mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
updating descriptions
This commit is contained in:
@@ -7,7 +7,11 @@ status: production
|
||||
type: Hunting
|
||||
data_source:
|
||||
- Authentication Datamodel
|
||||
description: This analytic uses the 3-sigma approach to detect a distributed password spray attack. Utilising the authentication datamodel this detection is affective for all CIM mapped authication events.
|
||||
description: This analytic employs the 3-sigma approach to identify distributed password spray attacks. A
|
||||
distributed password spray attack is a type of brute force attack where the attacker attempts a few
|
||||
common passwords against many different accounts, connecting from multiple IP addresses to avoid detection.
|
||||
By utilizing the Authentication Data Model, this detection is effective for all CIM-mapped authentication
|
||||
events, providing comprehensive coverage and enhancing security against these attacks.
|
||||
search: '| tstats `security_content_summariesonly` dc(Authentication.user) AS unique_accounts dc(Authentication.src) as unique_src count(Authentication.user) as total_failures from datamodel=Authentication.Authentication where Authentication.action="failure" by Authentication.action, Authentication.signature_id, sourcetype, _time span=2m
|
||||
| `drop_dm_object_name("Authentication")`
|
||||
```fill out time buckets for 0-count events during entire search length```
|
||||
|
||||
@@ -7,7 +7,11 @@ status: production
|
||||
type: TTP
|
||||
data_source:
|
||||
- Authentication Datamodel
|
||||
description: This analytic uses the 3-sigma approach to detect an unusual volume of failed authentication from a single source. Utilising the authentication datamodel this detection is affective for all CIM mapped authication events.
|
||||
description: This analytic employs the 3-sigma approach to detect an unusual volume of failed authentication attempts
|
||||
from a single source. A password spray attack is a type of brute force attack where an attacker tries a few
|
||||
common passwords across many different accounts to avoid detection and account lockouts. By utilizing the
|
||||
Authentication Data Model, this detection is effective for all CIM-mapped authentication events, providing
|
||||
comprehensive coverage and enhancing security against these attacks.
|
||||
search: '| tstats `security_content_summariesonly` dc(Authentication.user) AS unique_accounts values(Authentication.app) as app count(Authentication.user) as total_failures from datamodel=Authentication.Authentication where Authentication.action="failure" by Authentication.src, Authentication.action, Authentication.signature_id, sourcetype, _time span=2m
|
||||
| `drop_dm_object_name("Authentication")`
|
||||
```fill out time buckets for 0-count events during entire search length```
|
||||
|
||||
@@ -7,7 +7,10 @@ status: production
|
||||
type: TTP
|
||||
data_source:
|
||||
- Windows Event Log Security 4728
|
||||
description: Detect when a user adds themselfs to an AD Group.
|
||||
description: This analytic detects instances where a user adds themselves to an Active Directory (AD) group. This activity
|
||||
is a common indicator of privilege escalation, where a user attempts to gain unauthorized access to higher
|
||||
privileges or sensitive resources. By monitoring AD logs, this detection identifies such suspicious behavior,
|
||||
which could be part of a larger attack strategy aimed at compromising critical systems and data.
|
||||
search: '`wineventlog_security` EventCode IN (4728)
|
||||
| where user=src_user
|
||||
| stats min(_time) as _time dc(user) as usercount, values(user) as user values(user_category) as user_category values(src_user_category) as src_user_category values(dvc) as dvc by signature, Group_Name, src_user
|
||||
|
||||
+7
-2
@@ -7,7 +7,11 @@ status: production
|
||||
type: TTP
|
||||
data_source:
|
||||
- XmlWinEventLog:Security
|
||||
description: Increase in group or AD object modifications.
|
||||
description: This analytic detects an increase in modifications to AD groups or objects.
|
||||
Frequent changes to AD groups or objects can indicate potential security risks,
|
||||
such as unauthorized access attempts, impairing defences or establishing persistence.
|
||||
By monitoring AD logs for unusual modification patterns, this detection helps identify
|
||||
suspicious behavior that could compromise the integrity and security of the AD environment.
|
||||
search: >-
|
||||
`wineventlog_security` EventCode IN (4670,4727,4731,4734,4735,4764)
|
||||
| bucket span=5m _time
|
||||
@@ -17,7 +21,7 @@ search: >-
|
||||
| eval isOutlier=if(objectCount > 10 and (objectCount >= upperBound), 1, 0)
|
||||
| search isOutlier=1
|
||||
| `windows_increase_in_group_or_object_modification_activity_filter`
|
||||
how_to_implement: Run over past 7 days for best results.
|
||||
how_to_implement: Run this detection looking over a 7 day timeframe for best results.
|
||||
known_false_positives: Unknown
|
||||
references: []
|
||||
tags:
|
||||
@@ -29,6 +33,7 @@ tags:
|
||||
message: Spike in Group or Object Modifications performed by $src_user$
|
||||
mitre_attack_id:
|
||||
- T1098
|
||||
- T1562
|
||||
observable:
|
||||
- name: src_user
|
||||
type: User
|
||||
|
||||
@@ -7,7 +7,11 @@ status: production
|
||||
type: TTP
|
||||
data_source:
|
||||
- XmlWinEventLog:Security
|
||||
description: Increase in user account modifications.
|
||||
description: This analytic detects an increase in modifications to AD user objects.
|
||||
A large volume of changes to user objects can indicate potential security risks,
|
||||
such as unauthorized access attempts, impairing defences or establishing persistence.
|
||||
By monitoring AD logs for unusual modification patterns, this detection helps identify
|
||||
suspicious behavior that could compromise the integrity and security of the AD environment.
|
||||
search: >-
|
||||
`wineventlog_security` EventCode IN (4720,4722,4723,4724,4725,4726,4728,4732,4733,4738,4743,4780)
|
||||
| bucket span=5m _time
|
||||
@@ -18,7 +22,7 @@ search: >-
|
||||
| search isOutlier=1
|
||||
| stats values(TargetDomainName) as TargetDomainName, values(user) as user, dc(user) as userCount, values(user_category) as user_category, values(src_user_category) as src_user_category, values(dest) as dest, values(dest_category) as dest_category values(signature) as signature by _time, src_user, status
|
||||
| `windows_increase_in_user_modification_activity_filter`
|
||||
how_to_implement: Run over past 7 days for best results.
|
||||
how_to_implement: Run this detection looking over a 7 day timeframe for best results.
|
||||
known_false_positives: Genuine activity
|
||||
references: []
|
||||
tags:
|
||||
@@ -30,6 +34,7 @@ tags:
|
||||
message: Spike in User Modification actions performed by $src_user$
|
||||
mitre_attack_id:
|
||||
- T1098
|
||||
- T1562
|
||||
observable:
|
||||
- name: src_user
|
||||
type: User
|
||||
|
||||
@@ -1,59 +0,0 @@
|
||||
name: Windows Network Share Discovery With Net
|
||||
id: 4dc3951f-b3f8-4f46-b412-76a483f72277
|
||||
version: 1
|
||||
date: '2023-04-21'
|
||||
author: Dean Luxton
|
||||
status: production
|
||||
type: TTP
|
||||
data_source:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1135/net_share/windows-sysmon.log
|
||||
description: Network share discovery performed on Windows using the Net Command.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.user_category) as user_category values(Processes.user_bunit) as user_bunit FROM datamodel=Endpoint.Processes WHERE ((Processes.process_name="net.exe" OR Processes.orig_process_name="net.exe") AND (Processes.process="*net*view*" OR Processes.process="*net*share*")) BY Processes.user Processes.dest Processes.process_exec Processes.parent_process_exec
|
||||
Processes.process Processes.parent_process
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| regex process="net\s+view|net\s+share"
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_network_share_discovery_with_net_filter`'
|
||||
how_to_implement: Ensure you are populating the endpoint datamodel.
|
||||
known_false_positives: Unknown
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1135/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Discovery
|
||||
- Active Directory Privilege Escalation
|
||||
- Network Discovery
|
||||
asset_type: Endpoint
|
||||
atomic_guid:
|
||||
- ab39a04f-0c93-4540-9ff2-83f862c385ae
|
||||
confidence: 100
|
||||
impact: 20
|
||||
message: Network share enumeration performed on $dest$ by $user$, executed by parent process $parent_process$
|
||||
mitre_attack_id:
|
||||
- T1135
|
||||
required_fields:
|
||||
- Processes.process_name
|
||||
- Processes.user
|
||||
- Processes.dest
|
||||
- Processes.process_exec
|
||||
- Processes.parent_process_exec
|
||||
- Processes.process
|
||||
- Processes.parent_process
|
||||
observable:
|
||||
- name: dest
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
risk_score: 20
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1135/net_share/windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
@@ -0,0 +1,71 @@
|
||||
name: Windows Network Share Interaction With Net
|
||||
id: 4dc3951f-b3f8-4f46-b412-76a483f72277
|
||||
version: 1
|
||||
date: '2023-04-21'
|
||||
author: Dean Luxton
|
||||
status: production
|
||||
type: TTP
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
description: This analytic detects network share discovery and collection activities performed on Windows systems using the Net command.
|
||||
Attackers often use network share discovery to identify accessible shared resources within a network,
|
||||
which can be a precursor to privilege escalation or data exfiltration. By monitoring Windows Event Logs for
|
||||
the usage of the Net command to list and interact with network shares, this detection helps identify potential reconnaissance and collection
|
||||
activities.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.user_category) as user_category values(Processes.user_bunit) as user_bunit FROM datamodel=Endpoint.Processes WHERE (Processes.process_name="net.exe" OR Processes.process_name="net1.exe" OR Processes.orig_process_name="net.exe" OR Processes.orig_process_name="net1net[\s\.ex1]+view|net[\s\.ex1]+share|net[\s\.ex1]+use\s.exe") BY Processes.user Processes.dest Processes.process_exec Processes.parent_process_exec
|
||||
Processes.process Processes.parent_process
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| regex process="net[\s\.ex1]+view|net[\s\.ex1]+share|net[\s\.ex1]+use\s"
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_network_share_interaction_with_net_filter`'
|
||||
how_to_implement: The detection is based on data originating from either Endpoint Detection and Response (EDR) telemetry or EventCode 4688 with
|
||||
process command line logging enabled. These sources provide security-related telemetry from the endpoints. To implement this search, you must
|
||||
ingest logs that contain the process name, parent process, and complete command-line executions. These logs must be mapped to the Splunk Common
|
||||
Information Model (CIM) to normalize the field names capture the data within the datamodel schema.
|
||||
known_false_positives: Unknown
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1135/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Discovery
|
||||
- Active Directory Privilege Escalation
|
||||
- Network Discovery
|
||||
asset_type: Endpoint
|
||||
atomic_guid:
|
||||
- ab39a04f-0c93-4540-9ff2-83f862c385ae
|
||||
confidence: 100
|
||||
impact: 20
|
||||
message: User $user$ leveraged net.exe on $dest$ to interact with network shares, executed by parent process $parent_process$
|
||||
mitre_attack_id:
|
||||
- T1135
|
||||
- T1039
|
||||
required_fields:
|
||||
- Processes.process_name
|
||||
- Processes.user
|
||||
- Processes.dest
|
||||
- Processes.process_exec
|
||||
- Processes.parent_process_exec
|
||||
- Processes.process
|
||||
- Processes.parent_process
|
||||
observable:
|
||||
- name: dest
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
- name: user
|
||||
type: User
|
||||
role:
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
risk_score: 20
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1135/net_share/windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
@@ -7,18 +7,21 @@ status: production
|
||||
type: TTP
|
||||
data_source:
|
||||
- XmlWinEventLog System EventCode 7045
|
||||
description: The following analytic utilises a known list of vulnerable Windows drivers
|
||||
to help defenders find potential persistence or privelege escalation via a vulnerable
|
||||
driver. This analytic uses native windows system service install events to capture when the vulnerable driver is installed.
|
||||
A known gap with this lookup is that it does not use the hash or known signer of the vulnerable driver
|
||||
therefore it is up to the defender to identify version and signing info and confirm
|
||||
it is a vulnerable driver.
|
||||
This detection is a winventlog copy of the Sysmon driver loaded detection written by Michael Haag.
|
||||
description: The following analytic detects the loading of known vulnerable Windows
|
||||
drivers, which may indicate potential persistence or privilege escalation attempts.
|
||||
It leverages Windows System service install EventCode 7045 to identify driver loading
|
||||
events and cross-references them with a list of vulnerable drivers. This activity is
|
||||
significant as attackers often exploit vulnerable drivers to gain elevated privileges
|
||||
or maintain persistence on a system. If confirmed malicious, this could allow attackers
|
||||
to execute arbitrary code with high privileges, leading to further system compromise
|
||||
and potential data exfiltration. This detection is a Windows Event Log adaptation of
|
||||
the Sysmon driver loaded detection written by Michael Haag.
|
||||
search: '`wineventlog_system` EventCode=7045 ServiceType="kernel mode driver" | table _time dest EventCode ImagePath ServiceName ServiceType | lookup loldrivers driver_name AS ImagePath OUTPUT is_driver driver_description | search is_driver = TRUE | `windows_vulnerable_driver_installed_filter`'
|
||||
how_to_implement: Ensure the Splunk is collecting XmlWinEventLog:System events and the EventCode 7045 is being ingested.
|
||||
known_false_positives: False positives may be present. Drill down into the driver
|
||||
known_false_positives: False positives will be present. Drill down into the driver
|
||||
further by version number and cross reference by signer. Review the reference material
|
||||
in the lookup.
|
||||
in the lookup. In addition, modify the query to look within specific paths, which
|
||||
will remove a lot of "normal" drivers.
|
||||
references:
|
||||
- https://loldrivers.io/
|
||||
- https://github.com/SpikySabra/Kernel-Cactus
|
||||
|
||||
@@ -6,7 +6,12 @@ author: Dean Luxton
|
||||
status: production
|
||||
type: TTP
|
||||
data_source: []
|
||||
description: This analytic detects where an internal host has attempted to communicate with 250 or more destination IP addresses using the same port / protocol.
|
||||
description: This analytic identifies instances where an internal host has attempted to communicate
|
||||
with 250 or more destination IP addresses using the same port and protocol. Horizontal
|
||||
port scans from internal hosts can indicate reconnaissance or scanning activities,
|
||||
potentially signaling malicious intent or misconfiguration. By monitoring network
|
||||
traffic logs, this detection helps detect and respond to such behavior promptly,
|
||||
enhancing network security and preventing potential threats.
|
||||
search: '| tstats `security_content_summariesonly` values(All_Traffic.action) as action
|
||||
values(All_Traffic.src_category) as src_category values(All_Traffic.dest_zone) as
|
||||
dest_zone values(All_Traffic.src_zone) as src_zone count from datamodel=Network_Traffic
|
||||
@@ -19,7 +24,9 @@ search: '| tstats `security_content_summariesonly` values(All_Traffic.action) as
|
||||
min(_time) as _time values(action) as action sum(totalDestIPCount) as totalDestIPCount
|
||||
values(src_category) as src_category values(dest_port) as dest_ports values(dest_zone)
|
||||
as dest_zone values(src_zone) as src_zone by src_ip gtime | fields - gtime | `internal_horizontal_port_scan_filter`'
|
||||
how_to_implement: Ensure your network traffic data is populating the Network_Traffic data model.
|
||||
how_to_implement: To properly run this search, Splunk needs to ingest data from networking telemetry sources such as
|
||||
firewalls, NetFlow, or host-based networking events. Ensure that the Network_Traffic data model is populated to
|
||||
enable this search effectively.
|
||||
known_false_positives: Unknown
|
||||
references: []
|
||||
tags:
|
||||
|
||||
@@ -6,7 +6,12 @@ author: Dean Luxton
|
||||
status: production
|
||||
type: TTP
|
||||
data_source: []
|
||||
description: This analytic detects an internal host has attempted to communicate with over 500 ports on a single destination IP. Additional filtering is performed on the number of privileged ports within the request to filter out applications performing port scans over ephemeral port ranges.
|
||||
description: This analytic detects instances where an internal host attempts to communicate
|
||||
with over 500 ports on a single destination IP address. It includes filtering
|
||||
criteria to exclude applications performing scans over ephemeral port ranges,
|
||||
focusing on potential reconnaissance or scanning activities. Monitoring network
|
||||
traffic logs allows for timely detection and response to such behavior, enhancing
|
||||
network security by identifying and mitigating potential threats promptly.
|
||||
search: '| tstats `security_content_summariesonly` values(All_Traffic.action) as action
|
||||
values(All_Traffic.src_category) as src_category values(All_Traffic.dest_zone) as
|
||||
dest_zone values(All_Traffic.src_zone) as src_zone count from datamodel=Network_Traffic
|
||||
@@ -21,7 +26,9 @@ search: '| tstats `security_content_summariesonly` values(All_Traffic.action) as
|
||||
dest_ip transport gtime | eval totalDestPortCount=totalDestUdpPortCount+totalDestTcpPortCount,
|
||||
privilegedDestPortCount=privilegedDestTcpPortCount+privilegedDestUdpPortCount| where
|
||||
(totalDestPortCount>=500 AND privilegedDestPortCount>=20) | fields - gtime | `internal_vertical_port_scan_filter`'
|
||||
how_to_implement: Ensure your network traffic data is populating the Network_Traffic data model.
|
||||
how_to_implement: To properly run this search, Splunk needs to ingest data from networking telemetry sources such as
|
||||
firewalls, NetFlow, or host-based networking events. Ensure that the Network_Traffic data model is populated to
|
||||
enable this search effectively.
|
||||
known_false_positives: Unknown
|
||||
references: []
|
||||
tags:
|
||||
|
||||
@@ -6,7 +6,11 @@ author: Dean Luxton
|
||||
status: experimental
|
||||
type: TTP
|
||||
data_source: []
|
||||
description: This analytic detects internal hosts triggering multiple IDS signatures (either more than 25 signatures against a single host, or a single signature across over 25 destinations), which can be indicative of active vulnerability scanning performed within the network.
|
||||
description: This analytic detects internal hosts triggering multiple IDS signatures, which may include either
|
||||
more than 25 signatures against a single host or a single signature across over 25 destination IP addresses.
|
||||
Such patterns can indicate active vulnerability scanning activities within the network. By monitoring
|
||||
IDS logs, this detection helps identify and respond to potential vulnerability scanning attempts,
|
||||
enhancing the network's security posture and preventing potential exploits.
|
||||
search: '| tstats `security_content_summariesonly` values(IDS_Attacks.action) as action
|
||||
values(IDS_Attacks.src_category) as src_category values(IDS_Attacks.dest_category)
|
||||
as dest_category count from datamodel=Intrusion_Detection.IDS_Attacks where IDS_Attacks.src
|
||||
@@ -21,8 +25,10 @@ search: '| tstats `security_content_summariesonly` values(IDS_Attacks.action) as
|
||||
values(dest_category) as dest_category values(severity) as severity values(dest_port)
|
||||
as dest_ports by src gtime | fields - gtime | where destCount>25 OR sigCount>25
|
||||
| `internal_vulnerability_scan_filter`'
|
||||
how_to_implement: CIM mapped IDS/IPS logs are a required to drive this detection.
|
||||
known_false_positives: Vulnerability Scanners and informational / low severity signatures.
|
||||
how_to_implement: For this detection to function effectively, it is essential to ingest IDS/IPS logs that are
|
||||
mapped to the Common Information Model (CIM). These logs provide the necessary security-related telemetry
|
||||
and contextual information needed to accurately identify and analyze potential threats.
|
||||
known_false_positives: Internal vulnerability scanners will trigger this detection.
|
||||
references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
|
||||
Reference in New Issue
Block a user