diff --git a/detections/endpoint/linux_deletion_of_cron_jobs.yml b/detections/endpoint/linux_deletion_of_cron_jobs.yml new file mode 100644 index 0000000000..feb23356c2 --- /dev/null +++ b/detections/endpoint/linux_deletion_of_cron_jobs.yml @@ -0,0 +1,86 @@ +name: Linux Deletion Of Cron Jobs +id: 3b132a71-9335-4f33-9932-00bb4f6ac7e8 +version: 1 +date: '2022-04-12' +author: Teoderick Contreras, Splunk +type: Anomaly +datamodel: +- Endpoint +description: This analytic is to detect a deletion of cron job in a linux machine. + This technique can be related to an attacker, threat actor or malware to disable scheduled cron jobs that might be related to security or + to evade some detections. We also saw that this technique can be a good indicator for malware that is trying to wipe or delete several files on the compromised host + like the acidrain malware. This anomaly detection can be a good pivot detection to look for process and user doing it why they doing. Take note that this event can be done + by administrator so filtering on those possible false positive event is needed. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem + where Filesystem.action=deleted Filesystem.file_path ="/etc/cron.*" + by _time span=1h Filesystem.file_name Filesystem.file_path Filesystem.dest Filesystem.process_guid Filesystem.action + | `drop_dm_object_name(Filesystem)` + |rename process_guid as proc_guid + |join proc_guid, _time [ + | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid + | `drop_dm_object_name(Processes)` + |rename process_guid as proc_guid + | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] + | table process_name process proc_guid file_name file_path action _time parent_process_name parent_process process_path dest user + | `linux_deletion_of_cron_jobs_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from + Splunkbase. +known_false_positives: Administrator or network operator can execute this command. + Please update the filter macros to remove false positives. +references: +- https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/ +tags: + analytic_story: + - AcidRain + asset_type: endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log + impact: 70 + kill_chain_phases: + - Exploitation + message: a $process_name$ deleting cron jobs in $dest$ + mitre_attack_id: + - T1485 + - T1070.004 + - T1070 + nist: + - DE.CM + observable: + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Filesystem.dest + - Filesystem.file_create_time + - Filesystem.file_name + - Filesystem.process_guid + - Filesystem.file_path + - Filesystem.action + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.process_name + - Processes.process_path + - Processes.process + - Processes.process_id + - Processes.parent_process_id + risk_score: 49 + security_domain: endpoint diff --git a/detections/endpoint/linux_deletion_of_init_daemon_script.yml b/detections/endpoint/linux_deletion_of_init_daemon_script.yml new file mode 100644 index 0000000000..cee914c96d --- /dev/null +++ b/detections/endpoint/linux_deletion_of_init_daemon_script.yml @@ -0,0 +1,87 @@ +name: Linux Deletion Of Init Daemon Script +id: 729aab57-d26f-4156-b97f-ab8dda8f44b1 +version: 1 +date: '2022-04-12' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a deletion of init daemon script in a linux machine. + daemon script that place in /etc/init.d/ is a directory that can start and stop some daemon services in linux machines. + attacker may delete or modify daemon script to impair some security features or act as defense evasion in a compromised linux machine. + This TTP can be also a good indicator of a malware trying to wipe or delete several files in compromised host as part of its destructive payload like what + acidrain malware does in linux or router machines. This detection can be a good pivot to check what process and user + tries to delete this type of files which is not so common and need further investigation. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem + where Filesystem.action=deleted Filesystem.file_path IN ( "/etc/init.d/*") + by _time span=1h Filesystem.file_name Filesystem.file_path Filesystem.dest Filesystem.process_guid Filesystem.action + | `drop_dm_object_name(Filesystem)` + |rename process_guid as proc_guid + |join proc_guid, _time [ + | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid + | `drop_dm_object_name(Processes)` + |rename process_guid as proc_guid + | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] + | table process_name process proc_guid file_name file_path action _time parent_process_name parent_process process_path dest user + | `linux_deletion_of_init_daemon_script_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from + Splunkbase. +known_false_positives: Administrator or network operator can execute this command. + Please update the filter macros to remove false positives. +references: +- https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/ +tags: + analytic_story: + - AcidRain + asset_type: endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log + impact: 70 + kill_chain_phases: + - Exploitation + message: a $process_name$ deleting a daemon script in $dest$ + mitre_attack_id: + - T1485 + - T1070.004 + - T1070 + nist: + - DE.CM + observable: + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Filesystem.dest + - Filesystem.file_create_time + - Filesystem.file_name + - Filesystem.process_guid + - Filesystem.file_path + - Filesystem.action + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.process_name + - Processes.process_path + - Processes.process + - Processes.process_id + - Processes.parent_process_id + risk_score: 49 + security_domain: endpoint diff --git a/detections/endpoint/linux_deletion_of_services.yml b/detections/endpoint/linux_deletion_of_services.yml new file mode 100644 index 0000000000..5b99f4d004 --- /dev/null +++ b/detections/endpoint/linux_deletion_of_services.yml @@ -0,0 +1,86 @@ +name: Linux Deletion Of Services +id: b509bbd3-0331-4aaa-8e4a-d2affe100af6 +version: 1 +date: '2022-04-12' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a deletion of services in a linux machine. + attacker may delete or modify services to impair some security features or act as defense evasion in a compromised linux machine. + This TTP can be also a good indicator of a malware trying to wipe or delete several files in a compromised host as part of its destructive payload like what + acidrain malware does in linux or router machines. This detection can be a good pivot to check what process and user + tries to delete this type of files which is not so common and need further investigation. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem + where Filesystem.action=deleted Filesystem.file_path IN ( "/etc/systemd/*", "/usr/lib/systemd/*") Filesystem.file_path = "*.service" + by _time span=1h Filesystem.file_name Filesystem.file_path Filesystem.dest Filesystem.process_guid Filesystem.action + | `drop_dm_object_name(Filesystem)` + |rename process_guid as proc_guid + |join proc_guid, _time [ + | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid + | `drop_dm_object_name(Processes)` + |rename process_guid as proc_guid + | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] + | table process_name process proc_guid file_name file_path action _time parent_process_name parent_process process_path dest user + | `linux_deletion_of_services_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from + Splunkbase. +known_false_positives: Administrator or network operator can execute this command. + Please update the filter macros to remove false positives. +references: +- https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/ +tags: + analytic_story: + - AcidRain + asset_type: endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log + impact: 80 + kill_chain_phases: + - Exploitation + message: a $process_name$ deleting a services in $dest$ + mitre_attack_id: + - T1485 + - T1070.004 + - T1070 + nist: + - DE.CM + observable: + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Filesystem.dest + - Filesystem.file_create_time + - Filesystem.file_name + - Filesystem.process_guid + - Filesystem.file_path + - Filesystem.action + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.process_name + - Processes.process_path + - Processes.process + - Processes.process_id + - Processes.parent_process_id + risk_score: 64 + security_domain: endpoint diff --git a/detections/endpoint/linux_deletion_of_ssh_key.yml b/detections/endpoint/linux_deletion_of_ssh_key.yml new file mode 100644 index 0000000000..c8e3cebb8f --- /dev/null +++ b/detections/endpoint/linux_deletion_of_ssh_key.yml @@ -0,0 +1,86 @@ +name: Linux deletion Of SSH Key +id: 73a56508-1cf5-4df7-b8d9-5737fbdc27d2 +version: 1 +date: '2022-04-12' +author: Teoderick Contreras, Splunk +type: Anomaly +datamodel: +- Endpoint +description: This analytic is to detect a deletion of ssh key in a linux machine. + attacker may delete or modify ssh key to impair some security features or act as defense evasion in compromised linux machine. + This Anomaly can be also a good indicator of a malware trying to wipe or delete several files in a compromised host as part of its destructive payload like what + acidrain malware does in linux or router machines. This detection can be a good pivot to check what process and user + tries to delete this type of files which is not so common and need further investigation. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem + where Filesystem.action=deleted Filesystem.file_path = "/etc/ssh/*" + by _time span=1h Filesystem.file_name Filesystem.file_path Filesystem.dest Filesystem.process_guid Filesystem.action + | `drop_dm_object_name(Filesystem)` + |rename process_guid as proc_guid + |join proc_guid, _time [ + | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid + | `drop_dm_object_name(Processes)` + |rename process_guid as proc_guid + | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] + | table process_name process proc_guid file_name file_path action _time parent_process_name parent_process process_path dest user + | `linux_deletion_of_ssh_key_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from + Splunkbase. +known_false_positives: Administrator or network operator can execute this command. + Please update the filter macros to remove false positives. +references: +- https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/ +tags: + analytic_story: + - Acidrain + asset_type: endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log + impact: 70 + kill_chain_phases: + - Exploitation + message: a $process_name$ deleting a SSH key in $dest$ + mitre_attack_id: + - T1485 + - T1070.004 + - T1070 + nist: + - DE.CM + observable: + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Filesystem.dest + - Filesystem.file_create_time + - Filesystem.file_name + - Filesystem.process_guid + - Filesystem.file_path + - Filesystem.action + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.process_name + - Processes.process_path + - Processes.process + - Processes.process_id + - Processes.parent_process_id + risk_score: 49 + security_domain: endpoint \ No newline at end of file diff --git a/detections/endpoint/linux_deletion_of_ssl_certificate.yml b/detections/endpoint/linux_deletion_of_ssl_certificate.yml new file mode 100644 index 0000000000..f90ac8ec8b --- /dev/null +++ b/detections/endpoint/linux_deletion_of_ssl_certificate.yml @@ -0,0 +1,86 @@ +name: Linux Deletion of SSL Certificate +id: 839ab790-a60a-4f81-bfb3-02567063f615 +version: 1 +date: '2022-04-12' +author: Teoderick Contreras, Splunk +type: Anomaly +datamodel: +- Endpoint +description: This analytic is to detect a deletion of ssl certificate in a linux machine. + attacker may delete or modify ssl certificate to impair some security features or act as defense evasion in compromised linux machine. + This Anomaly can be also a good indicator of a malware trying to wipe or delete several files in a compromised host as part of its destructive payload like what + acidrain malware does in linux or router machines. This detection can be a good pivot to check what process and user + tries to delete this type of files which is not so common and need further investigation. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem + where Filesystem.action=deleted Filesystem.file_path = "/etc/ssl/certs/*" Filesystem.file_path IN ("*.pem", "*.crt") + by _time span=1h Filesystem.file_name Filesystem.file_path Filesystem.dest Filesystem.process_guid Filesystem.action + | `drop_dm_object_name(Filesystem)` + |rename process_guid as proc_guid + |join proc_guid, _time [ + | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid + | `drop_dm_object_name(Processes)` + |rename process_guid as proc_guid + | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] + | table process_name process proc_guid file_name file_path action _time parent_process_name parent_process process_path dest user + | `linux_deletion_of_ssl_certificate_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from + Splunkbase. +known_false_positives: Administrator or network operator can execute this command. + Please update the filter macros to remove false positives. +references: +- https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/ +tags: + analytic_story: + - Acidrain + asset_type: endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log + impact: 70 + kill_chain_phases: + - Exploitation + message: a $process_name$ deleting a SSL certificate in $dest$ + mitre_attack_id: + - T1485 + - T1070.004 + - T1070 + nist: + - DE.CM + observable: + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Filesystem.dest + - Filesystem.file_create_time + - Filesystem.file_name + - Filesystem.process_guid + - Filesystem.file_path + - Filesystem.action + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.process_name + - Processes.process_path + - Processes.process + - Processes.process_id + - Processes.parent_process_id + risk_score: 49 + security_domain: endpoint \ No newline at end of file diff --git a/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml b/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml new file mode 100644 index 0000000000..0a1cf8a04a --- /dev/null +++ b/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml @@ -0,0 +1,87 @@ +name: Linux High Frequency Of File Deletion In Etc Folder +id: 9d867448-2aff-4d07-876c-89409a752ff8 +version: 1 +date: '2022-04-12' +author: Teoderick Contreras, Splunk +type: Anomaly +datamodel: +- Endpoint +description: This analytic is to detect a high frequency of file deletion relative to process name and process id /etc/ folder. + These events was seen in acidrain wiper malware where it tries to delete all files in a non-standard directory in linux directory. + This detection already contains some filter that might cause false positive during our testing. But we recommend to add more filter if needed. +search: '| tstats `security_content_summariesonly` values(Filesystem.file_name) as deletedFileNames values(Filesystem.file_path) as deletedFilePath dc(Filesystem.file_path) as numOfDelFilePath count min(_time) as firstTime max(_time) as lastTime + FROM datamodel=Endpoint.Filesystem + where Filesystem.action=deleted Filesystem.file_path = "/etc/*" + by _time span=1h Filesystem.dest Filesystem.process_guid Filesystem.action + | `drop_dm_object_name(Filesystem)` + |rename process_guid as proc_guid + |join proc_guid, _time [ + | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name != unknown + NOT (Processes.parent_process_name IN ("/usr/bin/dpkg", "*usr/bin/python*", "*/usr/bin/apt-*", "/bin/rm", "*splunkd", "/usr/bin/mandb")) + by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_path Processes.process_guid + | `drop_dm_object_name(Processes)` + |rename process_guid as proc_guid + | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data registry_key_name action] + | table process_name process proc_guid action _time deletedFileNames deletedFilePath numOfDelFilePath parent_process_name parent_process process_path dest user + | where numOfDelFilePath >= 200 + | `linux_high_frequency_of_file_deletion_in_etc_folder_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from + Splunkbase. +known_false_positives: linux package installer/uninstaller may cause this event. + Please update you filter macro to remove false positives. +references: +- https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/ +tags: + analytic_story: + - AcidRain + asset_type: endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log + impact: 70 + kill_chain_phases: + - Exploitation + message: a $process_name$ deleting multiple files in /etc/ folder in $dest$ + mitre_attack_id: + - T1485 + - T1070.004 + - T1070 + nist: + - DE.CM + observable: + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Filesystem.dest + - Filesystem.file_create_time + - Filesystem.file_name + - Filesystem.process_guid + - Filesystem.file_path + - Filesystem.action + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.process_name + - Processes.process_path + - Processes.process + - Processes.process_id + - Processes.parent_process_id + risk_score: 49 + security_domain: endpoint diff --git a/stories/acidrain.yml b/stories/acidrain.yml new file mode 100644 index 0000000000..d8cfdfce4f --- /dev/null +++ b/stories/acidrain.yml @@ -0,0 +1,23 @@ +name: AcidRain +id: c68717c6-4938-434b-987c-e1ce9d516124 +version: 1 +date: '2022-04-12' +author: Teoderick Contreras, Splunk +description: Leverage searches that allow you to detect and investigate unusual activities + that might relate to the acidrain malware including deleting of files and etc. + AcidRain is an ELF MIPS malware specifically designed to wipe modems and routers. + The complete list of targeted devices is unknown at this time, but WatchGuard FireBox has specifically been listed as a target. + This malware is capable of wiping and deleting non-standard linux files and overwriting storage device files that might related to router, ssd card and many more. +narrative: Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption + is the goal. +references: +- https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/ +tags: + analytic_story: AcidRain + category: + - Malware + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection diff --git a/tests/endpoint/linux_deletion_of_cron_jobs.test.yml b/tests/endpoint/linux_deletion_of_cron_jobs.test.yml new file mode 100644 index 0000000000..7a4ea5299b --- /dev/null +++ b/tests/endpoint/linux_deletion_of_cron_jobs.test.yml @@ -0,0 +1,12 @@ +name: Linux Deletion Of Cron Jobs Unit Test +tests: +- name: Linux Deletion Of Cron Jobs + file: endpoint/linux_deletion_of_cron_jobs.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon_linux.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log + source: Syslog:Linux-Sysmon/Operational + sourcetype: sysmon_linux diff --git a/tests/endpoint/linux_deletion_of_init_daemon_script.test.yml b/tests/endpoint/linux_deletion_of_init_daemon_script.test.yml new file mode 100644 index 0000000000..94bd4bd509 --- /dev/null +++ b/tests/endpoint/linux_deletion_of_init_daemon_script.test.yml @@ -0,0 +1,12 @@ +name: Linux Deletion Of Init Daemon Script Unit Test +tests: +- name: Linux Deletion Of Init Daemon Script + file: endpoint/linux_deletion_of_init_daemon_script.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon_linux.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log + source: Syslog:Linux-Sysmon/Operational + sourcetype: sysmon_linux diff --git a/tests/endpoint/linux_deletion_of_services.test.yml b/tests/endpoint/linux_deletion_of_services.test.yml new file mode 100644 index 0000000000..eb565c37c2 --- /dev/null +++ b/tests/endpoint/linux_deletion_of_services.test.yml @@ -0,0 +1,12 @@ +name: Linux Deletion Of Services Unit Test +tests: +- name: Linux Deletion Of Services + file: endpoint/linux_deletion_of_services.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon_linux.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log + source: Syslog:Linux-Sysmon/Operational + sourcetype: sysmon_linux diff --git a/tests/endpoint/linux_deletion_of_ssh_key.test.yml b/tests/endpoint/linux_deletion_of_ssh_key.test.yml new file mode 100644 index 0000000000..87f7977249 --- /dev/null +++ b/tests/endpoint/linux_deletion_of_ssh_key.test.yml @@ -0,0 +1,12 @@ +name: Linux deletion Of SSH Key Unit Test +tests: +- name: Linux deletion Of SSH Key + file: endpoint/linux_deletion_of_ssh_key.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon_linux.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log + source: Syslog:Linux-Sysmon/Operational + sourcetype: sysmon_linux diff --git a/tests/endpoint/linux_deletion_of_ssl_certificate.test.yml b/tests/endpoint/linux_deletion_of_ssl_certificate.test.yml new file mode 100644 index 0000000000..f590b6ea02 --- /dev/null +++ b/tests/endpoint/linux_deletion_of_ssl_certificate.test.yml @@ -0,0 +1,12 @@ +name: Linux Deletion of SSL Certificate Unit Test +tests: +- name: Linux Deletion of SSL Certificate + file: endpoint/linux_deletion_of_ssl_certificate.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon_linux.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log + source: Syslog:Linux-Sysmon/Operational + sourcetype: sysmon_linux diff --git a/tests/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.test.yml b/tests/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.test.yml new file mode 100644 index 0000000000..9fd487fb8d --- /dev/null +++ b/tests/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.test.yml @@ -0,0 +1,12 @@ +name: Linux High Frequency Of File Deletion In Etc Folder Unit Test +tests: +- name: Linux High Frequency Of File Deletion In Etc Folder + file: endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon_linux.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/acidrain/sysmon_linux.log + source: Syslog:Linux-Sysmon/Operational + sourcetype: sysmon_linux