From 5875cf6123e3964bc10690f8c2609c8453af9652 Mon Sep 17 00:00:00 2001 From: root Date: Thu, 9 Sep 2021 21:34:16 +0000 Subject: [PATCH] Added detection testing service results inGetDomainComputer with PowerShell Script Block --- ...omaincomputer_with_powershell_script_block.yml | 15 +++++++++------ 1 file changed, 9 insertions(+), 6 deletions(-) diff --git a/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml b/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml index 7832a1ab9f..6889381d89 100644 --- a/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml +++ b/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml @@ -7,11 +7,13 @@ type: TTP datamodel: - Endpoint description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) - to identify the execution of the `Get-DomainComputer` commandlet. `GetDomainComputer` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. - Red Teams and adversaries alike may use PowerView to enumerate domain computers for situational awareness and Active Directory Discovery. -search: '`powershell` EventCode=4104 (Message = "*Get-DomainComputer*") - | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message - ComputerName User | `security_content_ctime(firstTime)` | `getdomaincomputer_with_powershell_script_block_filter`' + to identify the execution of the `Get-DomainComputer` commandlet. `GetDomainComputer` + is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. + Red Teams and adversaries alike may use PowerView to enumerate domain computers + for situational awareness and Active Directory Discovery. +search: '`powershell` EventCode=4104 (Message = "*Get-DomainComputer*") | stats count + min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName + User | `security_content_ctime(firstTime)` | `getdomaincomputer_with_powershell_script_block_filter`' how_to_implement: To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell. @@ -47,4 +49,5 @@ tags: - name: dest type: Endpoint role: - - Victim \ No newline at end of file + - Victim + automated_detection_testing: passed