diff --git a/detections/application/detect_distributed_password_spray_attempts.yml b/detections/application/detect_distributed_password_spray_attempts.yml index 49332f4831..08399b0a9a 100644 --- a/detections/application/detect_distributed_password_spray_attempts.yml +++ b/detections/application/detect_distributed_password_spray_attempts.yml @@ -7,7 +7,11 @@ status: production type: Hunting data_source: - Authentication Datamodel -description: This analytic uses the 3-sigma approach to detect a distributed password spray attack. Utilising the authentication datamodel this detection is affective for all CIM mapped authication events. +description: This analytic employs the 3-sigma approach to identify distributed password spray attacks. A + distributed password spray attack is a type of brute force attack where the attacker attempts a few + common passwords against many different accounts, connecting from multiple IP addresses to avoid detection. + By utilizing the Authentication Data Model, this detection is effective for all CIM-mapped authentication + events, providing comprehensive coverage and enhancing security against these attacks. search: '| tstats `security_content_summariesonly` dc(Authentication.user) AS unique_accounts dc(Authentication.src) as unique_src count(Authentication.user) as total_failures from datamodel=Authentication.Authentication where Authentication.action="failure" by Authentication.action, Authentication.signature_id, sourcetype, _time span=2m | `drop_dm_object_name("Authentication")` ```fill out time buckets for 0-count events during entire search length``` diff --git a/detections/application/detect_password_spray_attempts.yml b/detections/application/detect_password_spray_attempts.yml index b5bf2c435b..c084024e91 100644 --- a/detections/application/detect_password_spray_attempts.yml +++ b/detections/application/detect_password_spray_attempts.yml @@ -7,7 +7,11 @@ status: production type: TTP data_source: - Authentication Datamodel -description: This analytic uses the 3-sigma approach to detect an unusual volume of failed authentication from a single source. Utilising the authentication datamodel this detection is affective for all CIM mapped authication events. +description: This analytic employs the 3-sigma approach to detect an unusual volume of failed authentication attempts + from a single source. A password spray attack is a type of brute force attack where an attacker tries a few + common passwords across many different accounts to avoid detection and account lockouts. By utilizing the + Authentication Data Model, this detection is effective for all CIM-mapped authentication events, providing + comprehensive coverage and enhancing security against these attacks. search: '| tstats `security_content_summariesonly` dc(Authentication.user) AS unique_accounts values(Authentication.app) as app count(Authentication.user) as total_failures from datamodel=Authentication.Authentication where Authentication.action="failure" by Authentication.src, Authentication.action, Authentication.signature_id, sourcetype, _time span=2m | `drop_dm_object_name("Authentication")` ```fill out time buckets for 0-count events during entire search length``` diff --git a/detections/application/windows_ad_add_self_to_group.yml b/detections/application/windows_ad_add_self_to_group.yml index b0caa2160d..d01cf4389e 100644 --- a/detections/application/windows_ad_add_self_to_group.yml +++ b/detections/application/windows_ad_add_self_to_group.yml @@ -7,7 +7,10 @@ status: production type: TTP data_source: - Windows Event Log Security 4728 -description: Detect when a user adds themselfs to an AD Group. +description: This analytic detects instances where a user adds themselves to an Active Directory (AD) group. This activity + is a common indicator of privilege escalation, where a user attempts to gain unauthorized access to higher + privileges or sensitive resources. By monitoring AD logs, this detection identifies such suspicious behavior, + which could be part of a larger attack strategy aimed at compromising critical systems and data. search: '`wineventlog_security` EventCode IN (4728) | where user=src_user | stats min(_time) as _time dc(user) as usercount, values(user) as user values(user_category) as user_category values(src_user_category) as src_user_category values(dvc) as dvc by signature, Group_Name, src_user diff --git a/detections/application/windows_increase_in_group_or_object_modification_activity.yml b/detections/application/windows_increase_in_group_or_object_modification_activity.yml index 1fdbd7f382..185773ebc9 100644 --- a/detections/application/windows_increase_in_group_or_object_modification_activity.yml +++ b/detections/application/windows_increase_in_group_or_object_modification_activity.yml @@ -7,7 +7,11 @@ status: production type: TTP data_source: - XmlWinEventLog:Security -description: Increase in group or AD object modifications. +description: This analytic detects an increase in modifications to AD groups or objects. + Frequent changes to AD groups or objects can indicate potential security risks, + such as unauthorized access attempts, impairing defences or establishing persistence. + By monitoring AD logs for unusual modification patterns, this detection helps identify + suspicious behavior that could compromise the integrity and security of the AD environment. search: >- `wineventlog_security` EventCode IN (4670,4727,4731,4734,4735,4764) | bucket span=5m _time @@ -17,7 +21,7 @@ search: >- | eval isOutlier=if(objectCount > 10 and (objectCount >= upperBound), 1, 0) | search isOutlier=1 | `windows_increase_in_group_or_object_modification_activity_filter` -how_to_implement: Run over past 7 days for best results. +how_to_implement: Run this detection looking over a 7 day timeframe for best results. known_false_positives: Unknown references: [] tags: @@ -29,6 +33,7 @@ tags: message: Spike in Group or Object Modifications performed by $src_user$ mitre_attack_id: - T1098 + - T1562 observable: - name: src_user type: User diff --git a/detections/application/windows_increase_in_user_modification_activity.yml b/detections/application/windows_increase_in_user_modification_activity.yml index cb8e263e59..f7eceacd10 100644 --- a/detections/application/windows_increase_in_user_modification_activity.yml +++ b/detections/application/windows_increase_in_user_modification_activity.yml @@ -7,7 +7,11 @@ status: production type: TTP data_source: - XmlWinEventLog:Security -description: Increase in user account modifications. +description: This analytic detects an increase in modifications to AD user objects. + A large volume of changes to user objects can indicate potential security risks, + such as unauthorized access attempts, impairing defences or establishing persistence. + By monitoring AD logs for unusual modification patterns, this detection helps identify + suspicious behavior that could compromise the integrity and security of the AD environment. search: >- `wineventlog_security` EventCode IN (4720,4722,4723,4724,4725,4726,4728,4732,4733,4738,4743,4780) | bucket span=5m _time @@ -18,7 +22,7 @@ search: >- | search isOutlier=1 | stats values(TargetDomainName) as TargetDomainName, values(user) as user, dc(user) as userCount, values(user_category) as user_category, values(src_user_category) as src_user_category, values(dest) as dest, values(dest_category) as dest_category values(signature) as signature by _time, src_user, status | `windows_increase_in_user_modification_activity_filter` -how_to_implement: Run over past 7 days for best results. +how_to_implement: Run this detection looking over a 7 day timeframe for best results. known_false_positives: Genuine activity references: [] tags: @@ -30,6 +34,7 @@ tags: message: Spike in User Modification actions performed by $src_user$ mitre_attack_id: - T1098 + - T1562 observable: - name: src_user type: User diff --git a/detections/endpoint/windows_network_share_discovery_with_net.yml b/detections/endpoint/windows_network_share_discovery_with_net.yml deleted file mode 100644 index 950f1a390d..0000000000 --- a/detections/endpoint/windows_network_share_discovery_with_net.yml +++ /dev/null @@ -1,59 +0,0 @@ -name: Windows Network Share Discovery With Net -id: 4dc3951f-b3f8-4f46-b412-76a483f72277 -version: 1 -date: '2023-04-21' -author: Dean Luxton -status: production -type: TTP -data_source: -- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1135/net_share/windows-sysmon.log -description: Network share discovery performed on Windows using the Net Command. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.user_category) as user_category values(Processes.user_bunit) as user_bunit FROM datamodel=Endpoint.Processes WHERE ((Processes.process_name="net.exe" OR Processes.orig_process_name="net.exe") AND (Processes.process="*net*view*" OR Processes.process="*net*share*")) BY Processes.user Processes.dest Processes.process_exec Processes.parent_process_exec - Processes.process Processes.parent_process - | `drop_dm_object_name(Processes)` - | regex process="net\s+view|net\s+share" - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `windows_network_share_discovery_with_net_filter`' -how_to_implement: Ensure you are populating the endpoint datamodel. -known_false_positives: Unknown -references: -- https://attack.mitre.org/techniques/T1135/ -tags: - analytic_story: - - Active Directory Discovery - - Active Directory Privilege Escalation - - Network Discovery - asset_type: Endpoint - atomic_guid: - - ab39a04f-0c93-4540-9ff2-83f862c385ae - confidence: 100 - impact: 20 - message: Network share enumeration performed on $dest$ by $user$, executed by parent process $parent_process$ - mitre_attack_id: - - T1135 - required_fields: - - Processes.process_name - - Processes.user - - Processes.dest - - Processes.process_exec - - Processes.parent_process_exec - - Processes.process - - Processes.parent_process - observable: - - name: dest - type: Hostname - role: - - Victim - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - risk_score: 20 - security_domain: endpoint -tests: -- name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1135/net_share/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog \ No newline at end of file diff --git a/detections/endpoint/windows_network_share_interaction_with_net.yml b/detections/endpoint/windows_network_share_interaction_with_net.yml new file mode 100644 index 0000000000..057b77623e --- /dev/null +++ b/detections/endpoint/windows_network_share_interaction_with_net.yml @@ -0,0 +1,71 @@ +name: Windows Network Share Interaction With Net +id: 4dc3951f-b3f8-4f46-b412-76a483f72277 +version: 1 +date: '2023-04-21' +author: Dean Luxton +status: production +type: TTP +data_source: +- Sysmon EventID 1 +description: This analytic detects network share discovery and collection activities performed on Windows systems using the Net command. + Attackers often use network share discovery to identify accessible shared resources within a network, + which can be a precursor to privilege escalation or data exfiltration. By monitoring Windows Event Logs for + the usage of the Net command to list and interact with network shares, this detection helps identify potential reconnaissance and collection + activities. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.user_category) as user_category values(Processes.user_bunit) as user_bunit FROM datamodel=Endpoint.Processes WHERE (Processes.process_name="net.exe" OR Processes.process_name="net1.exe" OR Processes.orig_process_name="net.exe" OR Processes.orig_process_name="net1net[\s\.ex1]+view|net[\s\.ex1]+share|net[\s\.ex1]+use\s.exe") BY Processes.user Processes.dest Processes.process_exec Processes.parent_process_exec + Processes.process Processes.parent_process + | `drop_dm_object_name(Processes)` + | regex process="net[\s\.ex1]+view|net[\s\.ex1]+share|net[\s\.ex1]+use\s" + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_network_share_interaction_with_net_filter`' +how_to_implement: The detection is based on data originating from either Endpoint Detection and Response (EDR) telemetry or EventCode 4688 with + process command line logging enabled. These sources provide security-related telemetry from the endpoints. To implement this search, you must + ingest logs that contain the process name, parent process, and complete command-line executions. These logs must be mapped to the Splunk Common + Information Model (CIM) to normalize the field names capture the data within the datamodel schema. +known_false_positives: Unknown +references: +- https://attack.mitre.org/techniques/T1135/ +tags: + analytic_story: + - Active Directory Discovery + - Active Directory Privilege Escalation + - Network Discovery + asset_type: Endpoint + atomic_guid: + - ab39a04f-0c93-4540-9ff2-83f862c385ae + confidence: 100 + impact: 20 + message: User $user$ leveraged net.exe on $dest$ to interact with network shares, executed by parent process $parent_process$ + mitre_attack_id: + - T1135 + - T1039 + required_fields: + - Processes.process_name + - Processes.user + - Processes.dest + - Processes.process_exec + - Processes.parent_process_exec + - Processes.process + - Processes.parent_process + observable: + - name: dest + type: Hostname + role: + - Victim + - name: user + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + risk_score: 20 + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1135/net_share/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/detections/endpoint/windows_vulnerable_driver_installed.yml b/detections/endpoint/windows_vulnerable_driver_installed.yml index 9c3c497ceb..e0324ffc1a 100644 --- a/detections/endpoint/windows_vulnerable_driver_installed.yml +++ b/detections/endpoint/windows_vulnerable_driver_installed.yml @@ -7,18 +7,21 @@ status: production type: TTP data_source: - XmlWinEventLog System EventCode 7045 -description: The following analytic utilises a known list of vulnerable Windows drivers - to help defenders find potential persistence or privelege escalation via a vulnerable - driver. This analytic uses native windows system service install events to capture when the vulnerable driver is installed. - A known gap with this lookup is that it does not use the hash or known signer of the vulnerable driver - therefore it is up to the defender to identify version and signing info and confirm - it is a vulnerable driver. - This detection is a winventlog copy of the Sysmon driver loaded detection written by Michael Haag. +description: The following analytic detects the loading of known vulnerable Windows + drivers, which may indicate potential persistence or privilege escalation attempts. + It leverages Windows System service install EventCode 7045 to identify driver loading + events and cross-references them with a list of vulnerable drivers. This activity is + significant as attackers often exploit vulnerable drivers to gain elevated privileges + or maintain persistence on a system. If confirmed malicious, this could allow attackers + to execute arbitrary code with high privileges, leading to further system compromise + and potential data exfiltration. This detection is a Windows Event Log adaptation of + the Sysmon driver loaded detection written by Michael Haag. search: '`wineventlog_system` EventCode=7045 ServiceType="kernel mode driver" | table _time dest EventCode ImagePath ServiceName ServiceType | lookup loldrivers driver_name AS ImagePath OUTPUT is_driver driver_description | search is_driver = TRUE | `windows_vulnerable_driver_installed_filter`' how_to_implement: Ensure the Splunk is collecting XmlWinEventLog:System events and the EventCode 7045 is being ingested. -known_false_positives: False positives may be present. Drill down into the driver +known_false_positives: False positives will be present. Drill down into the driver further by version number and cross reference by signer. Review the reference material - in the lookup. + in the lookup. In addition, modify the query to look within specific paths, which + will remove a lot of "normal" drivers. references: - https://loldrivers.io/ - https://github.com/SpikySabra/Kernel-Cactus diff --git a/detections/network/internal_horizontal_port_scan.yml b/detections/network/internal_horizontal_port_scan.yml index 505571fcfd..f2670befd9 100644 --- a/detections/network/internal_horizontal_port_scan.yml +++ b/detections/network/internal_horizontal_port_scan.yml @@ -6,7 +6,12 @@ author: Dean Luxton status: production type: TTP data_source: [] -description: This analytic detects where an internal host has attempted to communicate with 250 or more destination IP addresses using the same port / protocol. +description: This analytic identifies instances where an internal host has attempted to communicate + with 250 or more destination IP addresses using the same port and protocol. Horizontal + port scans from internal hosts can indicate reconnaissance or scanning activities, + potentially signaling malicious intent or misconfiguration. By monitoring network + traffic logs, this detection helps detect and respond to such behavior promptly, + enhancing network security and preventing potential threats. search: '| tstats `security_content_summariesonly` values(All_Traffic.action) as action values(All_Traffic.src_category) as src_category values(All_Traffic.dest_zone) as dest_zone values(All_Traffic.src_zone) as src_zone count from datamodel=Network_Traffic @@ -19,7 +24,9 @@ search: '| tstats `security_content_summariesonly` values(All_Traffic.action) as min(_time) as _time values(action) as action sum(totalDestIPCount) as totalDestIPCount values(src_category) as src_category values(dest_port) as dest_ports values(dest_zone) as dest_zone values(src_zone) as src_zone by src_ip gtime | fields - gtime | `internal_horizontal_port_scan_filter`' -how_to_implement: Ensure your network traffic data is populating the Network_Traffic data model. +how_to_implement: To properly run this search, Splunk needs to ingest data from networking telemetry sources such as + firewalls, NetFlow, or host-based networking events. Ensure that the Network_Traffic data model is populated to + enable this search effectively. known_false_positives: Unknown references: [] tags: diff --git a/detections/network/internal_vertical_port_scan.yml b/detections/network/internal_vertical_port_scan.yml index 95c8c63c30..8a18aac5f3 100644 --- a/detections/network/internal_vertical_port_scan.yml +++ b/detections/network/internal_vertical_port_scan.yml @@ -6,7 +6,12 @@ author: Dean Luxton status: production type: TTP data_source: [] -description: This analytic detects an internal host has attempted to communicate with over 500 ports on a single destination IP. Additional filtering is performed on the number of privileged ports within the request to filter out applications performing port scans over ephemeral port ranges. +description: This analytic detects instances where an internal host attempts to communicate + with over 500 ports on a single destination IP address. It includes filtering + criteria to exclude applications performing scans over ephemeral port ranges, + focusing on potential reconnaissance or scanning activities. Monitoring network + traffic logs allows for timely detection and response to such behavior, enhancing + network security by identifying and mitigating potential threats promptly. search: '| tstats `security_content_summariesonly` values(All_Traffic.action) as action values(All_Traffic.src_category) as src_category values(All_Traffic.dest_zone) as dest_zone values(All_Traffic.src_zone) as src_zone count from datamodel=Network_Traffic @@ -21,7 +26,9 @@ search: '| tstats `security_content_summariesonly` values(All_Traffic.action) as dest_ip transport gtime | eval totalDestPortCount=totalDestUdpPortCount+totalDestTcpPortCount, privilegedDestPortCount=privilegedDestTcpPortCount+privilegedDestUdpPortCount| where (totalDestPortCount>=500 AND privilegedDestPortCount>=20) | fields - gtime | `internal_vertical_port_scan_filter`' -how_to_implement: Ensure your network traffic data is populating the Network_Traffic data model. +how_to_implement: To properly run this search, Splunk needs to ingest data from networking telemetry sources such as + firewalls, NetFlow, or host-based networking events. Ensure that the Network_Traffic data model is populated to + enable this search effectively. known_false_positives: Unknown references: [] tags: diff --git a/detections/network/internal_vulnerability_scan.yml b/detections/network/internal_vulnerability_scan.yml index 2f2dab7164..342cb164d1 100644 --- a/detections/network/internal_vulnerability_scan.yml +++ b/detections/network/internal_vulnerability_scan.yml @@ -6,7 +6,11 @@ author: Dean Luxton status: experimental type: TTP data_source: [] -description: This analytic detects internal hosts triggering multiple IDS signatures (either more than 25 signatures against a single host, or a single signature across over 25 destinations), which can be indicative of active vulnerability scanning performed within the network. +description: This analytic detects internal hosts triggering multiple IDS signatures, which may include either + more than 25 signatures against a single host or a single signature across over 25 destination IP addresses. + Such patterns can indicate active vulnerability scanning activities within the network. By monitoring + IDS logs, this detection helps identify and respond to potential vulnerability scanning attempts, + enhancing the network's security posture and preventing potential exploits. search: '| tstats `security_content_summariesonly` values(IDS_Attacks.action) as action values(IDS_Attacks.src_category) as src_category values(IDS_Attacks.dest_category) as dest_category count from datamodel=Intrusion_Detection.IDS_Attacks where IDS_Attacks.src @@ -21,8 +25,10 @@ search: '| tstats `security_content_summariesonly` values(IDS_Attacks.action) as values(dest_category) as dest_category values(severity) as severity values(dest_port) as dest_ports by src gtime | fields - gtime | where destCount>25 OR sigCount>25 | `internal_vulnerability_scan_filter`' -how_to_implement: CIM mapped IDS/IPS logs are a required to drive this detection. -known_false_positives: Vulnerability Scanners and informational / low severity signatures. +how_to_implement: For this detection to function effectively, it is essential to ingest IDS/IPS logs that are + mapped to the Common Information Model (CIM). These logs provide the necessary security-related telemetry + and contextual information needed to accurately identify and analyze potential threats. +known_false_positives: Internal vulnerability scanners will trigger this detection. references: [] tags: analytic_story: