From 6973e3029006ef2a3812a2168e69ecdbdf5bb7e1 Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Thu, 22 Apr 2021 09:23:46 -0600 Subject: [PATCH] winword wsh --- .../endpoint/winword_spawning_powershell.yml | 1 + .../winword_spawning_windows_script_host.yml | 51 +++++++++++++++++++ ...word_spawning_windows_script_host.test.yml | 12 +++++ 3 files changed, 64 insertions(+) create mode 100644 detections/endpoint/winword_spawning_windows_script_host.yml create mode 100644 tests/endpoint/winword_spawning_windows_script_host.test.yml diff --git a/detections/endpoint/winword_spawning_powershell.yml b/detections/endpoint/winword_spawning_powershell.yml index 9aab36b3f2..938e19c154 100644 --- a/detections/endpoint/winword_spawning_powershell.yml +++ b/detections/endpoint/winword_spawning_powershell.yml @@ -28,6 +28,7 @@ references: - https://redcanary.com/threat-detection-report/techniques/powershell/ - https://attack.mitre.org/techniques/T1566/001/ - https://app.any.run/tasks/b79fa381-f35c-4b3e-8d02-507e7ee7342f/ +- https://app.any.run/tasks/181ac90b-0898-4631-8701-b778a30610ad/ tags: analytic_story: - Spearphishing Attachments diff --git a/detections/endpoint/winword_spawning_windows_script_host.yml b/detections/endpoint/winword_spawning_windows_script_host.yml new file mode 100644 index 0000000000..f3e509862d --- /dev/null +++ b/detections/endpoint/winword_spawning_windows_script_host.yml @@ -0,0 +1,51 @@ +name: Winword Spawning Windows Script Host +id: 637e1b5c-9be1-11eb-9c32-acde48001122 +version: 1 +date: '2021-04-12' +author: Michael Haag, Splunk +type: batch +datamodel: +- Endpoint +description: The following detection identifies Microsoft Winword.exe spawning Windows Script + Host - `cscript.exe` or `wscript.exe`. Typically, this is not common behavior and + not default with Winword.exe. Winword.exe will generally be found in the following path + `C:\Program Files\Microsoft Office\root\Office16` (version will vary). `cscript.exe` + or `wscript.exe` default location is `c:\windows\system32\` or c:windows\syswow64\`. + `cscript.exe` or `wscript.exe` spawning from Winword.exe is common for a spearphishing + attachment and is actively used. Albeit, the command-line executed will most likely + be obfuscated and captured via another detection. During triage, review parallel + processes and identify any files that may have been written. Review the reputation + of the remote destination and block accordingly. +search: ' | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="winword.exe" Processes.process_name IN ("cscript.exe", "wscript.exe") by Processes.dest Processes.user Processes.parent_process Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `winword_spawning_windows_script_host_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +known_false_positives: There will be limited false positives and it will be different for every environment. Tune by child process or command-line as needed. +references: + - https://attack.mitre.org/techniques/T1566/001/ +tags: + analytic_story: + - Spearphishing Attachment + dataset: [] + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1566.001 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - process_name + - process_id + - parent_process_name + - dest + - user + - parent_process_id + security_domain: endpoint \ No newline at end of file diff --git a/tests/endpoint/winword_spawning_windows_script_host.test.yml b/tests/endpoint/winword_spawning_windows_script_host.test.yml new file mode 100644 index 0000000000..b86e113fa5 --- /dev/null +++ b/tests/endpoint/winword_spawning_windows_script_host.test.yml @@ -0,0 +1,12 @@ +name: Winword Spawning Windows Script Host Unit Test +tests: +- name: Winword Spawning Windows Script Host + file: endpoint/winword_spawning_windows_script_host.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog