Branch was auto-updated.

This commit is contained in:
pyth0n1c
2022-03-28 00:31:31 -07:00
committed by GitHub
58 changed files with 91 additions and 9 deletions
@@ -37,6 +37,7 @@ references:
tags:
analytic_story:
- Prohibited Traffic Allowed or Protocol Mismatch
- Windows Registry Abuse
confidence: 30
context:
- Source:Endpoint
@@ -39,6 +39,7 @@ references:
tags:
analytic_story:
- Ransomware
- Windows Registry Abuse
confidence: 50
context:
- Source:Endpoint
@@ -28,6 +28,7 @@ tags:
analytic_story:
- Credential Dumping
- DarkSide Ransomware
- Windows Registry Abuse
asset_type: Endpoint
cis20:
- CIS 3
@@ -37,6 +37,7 @@ references:
tags:
analytic_story:
- BlackMatter Ransomware
- Windows Registry Abuse
confidence: 90
context:
- Source:Endpoint
@@ -30,6 +30,7 @@ tags:
analytic_story:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Windows Registry Abuse
confidence: 100
context:
- Source:Endpoint
@@ -35,6 +35,7 @@ references:
tags:
analytic_story:
- Ransomware
- Windows Registry Abuse
context:
- Source:Endpoint
- Stage:Defense Evasion
@@ -34,6 +34,7 @@ references:
tags:
analytic_story:
- IceID
- Windows Registry Abuse
confidence: 70
context:
- Source:Endpoint
@@ -33,6 +33,7 @@ references:
tags:
analytic_story:
- IceID
- Windows Registry Abuse
confidence: 70
context:
- Source:Endpoint
@@ -33,6 +33,7 @@ references:
tags:
analytic_story:
- IceID
- Windows Registry Abuse
confidence: 70
context:
- Source:Endpoint
@@ -34,6 +34,7 @@ references:
tags:
analytic_story:
- IceID
- Windows Registry Abuse
confidence: 70
context:
- Source:Endpoint
@@ -32,6 +32,7 @@ references:
tags:
analytic_story:
- IceID
- Windows Registry Abuse
confidence: 70
context:
- Source:Endpoint
@@ -32,6 +32,7 @@ references:
tags:
analytic_story:
- IceID
- Windows Registry Abuse
confidence: 70
context:
- Source:Endpoint
@@ -34,6 +34,7 @@ references:
tags:
analytic_story:
- Ransomware
- Windows Registry Abuse
context:
- Source:Endpoint
- Stage:Defense Evasion
@@ -34,6 +34,7 @@ references:
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Registry Abuse
confidence: 100
context:
- Source:Endpoint
@@ -34,6 +34,7 @@ references:
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Registry Abuse
confidence: 100
context:
- Source:Endpoint
@@ -35,6 +35,7 @@ references:
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Registry Abuse
confidence: 100
context:
- Source:Endpoint
@@ -37,6 +37,7 @@ tags:
analytic_story:
- Windows Defense Evasion Tactics
- Suspicious Windows Registry Activities
- Windows Registry Abuse
confidence: 100
context:
- Source:Endpoint
@@ -38,6 +38,7 @@ references:
tags:
analytic_story:
- XMRig
- Windows Registry Abuse
confidence: 100
context:
- Source:Endpoint
@@ -41,6 +41,7 @@ tags:
- Windows Defense Evasion Tactics
- Ransomware
- Revil Ransomware
- Windows Registry Abuse
confidence: 100
context:
- Source:Endpoint
@@ -33,6 +33,7 @@ references:
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Registry Abuse
confidence: 50
context:
- Source:Endpoint
@@ -34,6 +34,7 @@ references:
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Registry Abuse
confidence: 50
context:
- Source:Endpoint
@@ -33,6 +33,7 @@ references:
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Registry Abuse
confidence: 50
context:
- Source:Endpoint
@@ -35,6 +35,7 @@ references:
tags:
analytic_story:
- IceID
- Windows Registry Abuse
confidence: 70
context:
- Source:Endpoint
@@ -35,6 +35,7 @@ references:
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Registry Abuse
confidence: 50
context:
- Source:Endpoint
@@ -36,6 +36,7 @@ references:
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Registry Abuse
confidence: 50
context:
- Source:Endpoint
@@ -26,6 +26,7 @@ tags:
- Windows Defense Evasion Tactics
- Suspicious Windows Registry Activities
- Remcos
- Windows Registry Abuse
asset_type: Endpoint
cis20:
- CIS 8
@@ -37,6 +37,7 @@ references:
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Registry Abuse
confidence: 70
context:
- Source:Endpoint
@@ -51,8 +52,7 @@ tags:
message: The Windows registry was modified to disable system restore on $dest$ by
$user$.
mitre_attack_id:
- T1562.001
- T1562
- T1490
observable:
- name: user
type: User
@@ -35,6 +35,7 @@ references:
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Registry Abuse
confidence: 60
context:
- Source:Endpoint
@@ -34,6 +34,7 @@ references:
tags:
analytic_story:
- Prohibited Traffic Allowed or Protocol Mismatch
- Windows Registry Abuse
confidence: 100
context:
- Source:Endpoint
@@ -38,6 +38,7 @@ references:
tags:
analytic_story:
- Credential Dumping
- Windows Registry Abuse
confidence: 100
context:
- Source:Endpoint
@@ -37,6 +37,7 @@ tags:
analytic_story:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Windows Registry Abuse
confidence: 100
context:
- Source:Endpoint
@@ -41,6 +41,7 @@ tags:
- Windows Defense Evasion Tactics
- IcedID
- Living Off The Land
- Windows Registry Abuse
automated_detection_testing: passed
confidence: 100
context:
@@ -38,6 +38,7 @@ references:
tags:
analytic_story:
- XMRig
- Windows Registry Abuse
confidence: 80
context:
- Source:Endpoint
@@ -28,6 +28,7 @@ tags:
- Ransomware
- Revil Ransomware
- BlackMatter Ransomware
- Windows Registry Abuse
confidence: 90
context:
- Source:Endpoint
@@ -1,9 +1,9 @@
name: Modify ACL permission To Files Or Folder
id: 7e8458cc-acca-11eb-9e3f-acde48001122
version: 1
date: '2021-05-04'
version: 2
date: '2022-03-17'
author: Teoderick Contreras, Splunk
type: TTP
type: Anomaly
datamodel:
- Endpoint
description: This analytic identifies suspicious modification of ACL permission to
@@ -14,9 +14,9 @@ description: This analytic identifies suspicious modification of ACL permission
no permission to do so.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "cacls.exe"
OR Processes.process_name = "icacls.exe" OR Processes.process_name = "xcacls.exe"
AND (Processes.process = "*/G everyone:*" OR Processes.process = "*/G SYSTEM:*")
as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = "cacls.exe"
OR Processes.process_name = "icacls.exe" OR Processes.process_name = "xcacls.exe")
AND Processes.process = "*/G*" AND (Processes.process = "* everyone:*" OR Processes.process = "* SYSTEM:*" OR Processes.process = "* S-1-1-0:*")
by Processes.parent_process_name Processes.process_name Processes.dest Processes.user
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `modify_acl_permission_to_files_or_folder_filter`'
@@ -37,6 +37,7 @@ tags:
analytic_story:
- Suspicious Windows Registry Activities
- Windows Persistence Techniques
- Windows Registry Abuse
asset_type: Endpoint
cis20:
- CIS 8
@@ -31,6 +31,7 @@ tags:
analytic_story:
- Suspicious Windows Registry Activities
- Windows Persistence Techniques
- Windows Registry Abuse
asset_type: Endpoint
cis20:
- CIS 8
@@ -55,6 +55,7 @@ tags:
- 'Emotet Malware DHS Report TA18-201A '
- IcedID
- Remcos
- Windows Registry Abuse
asset_type: Endpoint
cis20:
- CIS 8
@@ -39,6 +39,7 @@ tags:
- Windows Privilege Escalation
- Suspicious Windows Registry Activities
- Cloud Federated Credential Abuse
- Windows Registry Abuse
cis20:
- CIS 8
confidence: 95
@@ -30,10 +30,12 @@ references:
tags:
analytic_story:
- Remcos
- Windows Registry Abuse
confidence: 100
context:
- Source:Endpoint
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_registry/sysmon.log
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_panel_client/remcos_registry_entry.log
impact: 90
kill_chain_phases:
@@ -35,6 +35,7 @@ tags:
analytic_story:
- Ransomware
- Revil Ransomware
- Windows Registry Abuse
confidence: 100
context:
- Source:Endpoint
@@ -31,6 +31,7 @@ tags:
analytic_story:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Windows Registry Abuse
confidence: 90
context:
- Source:Endpoint
+1
View File
@@ -37,6 +37,7 @@ references:
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Registry Abuse
confidence: 90
context:
- Source:Endpoint
@@ -35,6 +35,7 @@ references:
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Registry Abuse
confidence: 90
context:
- Source:Endpoint
@@ -38,6 +38,7 @@ tags:
analytic_story:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Windows Registry Abuse
confidence: 100
context:
- Source:Endpoint
@@ -34,6 +34,7 @@ tags:
analytic_story:
- Ransomware
- Windows Defense Evasion Tactics
- Windows Registry Abuse
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log
kill_chain_phases:
@@ -40,6 +40,7 @@ references:
tags:
analytic_story:
- Ransomware
- Windows Registry Abuse
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log
kill_chain_phases:
@@ -38,6 +38,7 @@ tags:
- Data Destruction
- Ransomware
- Hermetic Wiper
- Windows Registry Abuse
cis20:
- CIS 3
- CIS 5
@@ -35,6 +35,7 @@ references:
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Registry Abuse
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/disable_notif_center/sysmon.log
kill_chain_phases:
@@ -36,6 +36,7 @@ references:
tags:
analytic_story:
- Ransomware
- Windows Registry Abuse
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log
kill_chain_phases:
@@ -38,6 +38,7 @@ tags:
analytic_story:
- Ransomware
- Windows Defense Evasion Tactics
- Windows Registry Abuse
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log
kill_chain_phases:
@@ -30,6 +30,7 @@ tags:
analytic_story:
- Ryuk Ransomware
- Windows Defense Evasion Tactics
- Windows Registry Abuse
asset_type: Endpoint
cis20:
- CIS 8
@@ -34,6 +34,7 @@ tags:
analytic_story:
- Ransomware
- Windows Defense Evasion Tactics
- Windows Registry Abuse
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log
kill_chain_phases:
@@ -36,6 +36,7 @@ tags:
analytic_story:
- Windows Defense Evasion Tactics
- Hermetic Wiper
- Windows Registry Abuse
cis20:
- CIS 3
- CIS 5
@@ -38,6 +38,7 @@ tags:
- Active Directory Lateral Movement
- Suspicious Windows Registry Activities
- Windows Persistence Techniques
- Windows Registry Abuse
cis20:
- CIS 3
- CIS 5
@@ -37,6 +37,7 @@ tags:
analytic_story:
- Windows Defense Evasion Tactics
- Living Off The Land
- Windows Registry Abuse
confidence: 90
context:
- Source:Endpoint
+27
View File
@@ -0,0 +1,27 @@
name: Windows Registry Abuse
id: 78df1df1-25f1-4387-90f9-c4ea31ce6b75
version: 1
date: '2022-03-17'
author: Teoderick Contreras, Splunk
description: Windows services are often used by attackers for persistence, privilege escalation,
lateral movement, defense evasion, collection of data, a tool for recon, credential dumping and
payload impact. This Analytic Story helps you monitor your environment for indications
that Windows registry are being modified or created in a suspicious manner.
narrative: Windows Registry is one of the powerful and yet still mysterious Windows features
that can tweak or manipulate Windows policies and low-level configuration settings.
Because of this capability, most malware, adversaries or threat actors abuse this
hierarchical database to do their malicious intent on a targeted host or network environment.
In these cases, attackers often use tools to create or modify registry in ways that are not
typical for most environments, providing opportunities for detection.
references:
- https://attack.mitre.org/techniques/T1112/
- https://redcanary.com/blog/windows-registry-attacks-threat-detection/
tags:
analytic_story: Windows Registry Abuse
category:
- Malware
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection
@@ -7,6 +7,6 @@ tests:
latest_time: now
attack_data:
- file_name: remcos_registry_entry.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_panel_client/remcos_registry_entry.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos_registry/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog