From 0627d28ae3491dfb15c07b520bc8c0493a6f0d7a Mon Sep 17 00:00:00 2001 From: patel-bhavin Date: Mon, 28 Mar 2022 11:25:05 -0700 Subject: [PATCH] adding CIS tags --- ...ocess_running_from_unexpected_location.yml | 8 +- .../ssa___windows_bits_job_persistence.yml | 2 + .../ssa___windows_bitsadmin_download_file.yml | 5 + .../ssa___windows_certutil_decode_file.yml | 5 + ...a___windows_certutil_urlcache_download.yml | 5 + ...___windows_certutil_verifyctl_download.yml | 5 + ..._windows_powershell_start_bitstransfer.yml | 8 +- .../ssa___windows_rasautou_dll_execution.yml | 5 + dist/ssa/srs/ssa___delete_a_net_user.yml | 14 +-- ...fy_acls_permission_of_files_or_folders.yml | 21 ++-- ...ocess_running_from_unexpected_location.yml | 14 +-- .../ssa___wbadmin_delete_system_backups.yml | 63 +++++++++++ .../ssa___windows_bits_job_persistence.yml | 4 +- .../ssa___windows_bitsadmin_download_file.yml | 7 +- .../ssa___windows_certutil_decode_file.yml | 7 +- ...a___windows_certutil_urlcache_download.yml | 7 +- ...___windows_certutil_verifyctl_download.yml | 7 +- ...ows_dotnet_binary_in_non_standard_path.yml | 89 +++++++++++++++ ...ows_lolbin_binary_in_non_standard_path.yml | 102 ++++++++++++++++++ ..._windows_powershell_start_bitstransfer.yml | 7 +- .../ssa___windows_rasautou_dll_execution.yml | 7 +- ...sa___windows_script_host_spawn_msbuild.yml | 68 ++++++++++++ .../ssa___windows_wmiprvse_spawn_msbuild.yml | 69 ++++++++++++ 23 files changed, 485 insertions(+), 44 deletions(-) create mode 100644 dist/ssa/srs/ssa___wbadmin_delete_system_backups.yml create mode 100644 dist/ssa/srs/ssa___windows_dotnet_binary_in_non_standard_path.yml create mode 100644 dist/ssa/srs/ssa___windows_lolbin_binary_in_non_standard_path.yml create mode 100644 dist/ssa/srs/ssa___windows_script_host_spawn_msbuild.yml create mode 100644 dist/ssa/srs/ssa___windows_wmiprvse_spawn_msbuild.yml diff --git a/detections/endpoint/ssa___system_process_running_from_unexpected_location.yml b/detections/endpoint/ssa___system_process_running_from_unexpected_location.yml index a47954ee99..f2fdaaf06b 100644 --- a/detections/endpoint/ssa___system_process_running_from_unexpected_location.yml +++ b/detections/endpoint/ssa___system_process_running_from_unexpected_location.yml @@ -1,8 +1,8 @@ name: System Process Running from Unexpected Location id: 28179107-099a-464a-94d3-08301e6c055f version: 4 -date: '2022-03-17' -author: Ignacio Bermudez Corrales, Splunk +date: '2022-03-24' +author: Jose Hernadnez, Ignacio Bermudez Corrales, Splunk type: Anomaly datamodel: - Endpoint_Processes @@ -190,7 +190,7 @@ search: ' $ssa_input = | from read_ssa_enriched_events() | eval device=ucast(map OR process_name="sdclt.exe" OR process_name="sdiagnhost.exe" OR process_name="secinit.exe" OR process_name="services.exe" OR process_name="sessionmsg.exe" OR process_name="sethc.exe" OR process_name="setspn.exe" OR process_name="setupcl.exe" OR process_name="setupugc.exe" - OR process_name="setx.exe" OR process_name="shadow.exe" + OR process_name="setx.exe" OR process_name="sfc.exe" OR process_name="shadow.exe" OR process_name="shrpubw.exe" OR process_name="shutdown.exe" OR process_name="sigverif.exe" OR process_name="sihost.exe" OR process_name="slui.exe" OR process_name="smss.exe" OR process_name="snmptrap.exe" OR process_name="sort.exe" OR process_name="spinstall.exe" @@ -274,4 +274,4 @@ tags: risk_score: 56 risk_severity: medium security_domain: endpoint - asset_type: Endpoint + asset_type: Endpoint \ No newline at end of file diff --git a/detections/endpoint/ssa___windows_bits_job_persistence.yml b/detections/endpoint/ssa___windows_bits_job_persistence.yml index 35c93b77ae..ef49407953 100644 --- a/detections/endpoint/ssa___windows_bits_job_persistence.yml +++ b/detections/endpoint/ssa___windows_bits_job_persistence.yml @@ -53,6 +53,8 @@ tags: dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/bits-windows-security.log impact: 70 + cis20: [] + nist: [] kill_chain_phases: - Exploitation message: An instance of $parent_process_name$ spawning $process_name$ was identified diff --git a/detections/endpoint/ssa___windows_bitsadmin_download_file.yml b/detections/endpoint/ssa___windows_bitsadmin_download_file.yml index 6a09c4aa67..ad023bda5f 100644 --- a/detections/endpoint/ssa___windows_bitsadmin_download_file.yml +++ b/detections/endpoint/ssa___windows_bitsadmin_download_file.yml @@ -56,6 +56,11 @@ tags: dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/bits-windows-security.log impact: 70 + cis20: + - CIS 8 + nist: + - PR.PT + - DE.CM kill_chain_phases: - Exploitation message: An instance of $parent_process_name$ spawning $process_name$ was identified diff --git a/detections/endpoint/ssa___windows_certutil_decode_file.yml b/detections/endpoint/ssa___windows_certutil_decode_file.yml index 5b948abd66..c0932efdd2 100644 --- a/detections/endpoint/ssa___windows_certutil_decode_file.yml +++ b/detections/endpoint/ssa___windows_certutil_decode_file.yml @@ -51,6 +51,11 @@ tags: dataset: - https://media.githubusercontent.com/media/splunk/attack_data/ master/datasets/attack_techniques/T1140/atomic_red_team/encode-windows-security.log impact: 50 + cis20: + - CIS 8 + nist: + - PR.PT + - DE.CM kill_chain_phases: - Exploitation message: An instance of $parent_process_name$ spawning $process_name$ was identified diff --git a/detections/endpoint/ssa___windows_certutil_urlcache_download.yml b/detections/endpoint/ssa___windows_certutil_urlcache_download.yml index da493a5d98..1cc747b227 100644 --- a/detections/endpoint/ssa___windows_certutil_urlcache_download.yml +++ b/detections/endpoint/ssa___windows_certutil_urlcache_download.yml @@ -48,6 +48,11 @@ tags: dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/T1105-windows-security.log impact: 90 + cis20: + - CIS 8 + nist: + - PR.PT + - DE.CM kill_chain_phases: - Exploitation message: An instance of $parent_process_name$ spawning $process_name$ was identified diff --git a/detections/endpoint/ssa___windows_certutil_verifyctl_download.yml b/detections/endpoint/ssa___windows_certutil_verifyctl_download.yml index bfee568c4f..2cb22cbef7 100644 --- a/detections/endpoint/ssa___windows_certutil_verifyctl_download.yml +++ b/detections/endpoint/ssa___windows_certutil_verifyctl_download.yml @@ -43,6 +43,11 @@ tags: - Living Off The Land automated_detection_testing: passed confidence: 100 + cis20: + - CIS 8 + nist: + - PR.PT + - DE.CM context: - Source:Endpoint - Stage:Command And Control diff --git a/detections/endpoint/ssa___windows_powershell_start_bitstransfer.yml b/detections/endpoint/ssa___windows_powershell_start_bitstransfer.yml index 458fb2c1aa..950c228ced 100644 --- a/detections/endpoint/ssa___windows_powershell_start_bitstransfer.yml +++ b/detections/endpoint/ssa___windows_powershell_start_bitstransfer.yml @@ -40,8 +40,12 @@ tags: analytic_story: - BITS Jobs - Living Off The Land - automated_detection_testing: passed - cis20: [] + automated_detection_testing: passed + cis20: + - CIS 8 + nist: + - PR.PT + - DE.CM confidence: 70 context: - Source:Endpoint diff --git a/detections/endpoint/ssa___windows_rasautou_dll_execution.yml b/detections/endpoint/ssa___windows_rasautou_dll_execution.yml index 8f9fcb5e31..ff0ec076d5 100644 --- a/detections/endpoint/ssa___windows_rasautou_dll_execution.yml +++ b/detections/endpoint/ssa___windows_rasautou_dll_execution.yml @@ -46,6 +46,11 @@ tags: dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055.001/rasautou/windows-security.log impact: 80 + cis20: + - CIS 8 + nist: + - PR.PT + - DE.CM kill_chain_phases: - Exploitation message: An instance of $parent_process_name$ spawning $process_name$ was identified diff --git a/dist/ssa/srs/ssa___delete_a_net_user.yml b/dist/ssa/srs/ssa___delete_a_net_user.yml index b5436bb823..7e6dbad662 100644 --- a/dist/ssa/srs/ssa___delete_a_net_user.yml +++ b/dist/ssa/srs/ssa___delete_a_net_user.yml @@ -1,6 +1,6 @@ name: Delete A Net User id: 8776d79c-d26e-11eb-9a56-acde48001122 -version: 3 +version: 4 description: This analytic will detect a suspicious net.exe/net1.exe command-line to delete a user on a system. This technique may be use by an administrator for legitimate purposes, however this behavior has been used in the wild to impair some @@ -8,15 +8,15 @@ description: This analytic will detect a suspicious net.exe/net1.exe command-lin systems. During triage, review parallel processes for additional behavior. Identify any other user accounts created before or after. search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "_time"), "string", null)), process=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND like(cmd_line, "%/delete%") AND (process_name="net1.exe" + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string",null), + parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string",null), + event_id=ucast(map_get(input_event, "event_id"), "string", null) | where process + IS NOT NULL AND like(process, "%/delete%") AND like(process, "%user%") AND (process_name="net1.exe" OR process_name="net.exe") | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + "string", null)), body=create_map(["event_id", event_id, "process", process, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' how_to_implement: To successfully implement this search, you need to be ingesting diff --git a/dist/ssa/srs/ssa___modify_acls_permission_of_files_or_folders.yml b/dist/ssa/srs/ssa___modify_acls_permission_of_files_or_folders.yml index d31616dc32..f065ba01e8 100644 --- a/dist/ssa/srs/ssa___modify_acls_permission_of_files_or_folders.yml +++ b/dist/ssa/srs/ssa___modify_acls_permission_of_files_or_folders.yml @@ -1,6 +1,6 @@ name: Modify ACLs Permission Of Files Or Folders id: 9ae9a48a-cdbe-11eb-875a-acde48001122 -version: 2 +version: 3 description: This analytic identifies suspicious modification of ACL permission to a files or folder to make it available to everyone or to a specific user. This technique may be used by the adversary to evade ACLs or protected files access. This changes @@ -8,18 +8,19 @@ description: This analytic identifies suspicious modification of ACL permission This behavior raises suspicion if this command is seen on an endpoint utilized by an account with no permission to do so. search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", + "_time"), "string", null)), process=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line IS NOT NULL AND like(cmd_line, "%/G%") AND (match_regex(cmd_line, - /(?i)everyone:/)=true OR match_regex(cmd_line, /(?i)SYSTEM:/)=true) AND (process_name="cacls.exe" - OR process_name="xcacls.exe" OR process_name="icacls.exe") | eval start_time=timestamp, - end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, - "parent_process_name", parent_process_name, "process_path", process_path]) | into - write_ssa_detected_events();' + "string", null) | where process IS NOT NULL AND NOT like(process, "%:\\Windows\\QG\\ServiceNow%") + AND like(process, "%/g%") | where (match_regex(process, /(?i)everyone:/)=true OR + match_regex(process, /(?i)SYSTEM:/)=true OR match_regex(process, /(?i)S-1-1-0:/)=true) + | where (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "process", process, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the diff --git a/dist/ssa/srs/ssa___system_process_running_from_unexpected_location.yml b/dist/ssa/srs/ssa___system_process_running_from_unexpected_location.yml index cd38084f56..380636d2fd 100644 --- a/dist/ssa/srs/ssa___system_process_running_from_unexpected_location.yml +++ b/dist/ssa/srs/ssa___system_process_running_from_unexpected_location.yml @@ -1,6 +1,6 @@ name: System Process Running from Unexpected Location id: 28179107-099a-464a-94d3-08301e6c055f -version: 3 +version: 4 description: An attacker tries might try to use different version of a system command without overriding original, or they might try to avoid some detection running the process from a different folder. This detection checks that a list of system processes @@ -64,12 +64,12 @@ search: ' $ssa_input = | from read_ssa_enriched_events() | eval device=ucast(map OR process_name="rdpsauachelper.exe" OR process_name="reagentc.exe" OR process_name="recoverydrive.exe" OR process_name="register-cimprovider.exe" OR process_name="registeriepkeys.exe" OR process_name="relpost.exe" OR process_name="remoteposworker.exe" OR process_name="rmclient.exe" - OR process_name="robocopy.exe" OR process_name="rpcping.exe" OR process_name="runlegacycplelevated.exe" - OR process_name="runtimebroker.exe" OR process_name="sihclient.exe" OR process_name="searchfilterhost.exe" - OR process_name="searchindexer.exe" OR process_name="searchprotocolhost.exe" OR - process_name="secedit.exe" OR process_name="sensordataservice.exe" OR process_name="setieinstalleddate.exe" - OR process_name="settingsynchost.exe" OR process_name="slidetoshutdown.exe" OR process_name="smartscreensettings.exe" - OR process_name="sndvol.exe" OR process_name="snippingtool.exe" OR process_name="soundrecorder.exe" + OR process_name="rpcping.exe" OR process_name="runlegacycplelevated.exe" OR process_name="runtimebroker.exe" + OR process_name="sihclient.exe" OR process_name="searchfilterhost.exe" OR process_name="searchindexer.exe" + OR process_name="searchprotocolhost.exe" OR process_name="secedit.exe" OR process_name="sensordataservice.exe" + OR process_name="setieinstalleddate.exe" OR process_name="settingsynchost.exe" OR + process_name="slidetoshutdown.exe" OR process_name="smartscreensettings.exe" OR + process_name="sndvol.exe" OR process_name="snippingtool.exe" OR process_name="soundrecorder.exe" OR process_name="spaceagent.exe" OR process_name="sppextcomobj.exe" OR process_name="srtasks.exe" OR process_name="stikynot.exe" OR process_name="synchost.exe" OR process_name="sysreseterr.exe" OR process_name="systempropertiesadvanced.exe" OR process_name="systempropertiescomputername.exe" diff --git a/dist/ssa/srs/ssa___wbadmin_delete_system_backups.yml b/dist/ssa/srs/ssa___wbadmin_delete_system_backups.yml new file mode 100644 index 0000000000..12916987b5 --- /dev/null +++ b/dist/ssa/srs/ssa___wbadmin_delete_system_backups.yml @@ -0,0 +1,63 @@ +name: WBAdmin Delete System Backups +id: 71efbf52-4dbb-4c00-a520-306aa546cbb7 +version: 1 +description: This search looks for flags passed to wbadmin.exe (Windows Backup Administrator + Tool) that delete backup files. This is typically used by ransomware to prevent + recovery. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + (cmd_line IS NOT NULL AND process_name IS NOT NULL) | where process_name="wbadmin.exe" + | where like (cmd_line, "%delete%") OR like (cmd_line, "%catalog%") OR like (cmd_line, "%systemstatebackup%") + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +known_false_positives: Administrators may modify the boot configuration. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md +- https://thedfirreport.com/2020/10/08/ryuks-return/ +- https://attack.mitre.org/techniques/T1490/ +- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin +tags: + analytic_story: + - Ryuk Ransomware + - Ransomware + cis20: + - CIS 8 + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1490 + nist: + - PR.AC + - PR.IP + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 15 + security_domain: endpoint + risk_severity: low +test: + name: WBAdmin Delete System Backups Unit Test + tests: + - name: WBAdmin Delete System Backups + file: endpoint/ssa___wbadmin_delete_system_backups.yml + pass_condition: '@count_gt(0)' + attack_data: + - file_name: windows-security_bcdedit_wbadmin.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-security_bcdedit_wbadmin.log + source: WinEventLog:Security diff --git a/dist/ssa/srs/ssa___windows_bits_job_persistence.yml b/dist/ssa/srs/ssa___windows_bits_job_persistence.yml index c49263e82e..27e0401c36 100644 --- a/dist/ssa/srs/ssa___windows_bits_job_persistence.yml +++ b/dist/ssa/srs/ssa___windows_bits_job_persistence.yml @@ -40,12 +40,12 @@ tags: analytic_story: - BITS Jobs - Living Off The Land - cis20: null + cis20: [] kill_chain_phases: - Exploitation mitre_attack_id: - T1197 - nist: null + nist: [] required_fields: - _time - dest_device_id diff --git a/dist/ssa/srs/ssa___windows_bitsadmin_download_file.yml b/dist/ssa/srs/ssa___windows_bitsadmin_download_file.yml index 817a0573d7..63aaef432f 100644 --- a/dist/ssa/srs/ssa___windows_bitsadmin_download_file.yml +++ b/dist/ssa/srs/ssa___windows_bitsadmin_download_file.yml @@ -43,13 +43,16 @@ tags: - BITS Jobs - DarkSide Ransomware - Living Off The Land - cis20: null + cis20: + - CIS 8 kill_chain_phases: - Exploitation mitre_attack_id: - T1197 - T1105 - nist: null + nist: + - PR.PT + - DE.CM required_fields: - _time - dest_device_id diff --git a/dist/ssa/srs/ssa___windows_certutil_decode_file.yml b/dist/ssa/srs/ssa___windows_certutil_decode_file.yml index 26a4e9e2c6..67ebe38322 100644 --- a/dist/ssa/srs/ssa___windows_certutil_decode_file.yml +++ b/dist/ssa/srs/ssa___windows_certutil_decode_file.yml @@ -38,12 +38,15 @@ tags: analytic_story: - Deobfuscate-Decode Files or Information - Living Off The Land - cis20: null + cis20: + - CIS 8 kill_chain_phases: - Exploitation mitre_attack_id: - T1140 - nist: null + nist: + - PR.PT + - DE.CM required_fields: - _time - dest_device_id diff --git a/dist/ssa/srs/ssa___windows_certutil_urlcache_download.yml b/dist/ssa/srs/ssa___windows_certutil_urlcache_download.yml index cf7dbfc9fe..1bcdce8807 100644 --- a/dist/ssa/srs/ssa___windows_certutil_urlcache_download.yml +++ b/dist/ssa/srs/ssa___windows_certutil_urlcache_download.yml @@ -35,12 +35,15 @@ tags: - Ingress Tool Transfer - DarkSide Ransomware - Living Off The Land - cis20: null + cis20: + - CIS 8 kill_chain_phases: - Exploitation mitre_attack_id: - T1105 - nist: null + nist: + - PR.PT + - DE.CM required_fields: - _time - dest_device_id diff --git a/dist/ssa/srs/ssa___windows_certutil_verifyctl_download.yml b/dist/ssa/srs/ssa___windows_certutil_verifyctl_download.yml index 289ffd16f8..f7e4f65f4b 100644 --- a/dist/ssa/srs/ssa___windows_certutil_verifyctl_download.yml +++ b/dist/ssa/srs/ssa___windows_certutil_verifyctl_download.yml @@ -36,12 +36,15 @@ tags: - Ingress Tool Transfer - DarkSide Ransomware - Living Off The Land - cis20: null + cis20: + - CIS 8 kill_chain_phases: - Exploitation mitre_attack_id: - T1105 - nist: null + nist: + - PR.PT + - DE.CM required_fields: - _time - dest_device_id diff --git a/dist/ssa/srs/ssa___windows_dotnet_binary_in_non_standard_path.yml b/dist/ssa/srs/ssa___windows_dotnet_binary_in_non_standard_path.yml new file mode 100644 index 0000000000..cd5d7489ac --- /dev/null +++ b/dist/ssa/srs/ssa___windows_dotnet_binary_in_non_standard_path.yml @@ -0,0 +1,89 @@ +name: Windows DotNet Binary in Non Standard Path +id: 21179107-099a-324a-94d3-08301e6c065f +version: 1 +description: The following analytic identifies native .net binaries within the Windows + operating system that may be abused by adversaries by moving it to a new directory. + The analytic identifies the .net binary by using a list. If one or the other matches + an alert will be generated. Adversaries abuse these binaries as they are native + to Windows and native DotNet. Note that not all SDK (post install of Windows) are + captured in the list. Lookup - https://github.com/splunk/security_content/blob/develop/lookups/is_net_windows_file.csv. +search: ' $ssa_input = | from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null); + + $cond_1 = | from $ssa_input | where process_name="msbuild.exe" OR process_name="comsvcconfig.exe" + OR process_name="dfsradmin.exe" OR process_name="dfsvc.exe" OR process_name="microsoft.workflow.compiler.exe" + OR process_name="smsvchost.exe" OR process_name="wsatconfig.exe" OR process_name="addinprocess.exe" + OR process_name="addinprocess32.exe" OR process_name="addinutil.exe" OR process_name="aspnet_compiler.exe" + OR process_name="aspnet_regbrowsers.exe" OR process_name="aspnet_regsql.exe" OR + process_name="caspol.exe" OR process_name="datasvcutil.exe" OR process_name="edmgen.exe" + OR process_name="installutil.exe" OR process_name="jsc.exe" OR process_name="ngentask.exe" + OR process_name="regasm.exe" OR process_name="regsvcs.exe" OR process_name="sdnbr.exe" + OR process_name="acu.exe" OR process_name="appvstreamingux.exe" OR process_name="dsac.exe" + OR process_name="lbfoadmin.exe" OR process_name="microsoft.uev.synccontroller.exe" + OR process_name="mtedit.exe" OR process_name="scriptrunner.exe" OR process_name="servermanager.exe" + OR process_name="stordiag.exe" OR process_name="tzsync.exe" OR process_name="uevagentpolicygenerator.exe" + OR process_name="uevappmonitor.exe" OR process_name="uevtemplatebaselinegenerator.exe" + OR process_name="uevtemplateconfigitemgenerator.exe" OR process_name="powershell_ise.exe" + OR process_name="iediagcmd.exe" OR process_name="xbox.tcui.exe" OR process_name="microsoft.activedirectory.webservices.exe" + OR process_name="iisual.exe" OR process_name="filehistory.exe" OR process_name="secureassessmentbrowser.exe"; + + | from $cond_1 | where match_regex(process_path, /(?i)\\windows\\system32/)=false + AND match_regex(process_path, /(?i)\\windows\\syswow64/)=false AND match_regex(process_path, + /(?i)\\windows\\adws/)=false AND match_regex(process_path, /(?i)\\windows\\networkcontroller/)=false + AND match_regex(process_path, /(?i)\\windows\\systemapps/)=false AND match_regex(process_path, + /(?i)\\winsxs/)=false AND match_regex(process_path, /(?i)\\microsoft.net/)=false + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(device, user), + body=create_map(["event_id", event_id, "process_path", process_path, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: Collect endpoint data such as sysmon or 4688 events. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md +tags: + analytic_story: + - Masquerading - Rename System Utilities + - Unusual Processes + - Ransomware + - Signed Binary Proxy Execution InstallUtil + - WhisperGate + cis20: + - CIS 8 + kill_chain_phases: + - Actions on Objectives + mitre_attack_id: + - T1036 + - T1036.003 + - T1218 + - T1218.004 + nist: + - PR.PT + - DE.CM + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + - cmd_line + risk_score: 49 + security_domain: endpoint + risk_severity: low +test: + name: Windows DotNet Binary in Non Standard Path Unit Test + tests: + - name: Windows DotNet Binary in Non Standard Path + file: endpoint/ssa___windows_dotnet_binary_in_non_standard_path.yml + pass_condition: '@count_eq(1)' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/dotnet_lolbin-windows-security.log + source: WinEventLog:Security diff --git a/dist/ssa/srs/ssa___windows_lolbin_binary_in_non_standard_path.yml b/dist/ssa/srs/ssa___windows_lolbin_binary_in_non_standard_path.yml new file mode 100644 index 0000000000..ce9f85240e --- /dev/null +++ b/dist/ssa/srs/ssa___windows_lolbin_binary_in_non_standard_path.yml @@ -0,0 +1,102 @@ +name: Windows LOLBin Binary in Non Standard Path +id: 25689101-012a-324a-94d3-08301e6c065a +version: 1 +description: The following analytic identifies native living off the land binaries + within the Windows operating system that may be abused by adversaries by moving + it to a new directory. The list of binaries was derived from the https://lolbas-project.github.io + site, and excluded common process names (cmd.exe) and DotNet binaries. It also does + not include the category of OtherMSBinaries. +search: ' $ssa_input = | from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null); + + $cond_1 = | from $ssa_input | where process_name="appinstaller.exe" OR process_name="aspnet_compiler.exe" + OR process_name="at.exe" OR process_name="atbroker.exe" OR process_name="bash.exe" + OR process_name="bitsadmin.exe" OR process_name="certoc.exe" OR process_name="certreq.exe" + OR process_name="certutil.exe" OR process_name="cmd.exe" OR process_name="cmdkey.exe" + OR process_name="cmdl32.exe" OR process_name="cmstp.exe" OR process_name="configsecuritypolicy.exe" + OR process_name="control.exe" OR process_name="csc.exe" OR process_name="cscript.exe" + OR process_name="datasvcutil.exe" OR process_name="desktopimgdownldr.exe" OR process_name="dfsvc.exe" + OR process_name="diantz.exe" OR process_name="diskshadow.exe" OR process_name="dllhost.exe" + OR process_name="dnscmd.exe" OR process_name="esentutl.exe" OR process_name="eventvwr.exe" + OR process_name="expand.exe" OR process_name="explorer.exe" OR process_name="extexport.exe" + OR process_name="extrac32.exe" OR process_name="findstr.exe" OR process_name="finger.exe" + OR process_name="fltmc.exe" OR process_name="forfiles.exe" OR process_name="ftp.exe" + OR process_name="gfxdownloadwrapper.exe" OR process_name="gpscript.exe" OR process_name="hh.exe" + OR process_name="imewdbld.exe" OR process_name="ie4uinit.exe" OR process_name="ieexec.exe" + OR process_name="ilasm.exe" OR process_name="infdefaultinstall.exe" OR process_name="makecab.exe" + OR process_name="mavinject.exe" OR process_name="microsoft.workflow.compiler.exe" + OR process_name="mmc.exe" OR process_name="mpcmdrun.exe" OR process_name="msconfig.exe" + OR process_name="msdt.exe" OR process_name="mshta.exe" OR process_name="msiexec.exe" + OR process_name="netsh.exe" OR process_name="odbcconf.exe" OR process_name="offlinescannershell.exe" + OR process_name="onedrivestandaloneupdater.exe" OR process_name="pcalua.exe" OR + process_name="pcwrun.exe" OR process_name="pktmon.exe" OR process_name="pnputil.exe" + OR process_name="presentationhost.exe" OR process_name="print.exe" OR process_name="printbrm.exe" + OR process_name="psr.exe" OR process_name="rasautou.exe" OR process_name="reg.exe" + OR process_name="regedit.exe" OR process_name="regini.exe" OR process_name="register-cimprovider.exe" + OR process_name="regsvr32.exe" OR process_name="replace.exe" OR process_name="rpcping.exe" + OR process_name="rundll32.exe" OR process_name="runonce.exe" OR process_name="runscripthelper.exe" + OR process_name="sc.exe" OR process_name="schtasks.exe" OR process_name="scriptrunner.exe" + OR process_name="settingsynchost.exe" OR process_name="syncappvpublishingserver.exe" + OR process_name="ttdinject.exe" OR process_name="tttracer.exe" OR process_name="vbc.exe" + OR process_name="verclsid.exe" OR process_name="wab.exe" OR process_name="wlrmdr.exe" + OR process_name="wmic.exe" OR process_name="workfolders.exe" OR process_name="wscript.exe" + OR process_name="wsreset.exe" OR process_name="wuauclt.exe" OR process_name="xwizard.exe"; + + | from $cond_1 | where match_regex(process_path, /(?i)\\windows\\system32/)=false + AND match_regex(process_path, /(?i)\\windows\\syswow64/)=false AND match_regex(process_path, + /(?i)\\windows\\adws/)=false AND match_regex(process_path, /(?i)\\windows\\networkcontroller/)=false + AND match_regex(process_path, /(?i)\\windows\\systemapps/)=false AND match_regex(process_path, + /(?i)\\winsxs/)=false AND match_regex(process_path, /(?i)\\microsoft.net/)=false + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(device, user), + body=create_map(["event_id", event_id, "process_path", process_path, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: Collect endpoint data such as sysmon or 4688 events. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md +tags: + analytic_story: + - Unusual Processes + - Ransomware + - WhisperGate + cis20: + - CIS 8 + kill_chain_phases: + - Actions on Objectives + mitre_attack_id: + - T1036 + - T1036.003 + - T1218 + - T1218.004 + nist: + - PR.PT + - DE.CM + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + - cmd_line + risk_score: 49 + security_domain: endpoint + risk_severity: low +test: + name: Windows LOLBin Binary in Non Standard Path Unit Test + tests: + - name: Windows LOLBin Binary in Non Standard Path + file: endpoint/ssa___windows_lolbin_binary_in_non_standard_path.yml + pass_condition: '@count_eq(1)' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/dotnet_lolbin-windows-security.log + source: WinEventLog:Security diff --git a/dist/ssa/srs/ssa___windows_powershell_start_bitstransfer.yml b/dist/ssa/srs/ssa___windows_powershell_start_bitstransfer.yml index 581d1ac0d8..dbd60b9417 100644 --- a/dist/ssa/srs/ssa___windows_powershell_start_bitstransfer.yml +++ b/dist/ssa/srs/ssa___windows_powershell_start_bitstransfer.yml @@ -35,13 +35,16 @@ tags: analytic_story: - BITS Jobs - Living Off The Land - cis20: [] + cis20: + - CIS 8 kill_chain_phases: - Exploitation mitre_attack_id: - T1197 - T1105 - nist: null + nist: + - PR.PT + - DE.CM required_fields: - _time - dest_device_id diff --git a/dist/ssa/srs/ssa___windows_rasautou_dll_execution.yml b/dist/ssa/srs/ssa___windows_rasautou_dll_execution.yml index ef9827d8bd..9bb58732a6 100644 --- a/dist/ssa/srs/ssa___windows_rasautou_dll_execution.yml +++ b/dist/ssa/srs/ssa___windows_rasautou_dll_execution.yml @@ -34,14 +34,17 @@ tags: analytic_story: - Windows Defense Evasion Tactics - Living Off The Land - cis20: null + cis20: + - CIS 8 kill_chain_phases: - Exploitation mitre_attack_id: - T1055.001 - T1218 - T1055 - nist: null + nist: + - PR.PT + - DE.CM required_fields: - _time - dest_device_id diff --git a/dist/ssa/srs/ssa___windows_script_host_spawn_msbuild.yml b/dist/ssa/srs/ssa___windows_script_host_spawn_msbuild.yml new file mode 100644 index 0000000000..801886f472 --- /dev/null +++ b/dist/ssa/srs/ssa___windows_script_host_spawn_msbuild.yml @@ -0,0 +1,68 @@ +name: Windows Script Host Spawn MSBuild +id: 92886f1c-9b11-11ec-848a-acde48001122 +version: 1 +description: This analytic is to detect a suspicious child process of MSBuild spawned + by Windows Script Host - cscript or wscript. This behavior or event are commonly + seen and used by malware or adversaries to execute malicious msbuild process using + malicious script in the compromised host. During triage, review parallel processes + and identify any file modifications. MSBuild may load a script from the same path + without having command-line arguments. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL AND parent_process_name IS NOT + NULL | where (parent_process_name LIKE "%wscript.exe" OR parent_process_name LIKE + "%cscript.exe%") AND process_name="msbuild.exe" | eval start_time=timestamp, end_time=timestamp, + entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, + "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", + cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, + "process_path", process_path]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: False positives should be limited as developers do not spawn + MSBuild via a WSH. +references: +- https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/# +- https://github.com/redcanaryco/AtomicTestHarnesses/blob/master/TestHarnesses/T1127.001_MSBuild/InvokeMSBuild.ps1 +tags: + analytic_story: + - Trusted Developer Utilities Proxy Execution MSBuild + - Living Off The Land + cis20: + - CIS 8 + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1127.001 + - T1127 + nist: + - PR.PT + - DE.CM + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 80 + security_domain: endpoint + risk_severity: high +test: + name: Windows Script Host Spawn MSBuild Unit Test + tests: + - name: Windows Script Host Spawn MSBuild + file: endpoint/ssa___windows_script_host_spawn_msbuild.yml + pass_condition: '@count_gt(0)' + attack_data: + - file_name: msbuild-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/msbuild-windows-security.log + source: WinEventLog:Security diff --git a/dist/ssa/srs/ssa___windows_wmiprvse_spawn_msbuild.yml b/dist/ssa/srs/ssa___windows_wmiprvse_spawn_msbuild.yml new file mode 100644 index 0000000000..afdfddbbfa --- /dev/null +++ b/dist/ssa/srs/ssa___windows_wmiprvse_spawn_msbuild.yml @@ -0,0 +1,69 @@ +name: Windows WMIPrvse Spawn MSBuild +id: 76b3b290-9b31-11ec-a934-acde48001122 +version: 1 +description: The following analytic identifies wmiprvse.exe spawning msbuild.exe. + This behavior is indicative of a COM object being utilized to spawn msbuild from + wmiprvse.exe. It is common for MSBuild.exe to be spawned from devenv.exe while using + Visual Studio. In this instance, there will be command line arguments and file paths. + In a malicious instance, MSBuild.exe will spawn from non-standard processes and + have no command line arguments. For example, MSBuild.exe spawning from explorer.exe, + powershell.exe is far less common and should be investigated. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=lower(ucast(map_get(input_event, "parent_process_name"), + "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND parent_process_name + IS NOT NULL | where parent_process_name LIKE "%wmiprvse.exe%" AND process_name="msbuild.exe" + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Although unlikely, some legitimate applications may exhibit + this behavior, triggering a false positive. +references: +- https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md +tags: + analytic_story: + - Trusted Developer Utilities Proxy Execution MSBuild + - Living Off The Land + cis20: + - CIS 8 + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1127 + - T1127.001 + nist: + - PR.PT + - DE.CM + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 80 + security_domain: endpoint + risk_severity: high +test: + name: Windows WMIPrvse Spawn MSBuild Unit Test + tests: + - name: Windows WMIPrvse Spawn MSBuild + file: endpoint/ssa___windows_wmiprvse_spawn_msbuild.yml + pass_condition: '@count_gt(0)' + attack_data: + - file_name: msbuild-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/msbuild-windows-security.log + source: WinEventLog:Security