mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge branch 'data_source_improvements_2' of github.com:splunk/security_content into data_source_improvements_2
This commit is contained in:
@@ -9,7 +9,7 @@ sourcetype: xmlwineventlog
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -9,7 +9,7 @@ sourcetype: ActiveDirectory
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Guid
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Channel
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Channel
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Channel
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Channel
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ComputerName
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Channel
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ComputerName
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ComputerName
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Channel
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Caller_User_Name
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- AccessList
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- AccessList
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -12,7 +12,7 @@ configuration: Enabling Windows event log process command line logging via group
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- Caller_Domain
|
||||
- Caller_User_Name
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Account_Domain
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Account_Domain
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Caller_Domain
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Account_Domain
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Caller_Domain
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Caller_Domain
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Caller_Domain
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Account_Domain
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- AccountExpires
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Caller_Domain
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- AccountExpires
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- AccountExpires
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Channel
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Channel
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Channel
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Channel
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- AppCorrelationID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- AccessList
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActivityID
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- AccessList
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Account_Domain
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Account_Domain
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Account_Domain
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Channel
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- Channel
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- AccountName
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ActionName
|
||||
|
||||
@@ -10,4 +10,4 @@ separator: EventID
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: EventID
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.0
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
- ComputerName
|
||||
|
||||
@@ -1,15 +1,23 @@
|
||||
name: Active Setup Registry Autostart
|
||||
id: f64579c0-203f-11ec-abcc-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects suspicious modifications to the Active Setup registry for persistence and privilege escalation. It leverages data from the Endpoint.Registry data model, focusing on changes to the "StubPath" value within the "SOFTWARE\\Microsoft\\Active Setup\\Installed Components" path. This activity is significant as it is commonly used by malware, adware, and APTs to maintain persistence on compromised machines. If confirmed malicious, this could allow attackers to execute code upon system startup, potentially leading to further system compromise and unauthorized access.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_value_name= "StubPath" Registry.registry_path = "*\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components*") BY _time span=1h Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.dest Registry.user | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `active_setup_registry_autostart_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_value_name= "StubPath" Registry.registry_path = "*\\SOFTWARE\\Microsoft\\Active
|
||||
Setup\\Installed Components*") BY Registry.registry_path Registry.registry_key_name
|
||||
Registry.registry_value_name Registry.registry_value_data Registry.process_guid
|
||||
Registry.dest Registry.user | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`| `active_setup_registry_autostart_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: Active setup installer may add or modify this registry.
|
||||
references:
|
||||
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor%3AWin32%2FPoisonivy.E
|
||||
|
||||
@@ -1,16 +1,25 @@
|
||||
name: Add DefaultUser And Password In Registry
|
||||
id: d4a3eb62-0f1e-11ec-a971-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic detects suspicious registry modifications that implement auto admin logon by adding DefaultUserName and DefaultPassword values. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" registry path. This activity is significant because it is associated with BlackMatter ransomware, which uses this technique to automatically log on to compromised hosts and continue encryption after a safe mode boot. If confirmed malicious, this could allow attackers to maintain persistence and further encrypt the network, leading to significant data loss and operational disruption.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
- Sysmon EventID 14
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*" AND Registry.registry_value_name= DefaultPassword OR Registry.registry_value_name= DefaultUserName) BY _time span=1h Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `add_defaultuser_and_password_in_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*"
|
||||
AND Registry.registry_value_name= DefaultPassword OR Registry.registry_value_name=
|
||||
DefaultUserName) BY Registry.registry_path Registry.registry_key_name
|
||||
Registry.registry_value_name Registry.dest Registry.registry_value_data Registry.process_guid
|
||||
| `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `add_defaultuser_and_password_in_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/
|
||||
|
||||
@@ -1,16 +1,26 @@
|
||||
name: Allow Inbound Traffic By Firewall Rule Registry
|
||||
id: 0a46537c-be02-11eb-92ca-acde48001122
|
||||
version: 7
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 8
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects suspicious modifications to firewall rule registry settings that allow inbound traffic on specific ports with a public profile. It leverages data from the Endpoint.Registry data model, focusing on registry paths and values indicative of such changes. This activity is significant as it may indicate an adversary attempting to grant remote access to a machine by modifying firewall rules. If confirmed malicious, this could enable unauthorized remote access, potentially leading to further exploitation, data exfiltration, or lateral movement within the network.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*" Registry.registry_value_data = "*|Action=Allow|*" Registry.registry_value_data = "*|Dir=In|*" Registry.registry_value_data = "*|LPort=*") BY _time span=1h Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.dest Registry.user | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `allow_inbound_traffic_by_firewall_rule_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: network admin may add/remove/modify public inbound firewall rule that may cause this rule to be triggered.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*"
|
||||
Registry.registry_value_data = "*|Action=Allow|*" Registry.registry_value_data =
|
||||
"*|Dir=In|*" Registry.registry_value_data = "*|LPort=*") BY Registry.registry_path
|
||||
Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid Registry.dest Registry.user | `drop_dm_object_name(Registry)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `allow_inbound_traffic_by_firewall_rule_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: network admin may add/remove/modify public inbound firewall
|
||||
rule that may cause this rule to be triggered.
|
||||
references:
|
||||
- https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps
|
||||
drilldown_searches:
|
||||
|
||||
@@ -1,15 +1,24 @@
|
||||
name: Allow Operation with Consent Admin
|
||||
id: 7de17d7a-c9d8-11eb-a812-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects a registry modification that allows the 'Consent Admin' to perform operations requiring elevation without user consent or credentials. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the 'ConsentPromptBehaviorAdmin' value within the Windows Policies System registry path. This activity is significant as it indicates a potential privilege escalation attempt, which could allow an attacker to execute high-privilege tasks without user approval. If confirmed malicious, this could lead to unauthorized administrative access and control over the compromised machine, posing a severe security risk.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\Microsoft\\Windows\\CurrentVersion\\Policies\\System*" Registry.registry_value_name = ConsentPromptBehaviorAdmin Registry.registry_value_data = "0x00000000") BY _time span=1h Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.dest Registry.user | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `allow_operation_with_consent_admin_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\Microsoft\\Windows\\CurrentVersion\\Policies\\System*"
|
||||
Registry.registry_value_name = ConsentPromptBehaviorAdmin Registry.registry_value_data
|
||||
= "0x00000000") BY Registry.registry_path Registry.registry_key_name
|
||||
Registry.registry_value_name Registry.registry_value_data Registry.process_guid
|
||||
Registry.dest Registry.user | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `allow_operation_with_consent_admin_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-gpsb/341747f5-6b5d-4d30-85fc-fa1cc04038d4
|
||||
|
||||
@@ -1,15 +1,24 @@
|
||||
name: Auto Admin Logon Registry Entry
|
||||
id: 1379d2b8-0f18-11ec-8ca3-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects a suspicious registry modification that enables auto admin logon on a host. It leverages data from the Endpoint.Registry data model, specifically looking for changes to the "AutoAdminLogon" value within the "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon" registry path. This activity is significant because it was observed in BlackMatter ransomware attacks to maintain access after a safe mode reboot, facilitating further encryption. If confirmed malicious, this could allow attackers to automatically log in and continue their operations, potentially leading to widespread network encryption and data loss.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*" AND Registry.registry_value_name=AutoAdminLogon AND Registry.registry_value_data=1) BY _time span=1h Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.dest | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `auto_admin_logon_registry_entry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon*"
|
||||
AND Registry.registry_value_name=AutoAdminLogon AND Registry.registry_value_data=1)
|
||||
BY Registry.registry_path Registry.registry_key_name Registry.registry_value_name
|
||||
Registry.registry_value_data Registry.process_guid Registry.dest | `drop_dm_object_name(Registry)`
|
||||
| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `auto_admin_logon_registry_entry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://news.sophos.com/en-us/2021/08/09/blackmatter-ransomware-emerges-from-the-shadow-of-darkside/
|
||||
|
||||
@@ -1,16 +1,26 @@
|
||||
name: Disable AMSI Through Registry
|
||||
id: 9c27ec42-d338-11eb-9044-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects modifications to the Windows registry that disable the Antimalware Scan Interface (AMSI) by setting the "AmsiEnable" value to "0x00000000". This detection leverages data from the Endpoint.Registry data model, specifically monitoring changes to the registry path "*\\SOFTWARE\\Microsoft\\Windows Script\\Settings\\AmsiEnable". Disabling AMSI is significant as it is a common technique used by ransomware, Remote Access Trojans (RATs), and Advanced Persistent Threats (APTs) to evade detection and impair defenses. If confirmed malicious, this activity could allow attackers to execute payloads with minimal alerts, leading to potential system compromise and data exfiltration.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Script\\Settings\\AmsiEnable" Registry.registry_value_data = "0x00000000") BY _time span=1h Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.dest Registry.user | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_amsi_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: network operator may disable this feature of windows but not so common.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Script\\Settings\\AmsiEnable"
|
||||
Registry.registry_value_data = "0x00000000") BY Registry.registry_path
|
||||
Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid Registry.dest Registry.user | `drop_dm_object_name(Registry)`
|
||||
| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `disable_amsi_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: network operator may disable this feature of windows but not
|
||||
so common.
|
||||
references:
|
||||
- https://blog.f-secure.com/hunting-for-amsi-bypasses/
|
||||
- https://gist.github.com/rxwx/8955e5abf18dc258fd6b43a3a7f4dbf9
|
||||
|
||||
@@ -1,15 +1,24 @@
|
||||
name: Disable Defender AntiVirus Registry
|
||||
id: aa4f695a-3024-11ec-9987-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the modification of Windows Defender registry settings to disable antivirus and antispyware protections. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to registry paths associated with Windows Defender policies. This activity is significant because disabling antivirus protections is a common tactic used by adversaries to evade detection and maintain persistence on compromised systems. If confirmed malicious, this action could allow attackers to execute further malicious activities undetected, leading to potential data breaches, system compromise, and further propagation of malware within the network.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender*" Registry.registry_value_name IN ("DisableAntiSpyware","DisableAntiVirus") Registry.registry_value_data = 0x00000001) BY _time span=1h Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.user Registry.dest | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_defender_antivirus_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender*" Registry.registry_value_name
|
||||
IN ("DisableAntiSpyware","DisableAntiVirus") Registry.registry_value_data = 0x00000001)
|
||||
BY Registry.registry_path Registry.registry_key_name Registry.registry_value_name
|
||||
Registry.registry_value_data Registry.process_guid Registry.user Registry.dest |
|
||||
`drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `disable_defender_antivirus_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin or user may choose to disable windows defender product
|
||||
references:
|
||||
- https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
|
||||
|
||||
@@ -1,15 +1,31 @@
|
||||
name: Disable Defender BlockAtFirstSeen Feature
|
||||
id: 2dd719ac-3021-11ec-97b4-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
description: The following analytic detects the modification of the Windows registry to disable the Windows Defender BlockAtFirstSeen feature. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the registry path associated with Windows Defender SpyNet and the DisableBlockAtFirstSeen value. This activity is significant because disabling this feature can allow malicious files to bypass initial detection by Windows Defender, increasing the risk of malware infection. If confirmed malicious, this action could enable attackers to execute malicious code undetected, leading to potential system compromise and data breaches.
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = DisableBlockAtFirstSeen Registry.registry_value_data = 0x00000001) BY _time span=1h Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.user Registry.dest | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_defender_blockatfirstseen_feature_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
description: The following analytic detects the modification of the Windows registry
|
||||
to disable the Windows Defender BlockAtFirstSeen feature. It leverages data from
|
||||
the Endpoint.Registry data model, specifically monitoring changes to the registry
|
||||
path associated with Windows Defender SpyNet and the DisableBlockAtFirstSeen value.
|
||||
This activity is significant because disabling this feature can allow malicious
|
||||
files to bypass initial detection by Windows Defender, increasing the risk of malware
|
||||
infection. If confirmed malicious, this action could enable attackers to execute
|
||||
malicious code undetected, leading to potential system compromise and data breaches.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name
|
||||
= DisableBlockAtFirstSeen Registry.registry_value_data = 0x00000001) BY
|
||||
Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid Registry.user Registry.dest | `drop_dm_object_name(Registry)`
|
||||
| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `disable_defender_blockatfirstseen_feature_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin or user may choose to disable windows defender product
|
||||
references:
|
||||
- https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
name: Disable Defender Enhanced Notification
|
||||
id: dc65678c-301f-11ec-8e30-acde48001122
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the modification of the registry to disable Windows Defender's Enhanced Notification feature. It leverages data from Endpoint Detection and Response (EDR) agents, specifically monitoring changes to the registry path associated with Windows Defender reporting. This activity is significant because disabling Enhanced Notifications can prevent users and administrators from receiving critical security alerts, potentially allowing malicious activities to go unnoticed. If confirmed malicious, this action could enable an attacker to bypass detection mechanisms, maintain persistence, and escalate their activities without triggering alerts.
|
||||
|
||||
@@ -1,15 +1,24 @@
|
||||
name: Disable Defender MpEngine Registry
|
||||
id: cc391750-3024-11ec-955a-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-10-04'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the modification of the Windows Defender MpEngine registry value, specifically setting MpEnablePus to 0x00000000. This detection leverages endpoint registry logs, focusing on changes within the path "*\\Policies\\Microsoft\\Windows Defender\\MpEngine*". This activity is significant as it indicates an attempt to disable key Windows Defender features, potentially allowing malware to evade detection. If confirmed malicious, this could lead to undetected malware execution, persistence, and further system compromise. Immediate investigation and endpoint isolation are recommended.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender\\MpEngine*" Registry.registry_value_name = MpEnablePus Registry.registry_value_data = 0x00000000) BY _time span=1h Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.user Registry.dest | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_defender_mpengine_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender\\MpEngine*"
|
||||
Registry.registry_value_name = MpEnablePus Registry.registry_value_data = 0x00000000)
|
||||
BY Registry.registry_path Registry.registry_key_name Registry.registry_value_name
|
||||
Registry.registry_value_data Registry.process_guid Registry.user Registry.dest |
|
||||
`drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `disable_defender_mpengine_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin or user may choose to disable windows defender product
|
||||
references:
|
||||
- https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
|
||||
|
||||
@@ -1,15 +1,24 @@
|
||||
name: Disable Defender Spynet Reporting
|
||||
id: 898debf4-3021-11ec-ba7c-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the modification of the registry to disable Windows Defender SpyNet reporting. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the registry path associated with Windows Defender SpyNet settings. This activity is significant because disabling SpyNet reporting can prevent Windows Defender from sending telemetry data, potentially allowing malicious activities to go undetected. If confirmed malicious, this action could enable an attacker to evade detection, maintain persistence, and carry out further attacks without being flagged by Windows Defender.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = SpynetReporting Registry.registry_value_data = 0x00000000) BY _time span=1h Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.user Registry.dest | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_defender_spynet_reporting_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name
|
||||
= SpynetReporting Registry.registry_value_data = 0x00000000) BY Registry.registry_path
|
||||
Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid Registry.user Registry.dest | `drop_dm_object_name(Registry)`
|
||||
| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `disable_defender_spynet_reporting_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin or user may choose to disable windows defender product
|
||||
references:
|
||||
- https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
|
||||
|
||||
@@ -1,15 +1,24 @@
|
||||
name: Disable Defender Submit Samples Consent Feature
|
||||
id: 73922ff8-3022-11ec-bf5e-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk,Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the modification of the Windows registry to disable the Windows Defender Submit Samples Consent feature. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the registry path associated with Windows Defender SpyNet and the SubmitSamplesConsent value set to 0x00000000. This activity is significant as it indicates an attempt to bypass or evade detection by preventing Windows Defender from submitting samples for further analysis. If confirmed malicious, this could allow an attacker to execute malicious code without being detected by Windows Defender, leading to potential system compromise.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name = SubmitSamplesConsent Registry.registry_value_data = 0x00000000) BY _time span=1h Registry.user Registry.dest Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_defender_submit_samples_consent_feature_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path = "*\\Microsoft\\Windows Defender\\SpyNet*" Registry.registry_value_name
|
||||
= SubmitSamplesConsent Registry.registry_value_data = 0x00000000) BY
|
||||
Registry.user Registry.dest Registry.registry_path Registry.registry_key_name Registry.registry_value_name
|
||||
Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`
|
||||
| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `disable_defender_submit_samples_consent_feature_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin or user may choose to disable windows defender product
|
||||
references:
|
||||
- https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
|
||||
|
||||
@@ -1,16 +1,25 @@
|
||||
name: Disable ETW Through Registry
|
||||
id: f0eacfa4-d33f-11eb-8f9d-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects modifications to the registry that disable the Event Tracing for Windows (ETW) feature. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the registry path "*\\SOFTWARE\\Microsoft\\.NETFramework\\ETWEnabled" with a value set to "0x00000000". This activity is significant because disabling ETW can allow attackers to evade detection mechanisms, making it harder for security tools to monitor malicious activities. If confirmed malicious, this could enable attackers to execute payloads with minimal alerts, impairing defenses and potentially leading to further compromise of the system.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\.NETFramework\\ETWEnabled" Registry.registry_value_data = "0x00000000") BY _time span=1h Registry.dest Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_etw_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: network operator may disable this feature of windows but not so common.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\.NETFramework\\ETWEnabled"
|
||||
Registry.registry_value_data = "0x00000000") BY Registry.dest Registry.registry_path
|
||||
Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_etw_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: network operator may disable this feature of windows but not
|
||||
so common.
|
||||
references:
|
||||
- https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/
|
||||
drilldown_searches:
|
||||
|
||||
@@ -1,15 +1,23 @@
|
||||
name: Disable Registry Tool
|
||||
id: cd2cf33c-9201-11eb-a10a-acde48001122
|
||||
version: 7
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 8
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects modifications to the Windows registry aimed at disabling the Registry Editor (regedit). It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the registry path "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableRegistryTools" with a value of "0x00000001". This activity is significant because malware, such as RATs or trojans, often disable registry tools to prevent the removal of their entries, aiding in persistence and defense evasion. If confirmed malicious, this could hinder incident response efforts and allow the attacker to maintain control over the compromised system.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableRegistryTools" Registry.registry_value_data = "0x00000001") BY _time span=1h Registry.user Registry.dest Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_registry_tool_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableRegistryTools"
|
||||
Registry.registry_value_data = "0x00000001") BY Registry.user Registry.dest
|
||||
Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)`| where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_registry_tool_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin may disable this application for non technical user.
|
||||
references:
|
||||
- https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry
|
||||
|
||||
@@ -1,15 +1,23 @@
|
||||
name: Disable Security Logs Using MiniNt Registry
|
||||
id: 39ebdc68-25b9-11ec-aec7-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects a suspicious registry modification aimed at disabling security audit logs by adding a specific registry entry. It leverages data from the Endpoint.Registry data model, focusing on changes to the "Control\\MiniNt" registry path. This activity is significant because it can prevent Windows from logging any events to the Security Log, effectively blinding security monitoring efforts. If confirmed malicious, this technique could allow an attacker to operate undetected, making it difficult to trace their actions and compromising the integrity of security audits.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path="*\\Control\\MiniNt\\*") BY _time span=1h Registry.user Registry.dest Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_security_logs_using_minint_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path="*\\Control\\MiniNt\\*") BY Registry.user
|
||||
Registry.dest Registry.registry_path Registry.registry_key_name Registry.registry_value_name
|
||||
Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`
|
||||
| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `disable_security_logs_using_minint_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: Unknown.
|
||||
references:
|
||||
- https://twitter.com/0gtweet/status/1182516740955226112
|
||||
|
||||
@@ -1,15 +1,25 @@
|
||||
name: Disable Show Hidden Files
|
||||
id: 6f3ccfa2-91fe-11eb-8f9b-acde48001122
|
||||
version: 7
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 8
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic detects modifications to the Windows registry that disable the display of hidden files. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to registry paths associated with hidden file settings. This activity is significant because malware, such as worms and trojan spyware, often use hidden files to evade detection. If confirmed malicious, this behavior could allow an attacker to conceal malicious files on the system, making it harder for security tools and analysts to identify and remove the threat.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden" OR (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt" Registry.registry_value_data = "0x00000001") OR (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden" Registry.registry_value_data = "0x00000000" )) BY _time span=1h Registry.user Registry.dest Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_show_hidden_files_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden"
|
||||
OR (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt"
|
||||
Registry.registry_value_data = "0x00000001") OR (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden"
|
||||
Registry.registry_value_data = "0x00000000" )) BY Registry.user Registry.dest
|
||||
Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_show_hidden_files_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/W32~Tiotua-P/detailed-analysis
|
||||
|
||||
@@ -1,15 +1,23 @@
|
||||
name: Disable UAC Remote Restriction
|
||||
id: 9928b732-210e-11ec-b65e-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the modification of the registry to disable UAC remote restriction by setting the "LocalAccountTokenFilterPolicy" value to "0x00000001". It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the registry path "*\\CurrentVersion\\Policies\\System*". This activity is significant because disabling UAC remote restriction can allow an attacker to bypass User Account Control (UAC) protections, potentially leading to privilege escalation. If confirmed malicious, this could enable an attacker to execute unauthorized actions with elevated privileges, compromising the security of the affected system.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path="*\\CurrentVersion\\Policies\\System*" Registry.registry_value_name="LocalAccountTokenFilterPolicy" Registry.registry_value_data="0x00000001" ) BY _time span=1h Registry.user Registry.dest Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_uac_remote_restriction_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path="*\\CurrentVersion\\Policies\\System*" Registry.registry_value_name="LocalAccountTokenFilterPolicy"
|
||||
Registry.registry_value_data="0x00000001" ) BY Registry.user Registry.dest
|
||||
Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)`| where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_uac_remote_restriction_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin may set this policy for non-critical machine.
|
||||
references:
|
||||
- https://docs.microsoft.com/en-us/troubleshoot/windows-server/windows-security/user-account-control-and-remote-restriction
|
||||
|
||||
@@ -1,15 +1,24 @@
|
||||
name: Disable Windows App Hotkeys
|
||||
id: 1490f224-ad8b-11eb-8c4f-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunkk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects a suspicious registry modification aimed at disabling Windows hotkeys for native applications. It leverages data from the Endpoint.Registry data model, focusing on specific registry paths and values indicative of this behavior. This activity is significant as it can impair an analyst's ability to use essential tools like Task Manager and Command Prompt, hindering incident response efforts. If confirmed malicious, this technique can allow an attacker to maintain persistence and evade detection, complicating the remediation process.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path="*\\Windows NT\\CurrentVersion\\Image File Execution Options\\*" AND Registry.registry_value_data= "HotKey Disabled" AND Registry.registry_value_name = "Debugger") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_windows_app_hotkeys_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path="*\\Windows NT\\CurrentVersion\\Image File Execution
|
||||
Options\\*" AND Registry.registry_value_data= "HotKey Disabled" AND Registry.registry_value_name
|
||||
= "Debugger") BY Registry.dest Registry.user Registry.registry_path
|
||||
Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_windows_app_hotkeys_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
|
||||
|
||||
@@ -1,15 +1,31 @@
|
||||
name: Disable Windows Behavior Monitoring
|
||||
id: 79439cae-9200-11eb-a4d3-acde48001122
|
||||
version: 8
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 9
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies modifications in the registry to disable Windows Defender's real-time behavior monitoring. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to registry paths associated with Windows Defender settings. This activity is significant because disabling real-time protection is a common tactic used by malware such as RATs, bots, or Trojans to evade detection. If confirmed malicious, this action could allow an attacker to execute code, escalate privileges, or persist in the environment without being detected by antivirus software.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableRealtimeMonitoring" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIntrusionPreventionSystem" OR Registry.registry_path= "*\\Real-Time Protection\\DisableIOAVProtection" OR Registry.registry_path= "*\\Real-Time Protection\\DisableScriptScanning" AND Registry.registry_value_data = "0x00000001") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_windows_behavior_monitoring_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time
|
||||
Protection\\DisableBehaviorMonitoring" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows
|
||||
Defender\\Real-Time Protection\\DisableOnAccessProtection" OR Registry.registry_path=
|
||||
"*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable"
|
||||
OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time
|
||||
Protection\\DisableRealtimeMonitoring" OR Registry.registry_path= "*\\Real-Time
|
||||
Protection\\DisableIntrusionPreventionSystem" OR Registry.registry_path= "*\\Real-Time
|
||||
Protection\\DisableIOAVProtection" OR Registry.registry_path= "*\\Real-Time Protection\\DisableScriptScanning"
|
||||
AND Registry.registry_value_data = "0x00000001") BY Registry.dest
|
||||
Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name
|
||||
Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`
|
||||
| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `disable_windows_behavior_monitoring_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin or user may choose to disable this windows features.
|
||||
references:
|
||||
- https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html
|
||||
|
||||
@@ -1,15 +1,24 @@
|
||||
name: Disable Windows SmartScreen Protection
|
||||
id: 664f0fd0-91ff-11eb-a56f-acde48001122
|
||||
version: 7
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 8
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects modifications to the Windows registry that disable SmartScreen protection. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to registry paths associated with SmartScreen settings. This activity is significant because SmartScreen provides an early warning system against phishing and malware. Disabling it can indicate malicious intent, often seen in Remote Access Trojans (RATs) to evade detection while downloading additional payloads. If confirmed malicious, this action could allow attackers to bypass security measures, increasing the risk of successful phishing attacks and malware infections.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE Registry.registry_path IN ("*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SmartScreenEnabled", "*\\Microsoft\\Windows\\System\\EnableSmartScreen") Registry.registry_value_data IN ("Off", "0") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disable_windows_smartscreen_protection_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE Registry.registry_path IN ("*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SmartScreenEnabled",
|
||||
"*\\Microsoft\\Windows\\System\\EnableSmartScreen") Registry.registry_value_data IN
|
||||
("Off", "0") BY Registry.dest Registry.user Registry.registry_path
|
||||
Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `disable_windows_smartscreen_protection_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin or user may choose to disable this windows features.
|
||||
references:
|
||||
- https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html
|
||||
|
||||
@@ -1,15 +1,23 @@
|
||||
name: Disabling CMD Application
|
||||
id: ff86077c-9212-11eb-a1e6-acde48001122
|
||||
version: 7
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 8
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects modifications to the registry that disable the CMD prompt application. It leverages data from the Endpoint.Registry data model, specifically looking for changes to the "DisableCMD" registry value. This activity is significant because disabling CMD can hinder an analyst's ability to investigate and remediate threats, a tactic often used by malware such as RATs, Trojans, or Worms. If confirmed malicious, this could prevent security teams from using CMD for directory and file traversal, complicating incident response and allowing the attacker to maintain persistence.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\DisableCMD" Registry.registry_value_data = "0x00000001") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_cmd_application_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\DisableCMD"
|
||||
Registry.registry_value_data = "0x00000001") BY Registry.dest Registry.user
|
||||
Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_cmd_application_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin may disable this application for non technical user.
|
||||
references:
|
||||
- https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry
|
||||
|
||||
@@ -1,15 +1,23 @@
|
||||
name: Disabling ControlPanel
|
||||
id: 6ae0148e-9215-11eb-a94a-acde48001122
|
||||
version: 7
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 8
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects registry modifications that disable the Control Panel on Windows systems. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the registry path "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel" with a value of "0x00000001". This activity is significant as it is commonly used by malware to prevent users from accessing the Control Panel, thereby hindering the removal of malicious artifacts and persistence mechanisms. If confirmed malicious, this could allow attackers to maintain control over the infected machine and prevent remediation efforts.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel" Registry.registry_value_data = "0x00000001") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_controlpanel_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel"
|
||||
Registry.registry_value_data = "0x00000001") BY Registry.dest Registry.user
|
||||
Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)`| where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_controlpanel_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin may disable this application for non technical user.
|
||||
references:
|
||||
- https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry
|
||||
|
||||
@@ -1,15 +1,25 @@
|
||||
name: Disabling Defender Services
|
||||
id: 911eacdc-317f-11ec-ad30-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the disabling of Windows Defender services by monitoring registry modifications. It leverages registry event data to identify changes to specific registry paths associated with Defender services, where the 'Start' value is set to '0x00000004'. This activity is significant because disabling Defender services can indicate an attempt by an adversary to evade detection and maintain persistence on the endpoint. If confirmed malicious, this action could allow attackers to execute further malicious activities undetected, leading to potential data breaches or system compromise.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path = "*\\System\\CurrentControlSet\\Services\\*" AND (Registry.registry_path IN("*WdBoot*", "*WdFilter*", "*WdNisDrv*", "*WdNisSvc*","*WinDefend*", "*SecurityHealthService*")) AND Registry.registry_value_name = Start Registry.registry_value_data = 0x00000004) BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_defender_services_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path = "*\\System\\CurrentControlSet\\Services\\*" AND
|
||||
(Registry.registry_path IN("*WdBoot*", "*WdFilter*", "*WdNisDrv*", "*WdNisSvc*","*WinDefend*",
|
||||
"*SecurityHealthService*")) AND Registry.registry_value_name = Start Registry.registry_value_data
|
||||
= 0x00000004) BY Registry.dest Registry.user Registry.registry_path
|
||||
Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)`| where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_defender_services_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin or user may choose to disable windows defender product
|
||||
references:
|
||||
- https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
|
||||
|
||||
@@ -1,15 +1,23 @@
|
||||
name: Disabling FolderOptions Windows Feature
|
||||
id: 83776de4-921a-11eb-868a-acde48001122
|
||||
version: 7
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 8
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the modification of the Windows registry to disable the Folder Options feature, which prevents users from showing hidden files and file extensions. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the registry path "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFolderOptions" with a value of "0x00000001". This activity is significant as it is commonly used by malware to conceal malicious files and deceive users with fake file extensions. If confirmed malicious, this could allow an attacker to hide their presence and malicious files, making detection and remediation more difficult.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFolderOptions" Registry.registry_value_data = "0x00000001") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_folderoptions_windows_feature_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFolderOptions"
|
||||
Registry.registry_value_data = "0x00000001") BY Registry.dest Registry.user
|
||||
Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)`| where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_folderoptions_windows_feature_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin may disable this application for non technical user.
|
||||
references:
|
||||
- https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry
|
||||
|
||||
@@ -1,15 +1,23 @@
|
||||
name: Disabling NoRun Windows App
|
||||
id: de81bc46-9213-11eb-adc9-acde48001122
|
||||
version: 7
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 8
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the modification of the Windows registry to disable the Run application in the Start menu. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the registry path "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun" with a value of "0x00000001". This activity is significant because the Run application is a useful shortcut for executing known applications and scripts. If confirmed malicious, this action could hinder system cleaning efforts and make it more difficult to run essential tools, thereby aiding malware persistence.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun" Registry.registry_value_data = "0x00000001") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_norun_windows_app_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun"
|
||||
Registry.registry_value_data = "0x00000001") BY Registry.dest Registry.user
|
||||
Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)`| where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_norun_windows_app_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin may disable this application for non technical user.
|
||||
references:
|
||||
- https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry
|
||||
|
||||
@@ -1,15 +1,26 @@
|
||||
name: Disabling SystemRestore In Registry
|
||||
id: f4f837e2-91fb-11eb-8bf6-acde48001122
|
||||
version: 7
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 8
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the modification of registry keys to disable System Restore on a machine. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to registry paths associated with System Restore settings. This activity is significant because disabling System Restore can hinder recovery efforts and is a tactic often used by Remote Access Trojans (RATs) to maintain persistence on an infected system. If confirmed malicious, this action could prevent system recovery, allowing the attacker to sustain their foothold and potentially cause further damage or data loss.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableConfig" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows NT\\SystemRestore\\DisableSR" OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows NT\\SystemRestore\\DisableConfig" Registry.registry_value_data = "0x00000001") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_systemrestore_in_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR"
|
||||
OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableConfig"
|
||||
OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows NT\\SystemRestore\\DisableSR"
|
||||
OR Registry.registry_path= "*\\SOFTWARE\\Policies\\Microsoft\\Windows NT\\SystemRestore\\DisableConfig"
|
||||
Registry.registry_value_data = "0x00000001") BY Registry.dest Registry.user
|
||||
Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)`| where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_systemrestore_in_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: in some cases admin can disable systemrestore on a machine.
|
||||
references:
|
||||
- https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html
|
||||
|
||||
@@ -1,15 +1,23 @@
|
||||
name: Disabling Task Manager
|
||||
id: dac279bc-9202-11eb-b7fb-acde48001122
|
||||
version: 7
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 8
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies modifications to the Windows registry that disable Task Manager. It leverages data from the Endpoint.Registry data model, specifically looking for changes to the registry path "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableTaskMgr" with a value of "0x00000001". This activity is significant as it is commonly associated with malware such as RATs, Trojans, and worms, which disable Task Manager to prevent users from terminating malicious processes. If confirmed malicious, this could allow attackers to maintain persistence and control over the infected system.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableTaskMgr" Registry.registry_value_data = "0x00000001") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_task_manager_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableTaskMgr"
|
||||
Registry.registry_value_data = "0x00000001") BY Registry.dest Registry.user
|
||||
Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_task_manager_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin may disable this application for non technical user.
|
||||
references:
|
||||
- https://any.run/report/ea4ea08407d4ee72e009103a3b77e5a09412b722fdef67315ea63f22011152af/a866d7b1-c236-4f26-a391-5ae32213dfc4#registry
|
||||
|
||||
@@ -1,15 +1,23 @@
|
||||
name: Enable RDP In Other Port Number
|
||||
id: 99495452-b899-11eb-96dc-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects modifications to the registry that enable RDP on a machine using a non-default port number. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the registry path "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" and the "PortNumber" value. This activity is significant as attackers often modify RDP settings to facilitate lateral movement and maintain remote access to compromised systems. If confirmed malicious, this could allow attackers to bypass network defenses, gain persistent access, and potentially control the compromised machine.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp*" Registry.registry_value_name = "PortNumber") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `enable_rdp_in_other_port_number_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal
|
||||
Server\\WinStations\\RDP-Tcp*" Registry.registry_value_name = "PortNumber") BY Registry.dest Registry.user Registry.registry_path Registry.registry_key_name
|
||||
Registry.registry_value_name Registry.registry_value_data Registry.process_guid
|
||||
| `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `enable_rdp_in_other_port_number_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://www.mvps.net/docs/how-to-secure-remote-desktop-rdp/
|
||||
|
||||
@@ -1,15 +1,24 @@
|
||||
name: Enable WDigest UseLogonCredential Registry
|
||||
id: 0c7d8ffe-25b1-11ec-9f39-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects a suspicious registry modification that enables the plain text credential feature in Windows by setting the "UseLogonCredential" value to 1 in the WDigest registry path. This detection leverages data from the Endpoint.Registry data model, focusing on specific registry paths and values. This activity is significant because it is commonly used by malware and tools like Mimikatz to dump plain text credentials, indicating a potential credential dumping attempt. If confirmed malicious, this could allow an attacker to obtain sensitive credentials, leading to further compromise and lateral movement within the network.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\\*" Registry.registry_value_name = "UseLogonCredential" Registry.registry_value_data=0x00000001) BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `enable_wdigest_uselogoncredential_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\\*"
|
||||
Registry.registry_value_name = "UseLogonCredential" Registry.registry_value_data=0x00000001)
|
||||
BY Registry.dest Registry.user Registry.registry_path Registry.registry_key_name
|
||||
Registry.registry_value_name Registry.registry_value_data Registry.process_guid
|
||||
| `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `enable_wdigest_uselogoncredential_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://www.csoonline.com/article/3438824/how-to-detect-and-halt-credential-theft-via-windows-wdigest.html
|
||||
|
||||
@@ -1,15 +1,24 @@
|
||||
name: ETW Registry Disabled
|
||||
id: 8ed523ac-276b-11ec-ac39-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects a registry modification that disables the Event Tracing for Windows (ETW) feature. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the ETWEnabled registry value under the .NETFramework path. This activity is significant because disabling ETW can allow attackers to evade Endpoint Detection and Response (EDR) tools and hide their execution from audit logs. If confirmed malicious, this action could enable attackers to operate undetected, potentially leading to further compromise and persistent access within the environment.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path="*\\SOFTWARE\\Microsoft\\.NETFramework*" Registry.registry_value_name = ETWEnabled Registry.registry_value_data=0x00000000) BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `etw_registry_disabled_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path="*\\SOFTWARE\\Microsoft\\.NETFramework*" Registry.registry_value_name
|
||||
= ETWEnabled Registry.registry_value_data=0x00000000) BY Registry.dest
|
||||
Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name
|
||||
Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`
|
||||
| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `etw_registry_disabled_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://gist.github.com/Cyb3rWard0g/a4a115fd3ab518a0e593525a379adee3
|
||||
|
||||
@@ -1,15 +1,24 @@
|
||||
name: Hide User Account From Sign-In Screen
|
||||
id: 834ba832-ad89-11eb-937d-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects a suspicious registry modification that hides a user account from the Windows Login screen. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the registry path "*\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist*" with a value of "0x00000000". This activity is significant as it may indicate an adversary attempting to create a hidden admin account to avoid detection and maintain persistence on the compromised machine. If confirmed malicious, this could allow the attacker to maintain undetected access and control over the system, posing a severe security risk.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path="*\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist*" AND Registry.registry_value_data = "0x00000000") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `hide_user_account_from_sign_in_screen_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path="*\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist*"
|
||||
AND Registry.registry_value_data = "0x00000000") BY Registry.dest
|
||||
Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name
|
||||
Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`
|
||||
| where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `hide_user_account_from_sign_in_screen_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: Unknown. Filter as needed.
|
||||
references:
|
||||
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
|
||||
|
||||
@@ -1,16 +1,25 @@
|
||||
name: Monitor Registry Keys for Print Monitors
|
||||
id: f5f6af30-7ba7-4295-bfe9-07de87c01bbc
|
||||
version: 7
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Bhavin Patel, Teoderick Contreras, Splunk
|
||||
version: 8
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick, Bhavin Patel
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects modifications to the registry key `HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors`. It leverages data from the Endpoint.Registry data model, focusing on events where the registry path is modified. This activity is significant because attackers can exploit this registry key to load arbitrary .dll files, which will execute with elevated SYSTEM permissions and persist after a reboot. If confirmed malicious, this could allow attackers to maintain persistence, execute code with high privileges, and potentially compromise the entire system.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.action=modified AND Registry.registry_path="*CurrentControlSet\\Control\\Print\\Monitors*") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `monitor_registry_keys_for_print_monitors_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: You will encounter noise from legitimate print-monitor registry entries.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.action=modified AND Registry.registry_path="*CurrentControlSet\\Control\\Print\\Monitors*")
|
||||
BY Registry.dest Registry.user Registry.registry_path Registry.registry_key_name
|
||||
Registry.registry_value_name Registry.registry_value_data Registry.process_guid
|
||||
| `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `monitor_registry_keys_for_print_monitors_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: You will encounter noise from legitimate print-monitor registry
|
||||
entries.
|
||||
references: []
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$dest$"
|
||||
|
||||
@@ -1,16 +1,25 @@
|
||||
name: Registry Keys for Creating SHIM Databases
|
||||
id: f5f6af30-7aa7-4295-bfe9-07fe87c01bbb
|
||||
version: 8
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Bhavin Patel, Patrick Bareiss, Teoderick Contreras, Splunk
|
||||
version: 9
|
||||
date: '2024-11-14'
|
||||
author: Patrick Bareiss, Teoderick Contreras, Splunk, Steven Dick, Bhavin Patel
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects registry activity related to the creation of application compatibility shims. It leverages data from the Endpoint.Registry data model, specifically monitoring registry paths associated with AppCompatFlags. This activity is significant because attackers can use shims to bypass security controls, achieve persistence, or escalate privileges. If confirmed malicious, this could allow an attacker to maintain long-term access, execute arbitrary code, or manipulate application behavior, posing a severe risk to the integrity and security of the affected systems.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path=*CurrentVersion\\AppCompatFlags\\Custom* OR Registry.registry_path=*CurrentVersion\\AppCompatFlags\\InstalledSDB*) BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `registry_keys_for_creating_shim_databases_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: There are many legitimate applications that leverage shim databases for compatibility purposes for legacy applications
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path=*CurrentVersion\\AppCompatFlags\\Custom* OR Registry.registry_path=*CurrentVersion\\AppCompatFlags\\InstalledSDB*)
|
||||
BY Registry.dest Registry.user Registry.registry_path Registry.registry_key_name
|
||||
Registry.registry_value_name Registry.registry_value_data Registry.process_guid
|
||||
| `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `registry_keys_for_creating_shim_databases_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: There are many legitimate applications that leverage shim databases
|
||||
for compatibility purposes for legacy applications
|
||||
references: []
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$dest$" and "$user$"
|
||||
|
||||
@@ -1,16 +1,26 @@
|
||||
name: Registry Keys Used For Privilege Escalation
|
||||
id: c9f4b923-f8af-4155-b697-1354f5bcbc5e
|
||||
version: 9
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, David Dorsey, Teoderick Contreras, Splunk
|
||||
version: 10
|
||||
date: '2024-11-14'
|
||||
author: David Dorsey, Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects modifications to registry keys under "Image File Execution Options" that can be used for privilege escalation. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to registry paths and values like GlobalFlag and Debugger. This activity is significant because attackers can use these modifications to intercept executable calls and attach malicious binaries to legitimate system binaries. If confirmed malicious, this could allow attackers to execute arbitrary code with elevated privileges, leading to potential system compromise and persistent access.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE ((Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*") AND (Registry.registry_value_name=GlobalFlag OR Registry.registry_value_name=Debugger)) BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `registry_keys_used_for_privilege_escalation_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: There are many legitimate applications that must execute upon system startup and will use these registry keys to accomplish that task.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE ((Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File
|
||||
Execution Options*") AND (Registry.registry_value_name=GlobalFlag OR Registry.registry_value_name=Debugger))
|
||||
BY Registry.dest Registry.user Registry.registry_path Registry.registry_key_name
|
||||
Registry.registry_value_name Registry.registry_value_data Registry.process_guid
|
||||
| `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `registry_keys_used_for_privilege_escalation_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: There are many legitimate applications that must execute upon
|
||||
system startup and will use these registry keys to accomplish that task.
|
||||
references:
|
||||
- https://blog.malwarebytes.com/101/2015/12/an-introduction-to-image-file-execution-options/
|
||||
drilldown_searches:
|
||||
|
||||
@@ -1,15 +1,23 @@
|
||||
name: Time Provider Persistence Registry
|
||||
id: 5ba382c4-2105-11ec-8d8f-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects suspicious modifications to the time provider registry for persistence and autostart. It leverages data from the Endpoint.Registry data model, focusing on changes to the "CurrentControlSet\\Services\\W32Time\\TimeProviders" registry path. This activity is significant because such modifications are uncommon and can indicate an attempt to establish persistence on a compromised host. If confirmed malicious, this technique allows an attacker to maintain access and execute code automatically upon system boot, potentially leading to further exploitation and control over the affected system.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path="*\\CurrentControlSet\\Services\\W32Time\\TimeProviders*") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `time_provider_persistence_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path="*\\CurrentControlSet\\Services\\W32Time\\TimeProviders*")
|
||||
BY Registry.dest Registry.user Registry.registry_path Registry.registry_key_name
|
||||
Registry.registry_value_name Registry.registry_value_data Registry.process_guid
|
||||
| `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `time_provider_persistence_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://pentestlab.blog/2019/10/22/persistence-time-providers/
|
||||
|
||||
@@ -1,15 +1,23 @@
|
||||
name: Windows Defender Exclusion Registry Entry
|
||||
id: 13395a44-4dd9-11ec-9df7-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects modifications to the Windows Defender exclusion registry entries. It leverages endpoint registry data to identify changes in the registry path "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Exclusions\\*". This activity is significant because adversaries often modify these entries to bypass Windows Defender, allowing malicious code to execute without detection. If confirmed malicious, this behavior could enable attackers to evade antivirus defenses, maintain persistence, and execute further malicious activities undetected.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path = "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Exclusions\\*") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_defender_exclusion_registry_entry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path = "*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Exclusions\\*")
|
||||
BY Registry.dest Registry.user Registry.registry_path Registry.registry_key_name
|
||||
Registry.registry_value_name Registry.registry_value_data Registry.process_guid
|
||||
| `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_defender_exclusion_registry_entry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: admin or user may choose to use this windows features.
|
||||
references:
|
||||
- https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html
|
||||
|
||||
@@ -1,16 +1,26 @@
|
||||
name: Windows Disable Change Password Through Registry
|
||||
id: 0df33e1a-9ef6-11ec-a1ad-acde48001122
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic detects a suspicious registry modification that disables the Change Password feature on a Windows host. It identifies changes to the registry path "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableChangePassword" with a value of "0x00000001". This activity is significant as it can prevent users from changing their passwords, a tactic often used by ransomware to maintain control over compromised systems. If confirmed malicious, this could hinder user response to an attack, allowing the attacker to persist and potentially escalate their access within the network.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableChangePassword" Registry.registry_value_data = "0x00000001") BY _time span=1h Registry.dest Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_disable_change_password_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: This windows feature may implemented by administrator to prevent normal user to change the password of a critical host or server, In this type of scenario filter is needed to minimized false positive.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableChangePassword"
|
||||
Registry.registry_value_data = "0x00000001") BY Registry.dest Registry.registry_path
|
||||
Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_disable_change_password_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: This windows feature may implemented by administrator to prevent
|
||||
normal user to change the password of a critical host or server, In this type of
|
||||
scenario filter is needed to minimized false positive.
|
||||
references:
|
||||
- https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/ransom_heartbleed.thdobah
|
||||
drilldown_searches:
|
||||
|
||||
@@ -1,15 +1,23 @@
|
||||
name: Windows Disable Lock Workstation Feature Through Registry
|
||||
id: c82adbc6-9f00-11ec-a81f-acde48001122
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic detects a suspicious registry modification that disables the Lock Computer feature in Windows. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the registry path "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableLockWorkstation" with a value of "0x00000001". This activity is significant because it prevents users from locking their screens, a tactic often used by malware, including ransomware, to maintain control over compromised systems. If confirmed malicious, this could allow attackers to sustain their presence and execute further malicious actions without user interruption.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableLockWorkstation" Registry.registry_value_data = "0x00000001") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_disable_lock_workstation_feature_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableLockWorkstation"
|
||||
Registry.registry_value_data = "0x00000001") BY Registry.dest Registry.user
|
||||
Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_disable_lock_workstation_feature_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://www.bleepingcomputer.com/news/security/in-dev-ransomware-forces-you-do-to-survey-before-unlocking-computer/
|
||||
|
||||
@@ -1,16 +1,27 @@
|
||||
name: Windows Disable LogOff Button Through Registry
|
||||
id: b2fb6830-9ed1-11ec-9fcb-acde48001122
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Teoderick Contreras, Splunk, Steven Dick
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic detects a suspicious registry modification that disables the logoff feature on a Windows host. It leverages data from the Endpoint.Registry data model to identify changes to specific registry values associated with logoff functionality. This activity is significant because it can indicate ransomware attempting to make the compromised host unusable and hinder remediation efforts. If confirmed malicious, this action could prevent users from logging off, complicate incident response, and allow attackers to maintain persistence and control over the affected system.
|
||||
data_source:
|
||||
- Sysmon EventID 13
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*" Registry.registry_value_name IN ("NoLogOff", "StartMenuLogOff") Registry.registry_value_data = "0x00000001") BY _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_disable_logoff_button_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: This windows feature may implement by administrator in some server where shutdown is critical. In that scenario filter of machine and users that can modify this registry is needed.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
WHERE (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*"
|
||||
Registry.registry_value_name IN ("NoLogOff", "StartMenuLogOff") Registry.registry_value_data
|
||||
= "0x00000001") BY Registry.dest Registry.user Registry.registry_path
|
||||
Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)` | where isnotnull(registry_value_data)
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_disable_logoff_button_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the registry value name, registry path, and registry value data from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
|
||||
Sysmon TA. https://splunkbase.splunk.com/app/5709
|
||||
known_false_positives: This windows feature may implement by administrator in some
|
||||
server where shutdown is critical. In that scenario filter of machine and users
|
||||
that can modify this registry is needed.
|
||||
references:
|
||||
- https://www.hybrid-analysis.com/sample/e2d4018fd3bd541c153af98ef7c25b2bf4a66bc3bfb89e437cde89fd08a9dd7b/5b1f4d947ca3e10f22714774
|
||||
- https://malwiki.org/index.php?title=DigiPop.xp
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user