updating descriptions

This commit is contained in:
dluxtron
2024-07-11 18:06:51 +10:00
parent 0146d62e47
commit 65cdbcbaf8
11 changed files with 138 additions and 82 deletions
@@ -7,7 +7,11 @@ status: production
type: Hunting
data_source:
- Authentication Datamodel
description: This analytic uses the 3-sigma approach to detect a distributed password spray attack. Utilising the authentication datamodel this detection is affective for all CIM mapped authication events.
description: This analytic employs the 3-sigma approach to identify distributed password spray attacks. A
distributed password spray attack is a type of brute force attack where the attacker attempts a few
common passwords against many different accounts, connecting from multiple IP addresses to avoid detection.
By utilizing the Authentication Data Model, this detection is effective for all CIM-mapped authentication
events, providing comprehensive coverage and enhancing security against these attacks.
search: '| tstats `security_content_summariesonly` dc(Authentication.user) AS unique_accounts dc(Authentication.src) as unique_src count(Authentication.user) as total_failures from datamodel=Authentication.Authentication where Authentication.action="failure" by Authentication.action, Authentication.signature_id, sourcetype, _time span=2m
| `drop_dm_object_name("Authentication")`
```fill out time buckets for 0-count events during entire search length```
@@ -7,7 +7,11 @@ status: production
type: TTP
data_source:
- Authentication Datamodel
description: This analytic uses the 3-sigma approach to detect an unusual volume of failed authentication from a single source. Utilising the authentication datamodel this detection is affective for all CIM mapped authication events.
description: This analytic employs the 3-sigma approach to detect an unusual volume of failed authentication attempts
from a single source. A password spray attack is a type of brute force attack where an attacker tries a few
common passwords across many different accounts to avoid detection and account lockouts. By utilizing the
Authentication Data Model, this detection is effective for all CIM-mapped authentication events, providing
comprehensive coverage and enhancing security against these attacks.
search: '| tstats `security_content_summariesonly` dc(Authentication.user) AS unique_accounts values(Authentication.app) as app count(Authentication.user) as total_failures from datamodel=Authentication.Authentication where Authentication.action="failure" by Authentication.src, Authentication.action, Authentication.signature_id, sourcetype, _time span=2m
| `drop_dm_object_name("Authentication")`
```fill out time buckets for 0-count events during entire search length```
@@ -7,7 +7,10 @@ status: production
type: TTP
data_source:
- Windows Event Log Security 4728
description: Detect when a user adds themselfs to an AD Group.
description: This analytic detects instances where a user adds themselves to an Active Directory (AD) group. This activity
is a common indicator of privilege escalation, where a user attempts to gain unauthorized access to higher
privileges or sensitive resources. By monitoring AD logs, this detection identifies such suspicious behavior,
which could be part of a larger attack strategy aimed at compromising critical systems and data.
search: '`wineventlog_security` EventCode IN (4728)
| where user=src_user
| stats min(_time) as _time dc(user) as usercount, values(user) as user values(user_category) as user_category values(src_user_category) as src_user_category values(dvc) as dvc by signature, Group_Name, src_user
@@ -7,7 +7,11 @@ status: production
type: TTP
data_source:
- XmlWinEventLog:Security
description: Increase in group or AD object modifications.
description: This analytic detects an increase in modifications to AD groups or objects.
Frequent changes to AD groups or objects can indicate potential security risks,
such as unauthorized access attempts, impairing defences or establishing persistence.
By monitoring AD logs for unusual modification patterns, this detection helps identify
suspicious behavior that could compromise the integrity and security of the AD environment.
search: >-
`wineventlog_security` EventCode IN (4670,4727,4731,4734,4735,4764)
| bucket span=5m _time
@@ -17,7 +21,7 @@ search: >-
| eval isOutlier=if(objectCount > 10 and (objectCount >= upperBound), 1, 0)
| search isOutlier=1
| `windows_increase_in_group_or_object_modification_activity_filter`
how_to_implement: Run over past 7 days for best results.
how_to_implement: Run this detection looking over a 7 day timeframe for best results.
known_false_positives: Unknown
references: []
tags:
@@ -29,6 +33,7 @@ tags:
message: Spike in Group or Object Modifications performed by $src_user$
mitre_attack_id:
- T1098
- T1562
observable:
- name: src_user
type: User
@@ -7,7 +7,11 @@ status: production
type: TTP
data_source:
- XmlWinEventLog:Security
description: Increase in user account modifications.
description: This analytic detects an increase in modifications to AD user objects.
A large volume of changes to user objects can indicate potential security risks,
such as unauthorized access attempts, impairing defences or establishing persistence.
By monitoring AD logs for unusual modification patterns, this detection helps identify
suspicious behavior that could compromise the integrity and security of the AD environment.
search: >-
`wineventlog_security` EventCode IN (4720,4722,4723,4724,4725,4726,4728,4732,4733,4738,4743,4780)
| bucket span=5m _time
@@ -18,7 +22,7 @@ search: >-
| search isOutlier=1
| stats values(TargetDomainName) as TargetDomainName, values(user) as user, dc(user) as userCount, values(user_category) as user_category, values(src_user_category) as src_user_category, values(dest) as dest, values(dest_category) as dest_category values(signature) as signature by _time, src_user, status
| `windows_increase_in_user_modification_activity_filter`
how_to_implement: Run over past 7 days for best results.
how_to_implement: Run this detection looking over a 7 day timeframe for best results.
known_false_positives: Genuine activity
references: []
tags:
@@ -30,6 +34,7 @@ tags:
message: Spike in User Modification actions performed by $src_user$
mitre_attack_id:
- T1098
- T1562
observable:
- name: src_user
type: User
@@ -1,59 +0,0 @@
name: Windows Network Share Discovery With Net
id: 4dc3951f-b3f8-4f46-b412-76a483f72277
version: 1
date: '2023-04-21'
author: Dean Luxton
status: production
type: TTP
data_source:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1135/net_share/windows-sysmon.log
description: Network share discovery performed on Windows using the Net Command.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.user_category) as user_category values(Processes.user_bunit) as user_bunit FROM datamodel=Endpoint.Processes WHERE ((Processes.process_name="net.exe" OR Processes.orig_process_name="net.exe") AND (Processes.process="*net*view*" OR Processes.process="*net*share*")) BY Processes.user Processes.dest Processes.process_exec Processes.parent_process_exec
Processes.process Processes.parent_process
| `drop_dm_object_name(Processes)`
| regex process="net\s+view|net\s+share"
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_network_share_discovery_with_net_filter`'
how_to_implement: Ensure you are populating the endpoint datamodel.
known_false_positives: Unknown
references:
- https://attack.mitre.org/techniques/T1135/
tags:
analytic_story:
- Active Directory Discovery
- Active Directory Privilege Escalation
- Network Discovery
asset_type: Endpoint
atomic_guid:
- ab39a04f-0c93-4540-9ff2-83f862c385ae
confidence: 100
impact: 20
message: Network share enumeration performed on $dest$ by $user$, executed by parent process $parent_process$
mitre_attack_id:
- T1135
required_fields:
- Processes.process_name
- Processes.user
- Processes.dest
- Processes.process_exec
- Processes.parent_process_exec
- Processes.process
- Processes.parent_process
observable:
- name: dest
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 20
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1135/net_share/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,71 @@
name: Windows Network Share Interaction With Net
id: 4dc3951f-b3f8-4f46-b412-76a483f72277
version: 1
date: '2023-04-21'
author: Dean Luxton
status: production
type: TTP
data_source:
- Sysmon EventID 1
description: This analytic detects network share discovery and collection activities performed on Windows systems using the Net command.
Attackers often use network share discovery to identify accessible shared resources within a network,
which can be a precursor to privilege escalation or data exfiltration. By monitoring Windows Event Logs for
the usage of the Net command to list and interact with network shares, this detection helps identify potential reconnaissance and collection
activities.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.user_category) as user_category values(Processes.user_bunit) as user_bunit FROM datamodel=Endpoint.Processes WHERE (Processes.process_name="net.exe" OR Processes.process_name="net1.exe" OR Processes.orig_process_name="net.exe" OR Processes.orig_process_name="net1net[\s\.ex1]+view|net[\s\.ex1]+share|net[\s\.ex1]+use\s.exe") BY Processes.user Processes.dest Processes.process_exec Processes.parent_process_exec
Processes.process Processes.parent_process
| `drop_dm_object_name(Processes)`
| regex process="net[\s\.ex1]+view|net[\s\.ex1]+share|net[\s\.ex1]+use\s"
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_network_share_interaction_with_net_filter`'
how_to_implement: The detection is based on data originating from either Endpoint Detection and Response (EDR) telemetry or EventCode 4688 with
process command line logging enabled. These sources provide security-related telemetry from the endpoints. To implement this search, you must
ingest logs that contain the process name, parent process, and complete command-line executions. These logs must be mapped to the Splunk Common
Information Model (CIM) to normalize the field names capture the data within the datamodel schema.
known_false_positives: Unknown
references:
- https://attack.mitre.org/techniques/T1135/
tags:
analytic_story:
- Active Directory Discovery
- Active Directory Privilege Escalation
- Network Discovery
asset_type: Endpoint
atomic_guid:
- ab39a04f-0c93-4540-9ff2-83f862c385ae
confidence: 100
impact: 20
message: User $user$ leveraged net.exe on $dest$ to interact with network shares, executed by parent process $parent_process$
mitre_attack_id:
- T1135
- T1039
required_fields:
- Processes.process_name
- Processes.user
- Processes.dest
- Processes.process_exec
- Processes.parent_process_exec
- Processes.process
- Processes.parent_process
observable:
- name: dest
type: Hostname
role:
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 20
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1135/net_share/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -7,18 +7,21 @@ status: production
type: TTP
data_source:
- XmlWinEventLog System EventCode 7045
description: The following analytic utilises a known list of vulnerable Windows drivers
to help defenders find potential persistence or privelege escalation via a vulnerable
driver. This analytic uses native windows system service install events to capture when the vulnerable driver is installed.
A known gap with this lookup is that it does not use the hash or known signer of the vulnerable driver
therefore it is up to the defender to identify version and signing info and confirm
it is a vulnerable driver.
This detection is a winventlog copy of the Sysmon driver loaded detection written by Michael Haag.
description: The following analytic detects the loading of known vulnerable Windows
drivers, which may indicate potential persistence or privilege escalation attempts.
It leverages Windows System service install EventCode 7045 to identify driver loading
events and cross-references them with a list of vulnerable drivers. This activity is
significant as attackers often exploit vulnerable drivers to gain elevated privileges
or maintain persistence on a system. If confirmed malicious, this could allow attackers
to execute arbitrary code with high privileges, leading to further system compromise
and potential data exfiltration. This detection is a Windows Event Log adaptation of
the Sysmon driver loaded detection written by Michael Haag.
search: '`wineventlog_system` EventCode=7045 ServiceType="kernel mode driver" | table _time dest EventCode ImagePath ServiceName ServiceType | lookup loldrivers driver_name AS ImagePath OUTPUT is_driver driver_description | search is_driver = TRUE | `windows_vulnerable_driver_installed_filter`'
how_to_implement: Ensure the Splunk is collecting XmlWinEventLog:System events and the EventCode 7045 is being ingested.
known_false_positives: False positives may be present. Drill down into the driver
known_false_positives: False positives will be present. Drill down into the driver
further by version number and cross reference by signer. Review the reference material
in the lookup.
in the lookup. In addition, modify the query to look within specific paths, which
will remove a lot of "normal" drivers.
references:
- https://loldrivers.io/
- https://github.com/SpikySabra/Kernel-Cactus
@@ -6,7 +6,12 @@ author: Dean Luxton
status: production
type: TTP
data_source: []
description: This analytic detects where an internal host has attempted to communicate with 250 or more destination IP addresses using the same port / protocol.
description: This analytic identifies instances where an internal host has attempted to communicate
with 250 or more destination IP addresses using the same port and protocol. Horizontal
port scans from internal hosts can indicate reconnaissance or scanning activities,
potentially signaling malicious intent or misconfiguration. By monitoring network
traffic logs, this detection helps detect and respond to such behavior promptly,
enhancing network security and preventing potential threats.
search: '| tstats `security_content_summariesonly` values(All_Traffic.action) as action
values(All_Traffic.src_category) as src_category values(All_Traffic.dest_zone) as
dest_zone values(All_Traffic.src_zone) as src_zone count from datamodel=Network_Traffic
@@ -19,7 +24,9 @@ search: '| tstats `security_content_summariesonly` values(All_Traffic.action) as
min(_time) as _time values(action) as action sum(totalDestIPCount) as totalDestIPCount
values(src_category) as src_category values(dest_port) as dest_ports values(dest_zone)
as dest_zone values(src_zone) as src_zone by src_ip gtime | fields - gtime | `internal_horizontal_port_scan_filter`'
how_to_implement: Ensure your network traffic data is populating the Network_Traffic data model.
how_to_implement: To properly run this search, Splunk needs to ingest data from networking telemetry sources such as
firewalls, NetFlow, or host-based networking events. Ensure that the Network_Traffic data model is populated to
enable this search effectively.
known_false_positives: Unknown
references: []
tags:
@@ -6,7 +6,12 @@ author: Dean Luxton
status: production
type: TTP
data_source: []
description: This analytic detects an internal host has attempted to communicate with over 500 ports on a single destination IP. Additional filtering is performed on the number of privileged ports within the request to filter out applications performing port scans over ephemeral port ranges.
description: This analytic detects instances where an internal host attempts to communicate
with over 500 ports on a single destination IP address. It includes filtering
criteria to exclude applications performing scans over ephemeral port ranges,
focusing on potential reconnaissance or scanning activities. Monitoring network
traffic logs allows for timely detection and response to such behavior, enhancing
network security by identifying and mitigating potential threats promptly.
search: '| tstats `security_content_summariesonly` values(All_Traffic.action) as action
values(All_Traffic.src_category) as src_category values(All_Traffic.dest_zone) as
dest_zone values(All_Traffic.src_zone) as src_zone count from datamodel=Network_Traffic
@@ -21,7 +26,9 @@ search: '| tstats `security_content_summariesonly` values(All_Traffic.action) as
dest_ip transport gtime | eval totalDestPortCount=totalDestUdpPortCount+totalDestTcpPortCount,
privilegedDestPortCount=privilegedDestTcpPortCount+privilegedDestUdpPortCount| where
(totalDestPortCount>=500 AND privilegedDestPortCount>=20) | fields - gtime | `internal_vertical_port_scan_filter`'
how_to_implement: Ensure your network traffic data is populating the Network_Traffic data model.
how_to_implement: To properly run this search, Splunk needs to ingest data from networking telemetry sources such as
firewalls, NetFlow, or host-based networking events. Ensure that the Network_Traffic data model is populated to
enable this search effectively.
known_false_positives: Unknown
references: []
tags:
@@ -6,7 +6,11 @@ author: Dean Luxton
status: experimental
type: TTP
data_source: []
description: This analytic detects internal hosts triggering multiple IDS signatures (either more than 25 signatures against a single host, or a single signature across over 25 destinations), which can be indicative of active vulnerability scanning performed within the network.
description: This analytic detects internal hosts triggering multiple IDS signatures, which may include either
more than 25 signatures against a single host or a single signature across over 25 destination IP addresses.
Such patterns can indicate active vulnerability scanning activities within the network. By monitoring
IDS logs, this detection helps identify and respond to potential vulnerability scanning attempts,
enhancing the network's security posture and preventing potential exploits.
search: '| tstats `security_content_summariesonly` values(IDS_Attacks.action) as action
values(IDS_Attacks.src_category) as src_category values(IDS_Attacks.dest_category)
as dest_category count from datamodel=Intrusion_Detection.IDS_Attacks where IDS_Attacks.src
@@ -21,8 +25,10 @@ search: '| tstats `security_content_summariesonly` values(IDS_Attacks.action) as
values(dest_category) as dest_category values(severity) as severity values(dest_port)
as dest_ports by src gtime | fields - gtime | where destCount>25 OR sigCount>25
| `internal_vulnerability_scan_filter`'
how_to_implement: CIM mapped IDS/IPS logs are a required to drive this detection.
known_false_positives: Vulnerability Scanners and informational / low severity signatures.
how_to_implement: For this detection to function effectively, it is essential to ingest IDS/IPS logs that are
mapped to the Common Information Model (CIM). These logs provide the necessary security-related telemetry
and contextual information needed to accurately identify and analyze potential threats.
known_false_positives: Internal vulnerability scanners will trigger this detection.
references: []
tags:
analytic_story: