From ed612666f06be7e8ac684af72d9faee2088fd246 Mon Sep 17 00:00:00 2001 From: tccontre Date: Wed, 25 Aug 2021 11:00:06 +0200 Subject: [PATCH 01/21] AD_Discovery_TR-789_2 --- .../adsisearcher_account_discovery.yml | 60 ++++++++++++++++ .../domain_account_discovery_with_dsquery.yml | 71 +++++++++++++++++++ .../domain_account_discovery_with_net_app.yml | 69 ++++++++++++++++++ .../domain_account_discovery_with_wmic.yml | 71 +++++++++++++++++++ .../endpoint/get_aduser_with_powershell.yml | 71 +++++++++++++++++++ ...et_aduser_with_powershell_script_block.yml | 59 +++++++++++++++ .../get_domainuser_with_powershell.yml | 69 ++++++++++++++++++ ...omainuser_with_powershell_script_block.yml | 61 ++++++++++++++++ .../getwmiobject_ds_user_with_powershell.yml | 71 +++++++++++++++++++ ...t_ds_user_with_powershell_script_block.yml | 61 ++++++++++++++++ .../adsisearcher_account_discovery.test.yml | 12 ++++ ...in_account_discovery_with_dsquery.test.yml | 12 ++++ ...in_account_discovery_with_net_app.test.yml | 12 ++++ ...omain_account_discovery_with_wmic.test.yml | 12 ++++ .../get_aduser_with_powershell.test.yml | 12 ++++ ...user_with_powershell_script_block.test.yml | 12 ++++ .../get_domainuser_with_powershell.test.yml | 12 ++++ ...user_with_powershell_script_block.test.yml | 12 ++++ ...wmiobject_ds_user_with_powershell.test.yml | 12 ++++ ...user_with_powershell_script_block.test.yml | 12 ++++ 20 files changed, 783 insertions(+) create mode 100644 detections/endpoint/adsisearcher_account_discovery.yml create mode 100644 detections/endpoint/domain_account_discovery_with_dsquery.yml create mode 100644 detections/endpoint/domain_account_discovery_with_net_app.yml create mode 100644 detections/endpoint/domain_account_discovery_with_wmic.yml create mode 100644 detections/endpoint/get_aduser_with_powershell.yml create mode 100644 detections/endpoint/get_aduser_with_powershell_script_block.yml create mode 100644 detections/endpoint/get_domainuser_with_powershell.yml create mode 100644 detections/endpoint/get_domainuser_with_powershell_script_block.yml create mode 100644 detections/endpoint/getwmiobject_ds_user_with_powershell.yml create mode 100644 detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml create mode 100644 tests/endpoint/adsisearcher_account_discovery.test.yml create mode 100644 tests/endpoint/domain_account_discovery_with_dsquery.test.yml create mode 100644 tests/endpoint/domain_account_discovery_with_net_app.test.yml create mode 100644 tests/endpoint/domain_account_discovery_with_wmic.test.yml create mode 100644 tests/endpoint/get_aduser_with_powershell.test.yml create mode 100644 tests/endpoint/get_aduser_with_powershell_script_block.test.yml create mode 100644 tests/endpoint/get_domainuser_with_powershell.test.yml create mode 100644 tests/endpoint/get_domainuser_with_powershell_script_block.test.yml create mode 100644 tests/endpoint/getwmiobject_ds_user_with_powershell.test.yml create mode 100644 tests/endpoint/getwmiobject_ds_user_with_powershell_script_block.test.yml diff --git a/detections/endpoint/adsisearcher_account_discovery.yml b/detections/endpoint/adsisearcher_account_discovery.yml new file mode 100644 index 0000000000..f41fa74301 --- /dev/null +++ b/detections/endpoint/adsisearcher_account_discovery.yml @@ -0,0 +1,60 @@ +name: AdsiSearcher Account Discovery +id: de7fcadc-04f3-11ec-a241-acde48001122 +version: 1 +date: '2021-08-24' +author: Teoderick Contreras, Splunk +type: batch +datamodel: +- Endpoint +description: This search is to detect a powershell command adsisearcher to do user enumeration to the active directory. + This command can be a normal query of a network admin but since the output of this is not so much structure and cannot give a concrete or + specific information that admin may look upon this is still a good TTP to alert some malicious activities. +search: '`powershell` EventCode=4104 Message = "*[adsisearcher]*" Message = "*objectcategory=user*" Message = "*.findAll()*" + | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `adsisearcher_account_discovery_filter`' +how_to_implement: The following Hunting analytic requires PowerShell operational logs to be imported. + Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, + or PowerShell Script Block Logging. +known_false_positives: not commonly seen as a normal command from network admin but possible noise may exist. +references: +- https://www.blackhillsinfosec.com/red-blue-purple/ +tags: + analytic_story: + - Active Directory Discovery + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log + kill_chain_phases: + - Reconnaissance + mitre_attack_id: + - T1087.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - Message + - ComputerName + - User + security_domain: endpoint + impact: 50 + confidence: 50 + # (impact * confidence)/100 + risk_score: 25 + context: + - source:endpoint + - stage:Reconnaissance + message: powershell process having commandline $Message$ for user enumeration + observable: + - name: ComputerName + type: Hostname + role: + - Victim + - name: User + type: User + role: + - Victim + \ No newline at end of file diff --git a/detections/endpoint/domain_account_discovery_with_dsquery.yml b/detections/endpoint/domain_account_discovery_with_dsquery.yml new file mode 100644 index 0000000000..3b6dc6a699 --- /dev/null +++ b/detections/endpoint/domain_account_discovery_with_dsquery.yml @@ -0,0 +1,71 @@ +name: Domain Account Discovery with Dsquery +id: b1a8ce04-04c2-11ec-bea7-acde48001122 +version: 1 +date: '2021-08-24' +author: Teoderick Contreras, Splunk +type: Hunt +datamodel: +- Endpoint +description: This search is to detect a suspicious process commandline of dsquery for enumerating users. + This technique is commonly in attacker and red team to recon on users in targetted machine. + This command can also be used by network administrator but not by a normal user. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where Processes.process_name="dsquery.exe" AND Processes.process = "*user*" + by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + Processes.parent_process_name | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `domain_account_discovery_with_dsquery_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: network administrator may use this command but not commonly seen used by a user. +references: +- https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm +tags: + analytic_story: + - Active Directory Discovery + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log + kill_chain_phases: + - Reconnaissance + mitre_attack_id: + - T1087.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_id + - Processes.parent_process_name + security_domain: endpoint + impact: 50 + confidence: 50 + # (impact * confidence)/100 + risk_score: 25 + context: + - Source:Endpoint + - Stage:Reconnaissance + message: an instance of process $process_name$ with commandline $process$ in $dest$ + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + \ No newline at end of file diff --git a/detections/endpoint/domain_account_discovery_with_net_app.yml b/detections/endpoint/domain_account_discovery_with_net_app.yml new file mode 100644 index 0000000000..8cc9121553 --- /dev/null +++ b/detections/endpoint/domain_account_discovery_with_net_app.yml @@ -0,0 +1,69 @@ +name: Domain Account Discovery With Net App +id: 98f6a534-04c2-11ec-96b2-acde48001122 +version: 1 +date: '2021-08-24' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This search is to detect a process command line for AD discovery. This techique is using the windows built in net.exe application + to query AD users in the targetted machine. This techique was seen in several malware as part of there recon and can be a good pivot of analysis. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where (Processes.process_name="net.exe" OR Processes.process_name="net1.exe") AND Processes.process = "* user*" AND Processes.process = "*/do*" + by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + Processes.parent_process_name | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `domain_account_discovery_with_net_app_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: network operator can execute this command +references: +- https://docs.microsoft.com/en-us/defender-for-identity/playbook-domain-dominance +tags: + analytic_story: + - Active Directory Discovery + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log + kill_chain_phases: + - Reconnaissance + mitre_attack_id: + - T1087.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_id + - Processes.parent_process_name + security_domain: endpoint + impact: 50 + confidence: 50 + # (impact * confidence)/100 + risk_score: 25 + context: + - Source:Endpoint + - Stage:Reconnaissance + message: an instance of process $process_name$ with commandline $process$ in $dest$ + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process \ No newline at end of file diff --git a/detections/endpoint/domain_account_discovery_with_wmic.yml b/detections/endpoint/domain_account_discovery_with_wmic.yml new file mode 100644 index 0000000000..f0315614a3 --- /dev/null +++ b/detections/endpoint/domain_account_discovery_with_wmic.yml @@ -0,0 +1,71 @@ +name: Domain Account Discovery with Wmic +id: 383572e0-04c5-11ec-bdcc-acde48001122 +version: 1 +date: '2021-08-24' +author: Teoderick Contreras, Splunk +type: batch +datamodel: +- Endpoint +description: This search is to detect a wmic command for enumerating user in active directory. + This technique was commonly used in pentesting, red-team and also by some attacker to map all user in the targetted host. + This search may also catch this type of query made by network admin but not common in all the user in the network. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where Processes.process_name="wmic.exe" AND Processes.process = "*/NAMESPACE:\\\\root\\directory\\ldap*" AND Processes.process = "*ds_user*" AND Processes.process = "*GET*" AND Processes.process = "*ds_samaccountname*" + by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + Processes.parent_process_name | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `domain_account_discovery_with_wmic_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: network admin may execute this command for listing users. +references: +- https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm +tags: + analytic_story: + - Active Directory Discovery + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log + kill_chain_phases: + - Reconnaissance + mitre_attack_id: + - T1087.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_id + - Processes.parent_process_name + security_domain: endpoint + impact: 50 + confidence: 50 + # (impact * confidence)/100 + risk_score: 25 + context: + - Source:Endpoint + - Stage:Reconnaissance + message: an instance of process $process_name$ with commandline $process$ in $dest$ + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + \ No newline at end of file diff --git a/detections/endpoint/get_aduser_with_powershell.yml b/detections/endpoint/get_aduser_with_powershell.yml new file mode 100644 index 0000000000..2849c15766 --- /dev/null +++ b/detections/endpoint/get_aduser_with_powershell.yml @@ -0,0 +1,71 @@ +name: Get_ADUser with PowerShell +id: 0b6ee3f4-04e3-11ec-a87d-acde48001122 +version: 1 +date: '2021-08-24' +author: Teoderick Contreras, Splunk +type: Hunt +datamodel: +- Endpoint +description: This search is to detect a suspicious commandline that commonly uses for enumerating users in active directory. + This technique can be a good indicator to hunt further TTPs to the machine to check further anomalies. Since this is a hunt query expect + some noise from administrator or some IT within the network that may use this command. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*Get-ADUser*" AND Processes.process = "*-filter*" + by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + Processes.parent_process_name | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `get_aduser_with_powershell_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: network admin may use this command. +references: +- https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm +tags: + analytic_story: + - Active Directory Discovery + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log + kill_chain_phases: + - Reconnaissance + mitre_attack_id: + - T1087.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_id + - Processes.parent_process_name + security_domain: endpoint + impact: 50 + confidence: 50 + # (impact * confidence)/100 + risk_score: 25 + context: + - Source:Endpoint + - Stage:Reconnaissance + message: an instance of process $process_name$ with commandline $process$ in $dest$ + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + \ No newline at end of file diff --git a/detections/endpoint/get_aduser_with_powershell_script_block.yml b/detections/endpoint/get_aduser_with_powershell_script_block.yml new file mode 100644 index 0000000000..9fd21ba2ea --- /dev/null +++ b/detections/endpoint/get_aduser_with_powershell_script_block.yml @@ -0,0 +1,59 @@ +name: Get_ADUser with PowerShell Script Block +id: 21432e40-04f4-11ec-b7e6-acde48001122 +version: 1 +date: '2021-08-24' +author: Teoderick Contreras, Splunk +type: Hunt +datamodel: +- Endpoint +description: This search is to detect a powershell command get-aduser function to do user enumeration to the active directory. + This command can be a normal query of a network admin but since the output of this is not so much structure and cannot give a concrete or + specific information that admin may look upon this is still a good TTP to alert some malicious activities. +search: '`powershell` EventCode=4104 Message = "*get-aduser*" Message = "*-filter*" + | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `get_aduser_with_powershell_script_block_filter`' +how_to_implement: The following Hunting analytic requires PowerShell operational logs to be imported. + Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, + or PowerShell Script Block Logging. +known_false_positives: network admin may use this command and other IT operator to check AD users. +references: +- https://www.blackhillsinfosec.com/red-blue-purple/ +tags: + analytic_story: + - Active Directory Discovery + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log + kill_chain_phases: + - Reconnaissance + mitre_attack_id: + - T1087.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - Message + - ComputerName + - User + security_domain: endpoint + impact: 50 + confidence: 50 + # (impact * confidence)/100 + risk_score: 25 + context: + - source:endpoint + - stage:Reconnaissance + message: powershell process having commandline $Message$ for user enumeration + observable: + - name: ComputerName + type: Hostname + role: + - Victim + - name: User + type: User + role: + - Victim \ No newline at end of file diff --git a/detections/endpoint/get_domainuser_with_powershell.yml b/detections/endpoint/get_domainuser_with_powershell.yml new file mode 100644 index 0000000000..a805a03eaf --- /dev/null +++ b/detections/endpoint/get_domainuser_with_powershell.yml @@ -0,0 +1,69 @@ +name: Get_DomainUser with PowerShell +id: 9a5a41d6-04e7-11ec-923c-acde48001122 +version: 1 +date: '2021-08-24' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This search is to detect a cmdlet Get-DomainUser that are common on powerview or powersploit tool. + This cmdlet is used to recon on the targetted machine to enumerate all users in active directory. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*Get-DomainUser*" + by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + Processes.parent_process_name | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `get_domainuser_with_powershell_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: unknown +references: +- https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainUser/ +tags: + analytic_story: + - Active Directory Discovery + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log + kill_chain_phases: + - Reconnaissance + mitre_attack_id: + - T1087.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_id + - Processes.parent_process_name + security_domain: endpoint + impact: 50 + confidence: 50 + # (impact * confidence)/100 + risk_score: 25 + context: + - Source:Endpoint + - Stage:Reconnaissance + message: an instance of process $process_name$ with commandline $process$ in $dest$ + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process \ No newline at end of file diff --git a/detections/endpoint/get_domainuser_with_powershell_script_block.yml b/detections/endpoint/get_domainuser_with_powershell_script_block.yml new file mode 100644 index 0000000000..5ec13cf5c8 --- /dev/null +++ b/detections/endpoint/get_domainuser_with_powershell_script_block.yml @@ -0,0 +1,61 @@ +name: Get DomainUser with PowerShell Script Block +id: 61994268-04f4-11ec-865c-acde48001122 +version: 1 +date: '2021-08-24' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: his search is to detect a powershell command Get-DomainUser to do user enumeration to the active directory. + This command is function seen in powerspoit and powerview tool that are designed to pentest active directory or domain controller for possible attack. + This is a good TTP for alerting SOC if there is a pentest or recon happening on the system. try to look for lateral movement technique or credential + dumping techniques in the system. +search: '`powershell` EventCode=4104 Message = "*Get-DomainUser*" + | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `get_domainuser_with_powershell_script_block_filter`' +how_to_implement: The following Hunting analytic requires PowerShell operational logs to be imported. + Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, + or PowerShell Script Block Logging. +known_false_positives: unknown +references: +- https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainUser/ +tags: + analytic_story: + - Active Directory Discovery + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log + kill_chain_phases: + - Reconnaissance + mitre_attack_id: + - T1087.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - Message + - ComputerName + - User + security_domain: endpoint + impact: 50 + confidence: 50 + # (impact * confidence)/100 + risk_score: 25 + context: + - source:endpoint + - stage:Reconnaissance + message: powershell process having commandline $Message$ for user enumeration + observable: + - name: ComputerName + type: Hostname + role: + - Victim + - name: User + type: User + role: + - Victim + \ No newline at end of file diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml new file mode 100644 index 0000000000..42ea86e85d --- /dev/null +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml @@ -0,0 +1,71 @@ +name: GetWmiObject DS_User with PowerShell +id: 22d3b118-04df-11ec-8fa3-acde48001122 +version: 1 +date: '2021-08-24' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This search is to detect a suspicious execution wmi process that enumerate user in active directory. + This technique can be used by attacker and pentester to mapped all the users as part of its recon to the targetted host. + Network Admin may seen executing this command but not often and also not common to see in user events. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*get-wmiobject*" AND Processes.process = "*ds_user*" AND Processes.process = "*root\\directory\\ldap*" AND Processes.process = "*-namespace*" + by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + Processes.parent_process_name | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `getwmiobject_ds_user_with_powershell_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: network admin may execute this command. +references: +- https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm +tags: + analytic_story: + - Active Directory Discovery + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log + kill_chain_phases: + - Reconnaissance + mitre_attack_id: + - T1087.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_id + - Processes.parent_process_name + security_domain: endpoint + impact: 50 + confidence: 50 + # (impact * confidence)/100 + risk_score: 25 + context: + - Source:Endpoint + - Stage:Reconnaissance + message: an instance of process $process_name$ with commandline $process$ in $dest$ + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + \ No newline at end of file diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml new file mode 100644 index 0000000000..13664a1d18 --- /dev/null +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml @@ -0,0 +1,61 @@ +name: GetWmiObject DS_User with PowerShell Script Block +id: fabd364e-04f3-11ec-b34b-acde48001122 +version: 1 +date: '2021-08-24' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This search is to detect a powershell command get-wmiobject function to do user enumeration to the active directory. + This command can be a normal query of a network admin but since the output of this is not so much structure and cannot give a concrete or + specific information that admin may look upon this is still a good TTP to alert some malicious activities. +search: '`powershell` EventCode=4104 Message = "*get-wmiobject*" Message = "*ds_user*" Message = "*-namespace*" Message = "*root\\directory\\ldap*" + | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `getwmiobject_ds_user_with_powershell_script_block_filter`' +how_to_implement: he following Hunting analytic requires PowerShell operational logs to be imported. + Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, + or PowerShell Script Block Logging. +known_false_positives: not commonly seen as a normal command from network admin but possible noise may exist. +references: +- https://www.blackhillsinfosec.com/red-blue-purple/ +- https://docs.microsoft.com/en-us/windows/win32/wmisdk/describing-the-ldap-namespace +tags: + analytic_story: + - Active Directory Discovery + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log + kill_chain_phases: + - Reconnaissance + mitre_attack_id: + - T1087.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - Message + - ComputerName + - User + security_domain: endpoint + impact: 50 + confidence: 50 + # (impact * confidence)/100 + risk_score: 25 + context: + - source:endpoint + - stage:Reconnaissance + message: powershell process having commandline $Message$ for user enumeration + observable: + - name: ComputerName + type: Hostname + role: + - Victim + - name: User + type: User + role: + - Victim + \ No newline at end of file diff --git a/tests/endpoint/adsisearcher_account_discovery.test.yml b/tests/endpoint/adsisearcher_account_discovery.test.yml new file mode 100644 index 0000000000..b727b66bb5 --- /dev/null +++ b/tests/endpoint/adsisearcher_account_discovery.test.yml @@ -0,0 +1,12 @@ +name: AdsiSearcher Account Discovery Unit Test +tests: +- name: AdsiSearcher Account Discovery + file: endpoint/adsisearcher_account_discovery.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-powershell.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log + source: WinEventLog:Microsoft-Windows-PowerShell/Operational + sourcetype: WinEventLog \ No newline at end of file diff --git a/tests/endpoint/domain_account_discovery_with_dsquery.test.yml b/tests/endpoint/domain_account_discovery_with_dsquery.test.yml new file mode 100644 index 0000000000..998b007966 --- /dev/null +++ b/tests/endpoint/domain_account_discovery_with_dsquery.test.yml @@ -0,0 +1,12 @@ +name: Domain Account Discovery with Dsquery Unit Test +tests: +- name: Domain Account Discovery with Dsquery + file: endpoint/domain_account_discovery_with_dsquery.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/domain_account_discovery_with_net_app.test.yml b/tests/endpoint/domain_account_discovery_with_net_app.test.yml new file mode 100644 index 0000000000..4a78b48b43 --- /dev/null +++ b/tests/endpoint/domain_account_discovery_with_net_app.test.yml @@ -0,0 +1,12 @@ +name: Domain Account Discovery With Net App Unit Test +tests: +- name: Domain Account Discovery With Net App + file: endpoint/domain_account_discovery_with_net_app.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/domain_account_discovery_with_wmic.test.yml b/tests/endpoint/domain_account_discovery_with_wmic.test.yml new file mode 100644 index 0000000000..0cd381fae0 --- /dev/null +++ b/tests/endpoint/domain_account_discovery_with_wmic.test.yml @@ -0,0 +1,12 @@ +name: Domain Account Discovery with Wmic Unit Test +tests: +- name: Domain Account Discovery with Wmic + file: endpoint/domain_account_discovery_with_wmic.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/get_aduser_with_powershell.test.yml b/tests/endpoint/get_aduser_with_powershell.test.yml new file mode 100644 index 0000000000..e849e85044 --- /dev/null +++ b/tests/endpoint/get_aduser_with_powershell.test.yml @@ -0,0 +1,12 @@ +name: Get_ADUser with PowerShell Unit Test +tests: +- name: Get_ADUser with PowerShell + file: endpoint/get_aduser_with_powershell.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/get_aduser_with_powershell_script_block.test.yml b/tests/endpoint/get_aduser_with_powershell_script_block.test.yml new file mode 100644 index 0000000000..551e9e029e --- /dev/null +++ b/tests/endpoint/get_aduser_with_powershell_script_block.test.yml @@ -0,0 +1,12 @@ +name: Get_ADUser with PowerShell Script Block Unit Test +tests: +- name: Get_ADUser with PowerShell Script Block + file: endpoint/get_aduser_with_powershell_script_block.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-powershell.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log + source: WinEventLog:Microsoft-Windows-PowerShell/Operational + sourcetype: WinEventLog \ No newline at end of file diff --git a/tests/endpoint/get_domainuser_with_powershell.test.yml b/tests/endpoint/get_domainuser_with_powershell.test.yml new file mode 100644 index 0000000000..9f537cc3bc --- /dev/null +++ b/tests/endpoint/get_domainuser_with_powershell.test.yml @@ -0,0 +1,12 @@ +name: Get_DomainUser with PowerShell Unit Test +tests: +- name: Get_DomainUser with PowerShell + file: endpoint/get_domainuser_with_powershell.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/get_domainuser_with_powershell_script_block.test.yml b/tests/endpoint/get_domainuser_with_powershell_script_block.test.yml new file mode 100644 index 0000000000..ba153d19dd --- /dev/null +++ b/tests/endpoint/get_domainuser_with_powershell_script_block.test.yml @@ -0,0 +1,12 @@ +name: Get DomainUser with PowerShell Script Block Unit Test +tests: +- name: Get DomainUser with PowerShell Script Block + file: detections/endpoint/get_domainuser_with_powershell_script_block.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: UPDATE_FILE_NAME + data: UPDATE_DATASET_URL + source: UPDATE_SPLUNK_SOURCE + sourcetype: UPDATE_SPLUNK_SOURCETYPE \ No newline at end of file diff --git a/tests/endpoint/getwmiobject_ds_user_with_powershell.test.yml b/tests/endpoint/getwmiobject_ds_user_with_powershell.test.yml new file mode 100644 index 0000000000..67502e39bf --- /dev/null +++ b/tests/endpoint/getwmiobject_ds_user_with_powershell.test.yml @@ -0,0 +1,12 @@ +name: GetWmiObject DS_User with PowerShell Unit Test +tests: +- name: GetWmiObject DS_User with PowerShell + file: endpoint/getwmiobject_ds_user_with_powershell.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/getwmiobject_ds_user_with_powershell_script_block.test.yml b/tests/endpoint/getwmiobject_ds_user_with_powershell_script_block.test.yml new file mode 100644 index 0000000000..b4f5151cad --- /dev/null +++ b/tests/endpoint/getwmiobject_ds_user_with_powershell_script_block.test.yml @@ -0,0 +1,12 @@ +name: GetWmiObject DS_User with PowerShell Script Block Unit Test +tests: +- name: GetWmiObject DS_User with PowerShell Script Block + file: endpoint/getwmiobject_ds_user_with_powershell_script_block.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-powershell.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log + source: WinEventLog:Microsoft-Windows-PowerShell/Operational + sourcetype: WinEventLog \ No newline at end of file From ef362396b2291f367df6d935f803c9162310730c Mon Sep 17 00:00:00 2001 From: tccontre Date: Wed, 25 Aug 2021 17:16:13 +0200 Subject: [PATCH 02/21] AD_Discovery_TR-789_2 --- ...et_domainuser_with_powershell_script_block.test.yml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/tests/endpoint/get_domainuser_with_powershell_script_block.test.yml b/tests/endpoint/get_domainuser_with_powershell_script_block.test.yml index ba153d19dd..1b74cec450 100644 --- a/tests/endpoint/get_domainuser_with_powershell_script_block.test.yml +++ b/tests/endpoint/get_domainuser_with_powershell_script_block.test.yml @@ -1,12 +1,12 @@ name: Get DomainUser with PowerShell Script Block Unit Test tests: - name: Get DomainUser with PowerShell Script Block - file: detections/endpoint/get_domainuser_with_powershell_script_block.yml + file: endpoint/get_domainuser_with_powershell_script_block.yml pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' attack_data: - - file_name: UPDATE_FILE_NAME - data: UPDATE_DATASET_URL - source: UPDATE_SPLUNK_SOURCE - sourcetype: UPDATE_SPLUNK_SOURCETYPE \ No newline at end of file + - file_name: windows-powershell.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.002/AD_discovery/windows-powershell.log + source: WinEventLog:Microsoft-Windows-PowerShell/Operational + sourcetype: WinEventLog \ No newline at end of file From b371f23f6a60bd642e9dd917bb45eb062528531c Mon Sep 17 00:00:00 2001 From: tccontre Date: Wed, 25 Aug 2021 17:51:44 +0200 Subject: [PATCH 03/21] AD_Discovery_TR-789_2 --- detections/endpoint/adsisearcher_account_discovery.yml | 2 +- detections/endpoint/domain_account_discovery_with_dsquery.yml | 2 +- detections/endpoint/domain_account_discovery_with_wmic.yml | 2 +- detections/endpoint/get_aduser_with_powershell.yml | 2 +- detections/endpoint/get_aduser_with_powershell_script_block.yml | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) diff --git a/detections/endpoint/adsisearcher_account_discovery.yml b/detections/endpoint/adsisearcher_account_discovery.yml index f41fa74301..3ce89c3cd2 100644 --- a/detections/endpoint/adsisearcher_account_discovery.yml +++ b/detections/endpoint/adsisearcher_account_discovery.yml @@ -3,7 +3,7 @@ id: de7fcadc-04f3-11ec-a241-acde48001122 version: 1 date: '2021-08-24' author: Teoderick Contreras, Splunk -type: batch +type: TTP datamodel: - Endpoint description: This search is to detect a powershell command adsisearcher to do user enumeration to the active directory. diff --git a/detections/endpoint/domain_account_discovery_with_dsquery.yml b/detections/endpoint/domain_account_discovery_with_dsquery.yml index 3b6dc6a699..50740f59d8 100644 --- a/detections/endpoint/domain_account_discovery_with_dsquery.yml +++ b/detections/endpoint/domain_account_discovery_with_dsquery.yml @@ -3,7 +3,7 @@ id: b1a8ce04-04c2-11ec-bea7-acde48001122 version: 1 date: '2021-08-24' author: Teoderick Contreras, Splunk -type: Hunt +type: Hunting datamodel: - Endpoint description: This search is to detect a suspicious process commandline of dsquery for enumerating users. diff --git a/detections/endpoint/domain_account_discovery_with_wmic.yml b/detections/endpoint/domain_account_discovery_with_wmic.yml index f0315614a3..9c62578cd5 100644 --- a/detections/endpoint/domain_account_discovery_with_wmic.yml +++ b/detections/endpoint/domain_account_discovery_with_wmic.yml @@ -3,7 +3,7 @@ id: 383572e0-04c5-11ec-bdcc-acde48001122 version: 1 date: '2021-08-24' author: Teoderick Contreras, Splunk -type: batch +type: TTP datamodel: - Endpoint description: This search is to detect a wmic command for enumerating user in active directory. diff --git a/detections/endpoint/get_aduser_with_powershell.yml b/detections/endpoint/get_aduser_with_powershell.yml index 2849c15766..b37aebd272 100644 --- a/detections/endpoint/get_aduser_with_powershell.yml +++ b/detections/endpoint/get_aduser_with_powershell.yml @@ -3,7 +3,7 @@ id: 0b6ee3f4-04e3-11ec-a87d-acde48001122 version: 1 date: '2021-08-24' author: Teoderick Contreras, Splunk -type: Hunt +type: Hunting datamodel: - Endpoint description: This search is to detect a suspicious commandline that commonly uses for enumerating users in active directory. diff --git a/detections/endpoint/get_aduser_with_powershell_script_block.yml b/detections/endpoint/get_aduser_with_powershell_script_block.yml index 9fd21ba2ea..5ddb228220 100644 --- a/detections/endpoint/get_aduser_with_powershell_script_block.yml +++ b/detections/endpoint/get_aduser_with_powershell_script_block.yml @@ -3,7 +3,7 @@ id: 21432e40-04f4-11ec-b7e6-acde48001122 version: 1 date: '2021-08-24' author: Teoderick Contreras, Splunk -type: Hunt +type: Hunting datamodel: - Endpoint description: This search is to detect a powershell command get-aduser function to do user enumeration to the active directory. From 6bfad13aae72ce79d095dcc367c0b5a69204afe7 Mon Sep 17 00:00:00 2001 From: tccontre Date: Wed, 25 Aug 2021 17:57:13 +0200 Subject: [PATCH 04/21] AD_Discovery_TR-789_2 --- detections/endpoint/get_aduser_with_powershell.yml | 2 +- .../endpoint/get_aduser_with_powershell_script_block.yml | 2 +- detections/endpoint/get_domainuser_with_powershell.yml | 2 +- .../getwmiobject_ds_user_with_powershell_script_block.yml | 2 +- tests/endpoint/get_aduser_with_powershell.test.yml | 4 ++-- .../endpoint/get_aduser_with_powershell_script_block.test.yml | 4 ++-- tests/endpoint/get_domainuser_with_powershell.test.yml | 4 ++-- tests/endpoint/getwmiobject_ds_user_with_powershell.test.yml | 4 ++-- ...getwmiobject_ds_user_with_powershell_script_block.test.yml | 4 ++-- 9 files changed, 14 insertions(+), 14 deletions(-) diff --git a/detections/endpoint/get_aduser_with_powershell.yml b/detections/endpoint/get_aduser_with_powershell.yml index b37aebd272..5dd526e6be 100644 --- a/detections/endpoint/get_aduser_with_powershell.yml +++ b/detections/endpoint/get_aduser_with_powershell.yml @@ -1,4 +1,4 @@ -name: Get_ADUser with PowerShell +name: Get ADUser with PowerShell id: 0b6ee3f4-04e3-11ec-a87d-acde48001122 version: 1 date: '2021-08-24' diff --git a/detections/endpoint/get_aduser_with_powershell_script_block.yml b/detections/endpoint/get_aduser_with_powershell_script_block.yml index 5ddb228220..995401212c 100644 --- a/detections/endpoint/get_aduser_with_powershell_script_block.yml +++ b/detections/endpoint/get_aduser_with_powershell_script_block.yml @@ -1,4 +1,4 @@ -name: Get_ADUser with PowerShell Script Block +name: Get ADUser with PowerShell Script Block id: 21432e40-04f4-11ec-b7e6-acde48001122 version: 1 date: '2021-08-24' diff --git a/detections/endpoint/get_domainuser_with_powershell.yml b/detections/endpoint/get_domainuser_with_powershell.yml index a805a03eaf..531a62f336 100644 --- a/detections/endpoint/get_domainuser_with_powershell.yml +++ b/detections/endpoint/get_domainuser_with_powershell.yml @@ -1,4 +1,4 @@ -name: Get_DomainUser with PowerShell +name: Get DomainUser with PowerShell id: 9a5a41d6-04e7-11ec-923c-acde48001122 version: 1 date: '2021-08-24' diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml index 13664a1d18..c344da01df 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml @@ -1,4 +1,4 @@ -name: GetWmiObject DS_User with PowerShell Script Block +name: GetWmiObject DS User with PowerShell Script Block id: fabd364e-04f3-11ec-b34b-acde48001122 version: 1 date: '2021-08-24' diff --git a/tests/endpoint/get_aduser_with_powershell.test.yml b/tests/endpoint/get_aduser_with_powershell.test.yml index e849e85044..461b37924d 100644 --- a/tests/endpoint/get_aduser_with_powershell.test.yml +++ b/tests/endpoint/get_aduser_with_powershell.test.yml @@ -1,6 +1,6 @@ -name: Get_ADUser with PowerShell Unit Test +name: Get ADUser with PowerShell Unit Test tests: -- name: Get_ADUser with PowerShell +- name: Get ADUser with PowerShell file: endpoint/get_aduser_with_powershell.yml pass_condition: '| stats count | where count > 0' earliest_time: '-24h' diff --git