diff --git a/detections/endpoint/windows_powershell_remotesigned_file.yml b/detections/endpoint/windows_powershell_remotesigned_file.yml new file mode 100644 index 0000000000..459784176d --- /dev/null +++ b/detections/endpoint/windows_powershell_remotesigned_file.yml @@ -0,0 +1,68 @@ +name: Windows Powershell RemoteSigned File +id: f7f7456b-470d-4a95-9703-698250645ff4 +version: 1 +date: '2023-06-16' +author: Teoderick Contreras, Splunk +status: production +type: Anomaly +data_source: +- Sysmon EventCode 1 +description: This analytic identifies the use of "remotesigned" execution policy for a file. + This security setting determines whether PowerShell scripts can be executed on a computer. + When the execution policy is set to "remotesigned," it allows locally created scripts to run without any restrictions, + but scripts downloaded from the internet must have a digital signature from a trusted publisher. +search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where `process_powershell` Processes.process="* remotesigned *" Processes.process="* -File *" + by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_powershell_remotesigned_file_filter`' +how_to_implement: To successfully implement this analytic, you will need to enable + PowerShell Script Block Logging on some or all endpoints. Additional setup here + https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. +known_false_positives: It is possible administrators or scripts may run these commands, + filtering may be required. +references: +- https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/set-executionpolicy?view=powershell-7.3 +tags: + analytic_story: + - Amadey + asset_type: Endpoint + confidence: 50 + impact: 50 + message: A PowerShell commandline to remotesigned a powershell script in $dest$, + mitre_attack_id: + - T1059.001 + - T1059 + observable: + - name: Computer + type: Hostname + role: + - Victim + - name: User + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + risk_score: 25 + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.process_name + - Processes.original_file_name + - Processes.process + - Processes.process_id + - Processes.parent_process_id + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_remotesigned/remotesigned_sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog diff --git a/requirements.txt b/requirements.txt index 26da9fca96..69d835fe7a 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,6 +1,6 @@ attackcti==0.3.9 docker==6.1.3 -GitPython==3.1.31 +GitPython==3.1.32 Jinja2==3.1.2 jsonschema==4.17.3 mock==4.0.3 @@ -14,7 +14,7 @@ PyYAML>=5.4.1 questionary==1.10.0 requests==2.31.0 six==1.16.0 -splunk-sdk==1.7.3 +splunk-sdk==1.7.4 wrapt-timeout-decorator==1.3.12.2 xmltodict==0.13.0