From a658de3e25b176d2f0131d525fb115d8def831b9 Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Wed, 23 Feb 2022 15:03:51 -0700 Subject: [PATCH 1/7] MSHTA URl --- .../ssa___windows_mshta_command_line_url.yml | 93 +++++++++++++++++++ ...___windows_mshta_command_line_url.test.yml | 9 ++ 2 files changed, 102 insertions(+) create mode 100644 detections/endpoint/ssa___windows_mshta_command_line_url.yml create mode 100644 tests/endpoint/ssa___windows_mshta_command_line_url.test.yml diff --git a/detections/endpoint/ssa___windows_mshta_command_line_url.yml b/detections/endpoint/ssa___windows_mshta_command_line_url.yml new file mode 100644 index 0000000000..5606f0dc1c --- /dev/null +++ b/detections/endpoint/ssa___windows_mshta_command_line_url.yml @@ -0,0 +1,93 @@ +name: Windows MSHTA Command-Line URL +id: 9b35c538-94ef-11ec-9439-acde48001122 +version: 1 +date: '2022-02-23' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This analytic identifies when Microsoft HTML Application Host (mshta.exe) + utility is used to make remote http connections. Adversaries may use mshta.exe to + proxy the download and execution of remote .hta files. The analytic identifies command + line arguments of http and https being used. This technique is commonly used by + malicious software to bypass preventative controls. The search will return the first + time and last time these command-line arguments were used for these executions, + as well as the target system, the user, process "rundll32.exe" and its parent process. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL | where process_name="mshta.exe" AND (like (cmd_line, "%http://%") OR like (cmd_line, "%https://%")) + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: It is possible legitimate applications may perform this behavior + and will need to be filtered. +references: + - https://github.com/redcanaryco/AtomicTestHarnesses + - https://redcanary.com/blog/introducing-atomictestharnesses/ + - https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing +tags: + analytic_story: + - Suspicious MSHTA Activity + - Living Off The Land + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1218.005 + - T1218 + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + security_domain: endpoint + impact: 80 + confidence: 100 + # (impact * confidence)/100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to access a remote destination to + download an additional payload. + nist: + - PR.PT + - DE.CM + cis20: + - CIS 8 + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process \ No newline at end of file diff --git a/tests/endpoint/ssa___windows_mshta_command_line_url.test.yml b/tests/endpoint/ssa___windows_mshta_command_line_url.test.yml new file mode 100644 index 0000000000..b5d8fa3e40 --- /dev/null +++ b/tests/endpoint/ssa___windows_mshta_command_line_url.test.yml @@ -0,0 +1,9 @@ +name: Windows MSHTA Command-Line URL Unit Test +tests: +- name: Windows MSHTA Command-Line URL + file: endpoint/ssa___windows_mshta_command_line_url.yml + pass_condition: '@count_gt(0)' + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + source: WinEventLog:Security \ No newline at end of file From c9654f36cf0bd18e279a7a76a73ecdb1f5ee2c50 Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Wed, 23 Feb 2022 15:23:30 -0700 Subject: [PATCH 2/7] rundll32 inline --- ..._windows_rundll32_inline_hta_execution.yml | 97 +++++++++++++++++++ ...ows_rundll32_inline_hta_execution.test.yml | 9 ++ 2 files changed, 106 insertions(+) create mode 100644 detections/endpoint/ssa___windows_rundll32_inline_hta_execution.yml create mode 100644 tests/endpoint/ssa___windows_rundll32_inline_hta_execution.test.yml diff --git a/detections/endpoint/ssa___windows_rundll32_inline_hta_execution.yml b/detections/endpoint/ssa___windows_rundll32_inline_hta_execution.yml new file mode 100644 index 0000000000..d66cbe9df7 --- /dev/null +++ b/detections/endpoint/ssa___windows_rundll32_inline_hta_execution.yml @@ -0,0 +1,97 @@ +name: Windows Rundll32 Inline HTA Execution +id: 0caa1dd6-94f5-11ec-9786-acde48001122 +version: 1 +date: '2022-02-23' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: The following analytic identifies "rundll32.exe" execution with inline + protocol handlers. "JavaScript", "VBScript", and "About" are the only supported + options when invoking HTA content directly on the command-line. This type of behavior + is commonly observed with fileless malware or application whitelisting bypass techniques. + The search will return the first time and last time these command-line arguments + were used for these executions, as well as the target system, the user, process + "rundll32.exe" and its parent process. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL | where process_name="rundll32.exe" AND (like (cmd_line, "%vbscript%") OR like (cmd_line, "%javascript%") OR like (cmd_line, "%about%")) + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Although unlikely, some legitimate applications may exhibit + this behavior, triggering a false positive. +references: +- https://github.com/redcanaryco/AtomicTestHarnesses +- https://redcanary.com/blog/introducing-atomictestharnesses/ +- https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing +tags: + analytic_story: + - Suspicious MSHTA Activity + - NOBELIUM Group + - Living Off The Land + asset_type: Endpoint + automated_detection_testing: passed + cis20: + - CIS 8 + confidence: 80 + context: + - Source:Endpoint + - Stage:Initial Access + - Stage:Execution + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + impact: 70 + kill_chain_phases: + - Exploitation + message: Suspicious $process_name$ inline HTA execution on $dest_device_id$. + mitre_attack_id: + - T1218 + - T1218.005 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 56 + security_domain: endpoint + supported_tas: + - Splunk_TA_microsoft_sysmon diff --git a/tests/endpoint/ssa___windows_rundll32_inline_hta_execution.test.yml b/tests/endpoint/ssa___windows_rundll32_inline_hta_execution.test.yml new file mode 100644 index 0000000000..af29be37cf --- /dev/null +++ b/tests/endpoint/ssa___windows_rundll32_inline_hta_execution.test.yml @@ -0,0 +1,9 @@ +name: Windows Rundll32 Inline HTA Execution Unit Test +tests: +- name: Windows Rundll32 Inline HTA Execution + file: endpoint/ssa___windows_rundll32_inline_hta_execution.yml + pass_condition: '@count_gt(0)' + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + source: WinEventLog:Security \ No newline at end of file From e67e0c92bba1752ea9a3bd5ae4aafa9d1c9d53e3 Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Wed, 23 Feb 2022 20:56:51 -0700 Subject: [PATCH 3/7] mshta inline --- ...a___windows_mshta_inline_hta_execution.yml | 91 +++++++++++++++++++ ...indows_mshta_inline_hta_execution.test.yml | 9 ++ 2 files changed, 100 insertions(+) create mode 100644 detections/endpoint/ssa___windows_mshta_inline_hta_execution.yml create mode 100644 tests/endpoint/ssa___windows_mshta_inline_hta_execution.test.yml diff --git a/detections/endpoint/ssa___windows_mshta_inline_hta_execution.yml b/detections/endpoint/ssa___windows_mshta_inline_hta_execution.yml new file mode 100644 index 0000000000..708cb1d7b2 --- /dev/null +++ b/detections/endpoint/ssa___windows_mshta_inline_hta_execution.yml @@ -0,0 +1,91 @@ +name: Windows MSHTA Inline HTA Execution +id: 24962154-9524-11ec-9333-acde48001122 +version: 1 +date: '2022-02-23' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: The following analytic identifies "mshta.exe" execution with inline protocol + handlers. "JavaScript", "VBScript", and "About" are the only supported options when + invoking HTA content directly on the command-line. The search will return the first + time and last time these command-line arguments were used for these executions, + as well as the target system, the user, process "mshta.exe" and its parent process. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL | where process_name="mshta.exe" AND (like (cmd_line, "%vbscript%") OR like (cmd_line, "%javascript%") OR like (cmd_line, "%about%")) + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Although unlikely, some legitimate applications may exhibit + this behavior, triggering a false positive. +references: +- https://github.com/redcanaryco/AtomicTestHarnesses +- https://redcanary.com/blog/introducing-atomictestharnesses/ +- https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing +tags: + analytic_story: + - Suspicious MSHTA Activity + - Living Off The Land + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1218.005 + - T1218 + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + security_domain: endpoint + impact: 80 + confidence: 100 + # (impact * confidence)/100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ executing with inline HTA, indicative of defense + evasion. + nist: + - PR.PT + - DE.CM + cis20: + - CIS 8 + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process \ No newline at end of file diff --git a/tests/endpoint/ssa___windows_mshta_inline_hta_execution.test.yml b/tests/endpoint/ssa___windows_mshta_inline_hta_execution.test.yml new file mode 100644 index 0000000000..3ed94dc93a --- /dev/null +++ b/tests/endpoint/ssa___windows_mshta_inline_hta_execution.test.yml @@ -0,0 +1,9 @@ +name: Windows MSHTA Inline HTA Execution Unit Test +tests: +- name: Windows MSHTA Inline HTA Execution + file: endpoint/ssa___windows_mshta_inline_hta_execution.yml + pass_condition: '@count_gt(0)' + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + source: WinEventLog:Security \ No newline at end of file From dbce7115044b547243c5c701490cdc7419bb6df3 Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Wed, 23 Feb 2022 21:53:31 -0700 Subject: [PATCH 4/7] mshta child --- .../ssa___windows_mshta_child_process.yml | 90 +++++++++++++++++++ ...ssa___windows_mshta_child_process.test.yml | 9 ++ 2 files changed, 99 insertions(+) create mode 100644 detections/endpoint/ssa___windows_mshta_child_process.yml create mode 100644 tests/endpoint/ssa___windows_mshta_child_process.test.yml diff --git a/detections/endpoint/ssa___windows_mshta_child_process.yml b/detections/endpoint/ssa___windows_mshta_child_process.yml new file mode 100644 index 0000000000..d1c0effc0e --- /dev/null +++ b/detections/endpoint/ssa___windows_mshta_child_process.yml @@ -0,0 +1,90 @@ +name: Windows MSHTA Child Process +id: f63f7e9c-9526-11ec-9fc7-acde48001122 +version: 1 +date: '2022-02-23' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: The following analytic identifies child processes spawning from "mshta.exe". + The search will return the first time and last time these command-line arguments + were used for these executions, as well as the target system, the user, parent process + "mshta.exe" and its child process. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL AND parent_process_name IS NOT NULL | where parent_process_name="mshta.exe" AND process_name="powershell.exe" OR process_name="cmd.exe" OR + process_name="scrcons.exe" OR process_name="colorcpl.exe" OR process_name="msbuild.exe" OR process_name="microsoft.workflow.compiler.exe" + OR process_name="searchprotocolhost.exe" OR process_name="cscript.exe" OR process_name="wscript.exe" + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: Although unlikely, some legitimate applications may exhibit + this behavior, triggering a false positive. +references: +- https://github.com/redcanaryco/AtomicTestHarnesses +- https://redcanary.com/blog/introducing-atomictestharnesses/ +tags: + analytic_story: + - Suspicious MSHTA Activity + - Living Off The Land + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1218.005 + - T1218 + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + security_domain: endpoint + impact: 80 + confidence: 100 + # (impact * confidence)/100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to access a remote destination to + download an additional payload. + nist: + - PR.PT + - DE.CM + cis20: + - CIS 8 + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process \ No newline at end of file diff --git a/tests/endpoint/ssa___windows_mshta_child_process.test.yml b/tests/endpoint/ssa___windows_mshta_child_process.test.yml new file mode 100644 index 0000000000..b43d03d153 --- /dev/null +++ b/tests/endpoint/ssa___windows_mshta_child_process.test.yml @@ -0,0 +1,9 @@ +name: Windows MSHTA Child Process Unit Test +tests: +- name: Windows MSHTA Child Process + file: endpoint/ssa___windows_mshta_child_process.yml + pass_condition: '@count_gt(0)' + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + source: WinEventLog:Security \ No newline at end of file From f7a8cb0cc59961b445fd28c62c5b088f5f34b09d Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Thu, 24 Feb 2022 20:22:13 -0700 Subject: [PATCH 5/7] Working on --- .../ssa___windows_mshta_child_process.yml | 2 +- .../ssa___windows_wmiprvse_spawn_mshta.yml | 90 +++++++++++++++++++ ...sa___windows_wmiprvse_spawn_mshta.test.yml | 9 ++ 3 files changed, 100 insertions(+), 1 deletion(-) create mode 100644 detections/endpoint/ssa___windows_wmiprvse_spawn_mshta.yml create mode 100644 tests/endpoint/ssa___windows_wmiprvse_spawn_mshta.test.yml diff --git a/detections/endpoint/ssa___windows_mshta_child_process.yml b/detections/endpoint/ssa___windows_mshta_child_process.yml index d1c0effc0e..d5980dbe8d 100644 --- a/detections/endpoint/ssa___windows_mshta_child_process.yml +++ b/detections/endpoint/ssa___windows_mshta_child_process.yml @@ -10,7 +10,7 @@ description: The following analytic identifies child processes spawning from "m The search will return the first time and last time these command-line arguments were used for these executions, as well as the target system, the user, parent process "mshta.exe" and its child process. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", diff --git a/detections/endpoint/ssa___windows_wmiprvse_spawn_mshta.yml b/detections/endpoint/ssa___windows_wmiprvse_spawn_mshta.yml new file mode 100644 index 0000000000..1b5308cb3d --- /dev/null +++ b/detections/endpoint/ssa___windows_wmiprvse_spawn_mshta.yml @@ -0,0 +1,90 @@ +name: Windows Wmiprvse Spawn MSHTA +id: ba0a50e2-9598-11ec-9c6b-acde48001122 +version: 1 +date: '2022-02-24' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies wmiprvse.exe spawning mshta.exe. This + behavior is indicative of a DCOM object being utilized to spawn mshta from wmiprvse.exe + or svchost.exe. In this instance, adversaries may use LethalHTA that will spawn + mshta.exe from svchost.exe. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL AND parent_process_name IS NOT NULL | where parent_process_name="wmiprvse.exe" parent_process_name="svchost.exe" AND process_name="mshta.exe" + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Although unlikely, some legitimate applications may exhibit + this behavior, triggering a false positive. +references: +- https://codewhitesec.blogspot.com/2018/07/lethalhta.html +- https://github.com/redcanaryco/AtomicTestHarnesses +- https://redcanary.com/blog/introducing-atomictestharnesses/ +tags: + analytic_story: + - Suspicious MSHTA Activity + - Living Off The Land + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1218.005 + - T1218 + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + security_domain: endpoint + impact: 80 + confidence: 100 + # (impact * confidence)/100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Execution + - Stage:Defense Evasion + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ potentially indicative of defense evasion. + nist: + - PR.PT + - DE.CM + cis20: + - CIS 8 + observable: + - name: dest_user_id + type: User + role: + - Victim + - name: dest_device_id + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process \ No newline at end of file diff --git a/tests/endpoint/ssa___windows_wmiprvse_spawn_mshta.test.yml b/tests/endpoint/ssa___windows_wmiprvse_spawn_mshta.test.yml new file mode 100644 index 0000000000..b6b779c4d8 --- /dev/null +++ b/tests/endpoint/ssa___windows_wmiprvse_spawn_mshta.test.yml @@ -0,0 +1,9 @@ +name: Windows Wmiprvse Spawn MSHTA Unit Test +tests: +- name: Windows Wmiprvse Spawn MSHTA + file: endpoint/ssa___windows_wmiprvse_spawn_mshta.yml + pass_condition: '@count_gt(0)' + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + source: WinEventLog:Security \ No newline at end of file From efe95670b961983012d884a6da25753e9aec5533 Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Mon, 28 Feb 2022 13:57:32 -0700 Subject: [PATCH 6/7] removed --- .../ssa___windows_wmiprvse_spawn_mshta.yml | 90 ------------------- ...sa___windows_wmiprvse_spawn_mshta.test.yml | 9 -- 2 files changed, 99 deletions(-) delete mode 100644 detections/endpoint/ssa___windows_wmiprvse_spawn_mshta.yml delete mode 100644 tests/endpoint/ssa___windows_wmiprvse_spawn_mshta.test.yml diff --git a/detections/endpoint/ssa___windows_wmiprvse_spawn_mshta.yml b/detections/endpoint/ssa___windows_wmiprvse_spawn_mshta.yml deleted file mode 100644 index 1b5308cb3d..0000000000 --- a/detections/endpoint/ssa___windows_wmiprvse_spawn_mshta.yml +++ /dev/null @@ -1,90 +0,0 @@ -name: Windows Wmiprvse Spawn MSHTA -id: ba0a50e2-9598-11ec-9c6b-acde48001122 -version: 1 -date: '2022-02-24' -author: Michael Haag, Splunk -type: TTP -datamodel: -- Endpoint -description: The following analytic identifies wmiprvse.exe spawning mshta.exe. This - behavior is indicative of a DCOM object being utilized to spawn mshta from wmiprvse.exe - or svchost.exe. In this instance, adversaries may use LethalHTA that will spawn - mshta.exe from svchost.exe. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND process_name IS NOT NULL AND parent_process_name IS NOT NULL | where parent_process_name="wmiprvse.exe" parent_process_name="svchost.exe" AND process_name="mshta.exe" - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -known_false_positives: Although unlikely, some legitimate applications may exhibit - this behavior, triggering a false positive. -references: -- https://codewhitesec.blogspot.com/2018/07/lethalhta.html -- https://github.com/redcanaryco/AtomicTestHarnesses -- https://redcanary.com/blog/introducing-atomictestharnesses/ -tags: - analytic_story: - - Suspicious MSHTA Activity - - Living Off The Land - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log - kill_chain_phases: - - Exploitation - mitre_attack_id: - - T1218.005 - - T1218 - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - security_domain: endpoint - impact: 80 - confidence: 100 - # (impact * confidence)/100 - risk_score: 80 - context: - - Source:Endpoint - - Stage:Execution - - Stage:Defense Evasion - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ potentially indicative of defense evasion. - nist: - - PR.PT - - DE.CM - cis20: - - CIS 8 - observable: - - name: dest_user_id - type: User - role: - - Victim - - name: dest_device_id - type: Hostname - role: - - Victim - - name: parent_process_name - type: Parent Process - role: - - Parent Process - - name: process_name - type: Process - role: - - Child Process \ No newline at end of file diff --git a/tests/endpoint/ssa___windows_wmiprvse_spawn_mshta.test.yml b/tests/endpoint/ssa___windows_wmiprvse_spawn_mshta.test.yml deleted file mode 100644 index b6b779c4d8..0000000000 --- a/tests/endpoint/ssa___windows_wmiprvse_spawn_mshta.test.yml +++ /dev/null @@ -1,9 +0,0 @@ -name: Windows Wmiprvse Spawn MSHTA Unit Test -tests: -- name: Windows Wmiprvse Spawn MSHTA - file: endpoint/ssa___windows_wmiprvse_spawn_mshta.yml - pass_condition: '@count_gt(0)' - attack_data: - - file_name: windows-security.log - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log - source: WinEventLog:Security \ No newline at end of file From 28527a48a50a51ad08d992c066a4c84f928099e8 Mon Sep 17 00:00:00 2001 From: patel-bhavin Date: Wed, 2 Mar 2022 13:06:08 -0800 Subject: [PATCH 7/7] ssa package --- .../srs/ssa___windows_mshta_child_process.yml | 107 +++++++++++++++++ .../ssa___windows_mshta_command-line_url.yml | 109 +++++++++++++++++ ...a___windows_mshta_inline_hta_execution.yml | 107 +++++++++++++++++ ..._windows_rundll32_inline_hta_execution.yml | 112 ++++++++++++++++++ 4 files changed, 435 insertions(+) create mode 100644 dist/ssa/srs/ssa___windows_mshta_child_process.yml create mode 100644 dist/ssa/srs/ssa___windows_mshta_command-line_url.yml create mode 100644 dist/ssa/srs/ssa___windows_mshta_inline_hta_execution.yml create mode 100644 dist/ssa/srs/ssa___windows_rundll32_inline_hta_execution.yml diff --git a/dist/ssa/srs/ssa___windows_mshta_child_process.yml b/dist/ssa/srs/ssa___windows_mshta_child_process.yml new file mode 100644 index 0000000000..bc8fc0c0d9 --- /dev/null +++ b/dist/ssa/srs/ssa___windows_mshta_child_process.yml @@ -0,0 +1,107 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2022-02-23' +description: The following analytic identifies child processes spawning from "mshta.exe". + The search will return the first time and last time these command-line arguments + were used for these executions, as well as the target system, the user, parent process + "mshta.exe" and its child process. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: f63f7e9c-9526-11ec-9fc7-acde48001122 +known_false_positives: Although unlikely, some legitimate applications may exhibit + this behavior, triggering a false positive. +name: Windows MSHTA Child Process +product: +- Splunk Behavioral Analytics +references: +- https://github.com/redcanaryco/AtomicTestHarnesses +- https://redcanary.com/blog/introducing-atomictestharnesses/ +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to access a remote + destination to download an additional payload. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL AND parent_process_name IS NOT + NULL | where parent_process_name="mshta.exe" AND process_name="powershell.exe" OR + process_name="cmd.exe" OR process_name="scrcons.exe" OR process_name="colorcpl.exe" + OR process_name="msbuild.exe" OR process_name="microsoft.workflow.compiler.exe" + OR process_name="searchprotocolhost.exe" OR process_name="cscript.exe" OR process_name="wscript.exe" + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Suspicious MSHTA Activity + - Living Off The Land + cis20: + - CIS 8 + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + impact: 80 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to access a remote + destination to download an additional payload. + mitre_attack_id: + - T1218.005 + - T1218 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 80 + risk_severity: high + security_domain: endpoint +test: + name: Windows MSHTA Child Process Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + file: endpoint/ssa___windows_mshta_child_process.yml + name: Windows MSHTA Child Process + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___windows_mshta_command-line_url.yml b/dist/ssa/srs/ssa___windows_mshta_command-line_url.yml new file mode 100644 index 0000000000..60ef667e7a --- /dev/null +++ b/dist/ssa/srs/ssa___windows_mshta_command-line_url.yml @@ -0,0 +1,109 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2022-02-23' +description: This analytic identifies when Microsoft HTML Application Host (mshta.exe) + utility is used to make remote http connections. Adversaries may use mshta.exe to + proxy the download and execution of remote .hta files. The analytic identifies command + line arguments of http and https being used. This technique is commonly used by + malicious software to bypass preventative controls. The search will return the first + time and last time these command-line arguments were used for these executions, + as well as the target system, the user, process "rundll32.exe" and its parent process. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +id: 9b35c538-94ef-11ec-9439-acde48001122 +known_false_positives: It is possible legitimate applications may perform this behavior + and will need to be filtered. +name: Windows MSHTA Command-Line URL +product: +- Splunk Behavioral Analytics +references: +- https://github.com/redcanaryco/AtomicTestHarnesses +- https://redcanary.com/blog/introducing-atomictestharnesses/ +- https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to access a remote + destination to download an additional payload. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL | where process_name="mshta.exe" + AND (like (cmd_line, "%http://%") OR like (cmd_line, "%https://%")) | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, + "parent_process_name", parent_process_name, "process_path", process_path]) | into + write_ssa_detected_events();' +tags: + analytic_story: + - Suspicious MSHTA Activity + - Living Off The Land + cis20: + - CIS 8 + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + impact: 80 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to access a remote + destination to download an additional payload. + mitre_attack_id: + - T1218.005 + - T1218 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 80 + risk_severity: high + security_domain: endpoint +test: + name: Windows MSHTA Command-Line URL Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + file: endpoint/ssa___windows_mshta_command_line_url.yml + name: Windows MSHTA Command-Line URL + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___windows_mshta_inline_hta_execution.yml b/dist/ssa/srs/ssa___windows_mshta_inline_hta_execution.yml new file mode 100644 index 0000000000..d3c940e30f --- /dev/null +++ b/dist/ssa/srs/ssa___windows_mshta_inline_hta_execution.yml @@ -0,0 +1,107 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2022-02-23' +description: The following analytic identifies "mshta.exe" execution with inline protocol + handlers. "JavaScript", "VBScript", and "About" are the only supported options when + invoking HTA content directly on the command-line. The search will return the first + time and last time these command-line arguments were used for these executions, + as well as the target system, the user, process "mshta.exe" and its parent process. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +id: 24962154-9524-11ec-9333-acde48001122 +known_false_positives: Although unlikely, some legitimate applications may exhibit + this behavior, triggering a false positive. +name: Windows MSHTA Inline HTA Execution +product: +- Splunk Behavioral Analytics +references: +- https://github.com/redcanaryco/AtomicTestHarnesses +- https://redcanary.com/blog/introducing-atomictestharnesses/ +- https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ executing with inline HTA, indicative + of defense evasion. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL | where process_name="mshta.exe" + AND (like (cmd_line, "%vbscript%") OR like (cmd_line, "%javascript%") OR like (cmd_line, + "%about%")) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Suspicious MSHTA Activity + - Living Off The Land + cis20: + - CIS 8 + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + impact: 80 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ executing with inline HTA, + indicative of defense evasion. + mitre_attack_id: + - T1218.005 + - T1218 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 80 + risk_severity: high + security_domain: endpoint +test: + name: Windows MSHTA Inline HTA Execution Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + file: endpoint/ssa___windows_mshta_inline_hta_execution.yml + name: Windows MSHTA Inline HTA Execution + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___windows_rundll32_inline_hta_execution.yml b/dist/ssa/srs/ssa___windows_rundll32_inline_hta_execution.yml new file mode 100644 index 0000000000..01067f33bc --- /dev/null +++ b/dist/ssa/srs/ssa___windows_rundll32_inline_hta_execution.yml @@ -0,0 +1,112 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2022-02-23' +description: The following analytic identifies "rundll32.exe" execution with inline + protocol handlers. "JavaScript", "VBScript", and "About" are the only supported + options when invoking HTA content directly on the command-line. This type of behavior + is commonly observed with fileless malware or application whitelisting bypass techniques. + The search will return the first time and last time these command-line arguments + were used for these executions, as well as the target system, the user, process + "rundll32.exe" and its parent process. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +id: 0caa1dd6-94f5-11ec-9786-acde48001122 +known_false_positives: Although unlikely, some legitimate applications may exhibit + this behavior, triggering a false positive. +name: Windows Rundll32 Inline HTA Execution +product: +- Splunk Behavioral Analytics +references: +- https://github.com/redcanaryco/AtomicTestHarnesses +- https://redcanary.com/blog/introducing-atomictestharnesses/ +- https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing +risk_message: Suspicious $process_name$ inline HTA execution on $dest_device_id$. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL | where process_name="rundll32.exe" + AND (like (cmd_line, "%vbscript%") OR like (cmd_line, "%javascript%") OR like (cmd_line, + "%about%")) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Suspicious MSHTA Activity + - NOBELIUM Group + - Living Off The Land + asset_type: Endpoint + automated_detection_testing: passed + cis20: + - CIS 8 + confidence: 80 + context: + - Source:Endpoint + - Stage:Initial Access + - Stage:Execution + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + impact: 70 + kill_chain_phases: + - Exploitation + message: Suspicious $process_name$ inline HTA execution on $dest_device_id$. + mitre_attack_id: + - T1218 + - T1218.005 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 56 + risk_severity: medium + security_domain: endpoint + supported_tas: + - Splunk_TA_microsoft_sysmon +test: + name: Windows Rundll32 Inline HTA Execution Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + file: endpoint/ssa___windows_rundll32_inline_hta_execution.yml + name: Windows Rundll32 Inline HTA Execution + pass_condition: '@count_gt(0)' +type: TTP +version: 1