkGate Malware
- Remcos
- RedLine Stealer
- AgentTesla
- Snake Keylogger
- CISA AA23-347A
- China-Nexus Threat Activity
- Remcos
- FIN7
- Phemedrone Stealer
- SnappyBee
- RedLine Stealer
- Warzone RAT
- Salt Typhoon
- 3CX Supply Chain Attack
- DarkGate Malware
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- T1555.003
@@ -1,7 +1,7 @@
name: Non Firefox Process Access Firefox Profile Dir
id: e6fc13b0-1609-11ec-b533-acde48001122
version: '7'
date: '2025-02-13'
version: '8'
date: '2025-03-19'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -48,21 +48,21 @@ rba:
threat_objects: []
tags:
analytic_story:
- SnappyBee
- Phemedrone Stealer
- Snake Keylogger
- NjRAT
- CISA AA23-347A
- 3CX Supply Chain Attack
- Azorult
- China-Nexus Threat Activity
- Warzone RAT
- AgentTesla
- RedLine Stealer
- DarkGate Malware
- Snake Keylogger
- CISA AA23-347A
- China-Nexus Threat Activity
- Remcos
- Earth Estries
- FIN7
- Phemedrone Stealer
- SnappyBee
- Azorult
- RedLine Stealer
- Warzone RAT
- Salt Typhoon
- 3CX Supply Chain Attack
- DarkGate Malware
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- T1555.003
+12 -11
View File
@@ -59,20 +59,21 @@ references:
- https://adlumin.com/post/powerdrop-a-new-insidious-powershell-script-for-command-and-control-attacks-targets-u-s-aerospace-defense-industry/
tags:
analytic_story:
- Hermetic Wiper
- Flax Typhoon
- China-Nexus Threat Activity
- Lumma Stealer
- Data Destruction
- CISA AA23-347A
- Cleo File Transfer Software
- Medusa Ransomware
- CISA AA24-241A
- Earth Estries
- Braodo Stealer
- China-Nexus Threat Activity
- CISA AA23-347A
- CISA AA24-241A
- Cleo File Transfer Software
- DarkGate Malware
- Rhysida Ransomware
- Data Destruction
- Earth Estries
- Flax Typhoon
- Hermetic Wiper
- Lumma Stealer
- Malicious PowerShell
- Medusa Ransomware
- Rhysida Ransomware
- Salt Typhoon
- SystemBC
- PHP-CGI RCE Attack on Japanese Organizations
asset_type: Endpoint
@@ -78,39 +78,38 @@ rba:
threat_objects: []
tags:
analytic_story:
- Amadey
- AsyncRAT
- Azorult
- BlackByte Ransomware
- BlackSuit Ransomware
- Braodo Stealer
- Chaos Ransomware
- China-Nexus Threat Activity
- CISA AA23-347A
- DarkGate Malware
- Derusbi
- DHS Report TA18-074A
- Earth Estries
- Emotet Malware DHS Report TA18-201A
- IcedID
- MoonPeak
- NjRAT
- Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
- Qakbot
- Ransomware
- RedLine Stealer
- Remcos
- PHP-CGI RCE Attack on Japanese Organizations
- Snake Keylogger
- SnappyBee
- Sneaky Active Directory Persistence Tricks
- Suspicious MSHTA Activity
- Suspicious Windows Registry Activities
- SystemBC
- Warzone RAT
- WinDealer RAT
- Snake Keylogger
- China-Nexus Threat Activity
- Remcos
- AsyncRAT
- Windows Persistence Techniques
- Derusbi
- WinDealer RAT
- Suspicious MSHTA Activity
- DarkGate Malware
- Suspicious Windows Registry Activities
- Qakbot
- CISA AA23-347A
- Ransomware
- NjRAT
- Emotet Malware DHS Report TA18-201A
- Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
- Sneaky Active Directory Persistence Tricks
- SnappyBee
- Azorult
- Warzone RAT
- BlackByte Ransomware
- Chaos Ransomware
- RedLine Stealer
- BlackSuit Ransomware
- Windows Registry Abuse
- Amadey
- Salt Typhoon
- MoonPeak
- Braodo Stealer
- DHS Report TA18-074A
- IcedID
asset_type: Endpoint
mitre_attack_id:
- T1547.001
@@ -69,12 +69,12 @@ rba:
threat_objects: []
tags:
analytic_story:
- CISA AA23-347A
- China-Nexus Threat Activity
- Ransomware
- Active Directory Lateral Movement
- CISA AA23-347A
- Suspicious WMI Use
- Earth Estries
- Salt Typhoon
- Active Directory Lateral Movement
asset_type: Endpoint
mitre_attack_id:
- T1047
@@ -71,33 +71,34 @@ rba:
threat_objects: []
tags:
analytic_story:
- Prestige Ransomware
- Medusa Ransomware
- Earth Estries
- Scheduled Tasks
- RedLine Stealer
- Azorult
- Living Off The Land
- Sandworm Tools
- Trickbot
- ShrinkLocker
- MoonPeak
- Winter Vivern
- AsyncRAT
- AgentTesla
- Amadey
- AsyncRAT
- Azorult
- China-Nexus Threat Activity
- CISA AA22-257A
- NOBELIUM Group
- CISA AA23-347A
- Qakbot
- Windows Persistence Techniques
- CISA AA24-241A
- DarkCrystal RAT
- Amadey
- Rhysida Ransomware
- DHS Report TA18-074A
- Earth Estries
- Living Off The Land
- Medusa Ransomware
- MoonPeak
- NjRAT
- NOBELIUM Group
- Phemedrone Stealer
- China-Nexus Threat Activity
- Prestige Ransomware
- Qakbot
- RedLine Stealer
- Rhysida Ransomware
- Salt Typhoon
- Sandworm Tools
- Scheduled Tasks
- ShrinkLocker
- Trickbot
- Windows Persistence Techniques
- Winter Vivern
asset_type: Endpoint
mitre_attack_id:
- T1053.005
@@ -76,13 +76,13 @@ rba:
type: process_name
tags:
analytic_story:
- China-Nexus Threat Activity
- IcedID
- Qakbot
- Derusbi
- Living Off The Land
- Earth Estries
- Qakbot
- China-Nexus Threat Activity
- Derusbi
- Salt Typhoon
- Suspicious Regsvr32 Activity
- IcedID
asset_type: Endpoint
mitre_attack_id:
- T1218.010
@@ -69,20 +69,21 @@ rba:
threat_objects: []
tags:
analytic_story:
- CISA AA23-347A
- Ransomware
- MoonPeak
- Windows Persistence Techniques
- CISA AA24-241A
- Earth Estries
- Scheduled Tasks
- Medusa Ransomware
- DarkCrystal RAT
- Azorult
- Living Off The Land
- Crypto Stealer
- Ryuk Ransomware
- China-Nexus Threat Activity
- CISA AA23-347A
- CISA AA24-241A
- Crypto Stealer
- DarkCrystal RAT
- Earth Estries
- Living Off The Land
- Medusa Ransomware
- MoonPeak
- Ransomware
- Ryuk Ransomware
- Salt Typhoon
- Scheduled Tasks
- Windows Persistence Techniques
asset_type: Endpoint
mitre_attack_id:
- T1053.005
@@ -56,18 +56,18 @@ rba:
threat_objects: []
tags:
analytic_story:
- Meduza Stealer
- PlugX
- CISA AA23-347A
- China-Nexus Threat Activity
- AsyncRAT
- SnappyBee
- Derusbi
- WinDealer RAT
- Salt Typhoon
- DarkGate Malware
- ValleyRAT
- Brute Ratel C4
- WinDealer RAT
- Meduza Stealer
- CISA AA23-347A
- AsyncRAT
- Derusbi
- PlugX
- China-Nexus Threat Activity
- DarkGate Malware
- Earth Estries
asset_type: Endpoint
mitre_attack_id:
- T1134.002
@@ -1,23 +1,35 @@
name: Windows Anonymous Pipe Activity
id: ee301e1e-cd81-4011-a911-e5f049b9e3d5
version: 1
date: '2025-02-11'
version: '2'
date: '2025-03-19'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
description: The following analytic detects the creation or connection of anonymous pipes for inter-process communication (IPC) within a Windows environment. Anonymous pipes are commonly used by legitimate system processes, services, and applications to transfer data between related processes. However, adversaries frequently abuse anonymous pipes to facilitate stealthy process injection, command-and-control (C2) communication, credential theft, or privilege escalation. This detection monitors for unusual anonymous pipe activity, particularly involving non-system processes, unsigned executables, or unexpected parent-child process relationships. While legitimate use cases exist—such as Windows services, software installers, or security tools—unusual or high-frequency anonymous pipe activity should be investigated for potential malware, persistence mechanisms, or lateral movement techniques.
description: "The following analytic detects the creation or connection of anonymous\
\ pipes for inter-process communication (IPC) within a Windows environment. Anonymous\
\ pipes are commonly used by legitimate system processes, services, and applications\
\ to transfer data between related processes. However, adversaries frequently abuse\
\ anonymous pipes to facilitate stealthy process injection, command-and-control\
\ (C2) communication, credential theft, or privilege escalation. This detection\
\ monitors for unusual anonymous pipe activity, particularly involving non-system\
\ processes, unsigned executables, or unexpected parent-child process relationships.\
\ While legitimate use cases exist\u2014such as Windows services, software installers,\
\ or security tools\u2014unusual or high-frequency anonymous pipe activity should\
\ be investigated for potential malware, persistence mechanisms, or lateral movement\
\ techniques."
data_source:
- Sysmon EventID 17
- Sysmon EventID 18
search: '`sysmon` EventCode IN (17,18) EventType IN ( "CreatePipe", "ConnectPipe") PipeName="*Anonymous Pipe*" NOT( Image IN ("*\\Program Files\\*"))
| stats min(_time) as firstTime max(_time) as lastTime count by dest EventCode PipeName ProcessGuid ProcessId Image EventType
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
search: '`sysmon` EventCode IN (17,18) EventType IN ( "CreatePipe", "ConnectPipe")
PipeName="*Anonymous Pipe*" NOT( Image IN ("*\\Program Files\\*")) | stats min(_time)
as firstTime max(_time) as lastTime count by dest EventCode PipeName ProcessGuid
ProcessId Image EventType | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `windows_anonymous_pipe_activity_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name and pipename from your endpoints. If you are using Sysmon,
you must have at least version 6.0.4 of the Sysmon TA. .
known_false_positives: Automation tool might use anonymous pipe for task orchestration or process communication.
known_false_positives: Automation tool might use anonymous pipe for task orchestration
or process communication.
references:
- https://www.trendmicro.com/en_nl/research/24/k/earth-estries.html
drilldown_searches:
@@ -36,9 +48,9 @@ drilldown_searches:
latest_offset: $info_max_time$
tags:
analytic_story:
- SnappyBee
- Salt Typhoon
- China-Nexus Threat Activity
- Earth Estries
- SnappyBee
asset_type: Endpoint
mitre_attack_id:
- T1559
@@ -64,8 +64,8 @@ rba:
tags:
analytic_story:
- DarkGate Malware
- Salt Typhoon
- China-Nexus Threat Activity
- Earth Estries
asset_type: Endpoint
mitre_attack_id:
- T1560.001
@@ -1,7 +1,7 @@
name: Windows Credential Access From Browser Password Store
id: 72013a8e-5cea-408a-9d51-5585386b4d69
version: '8'
date: '2025-02-24'
version: '9'
date: '2025-03-19'
author: Teoderick Contreras, Bhavin Patel Splunk
data_source:
- Windows Event Log Security 4663
@@ -60,14 +60,14 @@ rba:
threat_objects: []
tags:
analytic_story:
- Meduza Stealer
- Snake Keylogger
- China-Nexus Threat Activity
- SnappyBee
- PXA Stealer
- Salt Typhoon
- MoonPeak
- Braodo Stealer
- Snake Keylogger
- Meduza Stealer
- PXA Stealer
- China-Nexus Threat Activity
- Earth Estries
asset_type: Endpoint
mitre_attack_id:
- T1012
@@ -1,7 +1,7 @@
name: Windows Credentials from Password Stores Chrome LocalState Access
id: 3b1d09a8-a26f-473e-a510-6c6613573657
version: '8'
date: '2025-02-24'
version: '9'
date: '2025-03-19'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -51,20 +51,20 @@ rba:
threat_objects: []
tags:
analytic_story:
- SnappyBee
- MoonPeak
- Phemedrone Stealer
- Braodo Stealer
- Snake Keylogger
- Meduza Stealer
- NjRAT
- Amadey
- PXA Stealer
- Warzone RAT
- Snake Keylogger
- China-Nexus Threat Activity
- DarkGate Malware
- Phemedrone Stealer
- SnappyBee
- PXA Stealer
- RedLine Stealer
- Earth Estries
- Warzone RAT
- Salt Typhoon
- DarkGate Malware
- MoonPeak
- Braodo Stealer
- Amadey
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- T1012
@@ -1,7 +1,7 @@
name: Windows Credentials from Password Stores Chrome Login Data Access
id: 0d32ba37-80fc-4429-809c-0ba15801aeaf
version: '8'
date: '2025-02-24'
version: '9'
date: '2025-03-19'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -52,20 +52,20 @@ rba:
threat_objects: []
tags:
analytic_story:
- SnappyBee
- MoonPeak
- Phemedrone Stealer
- Braodo Stealer
- Snake Keylogger
- Meduza Stealer
- NjRAT
- Amadey
- PXA Stealer
- Warzone RAT
- Snake Keylogger
- China-Nexus Threat Activity
- DarkGate Malware
- Phemedrone Stealer
- SnappyBee
- PXA Stealer
- RedLine Stealer
- Earth Estries
- Warzone RAT
- Salt Typhoon
- DarkGate Malware
- MoonPeak
- Braodo Stealer
- Amadey
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- T1012
@@ -73,13 +73,13 @@ rba:
type: process_name
tags:
analytic_story:
- Black Basta Ransomware
- China-Nexus Threat Activity
- Forest Blizzard
- Compromised Windows Host
- Salt Typhoon
- Ingress Tool Transfer
- IcedID
- Forest Blizzard
- Earth Estries
- Black Basta Ransomware
- Compromised Windows Host
asset_type: Endpoint
mitre_attack_id:
- T1105
@@ -67,8 +67,8 @@ rba:
type: parent_process_name
tags:
analytic_story:
- Salt Typhoon
- China-Nexus Threat Activity
- Earth Estries
- SnappyBee
asset_type: Endpoint
mitre_attack_id:
@@ -1,7 +1,7 @@
name: Windows Query Registry Browser List Application
id: 45ebd21c-f4bf-4ced-bd49-d25b6526cebb
version: '5'
date: '2025-02-07'
version: '6'
date: '2025-03-19'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
@@ -51,10 +51,10 @@ rba:
threat_objects: []
tags:
analytic_story:
- China-Nexus Threat Activity
- SnappyBee
- RedLine Stealer
- Earth Estries
- China-Nexus Threat Activity
- Salt Typhoon
asset_type: Endpoint
mitre_attack_id:
- T1012
@@ -62,12 +62,12 @@ rba:
type: file_name
tags:
analytic_story:
- NjRAT
- PlugX
- China-Nexus Threat Activity
- Chaos Ransomware
- Derusbi
- PlugX
- Earth Estries
- Salt Typhoon
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- T1091
@@ -1,7 +1,7 @@
name: Windows Service Created with Suspicious Service Path
id: 429141be-8311-11eb-adb6-acde48001122
version: '13'
date: '2025-02-24'
version: '14'
date: '2025-03-19'
author: Teoderick Contreras, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -54,18 +54,18 @@ rba:
type: service
tags:
analytic_story:
- China-Nexus Threat Activity
- Crypto Stealer
- Qakbot
- Snake Malware
- Brute Ratel C4
- Derusbi
- Active Directory Lateral Movement
- Clop Ransomware
- Flax Typhoon
- CISA AA23-347A
- PlugX
- Earth Estries
- Qakbot
- China-Nexus Threat Activity
- CISA AA23-347A
- Flax Typhoon
- Derusbi
- Salt Typhoon
- Active Directory Lateral Movement
- Snake Malware
- Clop Ransomware
- Crypto Stealer
- Brute Ratel C4
asset_type: Endpoint
mitre_attack_id:
- T1569.002
@@ -65,11 +65,11 @@ rba:
threat_objects: []
tags:
analytic_story:
- SnappyBee
- CISA AA23-347A
- Active Directory Lateral Movement
- China-Nexus Threat Activity
- Earth Estries
- CISA AA23-347A
- SnappyBee
- Salt Typhoon
- Active Directory Lateral Movement
asset_type: Endpoint
mitre_attack_id:
- T1543.003
@@ -54,18 +54,18 @@ rba:
threat_objects: []
tags:
analytic_story:
- SnappyBee
- Windows Persistence Techniques
- Brute Ratel C4
- CISA AA23-347A
- Suspicious Windows Registry Activities
- China-Nexus Threat Activity
- Derusbi
- PlugX
- CISA AA23-347A
- China-Nexus Threat Activity
- Windows Persistence Techniques
- SnappyBee
- Derusbi
- Windows Registry Abuse
- Salt Typhoon
- Active Directory Lateral Movement
- Suspicious Windows Registry Activities
- Crypto Stealer
- Earth Estries
- Brute Ratel C4
asset_type: Endpoint
mitre_attack_id:
- T1574.011
@@ -57,9 +57,9 @@ rba:
threat_objects: []
tags:
analytic_story:
- SnappyBee
- Salt Typhoon
- China-Nexus Threat Activity
- Earth Estries
- SnappyBee
asset_type: Endpoint
mitre_attack_id:
- T1112
@@ -74,44 +74,44 @@ rba:
type: process_name
tags:
analytic_story:
- Double Zero Destructor
- Graceful Wipe Out Attack
- AsyncRAT
- WhisperGate
- Prestige Ransomware
- DarkGate Malware
- AgentTesla
- Brute Ratel C4
- RedLine Stealer
- Rhysida Ransomware
- Swift Slicer
- IcedID
- DarkCrystal RAT
- Chaos Ransomware
- PlugX
- Industroyer2
- Azorult
- Remcos
- XMRig
- Qakbot
- Volt Typhoon
- Hermetic Wiper
- Warzone RAT
- Trickbot
- Amadey
- BlackByte Ransomware
- LockBit Ransomware
- CISA AA23-347A
- Data Destruction
- Phemedrone Stealer
- Handala Wiper
- MoonPeak
- ValleyRAT
- Meduza Stealer
- SystemBC
- China-Nexus Threat Activity
- Earth Estries
- Remcos
- LockBit Ransomware
- AsyncRAT
- DarkCrystal RAT
- DarkGate Malware
- ValleyRAT
- PlugX
- Data Destruction
- Qakbot
- CISA AA23-347A
- Hermetic Wiper
- Volt Typhoon
- Double Zero Destructor
- AgentTesla
- Trickbot
- Meduza Stealer
- Phemedrone Stealer
- SnappyBee
- Azorult
- WhisperGate
- Warzone RAT
- Swift Slicer
- Rhysida Ransomware
- Brute Ratel C4
- Prestige Ransomware
- BlackByte Ransomware
- Graceful Wipe Out Attack
- Chaos Ransomware
- Handala Wiper
- RedLine Stealer
- Salt Typhoon
- XMRig
- MoonPeak
- Industroyer2
- Amadey
- IcedID
asset_type: Endpoint
mitre_attack_id:
- T1543
@@ -54,11 +54,11 @@ rba:
threat_objects: []
tags:
analytic_story:
- Warzone RAT
- NjRAT
- China-Nexus Threat Activity
- Derusbi
- Earth Estries
- Warzone RAT
- Salt Typhoon
- NjRAT
asset_type: Endpoint
mitre_attack_id:
- T1574.002
@@ -56,12 +56,12 @@ rba:
threat_objects: []
tags:
analytic_story:
- China-Nexus Threat Activity
- Derusbi
- DarkGate Malware
- PlugX
- Earth Estries
- China-Nexus Threat Activity
- SnappyBee
- Derusbi
- Salt Typhoon
- DarkGate Malware
asset_type: Endpoint
mitre_attack_id:
- T1574.002
@@ -68,8 +68,8 @@ tags:
analytic_story:
- China-Nexus Threat Activity
- Derusbi
- Salt Typhoon
- APT29 Diplomatic Deceptions with WINELOADER
- Earth Estries
group:
- APT29
- Cozy Bear
@@ -65,9 +65,9 @@ rba:
type: process_name
tags:
analytic_story:
- China-Nexus Threat Activity
- DarkGate Malware
- Earth Estries
- Salt Typhoon
- China-Nexus Threat Activity
asset_type: Endpoint
mitre_attack_id:
- T1036.009
@@ -1,7 +1,7 @@
name: WinEvent Scheduled Task Created to Spawn Shell
id: 203ef0ea-9bd8-11eb-8201-acde48001122
version: '12'
date: '2025-03-14'
date: '2025-03-19'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -54,18 +54,19 @@ rba:
threat_objects: []
tags:
analytic_story:
- Windows Error Reporting Service Elevation of Privilege Vulnerability
- CISA AA22-257A
- Ransomware
- Medusa Ransomware
- Windows Persistence Techniques
- Earth Estries
- Scheduled Tasks
- Compromised Windows Host
- Ryuk Ransomware
- Winter Vivern
- China-Nexus Threat Activity
- Compromised Windows Host
- Earth Estries
- Medusa Ransomware
- Ransomware
- Ryuk Ransomware
- Salt Typhoon
- Scheduled Tasks
- SystemBC
- Windows Error Reporting Service Elevation of Privilege Vulnerability
- Windows Persistence Techniques
- Winter Vivern
asset_type: Endpoint
mitre_attack_id:
- T1053.005
@@ -1,7 +1,7 @@
name: WinEvent Scheduled Task Created Within Public Path
id: 5d9c6eee-988c-11eb-8253-acde48001122
version: '12'
date: '2025-03-14'
date: '2025-03-19'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -55,23 +55,24 @@ rba:
tags:
analytic_story:
- Active Directory Lateral Movement
- Industroyer2
- AsyncRAT
- China-Nexus Threat Activity
- CISA AA22-257A
- Data Destruction
- CISA AA23-347A
- Compromised Windows Host
- Data Destruction
- Earth Estries
- IcedID
- Industroyer2
- Medusa Ransomware
- Prestige Ransomware
- Ransomware
- Medusa Ransomware
- Windows Persistence Techniques
- Earth Estries
- Scheduled Tasks
- Compromised Windows Host
- IcedID
- Ryuk Ransomware
- Winter Vivern
- China-Nexus Threat Activity
- Salt Typhoon
- Scheduled Tasks
- SystemBC
- Windows Persistence Techniques
- Winter Vivern
asset_type: Endpoint
mitre_attack_id:
- T1053.005
+18
View File
@@ -0,0 +1,18 @@
name: Salt Typhoon
id: 7df800b1-af23-4f65-ac36-abe87374ee72
version: 1
date: '2025-03-19'
author: Teoderick Contreras, Splunk
status: production
description: Leverage searches that allow you to detect and investigate unusual activities that might relate to Salt Typhoon, a sophisticated threat actor targeting various sectors with espionage-focused campaigns. Monitor for indicators such as spear-phishing emails, unauthorized access attempts, and lateral movement within your network. Investigate anomalous data exfiltration patterns and command-and-control (C2) traffic consistent with known tactics, techniques, and procedures (TTPs) of this group. Combining threat intelligence with advanced monitoring tools helps identify potential Salt Typhoon activity early, enabling swift response to mitigate risks effectively.
narrative: Salt Typhoon is a highly capable threat actor known for conducting targeted espionage campaigns against diverse sectors, including government, technology, and critical infrastructure. This group leverages sophisticated tactics such as spear-phishing, credential theft, and exploiting software vulnerabilities to gain initial access. Once inside a network, Salt Typhoon demonstrates expertise in lateral movement, privilege escalation, and covert data exfiltration. Their use of custom malware and command-and-control (C2) infrastructures highlights their adaptability. Detecting their activity requires robust threat intelligence and proactive monitoring of unusual behaviors and network anomalies.
references:
- https://www.trendmicro.com/en_nl/research/24/k/earth-estries.html
tags:
category:
- Malware
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection