diff --git a/detections/endpoint/any_powershell_downloadfile.yml b/detections/endpoint/any_powershell_downloadfile.yml index b17b566403..f036b0bbed 100644 --- a/detections/endpoint/any_powershell_downloadfile.yml +++ b/detections/endpoint/any_powershell_downloadfile.yml @@ -74,18 +74,18 @@ rba: type: process_name tags: analytic_story: - - Ingress Tool Transfer + - Data Destruction + - Malicious PowerShell - China-Nexus Threat Activity - - Crypto Stealer - Hermetic Wiper - DarkCrystal RAT - - Malicious PowerShell - - Earth Estries - Phemedrone Stealer - - Braodo Stealer - PXA Stealer - - Data Destruction - Log4Shell CVE-2021-44228 + - Salt Typhoon + - Braodo Stealer + - Crypto Stealer + - Ingress Tool Transfer - PHP-CGI RCE Attack on Japanese Organizations asset_type: Endpoint cve: diff --git a/detections/endpoint/detect_rare_executables.yml b/detections/endpoint/detect_rare_executables.yml index caa455178d..7367c7f959 100644 --- a/detections/endpoint/detect_rare_executables.yml +++ b/detections/endpoint/detect_rare_executables.yml @@ -68,12 +68,12 @@ rba: threat_objects: [] tags: analytic_story: - - SnappyBee - - Rhysida Ransomware - China-Nexus Threat Activity - - Crypto Stealer - - Earth Estries - Unusual Processes + - SnappyBee + - Salt Typhoon + - Rhysida Ransomware + - Crypto Stealer asset_type: Endpoint mitre_attack_id: - T1204 diff --git a/detections/endpoint/detect_renamed_psexec.yml b/detections/endpoint/detect_renamed_psexec.yml index baad183cdd..7cb449ea4a 100644 --- a/detections/endpoint/detect_renamed_psexec.yml +++ b/detections/endpoint/detect_renamed_psexec.yml @@ -42,19 +42,20 @@ references: - https://redcanary.com/blog/threat-hunting-psexec-lateral-movement/ tags: analytic_story: - - DHS Report TA18-074A - Active Directory Lateral Movement - BlackByte Ransomware - - HAFNIUM Group - - Rhysida Ransomware - - Medusa Ransomware - - DarkSide Ransomware - - Earth Estries - - SamSam Ransomware - - DarkGate Malware - - CISA AA22-320A - - Sandworm Tools - China-Nexus Threat Activity + - CISA AA22-320A + - DarkGate Malware + - DarkSide Ransomware + - DHS Report TA18-074A + - Earth Estries + - HAFNIUM Group + - Medusa Ransomware + - Rhysida Ransomware + - Salt Typhoon + - SamSam Ransomware + - Sandworm Tools - VanHelsing Ransomware asset_type: Endpoint mitre_attack_id: diff --git a/detections/endpoint/detect_renamed_winrar.yml b/detections/endpoint/detect_renamed_winrar.yml index 8900ec7c2a..135eea84a2 100644 --- a/detections/endpoint/detect_renamed_winrar.yml +++ b/detections/endpoint/detect_renamed_winrar.yml @@ -42,9 +42,9 @@ references: tags: analytic_story: - China-Nexus Threat Activity - - CISA AA22-277A - Collection and Staging - - Earth Estries + - CISA AA22-277A + - Salt Typhoon asset_type: Endpoint mitre_attack_id: - T1560.001 diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml index 2250bca972..77848c7be3 100644 --- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml @@ -63,48 +63,48 @@ rba: type: file_name tags: analytic_story: - - BlackByte Ransomware - - Brute Ratel C4 - - Trickbot - - Snake Keylogger - - Graceful Wipe Out Attack - - PlugX - - Handala Wiper - - Earth Estries - - Warzone RAT - - ValleyRAT - - NjRAT - - LockBit Ransomware - - Double Zero Destructor - - Swift Slicer - - DarkCrystal RAT - - AsyncRAT - - Volt Typhoon - - Chaos Ransomware - - Hermetic Wiper - - Derusbi - - XMRig - - AgentTesla - - WinDealer RAT - - RedLine Stealer - - Remcos - - Rhysida Ransomware - - China-Nexus Threat Activity - - Crypto Stealer - - Qakbot - - IcedID - - Meduza Stealer - - AcidPour - - MoonPeak - - CISA AA23-347A - - DarkGate Malware - - Industroyer2 - - Azorult - - Data Destruction - - Amadey - - SnappyBee - - WhisperGate - SystemBC + - Snake Keylogger + - China-Nexus Threat Activity + - Remcos + - LockBit Ransomware + - AsyncRAT + - DarkCrystal RAT + - Derusbi + - WinDealer RAT + - DarkGate Malware + - Crypto Stealer + - ValleyRAT + - AcidPour + - PlugX + - Data Destruction + - Qakbot + - CISA AA23-347A + - Hermetic Wiper + - Volt Typhoon + - Double Zero Destructor + - NjRAT + - Trickbot + - AgentTesla + - Meduza Stealer + - SnappyBee + - Azorult + - WhisperGate + - Warzone RAT + - Swift Slicer + - Rhysida Ransomware + - Brute Ratel C4 + - BlackByte Ransomware + - Graceful Wipe Out Attack + - Chaos Ransomware + - Handala Wiper + - RedLine Stealer + - Salt Typhoon + - XMRig + - MoonPeak + - Industroyer2 + - Amadey + - IcedID asset_type: Endpoint mitre_attack_id: - T1036 diff --git a/detections/endpoint/executables_or_script_creation_in_temp_path.yml b/detections/endpoint/executables_or_script_creation_in_temp_path.yml index 22f4901a81..ecdd3c4717 100644 --- a/detections/endpoint/executables_or_script_creation_in_temp_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_temp_path.yml @@ -60,47 +60,47 @@ rba: type: file_name tags: analytic_story: - - Chaos Ransomware - - Trickbot - Snake Keylogger - - CISA AA23-347A - - Industroyer2 - - WinDealer RAT - - Qakbot - - Warzone RAT - - IcedID - - ValleyRAT - - Azorult - - Handala Wiper - - LockBit Ransomware - - Meduza Stealer - - Brute Ratel C4 - - AsyncRAT - - AcidPour - - Derusbi - - DarkGate Malware - - Graceful Wipe Out Attack - - NjRAT - - WhisperGate - - Data Destruction - - BlackByte Ransomware - - AgentTesla - - Swift Slicer - - Crypto Stealer - - Hermetic Wiper - - MoonPeak - - Double Zero Destructor - - XMRig - - PlugX - - Amadey - - DarkCrystal RAT - - Remcos - China-Nexus Threat Activity - - Earth Estries - - Rhysida Ransomware - - RedLine Stealer + - Remcos + - LockBit Ransomware + - AsyncRAT + - DarkCrystal RAT + - Derusbi + - WinDealer RAT + - DarkGate Malware + - AcidPour + - ValleyRAT + - Crypto Stealer + - PlugX + - Data Destruction + - Qakbot + - CISA AA23-347A + - Hermetic Wiper - Volt Typhoon + - Double Zero Destructor + - NjRAT + - Trickbot + - Meduza Stealer + - AgentTesla - SnappyBee + - Azorult + - WhisperGate + - Warzone RAT + - Swift Slicer + - Rhysida Ransomware + - Brute Ratel C4 + - BlackByte Ransomware + - Graceful Wipe Out Attack + - Chaos Ransomware + - Handala Wiper + - RedLine Stealer + - Salt Typhoon + - XMRig + - MoonPeak + - Industroyer2 + - Amadey + - IcedID asset_type: Endpoint mitre_attack_id: - T1036 diff --git a/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml b/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml index c67f79f8db..44f5a6a8a0 100644 --- a/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml +++ b/detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml @@ -1,8 +1,8 @@ name: Linux Auditd File Permission Modification Via Chmod id: 5f1d2ea7-eec0-4790-8b24-6875312ad492 -version: 9 -date: '2025-02-24' -author: Teoderick Contreras, Splunk, Ivar Nygård +version: '10' +date: '2025-03-19' +author: "Teoderick Contreras, Splunk, Ivar Nyg\xE5rd" status: production type: Anomaly description: The following analytic detects suspicious file permission modifications @@ -15,12 +15,10 @@ description: The following analytic detects suspicious file permission modificat actions on the system. data_source: - Linux Auditd Proctitle -search: '`linux_auditd` proctitle="*chmod*" AND proctitle IN ("* 777 *", "* 755 *", "*+*x*", "* 754 *") - | rename host as dest - | stats count min(_time) as firstTime max(_time) as lastTime by proctitle dest - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `linux_auditd_file_permission_modification_via_chmod_filter`' +search: '`linux_auditd` proctitle="*chmod*" AND proctitle IN ("* 777 *", "* 755 *", + "*+*x*", "* 754 *") | rename host as dest | stats count min(_time) as firstTime + max(_time) as lastTime by proctitle dest | `security_content_ctime(firstTime)` | + `security_content_ctime(lastTime)` | `linux_auditd_file_permission_modification_via_chmod_filter`' how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should @@ -58,13 +56,13 @@ rba: threat_objects: [] tags: analytic_story: - - China-Nexus Threat Activity - Linux Persistence Techniques - - XorDDos - - Linux Privilege Escalation - Compromised Linux Host + - China-Nexus Threat Activity - Linux Living Off The Land - - Earth Estries + - XorDDos + - Salt Typhoon + - Linux Privilege Escalation asset_type: Endpoint mitre_attack_id: - T1222.002 @@ -76,8 +74,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chmod_exec_attrib/auditd_proctitle_chmod.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chmod_exec_attrib/auditd_proctitle_chmod.log source: auditd sourcetype: auditd - diff --git a/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml b/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml index e63b07e312..aad95585df 100644 --- a/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml +++ b/detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml @@ -1,7 +1,7 @@ name: Linux Auditd Nopasswd Entry In Sudoers File id: 651df959-ad17-4b73-a323-90cb96d5fa1b -version: 6 -date: '2025-02-24' +version: '7' +date: '2025-03-19' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -14,11 +14,9 @@ description: The following analytic detects the addition of NOPASSWD entries to and potential compromise of sensitive data and system integrity. data_source: - Linux Auditd Proctitle -search: '`linux_auditd` proctitle = "*NOPASSWD*" - | rename host as dest - | stats count min(_time) as firstTime max(_time) as lastTime by proctitle dest - | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` - | `linux_auditd_nopasswd_entry_in_sudoers_file_filter`' +search: '`linux_auditd` proctitle = "*NOPASSWD*" | rename host as dest | stats count + min(_time) as firstTime max(_time) as lastTime by proctitle dest | `security_content_ctime(firstTime)`| + `security_content_ctime(lastTime)` | `linux_auditd_nopasswd_entry_in_sudoers_file_filter`' how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consist SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested @@ -57,11 +55,11 @@ rba: threat_objects: [] tags: analytic_story: - - China-Nexus Threat Activity - Linux Persistence Techniques - - Linux Privilege Escalation - Compromised Linux Host - - Earth Estries + - China-Nexus Threat Activity + - Salt Typhoon + - Linux Privilege Escalation asset_type: Endpoint mitre_attack_id: - T1548.003 @@ -73,8 +71,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_nopasswd/linux_auditd_nopasswd2.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_nopasswd/linux_auditd_nopasswd2.log source: auditd sourcetype: auditd - diff --git a/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml b/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml index 664b6dc24f..5e3d2312b2 100644 --- a/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml +++ b/detections/endpoint/linux_auditd_possible_access_to_credential_files.yml @@ -1,7 +1,7 @@ name: Linux Auditd Possible Access To Credential Files id: 0419cb7a-57ea-467b-974f-77c303dfe2a3 -version: 7 -date: '2025-02-24' +version: '8' +date: '2025-03-19' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -14,11 +14,10 @@ description: The following analytic detects attempts to access or dump the conte offline cracking, leading to unauthorized access and potential system compromise. data_source: - Linux Auditd Proctitle -search: '`linux_auditd` proctitle IN ("*shadow*", "*passwd*") AND proctitle IN ("*cat *", "*nano *", "*vim *", "*vi *") - | rename host as dest - | stats count min(_time) as firstTime max(_time) as lastTime by proctitle dest - | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `linux_auditd_possible_access_to_credential_files_filter`' +search: '`linux_auditd` proctitle IN ("*shadow*", "*passwd*") AND proctitle IN ("*cat + *", "*nano *", "*vim *", "*vi *") | rename host as dest | stats count min(_time) + as firstTime max(_time) as lastTime by proctitle dest | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `linux_auditd_possible_access_to_credential_files_filter`' how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consist SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should be ingested @@ -48,8 +47,8 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: A [$proctitle$] event occurred on host - [$dest$] to access or dump - the contents of /etc/passwd and /etc/shadow files. + message: A [$proctitle$] event occurred on host - [$dest$] to access or dump the + contents of /etc/passwd and /etc/shadow files. risk_objects: - field: dest type: system @@ -57,11 +56,11 @@ rba: threat_objects: [] tags: analytic_story: - - China-Nexus Threat Activity - Linux Persistence Techniques - - Linux Privilege Escalation - Compromised Linux Host - - Earth Estries + - China-Nexus Threat Activity + - Salt Typhoon + - Linux Privilege Escalation asset_type: Endpoint mitre_attack_id: - T1003.008 @@ -73,7 +72,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/linux_auditd_access_credential/auditd_proctitle_access_cred.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/linux_auditd_access_credential/auditd_proctitle_access_cred.log source: auditd sourcetype: auditd - diff --git a/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml b/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml index 7956cd39cd..fc9e2d1a8b 100644 --- a/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml +++ b/detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml @@ -1,7 +1,7 @@ name: Linux Auditd Possible Access To Sudoers File id: 8be88f46-f7e8-4ae6-b15e-cf1b13392834 -version: 7 -date: '2025-02-24' +version: '8' +date: '2025-03-19' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -56,11 +56,11 @@ rba: threat_objects: [] tags: analytic_story: - - China-Nexus Threat Activity - Linux Persistence Techniques - - Linux Privilege Escalation - Compromised Linux Host - - Earth Estries + - China-Nexus Threat Activity + - Salt Typhoon + - Linux Privilege Escalation asset_type: Endpoint mitre_attack_id: - T1548.003 @@ -72,8 +72,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudoers_access/linux_auditd_sudoers_access.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudoers_access/linux_auditd_sudoers_access.log source: auditd sourcetype: auditd - diff --git a/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml b/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml index 768f61b597..f4906c1255 100644 --- a/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml +++ b/detections/endpoint/linux_auditd_preload_hijack_library_calls.yml @@ -1,7 +1,7 @@ name: Linux Auditd Preload Hijack Library Calls id: 35c50572-a70b-452f-afa9-bebdf3c3ce36 -version: 7 -date: '2025-02-24' +version: '8' +date: '2025-03-19' author: Teoderick Contreras, Splunk status: production type: TTP @@ -15,13 +15,10 @@ description: The following analytic detects the use of the LD_PRELOAD environmen access to the system. data_source: - Linux Auditd Execve -search: '`linux_auditd` execve_command = "*LD_PRELOAD*" - | rename host as dest - | rename comm as process_name - | rename exe as process - | stats count min(_time) as firstTime max(_time) as lastTime by argc execve_command dest - | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` - | `linux_auditd_preload_hijack_library_calls_filter`' +search: '`linux_auditd` execve_command = "*LD_PRELOAD*" | rename host as dest | rename + comm as process_name | rename exe as process | stats count min(_time) as firstTime + max(_time) as lastTime by argc execve_command dest | `security_content_ctime(firstTime)`| + `security_content_ctime(lastTime)` | `linux_auditd_preload_hijack_library_calls_filter`' how_to_implement: To implement this detection, the process begins by ingesting auditd data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line executions and process details on Unix/Linux systems. These logs should @@ -59,11 +56,11 @@ rba: threat_objects: [] tags: analytic_story: - - China-Nexus Threat Activity - Linux Persistence Techniques - - Linux Privilege Escalation - Compromised Linux Host - - Earth Estries + - China-Nexus Threat Activity + - Salt Typhoon + - Linux Privilege Escalation asset_type: Endpoint mitre_attack_id: - T1574.006 @@ -75,8 +72,6 @@ tags: tests: - name: True Positive Test attack_data: - - data: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/linux_auditd_ldpreload/auditd_execve_ldpreload.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/linux_auditd_ldpreload/auditd_execve_ldpreload.log source: auditd sourcetype: auditd - diff --git a/detections/endpoint/linux_common_process_for_elevation_control.yml b/detections/endpoint/linux_common_process_for_elevation_control.yml index 8f25bd671c..c4b241c16d 100644 --- a/detections/endpoint/linux_common_process_for_elevation_control.yml +++ b/detections/endpoint/linux_common_process_for_elevation_control.yml @@ -48,11 +48,11 @@ references: - https://github.com/microsoft/MSTIC-Sysmon/blob/main/linux/configs/attack-based/privilege_escalation/T1548.001_ElevationControl_CommonProcesses.xml tags: analytic_story: - - China-Nexus Threat Activity - Linux Persistence Techniques - - Linux Privilege Escalation + - China-Nexus Threat Activity - Linux Living Off The Land - - Earth Estries + - Salt Typhoon + - Linux Privilege Escalation asset_type: Endpoint mitre_attack_id: - T1548.001 diff --git a/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml b/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml index fffdf4fa11..93fcb838a1 100644 --- a/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml +++ b/detections/endpoint/linux_nopasswd_entry_in_sudoers_file.yml @@ -61,10 +61,10 @@ rba: threat_objects: [] tags: analytic_story: - - China-Nexus Threat Activity - Linux Persistence Techniques + - China-Nexus Threat Activity + - Salt Typhoon - Linux Privilege Escalation - - Earth Estries asset_type: Endpoint mitre_attack_id: - T1548.003 diff --git a/detections/endpoint/linux_possible_access_to_credential_files.yml b/detections/endpoint/linux_possible_access_to_credential_files.yml index 594cbc6f4b..464ef2c05d 100644 --- a/detections/endpoint/linux_possible_access_to_credential_files.yml +++ b/detections/endpoint/linux_possible_access_to_credential_files.yml @@ -61,11 +61,11 @@ rba: threat_objects: [] tags: analytic_story: - - China-Nexus Threat Activity - Linux Persistence Techniques + - China-Nexus Threat Activity - XorDDos + - Salt Typhoon - Linux Privilege Escalation - - Earth Estries asset_type: Endpoint mitre_attack_id: - T1003.008 diff --git a/detections/endpoint/linux_possible_access_to_sudoers_file.yml b/detections/endpoint/linux_possible_access_to_sudoers_file.yml index a430dc63b1..a57047bb68 100644 --- a/detections/endpoint/linux_possible_access_to_sudoers_file.yml +++ b/detections/endpoint/linux_possible_access_to_sudoers_file.yml @@ -61,10 +61,10 @@ rba: threat_objects: [] tags: analytic_story: - - China-Nexus Threat Activity - Linux Persistence Techniques + - China-Nexus Threat Activity + - Salt Typhoon - Linux Privilege Escalation - - Earth Estries asset_type: Endpoint mitre_attack_id: - T1548.003 diff --git a/detections/endpoint/linux_preload_hijack_library_calls.yml b/detections/endpoint/linux_preload_hijack_library_calls.yml index 1fb96b33be..9f82133d5f 100644 --- a/detections/endpoint/linux_preload_hijack_library_calls.yml +++ b/detections/endpoint/linux_preload_hijack_library_calls.yml @@ -60,10 +60,10 @@ rba: threat_objects: [] tags: analytic_story: - - China-Nexus Threat Activity - Linux Persistence Techniques + - China-Nexus Threat Activity + - Salt Typhoon - Linux Privilege Escalation - - Earth Estries asset_type: Endpoint mitre_attack_id: - T1574.006 diff --git a/detections/endpoint/linux_sudoers_tmp_file_creation.yml b/detections/endpoint/linux_sudoers_tmp_file_creation.yml index 0c994d9040..0a529c7205 100644 --- a/detections/endpoint/linux_sudoers_tmp_file_creation.yml +++ b/detections/endpoint/linux_sudoers_tmp_file_creation.yml @@ -53,10 +53,10 @@ rba: threat_objects: [] tags: analytic_story: - - China-Nexus Threat Activity - Linux Persistence Techniques + - China-Nexus Threat Activity + - Salt Typhoon - Linux Privilege Escalation - - Earth Estries asset_type: Endpoint mitre_attack_id: - T1548.003 diff --git a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml index 32757b4ae4..058fd211ae 100644 --- a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml +++ b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml @@ -67,12 +67,12 @@ rba: tags: analytic_story: - China-Nexus Threat Activity + - AsyncRAT + - DarkCrystal RAT + - Volt Typhoon + - Salt Typhoon - HAFNIUM Group - DHS Report TA18-074A - - DarkCrystal RAT - - AsyncRAT - - Earth Estries - - Volt Typhoon asset_type: Endpoint mitre_attack_id: - T1059.001 diff --git a/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml b/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml index 061a40ecc7..fcc41a5bd0 100644 --- a/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml +++ b/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml @@ -1,7 +1,7 @@ name: Non Chrome Process Accessing Chrome Default Dir id: 81263de4-160a-11ec-944f-acde48001122 -version: '8' -date: '2025-02-24' +version: '9' +date: '2025-03-19' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -49,20 +49,20 @@ rba: threat_objects: [] tags: analytic_story: - - SnappyBee - - Phemedrone Stealer - - Snake Keylogger - - NjRAT - - CISA AA23-347A - - 3CX Supply Chain Attack - - FIN7 - - Earth Estries - - Warzone RAT - - China-Nexus Threat Activity - - DarkGate Malware - - Remcos - - RedLine Stealer - AgentTesla + - Snake Keylogger + - CISA AA23-347A + - China-Nexus Threat Activity + - Remcos + - FIN7 + - Phemedrone Stealer + - SnappyBee + - RedLine Stealer + - Warzone RAT + - Salt Typhoon + - 3CX Supply Chain Attack + - DarkGate Malware + - NjRAT asset_type: Endpoint mitre_attack_id: - T1555.003 diff --git a/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml b/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml index c9e182d0f7..ea7222e188 100644 --- a/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml +++ b/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml @@ -1,7 +1,7 @@ name: Non Firefox Process Access Firefox Profile Dir id: e6fc13b0-1609-11ec-b533-acde48001122 -version: '7' -date: '2025-02-13' +version: '8' +date: '2025-03-19' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -48,21 +48,21 @@ rba: threat_objects: [] tags: analytic_story: - - SnappyBee - - Phemedrone Stealer - - Snake Keylogger - - NjRAT - - CISA AA23-347A - - 3CX Supply Chain Attack - - Azorult - - China-Nexus Threat Activity - - Warzone RAT - AgentTesla - - RedLine Stealer - - DarkGate Malware + - Snake Keylogger + - CISA AA23-347A + - China-Nexus Threat Activity - Remcos - - Earth Estries - FIN7 + - Phemedrone Stealer + - SnappyBee + - Azorult + - RedLine Stealer + - Warzone RAT + - Salt Typhoon + - 3CX Supply Chain Attack + - DarkGate Malware + - NjRAT asset_type: Endpoint mitre_attack_id: - T1555.003 diff --git a/detections/endpoint/powershell_4104_hunting.yml b/detections/endpoint/powershell_4104_hunting.yml index 7f03026ec7..292eb93fbf 100644 --- a/detections/endpoint/powershell_4104_hunting.yml +++ b/detections/endpoint/powershell_4104_hunting.yml @@ -59,20 +59,21 @@ references: - https://adlumin.com/post/powerdrop-a-new-insidious-powershell-script-for-command-and-control-attacks-targets-u-s-aerospace-defense-industry/ tags: analytic_story: - - Hermetic Wiper - - Flax Typhoon - - China-Nexus Threat Activity - - Lumma Stealer - - Data Destruction - - CISA AA23-347A - - Cleo File Transfer Software - - Medusa Ransomware - - CISA AA24-241A - - Earth Estries - Braodo Stealer + - China-Nexus Threat Activity + - CISA AA23-347A + - CISA AA24-241A + - Cleo File Transfer Software - DarkGate Malware - - Rhysida Ransomware + - Data Destruction + - Earth Estries + - Flax Typhoon + - Hermetic Wiper + - Lumma Stealer - Malicious PowerShell + - Medusa Ransomware + - Rhysida Ransomware + - Salt Typhoon - SystemBC - PHP-CGI RCE Attack on Japanese Organizations asset_type: Endpoint diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 113ece6636..d9bd3c7a9b 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -78,39 +78,38 @@ rba: threat_objects: [] tags: analytic_story: - - Amadey - - AsyncRAT - - Azorult - - BlackByte Ransomware - - BlackSuit Ransomware - - Braodo Stealer - - Chaos Ransomware - - China-Nexus Threat Activity - - CISA AA23-347A - - DarkGate Malware - - Derusbi - - DHS Report TA18-074A - - Earth Estries - - Emotet Malware DHS Report TA18-201A - - IcedID - - MoonPeak - - NjRAT - - Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns - - Qakbot - - Ransomware - - RedLine Stealer - - Remcos - - PHP-CGI RCE Attack on Japanese Organizations - - Snake Keylogger - - SnappyBee - - Sneaky Active Directory Persistence Tricks - - Suspicious MSHTA Activity - - Suspicious Windows Registry Activities - SystemBC - - Warzone RAT - - WinDealer RAT + - Snake Keylogger + - China-Nexus Threat Activity + - Remcos + - AsyncRAT - Windows Persistence Techniques + - Derusbi + - WinDealer RAT + - Suspicious MSHTA Activity + - DarkGate Malware + - Suspicious Windows Registry Activities + - Qakbot + - CISA AA23-347A + - Ransomware + - NjRAT + - Emotet Malware DHS Report TA18-201A + - Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns + - Sneaky Active Directory Persistence Tricks + - SnappyBee + - Azorult + - Warzone RAT + - BlackByte Ransomware + - Chaos Ransomware + - RedLine Stealer + - BlackSuit Ransomware - Windows Registry Abuse + - Amadey + - Salt Typhoon + - MoonPeak + - Braodo Stealer + - DHS Report TA18-074A + - IcedID asset_type: Endpoint mitre_attack_id: - T1547.001 diff --git a/detections/endpoint/remote_process_instantiation_via_wmi.yml b/detections/endpoint/remote_process_instantiation_via_wmi.yml index 8c6f4613b2..e6815e33c7 100644 --- a/detections/endpoint/remote_process_instantiation_via_wmi.yml +++ b/detections/endpoint/remote_process_instantiation_via_wmi.yml @@ -69,12 +69,12 @@ rba: threat_objects: [] tags: analytic_story: + - CISA AA23-347A - China-Nexus Threat Activity - Ransomware - - Active Directory Lateral Movement - - CISA AA23-347A - Suspicious WMI Use - - Earth Estries + - Salt Typhoon + - Active Directory Lateral Movement asset_type: Endpoint mitre_attack_id: - T1047 diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml index b286ad7d44..f9f43411a2 100644 --- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml +++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml @@ -71,33 +71,34 @@ rba: threat_objects: [] tags: analytic_story: - - Prestige Ransomware - - Medusa Ransomware - - Earth Estries - - Scheduled Tasks - - RedLine Stealer - - Azorult - - Living Off The Land - - Sandworm Tools - - Trickbot - - ShrinkLocker - - MoonPeak - - Winter Vivern - - AsyncRAT - AgentTesla + - Amadey + - AsyncRAT + - Azorult + - China-Nexus Threat Activity - CISA AA22-257A - - NOBELIUM Group - CISA AA23-347A - - Qakbot - - Windows Persistence Techniques - CISA AA24-241A - DarkCrystal RAT - - Amadey - - Rhysida Ransomware - DHS Report TA18-074A + - Earth Estries + - Living Off The Land + - Medusa Ransomware + - MoonPeak - NjRAT + - NOBELIUM Group - Phemedrone Stealer - - China-Nexus Threat Activity + - Prestige Ransomware + - Qakbot + - RedLine Stealer + - Rhysida Ransomware + - Salt Typhoon + - Sandworm Tools + - Scheduled Tasks + - ShrinkLocker + - Trickbot + - Windows Persistence Techniques + - Winter Vivern asset_type: Endpoint mitre_attack_id: - T1053.005 diff --git a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml index d009b01ced..3da8e91526 100644 --- a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml +++ b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml @@ -76,13 +76,13 @@ rba: type: process_name tags: analytic_story: - - China-Nexus Threat Activity - - IcedID - - Qakbot - - Derusbi - Living Off The Land - - Earth Estries + - Qakbot + - China-Nexus Threat Activity + - Derusbi + - Salt Typhoon - Suspicious Regsvr32 Activity + - IcedID asset_type: Endpoint mitre_attack_id: - T1218.010 diff --git a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml index 8038c090b8..3144dde09e 100644 --- a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml +++ b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml @@ -69,20 +69,21 @@ rba: threat_objects: [] tags: analytic_story: - - CISA AA23-347A - - Ransomware - - MoonPeak - - Windows Persistence Techniques - - CISA AA24-241A - - Earth Estries - - Scheduled Tasks - - Medusa Ransomware - - DarkCrystal RAT - Azorult - - Living Off The Land - - Crypto Stealer - - Ryuk Ransomware - China-Nexus Threat Activity + - CISA AA23-347A + - CISA AA24-241A + - Crypto Stealer + - DarkCrystal RAT + - Earth Estries + - Living Off The Land + - Medusa Ransomware + - MoonPeak + - Ransomware + - Ryuk Ransomware + - Salt Typhoon + - Scheduled Tasks + - Windows Persistence Techniques asset_type: Endpoint mitre_attack_id: - T1053.005 diff --git a/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml b/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml index 28005dd373..37bf2399d9 100644 --- a/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml +++ b/detections/endpoint/windows_access_token_manipulation_sedebugprivilege.yml @@ -56,18 +56,18 @@ rba: threat_objects: [] tags: analytic_story: + - Meduza Stealer + - PlugX + - CISA AA23-347A + - China-Nexus Threat Activity + - AsyncRAT - SnappyBee + - Derusbi + - WinDealer RAT + - Salt Typhoon + - DarkGate Malware - ValleyRAT - Brute Ratel C4 - - WinDealer RAT - - Meduza Stealer - - CISA AA23-347A - - AsyncRAT - - Derusbi - - PlugX - - China-Nexus Threat Activity - - DarkGate Malware - - Earth Estries asset_type: Endpoint mitre_attack_id: - T1134.002 diff --git a/detections/endpoint/windows_anonymous_pipe_activity.yml b/detections/endpoint/windows_anonymous_pipe_activity.yml index 1102c6ffa3..436311b403 100644 --- a/detections/endpoint/windows_anonymous_pipe_activity.yml +++ b/detections/endpoint/windows_anonymous_pipe_activity.yml @@ -1,23 +1,35 @@ name: Windows Anonymous Pipe Activity id: ee301e1e-cd81-4011-a911-e5f049b9e3d5 -version: 1 -date: '2025-02-11' +version: '2' +date: '2025-03-19' author: Teoderick Contreras, Splunk status: production type: Hunting -description: The following analytic detects the creation or connection of anonymous pipes for inter-process communication (IPC) within a Windows environment. Anonymous pipes are commonly used by legitimate system processes, services, and applications to transfer data between related processes. However, adversaries frequently abuse anonymous pipes to facilitate stealthy process injection, command-and-control (C2) communication, credential theft, or privilege escalation. This detection monitors for unusual anonymous pipe activity, particularly involving non-system processes, unsigned executables, or unexpected parent-child process relationships. While legitimate use cases exist—such as Windows services, software installers, or security tools—unusual or high-frequency anonymous pipe activity should be investigated for potential malware, persistence mechanisms, or lateral movement techniques. +description: "The following analytic detects the creation or connection of anonymous\ + \ pipes for inter-process communication (IPC) within a Windows environment. Anonymous\ + \ pipes are commonly used by legitimate system processes, services, and applications\ + \ to transfer data between related processes. However, adversaries frequently abuse\ + \ anonymous pipes to facilitate stealthy process injection, command-and-control\ + \ (C2) communication, credential theft, or privilege escalation. This detection\ + \ monitors for unusual anonymous pipe activity, particularly involving non-system\ + \ processes, unsigned executables, or unexpected parent-child process relationships.\ + \ While legitimate use cases exist\u2014such as Windows services, software installers,\ + \ or security tools\u2014unusual or high-frequency anonymous pipe activity should\ + \ be investigated for potential malware, persistence mechanisms, or lateral movement\ + \ techniques." data_source: - Sysmon EventID 17 - Sysmon EventID 18 -search: '`sysmon` EventCode IN (17,18) EventType IN ( "CreatePipe", "ConnectPipe") PipeName="*Anonymous Pipe*" NOT( Image IN ("*\\Program Files\\*")) - | stats min(_time) as firstTime max(_time) as lastTime count by dest EventCode PipeName ProcessGuid ProcessId Image EventType - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` +search: '`sysmon` EventCode IN (17,18) EventType IN ( "CreatePipe", "ConnectPipe") + PipeName="*Anonymous Pipe*" NOT( Image IN ("*\\Program Files\\*")) | stats min(_time) + as firstTime max(_time) as lastTime count by dest EventCode PipeName ProcessGuid + ProcessId Image EventType | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_anonymous_pipe_activity_filter`' -how_to_implement: To successfully implement this search, you need to be ingesting +how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name and pipename from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. . -known_false_positives: Automation tool might use anonymous pipe for task orchestration or process communication. +known_false_positives: Automation tool might use anonymous pipe for task orchestration + or process communication. references: - https://www.trendmicro.com/en_nl/research/24/k/earth-estries.html drilldown_searches: @@ -36,9 +48,9 @@ drilldown_searches: latest_offset: $info_max_time$ tags: analytic_story: - - SnappyBee + - Salt Typhoon - China-Nexus Threat Activity - - Earth Estries + - SnappyBee asset_type: Endpoint mitre_attack_id: - T1559 diff --git a/detections/endpoint/windows_archive_collected_data_via_rar.yml b/detections/endpoint/windows_archive_collected_data_via_rar.yml index e23b8d7b07..bdd86d5ef6 100644 --- a/detections/endpoint/windows_archive_collected_data_via_rar.yml +++ b/detections/endpoint/windows_archive_collected_data_via_rar.yml @@ -64,8 +64,8 @@ rba: tags: analytic_story: - DarkGate Malware + - Salt Typhoon - China-Nexus Threat Activity - - Earth Estries asset_type: Endpoint mitre_attack_id: - T1560.001 diff --git a/detections/endpoint/windows_credential_access_from_browser_password_store.yml b/detections/endpoint/windows_credential_access_from_browser_password_store.yml index 61810fbdd1..b6507e816b 100644 --- a/detections/endpoint/windows_credential_access_from_browser_password_store.yml +++ b/detections/endpoint/windows_credential_access_from_browser_password_store.yml @@ -1,7 +1,7 @@ name: Windows Credential Access From Browser Password Store id: 72013a8e-5cea-408a-9d51-5585386b4d69 -version: '8' -date: '2025-02-24' +version: '9' +date: '2025-03-19' author: Teoderick Contreras, Bhavin Patel Splunk data_source: - Windows Event Log Security 4663 @@ -60,14 +60,14 @@ rba: threat_objects: [] tags: analytic_story: + - Meduza Stealer + - Snake Keylogger + - China-Nexus Threat Activity - SnappyBee + - PXA Stealer + - Salt Typhoon - MoonPeak - Braodo Stealer - - Snake Keylogger - - Meduza Stealer - - PXA Stealer - - China-Nexus Threat Activity - - Earth Estries asset_type: Endpoint mitre_attack_id: - T1012 diff --git a/detections/endpoint/windows_credentials_from_password_stores_chrome_localstate_access.yml b/detections/endpoint/windows_credentials_from_password_stores_chrome_localstate_access.yml index c8b4b527d4..a00adb48c6 100644 --- a/detections/endpoint/windows_credentials_from_password_stores_chrome_localstate_access.yml +++ b/detections/endpoint/windows_credentials_from_password_stores_chrome_localstate_access.yml @@ -1,7 +1,7 @@ name: Windows Credentials from Password Stores Chrome LocalState Access id: 3b1d09a8-a26f-473e-a510-6c6613573657 -version: '8' -date: '2025-02-24' +version: '9' +date: '2025-03-19' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -51,20 +51,20 @@ rba: threat_objects: [] tags: analytic_story: - - SnappyBee - - MoonPeak - - Phemedrone Stealer - - Braodo Stealer - - Snake Keylogger - Meduza Stealer - - NjRAT - - Amadey - - PXA Stealer - - Warzone RAT + - Snake Keylogger - China-Nexus Threat Activity - - DarkGate Malware + - Phemedrone Stealer + - SnappyBee + - PXA Stealer - RedLine Stealer - - Earth Estries + - Warzone RAT + - Salt Typhoon + - DarkGate Malware + - MoonPeak + - Braodo Stealer + - Amadey + - NjRAT asset_type: Endpoint mitre_attack_id: - T1012 diff --git a/detections/endpoint/windows_credentials_from_password_stores_chrome_login_data_access.yml b/detections/endpoint/windows_credentials_from_password_stores_chrome_login_data_access.yml index 6db791d295..2ac51493f5 100644 --- a/detections/endpoint/windows_credentials_from_password_stores_chrome_login_data_access.yml +++ b/detections/endpoint/windows_credentials_from_password_stores_chrome_login_data_access.yml @@ -1,7 +1,7 @@ name: Windows Credentials from Password Stores Chrome Login Data Access id: 0d32ba37-80fc-4429-809c-0ba15801aeaf -version: '8' -date: '2025-02-24' +version: '9' +date: '2025-03-19' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -52,20 +52,20 @@ rba: threat_objects: [] tags: analytic_story: - - SnappyBee - - MoonPeak - - Phemedrone Stealer - - Braodo Stealer - - Snake Keylogger - Meduza Stealer - - NjRAT - - Amadey - - PXA Stealer - - Warzone RAT + - Snake Keylogger - China-Nexus Threat Activity - - DarkGate Malware + - Phemedrone Stealer + - SnappyBee + - PXA Stealer - RedLine Stealer - - Earth Estries + - Warzone RAT + - Salt Typhoon + - DarkGate Malware + - MoonPeak + - Braodo Stealer + - Amadey + - NjRAT asset_type: Endpoint mitre_attack_id: - T1012 diff --git a/detections/endpoint/windows_curl_download_to_suspicious_path.yml b/detections/endpoint/windows_curl_download_to_suspicious_path.yml index 9348119cc9..799f30ca99 100644 --- a/detections/endpoint/windows_curl_download_to_suspicious_path.yml +++ b/detections/endpoint/windows_curl_download_to_suspicious_path.yml @@ -73,13 +73,13 @@ rba: type: process_name tags: analytic_story: + - Black Basta Ransomware - China-Nexus Threat Activity + - Forest Blizzard + - Compromised Windows Host + - Salt Typhoon - Ingress Tool Transfer - IcedID - - Forest Blizzard - - Earth Estries - - Black Basta Ransomware - - Compromised Windows Host asset_type: Endpoint mitre_attack_id: - T1105 diff --git a/detections/endpoint/windows_process_execution_from_programdata.yml b/detections/endpoint/windows_process_execution_from_programdata.yml index 33d9358fa4..ae0b14501e 100644 --- a/detections/endpoint/windows_process_execution_from_programdata.yml +++ b/detections/endpoint/windows_process_execution_from_programdata.yml @@ -67,8 +67,8 @@ rba: type: parent_process_name tags: analytic_story: + - Salt Typhoon - China-Nexus Threat Activity - - Earth Estries - SnappyBee asset_type: Endpoint mitre_attack_id: diff --git a/detections/endpoint/windows_query_registry_browser_list_application.yml b/detections/endpoint/windows_query_registry_browser_list_application.yml index 1672d23bfe..efe1db1c2d 100644 --- a/detections/endpoint/windows_query_registry_browser_list_application.yml +++ b/detections/endpoint/windows_query_registry_browser_list_application.yml @@ -1,7 +1,7 @@ name: Windows Query Registry Browser List Application id: 45ebd21c-f4bf-4ced-bd49-d25b6526cebb -version: '5' -date: '2025-02-07' +version: '6' +date: '2025-03-19' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -51,10 +51,10 @@ rba: threat_objects: [] tags: analytic_story: + - China-Nexus Threat Activity - SnappyBee - RedLine Stealer - - Earth Estries - - China-Nexus Threat Activity + - Salt Typhoon asset_type: Endpoint mitre_attack_id: - T1012 diff --git a/detections/endpoint/windows_replication_through_removable_media.yml b/detections/endpoint/windows_replication_through_removable_media.yml index 0bede66e7c..9661ee7e63 100644 --- a/detections/endpoint/windows_replication_through_removable_media.yml +++ b/detections/endpoint/windows_replication_through_removable_media.yml @@ -62,12 +62,12 @@ rba: type: file_name tags: analytic_story: - - NjRAT + - PlugX - China-Nexus Threat Activity - Chaos Ransomware - Derusbi - - PlugX - - Earth Estries + - Salt Typhoon + - NjRAT asset_type: Endpoint mitre_attack_id: - T1091 diff --git a/detections/endpoint/windows_service_created_with_suspicious_service_path.yml b/detections/endpoint/windows_service_created_with_suspicious_service_path.yml index af4539abce..11d6a0e95f 100644 --- a/detections/endpoint/windows_service_created_with_suspicious_service_path.yml +++ b/detections/endpoint/windows_service_created_with_suspicious_service_path.yml @@ -1,7 +1,7 @@ name: Windows Service Created with Suspicious Service Path id: 429141be-8311-11eb-adb6-acde48001122 -version: '13' -date: '2025-02-24' +version: '14' +date: '2025-03-19' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -54,18 +54,18 @@ rba: type: service tags: analytic_story: - - China-Nexus Threat Activity - - Crypto Stealer - - Qakbot - - Snake Malware - - Brute Ratel C4 - - Derusbi - - Active Directory Lateral Movement - - Clop Ransomware - - Flax Typhoon - - CISA AA23-347A - PlugX - - Earth Estries + - Qakbot + - China-Nexus Threat Activity + - CISA AA23-347A + - Flax Typhoon + - Derusbi + - Salt Typhoon + - Active Directory Lateral Movement + - Snake Malware + - Clop Ransomware + - Crypto Stealer + - Brute Ratel C4 asset_type: Endpoint mitre_attack_id: - T1569.002 diff --git a/detections/endpoint/windows_service_creation_on_remote_endpoint.yml b/detections/endpoint/windows_service_creation_on_remote_endpoint.yml index d8ef56b549..d893e7cae3 100644 --- a/detections/endpoint/windows_service_creation_on_remote_endpoint.yml +++ b/detections/endpoint/windows_service_creation_on_remote_endpoint.yml @@ -65,11 +65,11 @@ rba: threat_objects: [] tags: analytic_story: - - SnappyBee - - CISA AA23-347A - - Active Directory Lateral Movement - China-Nexus Threat Activity - - Earth Estries + - CISA AA23-347A + - SnappyBee + - Salt Typhoon + - Active Directory Lateral Movement asset_type: Endpoint mitre_attack_id: - T1543.003 diff --git a/detections/endpoint/windows_service_creation_using_registry_entry.yml b/detections/endpoint/windows_service_creation_using_registry_entry.yml index 2c15c4949d..f3eacbc039 100644 --- a/detections/endpoint/windows_service_creation_using_registry_entry.yml +++ b/detections/endpoint/windows_service_creation_using_registry_entry.yml @@ -54,18 +54,18 @@ rba: threat_objects: [] tags: analytic_story: - - SnappyBee - - Windows Persistence Techniques - - Brute Ratel C4 - - CISA AA23-347A - - Suspicious Windows Registry Activities - - China-Nexus Threat Activity - - Derusbi - PlugX + - CISA AA23-347A + - China-Nexus Threat Activity + - Windows Persistence Techniques + - SnappyBee + - Derusbi - Windows Registry Abuse + - Salt Typhoon - Active Directory Lateral Movement + - Suspicious Windows Registry Activities - Crypto Stealer - - Earth Estries + - Brute Ratel C4 asset_type: Endpoint mitre_attack_id: - T1574.011 diff --git a/detections/endpoint/windows_snappybee_create_test_registry.yml b/detections/endpoint/windows_snappybee_create_test_registry.yml index 7399927deb..98f2114f7b 100644 --- a/detections/endpoint/windows_snappybee_create_test_registry.yml +++ b/detections/endpoint/windows_snappybee_create_test_registry.yml @@ -57,9 +57,9 @@ rba: threat_objects: [] tags: analytic_story: - - SnappyBee + - Salt Typhoon - China-Nexus Threat Activity - - Earth Estries + - SnappyBee asset_type: Endpoint mitre_attack_id: - T1112 diff --git a/detections/endpoint/windows_suspicious_process_file_path.yml b/detections/endpoint/windows_suspicious_process_file_path.yml index cc8af90dbc..5f36c49ea0 100644 --- a/detections/endpoint/windows_suspicious_process_file_path.yml +++ b/detections/endpoint/windows_suspicious_process_file_path.yml @@ -74,44 +74,44 @@ rba: type: process_name tags: analytic_story: - - Double Zero Destructor - - Graceful Wipe Out Attack - - AsyncRAT - - WhisperGate - - Prestige Ransomware - - DarkGate Malware - - AgentTesla - - Brute Ratel C4 - - RedLine Stealer - - Rhysida Ransomware - - Swift Slicer - - IcedID - - DarkCrystal RAT - - Chaos Ransomware - - PlugX - - Industroyer2 - - Azorult - - Remcos - - XMRig - - Qakbot - - Volt Typhoon - - Hermetic Wiper - - Warzone RAT - - Trickbot - - Amadey - - BlackByte Ransomware - - LockBit Ransomware - - CISA AA23-347A - - Data Destruction - - Phemedrone Stealer - - Handala Wiper - - MoonPeak - - ValleyRAT - - Meduza Stealer - SystemBC - China-Nexus Threat Activity - - Earth Estries + - Remcos + - LockBit Ransomware + - AsyncRAT + - DarkCrystal RAT + - DarkGate Malware + - ValleyRAT + - PlugX + - Data Destruction + - Qakbot + - CISA AA23-347A + - Hermetic Wiper + - Volt Typhoon + - Double Zero Destructor + - AgentTesla + - Trickbot + - Meduza Stealer + - Phemedrone Stealer - SnappyBee + - Azorult + - WhisperGate + - Warzone RAT + - Swift Slicer + - Rhysida Ransomware + - Brute Ratel C4 + - Prestige Ransomware + - BlackByte Ransomware + - Graceful Wipe Out Attack + - Chaos Ransomware + - Handala Wiper + - RedLine Stealer + - Salt Typhoon + - XMRig + - MoonPeak + - Industroyer2 + - Amadey + - IcedID asset_type: Endpoint mitre_attack_id: - T1543 diff --git a/detections/endpoint/windows_unsigned_dll_side_loading.yml b/detections/endpoint/windows_unsigned_dll_side_loading.yml index 90e2892c28..9748a37bc5 100644 --- a/detections/endpoint/windows_unsigned_dll_side_loading.yml +++ b/detections/endpoint/windows_unsigned_dll_side_loading.yml @@ -54,11 +54,11 @@ rba: threat_objects: [] tags: analytic_story: - - Warzone RAT - - NjRAT - China-Nexus Threat Activity - Derusbi - - Earth Estries + - Warzone RAT + - Salt Typhoon + - NjRAT asset_type: Endpoint mitre_attack_id: - T1574.002 diff --git a/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml b/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml index b0c9369d68..9c4a6abc6d 100644 --- a/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml +++ b/detections/endpoint/windows_unsigned_dll_side_loading_in_same_process_path.yml @@ -56,12 +56,12 @@ rba: threat_objects: [] tags: analytic_story: - - China-Nexus Threat Activity - - Derusbi - - DarkGate Malware - PlugX - - Earth Estries + - China-Nexus Threat Activity - SnappyBee + - Derusbi + - Salt Typhoon + - DarkGate Malware asset_type: Endpoint mitre_attack_id: - T1574.002 diff --git a/detections/endpoint/windows_unsigned_ms_dll_side_loading.yml b/detections/endpoint/windows_unsigned_ms_dll_side_loading.yml index 5bb4b7e9cd..cbd3572b89 100644 --- a/detections/endpoint/windows_unsigned_ms_dll_side_loading.yml +++ b/detections/endpoint/windows_unsigned_ms_dll_side_loading.yml @@ -68,8 +68,8 @@ tags: analytic_story: - China-Nexus Threat Activity - Derusbi + - Salt Typhoon - APT29 Diplomatic Deceptions with WINELOADER - - Earth Estries group: - APT29 - Cozy Bear diff --git a/detections/endpoint/windows_unusual_syswow64_process_run_system32_executable.yml b/detections/endpoint/windows_unusual_syswow64_process_run_system32_executable.yml index c02d21c59d..8f085d06b0 100644 --- a/detections/endpoint/windows_unusual_syswow64_process_run_system32_executable.yml +++ b/detections/endpoint/windows_unusual_syswow64_process_run_system32_executable.yml @@ -65,9 +65,9 @@ rba: type: process_name tags: analytic_story: - - China-Nexus Threat Activity - DarkGate Malware - - Earth Estries + - Salt Typhoon + - China-Nexus Threat Activity asset_type: Endpoint mitre_attack_id: - T1036.009 diff --git a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml index 3612f9973d..6fea984d65 100644 --- a/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml +++ b/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml @@ -1,7 +1,7 @@ name: WinEvent Scheduled Task Created to Spawn Shell id: 203ef0ea-9bd8-11eb-8201-acde48001122 version: '12' -date: '2025-03-14' +date: '2025-03-19' author: Michael Haag, Splunk status: production type: TTP @@ -54,18 +54,19 @@ rba: threat_objects: [] tags: analytic_story: - - Windows Error Reporting Service Elevation of Privilege Vulnerability - CISA AA22-257A - - Ransomware - - Medusa Ransomware - - Windows Persistence Techniques - - Earth Estries - - Scheduled Tasks - - Compromised Windows Host - - Ryuk Ransomware - - Winter Vivern - China-Nexus Threat Activity + - Compromised Windows Host + - Earth Estries + - Medusa Ransomware + - Ransomware + - Ryuk Ransomware + - Salt Typhoon + - Scheduled Tasks - SystemBC + - Windows Error Reporting Service Elevation of Privilege Vulnerability + - Windows Persistence Techniques + - Winter Vivern asset_type: Endpoint mitre_attack_id: - T1053.005 diff --git a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml index b7cb512d28..11a93c079e 100644 --- a/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml +++ b/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml @@ -1,7 +1,7 @@ name: WinEvent Scheduled Task Created Within Public Path id: 5d9c6eee-988c-11eb-8253-acde48001122 version: '12' -date: '2025-03-14' +date: '2025-03-19' author: Michael Haag, Splunk status: production type: TTP @@ -55,23 +55,24 @@ rba: tags: analytic_story: - Active Directory Lateral Movement - - Industroyer2 - AsyncRAT + - China-Nexus Threat Activity - CISA AA22-257A - - Data Destruction - CISA AA23-347A + - Compromised Windows Host + - Data Destruction + - Earth Estries + - IcedID + - Industroyer2 + - Medusa Ransomware - Prestige Ransomware - Ransomware - - Medusa Ransomware - - Windows Persistence Techniques - - Earth Estries - - Scheduled Tasks - - Compromised Windows Host - - IcedID - Ryuk Ransomware - - Winter Vivern - - China-Nexus Threat Activity + - Salt Typhoon + - Scheduled Tasks - SystemBC + - Windows Persistence Techniques + - Winter Vivern asset_type: Endpoint mitre_attack_id: - T1053.005 diff --git a/stories/earth_estries.yml b/stories/deprecated/earth_estries.yml similarity index 100% rename from stories/earth_estries.yml rename to stories/deprecated/earth_estries.yml diff --git a/stories/salt_typhoon.yml b/stories/salt_typhoon.yml new file mode 100644 index 0000000000..61150f3829 --- /dev/null +++ b/stories/salt_typhoon.yml @@ -0,0 +1,18 @@ +name: Salt Typhoon +id: 7df800b1-af23-4f65-ac36-abe87374ee72 +version: 1 +date: '2025-03-19' +author: Teoderick Contreras, Splunk +status: production +description: Leverage searches that allow you to detect and investigate unusual activities that might relate to Salt Typhoon, a sophisticated threat actor targeting various sectors with espionage-focused campaigns. Monitor for indicators such as spear-phishing emails, unauthorized access attempts, and lateral movement within your network. Investigate anomalous data exfiltration patterns and command-and-control (C2) traffic consistent with known tactics, techniques, and procedures (TTPs) of this group. Combining threat intelligence with advanced monitoring tools helps identify potential Salt Typhoon activity early, enabling swift response to mitigate risks effectively. +narrative: Salt Typhoon is a highly capable threat actor known for conducting targeted espionage campaigns against diverse sectors, including government, technology, and critical infrastructure. This group leverages sophisticated tactics such as spear-phishing, credential theft, and exploiting software vulnerabilities to gain initial access. Once inside a network, Salt Typhoon demonstrates expertise in lateral movement, privilege escalation, and covert data exfiltration. Their use of custom malware and command-and-control (C2) infrastructures highlights their adaptability. Detecting their activity requires robust threat intelligence and proactive monitoring of unusual behaviors and network anomalies. +references: +- https://www.trendmicro.com/en_nl/research/24/k/earth-estries.html +tags: + category: + - Malware + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection \ No newline at end of file