a/tests/endpoint/get_aduser_with_powershell_script_block.test.yml b/tests/endpoint/get_aduser_with_powershell_script_block.test.yml index 551e9e029e..31858a93c2 100644 --- a/tests/endpoint/get_aduser_with_powershell_script_block.test.yml +++ b/tests/endpoint/get_aduser_with_powershell_script_block.test.yml @@ -1,6 +1,6 @@ -name: Get_ADUser with PowerShell Script Block Unit Test +name: Get ADUser with PowerShell Script Block Unit Test tests: -- name: Get_ADUser with PowerShell Script Block +- name: Get ADUser with PowerShell Script Block file: endpoint/get_aduser_with_powershell_script_block.yml pass_condition: '| stats count | where count > 0' earliest_time: '-24h' diff --git a/tests/endpoint/get_domainuser_with_powershell.test.yml b/tests/endpoint/get_domainuser_with_powershell.test.yml index 9f537cc3bc..0abe5e6722 100644 --- a/tests/endpoint/get_domainuser_with_powershell.test.yml +++ b/tests/endpoint/get_domainuser_with_powershell.test.yml @@ -1,6 +1,6 @@ -name: Get_DomainUser with PowerShell Unit Test +name: Get DomainUser with PowerShell Unit Test tests: -- name: Get_DomainUser with PowerShell +- name: Get DomainUser with PowerShell file: endpoint/get_domainuser_with_powershell.yml pass_condition: '| stats count | where count > 0' earliest_time: '-24h' diff --git a/tests/endpoint/getwmiobject_ds_user_with_powershell.test.yml b/tests/endpoint/getwmiobject_ds_user_with_powershell.test.yml index 67502e39bf..6637d3263c 100644 --- a/tests/endpoint/getwmiobject_ds_user_with_powershell.test.yml +++ b/tests/endpoint/getwmiobject_ds_user_with_powershell.test.yml @@ -1,6 +1,6 @@ -name: GetWmiObject DS_User with PowerShell Unit Test +name: GetWmiObject DS User with PowerShell Unit Test tests: -- name: GetWmiObject DS_User with PowerShell +- name: GetWmiObject DS User with PowerShell file: endpoint/getwmiobject_ds_user_with_powershell.yml pass_condition: '| stats count | where count > 0' earliest_time: '-24h' diff --git a/tests/endpoint/getwmiobject_ds_user_with_powershell_script_block.test.yml b/tests/endpoint/getwmiobject_ds_user_with_powershell_script_block.test.yml index b4f5151cad..89c7c1a25e 100644 --- a/tests/endpoint/getwmiobject_ds_user_with_powershell_script_block.test.yml +++ b/tests/endpoint/getwmiobject_ds_user_with_powershell_script_block.test.yml @@ -1,6 +1,6 @@ -name: GetWmiObject DS_User with PowerShell Script Block Unit Test +name: GetWmiObject DS User with PowerShell Script Block Unit Test tests: -- name: GetWmiObject DS_User with PowerShell Script Block +- name: GetWmiObject DS User with PowerShell Script Block file: endpoint/getwmiobject_ds_user_with_powershell_script_block.yml pass_condition: '| stats count | where count > 0' earliest_time: '-24h' From b32a41893e54cc67e96b62b265c39d59ca8c1da6 Mon Sep 17 00:00:00 2001 From: tccontre Date: Wed, 25 Aug 2021 18:04:43 +0200 Subject: [PATCH 05/21] AD_Discovery_TR-789_2 --- detections/endpoint/getwmiobject_ds_user_with_powershell.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml index 42ea86e85d..638591a31b 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml @@ -1,4 +1,4 @@ -name: GetWmiObject DS_User with PowerShell +name: GetWmiObject DS User with PowerShell id: 22d3b118-04df-11ec-8fa3-acde48001122 version: 1 date: '2021-08-24' From c031c62510b4f1438b3c39b2c09369cd0c3fe644 Mon Sep 17 00:00:00 2001 From: root Date: Mon, 30 Aug 2021 08:27:33 +0000 Subject: [PATCH 06/21] Added detection testing service results inAdsiSearcher Account Discovery --- .../adsisearcher_account_discovery.yml | 33 ++++++++++--------- 1 file changed, 17 insertions(+), 16 deletions(-) diff --git a/detections/endpoint/adsisearcher_account_discovery.yml b/detections/endpoint/adsisearcher_account_discovery.yml index 3ce89c3cd2..fccf6eb36a 100644 --- a/detections/endpoint/adsisearcher_account_discovery.yml +++ b/detections/endpoint/adsisearcher_account_discovery.yml @@ -6,18 +6,20 @@ author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint -description: This search is to detect a powershell command adsisearcher to do user enumeration to the active directory. - This command can be a normal query of a network admin but since the output of this is not so much structure and cannot give a concrete or - specific information that admin may look upon this is still a good TTP to alert some malicious activities. -search: '`powershell` EventCode=4104 Message = "*[adsisearcher]*" Message = "*objectcategory=user*" Message = "*.findAll()*" - | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `adsisearcher_account_discovery_filter`' -how_to_implement: The following Hunting analytic requires PowerShell operational logs to be imported. - Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, - or PowerShell Script Block Logging. -known_false_positives: not commonly seen as a normal command from network admin but possible noise may exist. +description: This search is to detect a powershell command adsisearcher to do user + enumeration to the active directory. This command can be a normal query of a network + admin but since the output of this is not so much structure and cannot give a concrete + or specific information that admin may look upon this is still a good TTP to alert + some malicious activities. +search: '`powershell` EventCode=4104 Message = "*[adsisearcher]*" Message = "*objectcategory=user*" + Message = "*.findAll()*" | stats count min(_time) as firstTime max(_time) as lastTime + by EventCode Message ComputerName User | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `adsisearcher_account_discovery_filter`' +how_to_implement: The following Hunting analytic requires PowerShell operational logs + to be imported. Modify the powershell macro as needed to match the sourcetype or + add index. This analytic is specific to 4104, or PowerShell Script Block Logging. +known_false_positives: not commonly seen as a normal command from network admin but + possible noise may exist. references: - https://www.blackhillsinfosec.com/red-blue-purple/ tags: @@ -36,13 +38,12 @@ tags: required_fields: - _time - EventCode - - Message - - ComputerName + - Message + - ComputerName - User security_domain: endpoint impact: 50 confidence: 50 - # (impact * confidence)/100 risk_score: 25 context: - source:endpoint @@ -57,4 +58,4 @@ tags: type: User role: - Victim - \ No newline at end of file + automated_detection_testing: passed From 12528c9dd3388d59d9d29c7d744e976ded58d227 Mon Sep 17 00:00:00 2001 From: root Date: Mon, 30 Aug 2021 08:31:02 +0000 Subject: [PATCH 07/21] Added detection testing service results inDomain Account Discovery with Dsquery --- .../domain_account_discovery_with_dsquery.yml | 42 +++++++++---------- 1 file changed, 21 insertions(+), 21 deletions(-) diff --git a/detections/endpoint/domain_account_discovery_with_dsquery.yml b/detections/endpoint/domain_account_discovery_with_dsquery.yml index 50740f59d8..f6cb42ade4 100644 --- a/detections/endpoint/domain_account_discovery_with_dsquery.yml +++ b/detections/endpoint/domain_account_discovery_with_dsquery.yml @@ -6,21 +6,22 @@ author: Teoderick Contreras, Splunk type: Hunting datamodel: - Endpoint -description: This search is to detect a suspicious process commandline of dsquery for enumerating users. - This technique is commonly in attacker and red team to recon on users in targetted machine. - This command can also be used by network administrator but not by a normal user. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes - where Processes.process_name="dsquery.exe" AND Processes.process = "*user*" - by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id - Processes.parent_process_name | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `domain_account_discovery_with_dsquery_filter`' +description: This search is to detect a suspicious process commandline of dsquery + for enumerating users. This technique is commonly in attacker and red team to recon + on users in targetted machine. This command can also be used by network administrator + but not by a normal user. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name="dsquery.exe" + AND Processes.process = "*user*" by Processes.dest Processes.user Processes.parent_process + Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `domain_account_discovery_with_dsquery_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -known_false_positives: network administrator may use this command but not commonly seen used by a user. + Sysmon TA. +known_false_positives: network administrator may use this command but not commonly + seen used by a user. references: - https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm tags: @@ -38,18 +39,17 @@ tags: - Splunk Cloud required_fields: - _time - - Processes.dest - - Processes.user - - Processes.parent_process - - Processes.process_name - - Processes.process - - Processes.process_id + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id - Processes.parent_process_id - Processes.parent_process_name security_domain: endpoint impact: 50 - confidence: 50 - # (impact * confidence)/100 + confidence: 50 risk_score: 25 context: - Source:Endpoint @@ -68,4 +68,4 @@ tags: type: Parent Process role: - Parent Process - \ No newline at end of file + automated_detection_testing: passed From 2dfe045c03ea9a427c2657142ab8f4fc0c3bef71 Mon Sep 17 00:00:00 2001 From: root Date: Mon, 30 Aug 2021 08:47:33 +0000 Subject: [PATCH 08/21] Added detection testing service results inDomain Account Discovery With Net App --- .../domain_account_discovery_with_net_app.yml | 38 ++++++++++--------- 1 file changed, 20 insertions(+), 18 deletions(-) diff --git a/detections/endpoint/domain_account_discovery_with_net_app.yml b/detections/endpoint/domain_account_discovery_with_net_app.yml index 8cc9121553..957e770258 100644 --- a/detections/endpoint/domain_account_discovery_with_net_app.yml +++ b/detections/endpoint/domain_account_discovery_with_net_app.yml @@ -6,19 +6,21 @@ author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint -description: This search is to detect a process command line for AD discovery. This techique is using the windows built in net.exe application - to query AD users in the targetted machine. This techique was seen in several malware as part of there recon and can be a good pivot of analysis. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes - where (Processes.process_name="net.exe" OR Processes.process_name="net1.exe") AND Processes.process = "* user*" AND Processes.process = "*/do*" - by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id - Processes.parent_process_name | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` +description: This search is to detect a process command line for AD discovery. This + techique is using the windows built in net.exe application to query AD users in + the targetted machine. This techique was seen in several malware as part of there + recon and can be a good pivot of analysis. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="net.exe" + OR Processes.process_name="net1.exe") AND Processes.process = "* user*" AND Processes.process + = "*/do*" by Processes.dest Processes.user Processes.parent_process Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `domain_account_discovery_with_net_app_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. + Sysmon TA. known_false_positives: network operator can execute this command references: - https://docs.microsoft.com/en-us/defender-for-identity/playbook-domain-dominance @@ -37,18 +39,17 @@ tags: - Splunk Cloud required_fields: - _time - - Processes.dest - - Processes.user - - Processes.parent_process - - Processes.process_name - - Processes.process - - Processes.process_id + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id - Processes.parent_process_id - Processes.parent_process_name security_domain: endpoint impact: 50 - confidence: 50 - # (impact * confidence)/100 + confidence: 50 risk_score: 25 context: - Source:Endpoint @@ -66,4 +67,5 @@ tags: - name: parent_process_name type: Parent Process role: - - Parent Process \ No newline at end of file + - Parent Process + automated_detection_testing: passed From b74cb7d1a8545dda76f9c3921b5972057221380f Mon Sep 17 00:00:00 2001 From: root Date: Mon, 30 Aug 2021 09:14:19 +0000 Subject: [PATCH 09/21] Added detection testing service results inGet ADUser with PowerShell Script Block --- ...et_aduser_with_powershell_script_block.yml | 32 ++++++++++--------- 1 file changed, 17 insertions(+), 15 deletions(-) diff --git a/detections/endpoint/get_aduser_with_powershell_script_block.yml b/detections/endpoint/get_aduser_with_powershell_script_block.yml index 995401212c..bec9395557 100644 --- a/detections/endpoint/get_aduser_with_powershell_script_block.yml +++ b/detections/endpoint/get_aduser_with_powershell_script_block.yml @@ -6,18 +6,20 @@ author: Teoderick Contreras, Splunk type: Hunting datamodel: - Endpoint -description: This search is to detect a powershell command get-aduser function to do user enumeration to the active directory. - This command can be a normal query of a network admin but since the output of this is not so much structure and cannot give a concrete or - specific information that admin may look upon this is still a good TTP to alert some malicious activities. +description: This search is to detect a powershell command get-aduser function to + do user enumeration to the active directory. This command can be a normal query + of a network admin but since the output of this is not so much structure and cannot + give a concrete or specific information that admin may look upon this is still a + good TTP to alert some malicious activities. search: '`powershell` EventCode=4104 Message = "*get-aduser*" Message = "*-filter*" - | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `get_aduser_with_powershell_script_block_filter`' -how_to_implement: The following Hunting analytic requires PowerShell operational logs to be imported. - Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, - or PowerShell Script Block Logging. -known_false_positives: network admin may use this command and other IT operator to check AD users. + | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message + ComputerName User | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `get_aduser_with_powershell_script_block_filter`' +how_to_implement: The following Hunting analytic requires PowerShell operational logs + to be imported. Modify the powershell macro as needed to match the sourcetype or + add index. This analytic is specific to 4104, or PowerShell Script Block Logging. +known_false_positives: network admin may use this command and other IT operator to + check AD users. references: - https://www.blackhillsinfosec.com/red-blue-purple/ tags: @@ -36,13 +38,12 @@ tags: required_fields: - _time - EventCode - - Message - - ComputerName + - Message + - ComputerName - User security_domain: endpoint impact: 50 confidence: 50 - # (impact * confidence)/100 risk_score: 25 context: - source:endpoint @@ -56,4 +57,5 @@ tags: - name: User type: User role: - - Victim \ No newline at end of file + - Victim + automated_detection_testing: passed From a0286d1a9d280741538c9bb3ff7eae7fe6fcfa55 Mon Sep 17 00:00:00 2001 From: root Date: Mon, 30 Aug 2021 09:44:45 +0000 Subject: [PATCH 10/21] Added detection testing service results inGet ADUser with PowerShell --- .../endpoint/get_aduser_with_powershell.yml | 41 ++++++++++--------- 1 file changed, 21 insertions(+), 20 deletions(-) diff --git a/detections/endpoint/get_aduser_with_powershell.yml b/detections/endpoint/get_aduser_with_powershell.yml index 5dd526e6be..ee1a676957 100644 --- a/detections/endpoint/get_aduser_with_powershell.yml +++ b/detections/endpoint/get_aduser_with_powershell.yml @@ -6,20 +6,22 @@ author: Teoderick Contreras, Splunk type: Hunting datamodel: - Endpoint -description: This search is to detect a suspicious commandline that commonly uses for enumerating users in active directory. - This technique can be a good indicator to hunt further TTPs to the machine to check further anomalies. Since this is a hunt query expect - some noise from administrator or some IT within the network that may use this command. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes - where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*Get-ADUser*" AND Processes.process = "*-filter*" - by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id - Processes.parent_process_name | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `get_aduser_with_powershell_filter`' +description: This search is to detect a suspicious commandline that commonly uses + for enumerating users in active directory. This technique can be a good indicator + to hunt further TTPs to the machine to check further anomalies. Since this is a + hunt query expect some noise from administrator or some IT within the network that + may use this command. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" + OR Processes.process_name="powershell*") AND Processes.process = "*Get-ADUser*" + AND Processes.process = "*-filter*" by Processes.dest Processes.user Processes.parent_process + Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `get_aduser_with_powershell_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. + Sysmon TA. known_false_positives: network admin may use this command. references: - https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm @@ -38,18 +40,17 @@ tags: - Splunk Cloud required_fields: - _time - - Processes.dest - - Processes.user - - Processes.parent_process - - Processes.process_name - - Processes.process - - Processes.process_id + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id - Processes.parent_process_id - Processes.parent_process_name security_domain: endpoint impact: 50 - confidence: 50 - # (impact * confidence)/100 + confidence: 50 risk_score: 25 context: - Source:Endpoint @@ -68,4 +69,4 @@ tags: type: Parent Process role: - Parent Process - \ No newline at end of file + automated_detection_testing: passed From 4c1c4a077a1b2c60fe9af9109f4149541abfb489 Mon Sep 17 00:00:00 2001 From: root Date: Mon, 30 Aug 2021 10:23:58 +0000 Subject: [PATCH 11/21] Added detection testing service results inDomain Account Discovery with Wmic --- .../domain_account_discovery_with_wmic.yml | 39 ++++++++++--------- 1 file changed, 20 insertions(+), 19 deletions(-) diff --git a/detections/endpoint/domain_account_discovery_with_wmic.yml b/detections/endpoint/domain_account_discovery_with_wmic.yml index 9c62578cd5..bc8df65b34 100644 --- a/detections/endpoint/domain_account_discovery_with_wmic.yml +++ b/detections/endpoint/domain_account_discovery_with_wmic.yml @@ -6,20 +6,22 @@ author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint -description: This search is to detect a wmic command for enumerating user in active directory. - This technique was commonly used in pentesting, red-team and also by some attacker to map all user in the targetted host. - This search may also catch this type of query made by network admin but not common in all the user in the network. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes - where Processes.process_name="wmic.exe" AND Processes.process = "*/NAMESPACE:\\\\root\\directory\\ldap*" AND Processes.process = "*ds_user*" AND Processes.process = "*GET*" AND Processes.process = "*ds_samaccountname*" - by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id - Processes.parent_process_name | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` +description: This search is to detect a wmic command for enumerating user in active + directory. This technique was commonly used in pentesting, red-team and also by + some attacker to map all user in the targetted host. This search may also catch + this type of query made by network admin but not common in all the user in the network. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name="wmic.exe" + AND Processes.process = "*/NAMESPACE:\\\\root\\directory\\ldap*" AND Processes.process + = "*ds_user*" AND Processes.process = "*GET*" AND Processes.process = "*ds_samaccountname*" + by Processes.dest Processes.user Processes.parent_process Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `domain_account_discovery_with_wmic_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. + Sysmon TA. known_false_positives: network admin may execute this command for listing users. references: - https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm @@ -38,18 +40,17 @@ tags: - Splunk Cloud required_fields: - _time - - Processes.dest - - Processes.user - - Processes.parent_process - - Processes.process_name - - Processes.process - - Processes.process_id + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id - Processes.parent_process_id - Processes.parent_process_name security_domain: endpoint impact: 50 - confidence: 50 - # (impact * confidence)/100 + confidence: 50 risk_score: 25 context: - Source:Endpoint @@ -68,4 +69,4 @@ tags: type: Parent Process role: - Parent Process - \ No newline at end of file + automated_detection_testing: passed From 539783600dbc43eb7a7f60e534290020b58019b3 Mon Sep 17 00:00:00 2001 From: root Date: Mon, 30 Aug 2021 10:38:03 +0000 Subject: [PATCH 12/21] Added detection testing service results inDomain Account Discovery with Wmic --- .../domain_account_discovery_with_wmic.yml | 39 ++++++++++--------- 1 file changed, 20 insertions(+), 19 deletions(-) diff --git a/detections/endpoint/domain_account_discovery_with_wmic.yml b/detections/endpoint/domain_account_discovery_with_wmic.yml index 9c62578cd5..bc8df65b34 100644 --- a/detections/endpoint/domain_account_discovery_with_wmic.yml +++ b/detections/endpoint/domain_account_discovery_with_wmic.yml @@ -6,20 +6,22 @@ author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint -description: This search is to detect a wmic command for enumerating user in active directory. - This technique was commonly used in pentesting, red-team and also by some attacker to map all user in the targetted host. - This search may also catch this type of query made by network admin but not common in all the user in the network. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes - where Processes.process_name="wmic.exe" AND Processes.process = "*/NAMESPACE:\\\\root\\directory\\ldap*" AND Processes.process = "*ds_user*" AND Processes.process = "*GET*" AND Processes.process = "*ds_samaccountname*" - by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id - Processes.parent_process_name | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` +description: This search is to detect a wmic command for enumerating user in active + directory. This technique was commonly used in pentesting, red-team and also by + some attacker to map all user in the targetted host. This search may also catch + this type of query made by network admin but not common in all the user in the network. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name="wmic.exe" + AND Processes.process = "*/NAMESPACE:\\\\root\\directory\\ldap*" AND Processes.process + = "*ds_user*" AND Processes.process = "*GET*" AND Processes.process = "*ds_samaccountname*" + by Processes.dest Processes.user Processes.parent_process Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `domain_account_discovery_with_wmic_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. + Sysmon TA. known_false_positives: network admin may execute this command for listing users. references: - https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm @@ -38,18 +40,17 @@ tags: - Splunk Cloud required_fields: - _time - - Processes.dest - - Processes.user - - Processes.parent_process - - Processes.process_name - - Processes.process - - Processes.process_id + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id - Processes.parent_process_id - Processes.parent_process_name security_domain: endpoint impact: 50 - confidence: 50 - # (impact * confidence)/100 + confidence: 50 risk_score: 25 context: - Source:Endpoint @@ -68,4 +69,4 @@ tags: type: Parent Process role: - Parent Process - \ No newline at end of file + automated_detection_testing: passed From 8aab471d30648889bdccee70410b6f6fb0735e5e Mon Sep 17 00:00:00 2001 From: root Date: Mon, 30 Aug 2021 11:38:56 +0000 Subject: [PATCH 13/21] Added detection testing service results inGet DomainUser with PowerShell --- .../get_domainuser_with_powershell.yml | 37 ++++++++++--------- 1 file changed, 19 insertions(+), 18 deletions(-) diff --git a/detections/endpoint/get_domainuser_with_powershell.yml b/detections/endpoint/get_domainuser_with_powershell.yml index 531a62f336..d6f9432887 100644 --- a/detections/endpoint/get_domainuser_with_powershell.yml +++ b/detections/endpoint/get_domainuser_with_powershell.yml @@ -6,19 +6,20 @@ author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint -description: This search is to detect a cmdlet Get-DomainUser that are common on powerview or powersploit tool. - This cmdlet is used to recon on the targetted machine to enumerate all users in active directory. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes - where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*Get-DomainUser*" - by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id - Processes.parent_process_name | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` +description: This search is to detect a cmdlet Get-DomainUser that are common on powerview + or powersploit tool. This cmdlet is used to recon on the targetted machine to enumerate + all users in active directory. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" + OR Processes.process_name="powershell*") AND Processes.process = "*Get-DomainUser*" + by Processes.dest Processes.user Processes.parent_process Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id Processes.parent_process_name + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `get_domainuser_with_powershell_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. + Sysmon TA. known_false_positives: unknown references: - https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainUser/ @@ -37,18 +38,17 @@ tags: - Splunk Cloud required_fields: - _time - - Processes.dest - - Processes.user - - Processes.parent_process - - Processes.process_name - - Processes.process - - Processes.process_id + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id - Processes.parent_process_id - Processes.parent_process_name security_domain: endpoint impact: 50 - confidence: 50 - # (impact * confidence)/100 + confidence: 50 risk_score: 25 context: - Source:Endpoint @@ -66,4 +66,5 @@ tags: - name: parent_process_name type: Parent Process role: - - Parent Process \ No newline at end of file + - Parent Process + automated_detection_testing: passed From 05e85ad5bf87f169ee6f4de385fb5f4b378ee4fa Mon Sep 17 00:00:00 2001 From: tccontre Date: Mon, 30 Aug 2021 14:44:14 +0200 Subject: [PATCH 14/21] AD_Discovery_TR-789_2 --- .../get_domainuser_with_powershell_script_block.yml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/detections/endpoint/get_domainuser_with_powershell_script_block.yml b/detections/endpoint/get_domainuser_with_powershell_script_block.yml index 5ec13cf5c8..fb18ca66c4 100644 --- a/detections/endpoint/get_domainuser_with_powershell_script_block.yml +++ b/detections/endpoint/get_domainuser_with_powershell_script_block.yml @@ -11,10 +11,10 @@ description: his search is to detect a powershell command Get-DomainUser to do u This is a good TTP for alerting SOC if there is a pentest or recon happening on the system. try to look for lateral movement technique or credential dumping techniques in the system. search: '`powershell` EventCode=4104 Message = "*Get-DomainUser*" - | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `get_domainuser_with_powershell_script_block_filter`' + | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `get_domainuser_with_powershell_script_block_filter`' how_to_implement: The following Hunting analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. From 74e241a92e2350ffede91f6791f7d3c90041379b Mon Sep 17 00:00:00 2001 From: tccontre Date: Mon, 30 Aug 2021 15:38:27 +0200 Subject: [PATCH 15/21] AD_Discovery_TR-789_2 --- .../get_domainuser_with_powershell_script_block.test.yml | 2 +- .../getwmiobject_ds_user_with_powershell_script_block.test.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/tests/endpoint/get_domainuser_with_powershell_script_block.test.yml b/tests/endpoint/get_domainuser_with_powershell_script_block.test.yml index 1b74cec450..bae14d79d5 100644 --- a/tests/endpoint/get_domainuser_with_powershell_script_block.test.yml +++ b/tests/endpoint/get_domainuser_with_powershell_script_block.test.yml @@ -2,7 +2,7 @@ name: Get DomainUser with PowerShell Script Block Unit Test tests: - name: Get DomainUser with PowerShell Script Block file: endpoint/get_domainuser_with_powershell_script_block.yml - pass_condition: '| stats count | where count > 0' + pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' attack_data: diff --git a/tests/endpoint/getwmiobject_ds_user_with_powershell_script_block.test.yml b/tests/endpoint/getwmiobject_ds_user_with_powershell_script_block.test.yml index 89c7c1a25e..ee1809782e 100644 --- a/tests/endpoint/getwmiobject_ds_user_with_powershell_script_block.test.yml +++ b/tests/endpoint/getwmiobject_ds_user_with_powershell_script_block.test.yml @@ -2,7 +2,7 @@ name: GetWmiObject DS User with PowerShell Script Block Unit Test tests: - name: GetWmiObject DS User with PowerShell Script Block file: endpoint/getwmiobject_ds_user_with_powershell_script_block.yml - pass_condition: '| stats count | where count > 0' + pass_condition: '| stats count | where count > 0' earliest_time: '-24h' latest_time: 'now' attack_data: From 0129d12a324b8cb88fbae0d16d0595f9ead594b8 Mon Sep 17 00:00:00 2001 From: root Date: Mon, 30 Aug 2021 13:55:39 +0000 Subject: [PATCH 16/21] Added detection testing service results inGetWmiObject DS User with PowerShell Script Block --- ...t_ds_user_with_powershell_script_block.yml | 33 ++++++++++--------- 1 file changed, 17 insertions(+), 16 deletions(-) diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml index c344da01df..26b31ee511 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml @@ -6,18 +6,20 @@ author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint -description: This search is to detect a powershell command get-wmiobject function to do user enumeration to the active directory. - This command can be a normal query of a network admin but since the output of this is not so much structure and cannot give a concrete or - specific information that admin may look upon this is still a good TTP to alert some malicious activities. -search: '`powershell` EventCode=4104 Message = "*get-wmiobject*" Message = "*ds_user*" Message = "*-namespace*" Message = "*root\\directory\\ldap*" - | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `getwmiobject_ds_user_with_powershell_script_block_filter`' -how_to_implement: he following Hunting analytic requires PowerShell operational logs to be imported. - Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, - or PowerShell Script Block Logging. -known_false_positives: not commonly seen as a normal command from network admin but possible noise may exist. +description: This search is to detect a powershell command get-wmiobject function + to do user enumeration to the active directory. This command can be a normal query + of a network admin but since the output of this is not so much structure and cannot + give a concrete or specific information that admin may look upon this is still a + good TTP to alert some malicious activities. +search: '`powershell` EventCode=4104 Message = "*get-wmiobject*" Message = "*ds_user*" + Message = "*-namespace*" Message = "*root\\directory\\ldap*" | stats count min(_time) + as firstTime max(_time) as lastTime by EventCode Message ComputerName User | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `getwmiobject_ds_user_with_powershell_script_block_filter`' +how_to_implement: he following Hunting analytic requires PowerShell operational logs + to be imported. Modify the powershell macro as needed to match the sourcetype or + add index. This analytic is specific to 4104, or PowerShell Script Block Logging. +known_false_positives: not commonly seen as a normal command from network admin but + possible noise may exist. references: - https://www.blackhillsinfosec.com/red-blue-purple/ - https://docs.microsoft.com/en-us/windows/win32/wmisdk/describing-the-ldap-namespace @@ -37,13 +39,12 @@ tags: required_fields: - _time - EventCode - - Message - - ComputerName + - Message + - ComputerName - User security_domain: endpoint impact: 50 confidence: 50 - # (impact * confidence)/100 risk_score: 25 context: - source:endpoint @@ -58,4 +59,4 @@ tags: type: User role: - Victim - \ No newline at end of file + automated_detection_testing: passed From 2d4e4d11d1064fb85d99ef6751fa937de9b3174e Mon Sep 17 00:00:00 2001 From: root Date: Mon, 30 Aug 2021 13:55:51 +0000 Subject: [PATCH 17/21] Added detection testing service results inGetWmiObject DS User with PowerShell --- .../getwmiobject_ds_user_with_powershell.yml | 41 ++++++++++--------- 1 file changed, 21 insertions(+), 20 deletions(-) diff --git a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml index 638591a31b..7664fa83e3 100644 --- a/detections/endpoint/getwmiobject_ds_user_with_powershell.yml +++ b/detections/endpoint/getwmiobject_ds_user_with_powershell.yml @@ -6,20 +6,22 @@ author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint -description: This search is to detect a suspicious execution wmi process that enumerate user in active directory. - This technique can be used by attacker and pentester to mapped all the users as part of its recon to the targetted host. - Network Admin may seen executing this command but not often and also not common to see in user events. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes - where (Processes.process_name="cmd.exe" OR Processes.process_name="powershell*") AND Processes.process = "*get-wmiobject*" AND Processes.process = "*ds_user*" AND Processes.process = "*root\\directory\\ldap*" AND Processes.process = "*-namespace*" - by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id - Processes.parent_process_name | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `getwmiobject_ds_user_with_powershell_filter`' +description: This search is to detect a suspicious execution wmi process that enumerate + user in active directory. This technique can be used by attacker and pentester to + mapped all the users as part of its recon to the targetted host. Network Admin may + seen executing this command but not often and also not common to see in user events. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="cmd.exe" + OR Processes.process_name="powershell*") AND Processes.process = "*get-wmiobject*" + AND Processes.process = "*ds_user*" AND Processes.process = "*root\\directory\\ldap*" + AND Processes.process = "*-namespace*" by Processes.dest Processes.user Processes.parent_process + Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `getwmiobject_ds_user_with_powershell_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. + Sysmon TA. known_false_positives: network admin may execute this command. references: - https://jpcertcc.github.io/ToolAnalysisResultSheet/details/dsquery.htm @@ -38,18 +40,17 @@ tags: - Splunk Cloud required_fields: - _time - - Processes.dest - - Processes.user - - Processes.parent_process - - Processes.process_name - - Processes.process - - Processes.process_id + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.process_name + - Processes.process + - Processes.process_id - Processes.parent_process_id - Processes.parent_process_name security_domain: endpoint impact: 50 - confidence: 50 - # (impact * confidence)/100 + confidence: 50 risk_score: 25 context: - Source:Endpoint @@ -68,4 +69,4 @@ tags: type: Parent Process role: - Parent Process - \ No newline at end of file + automated_detection_testing: passed From f7db3ebe94494e3103291424febe7c0b38123d19 Mon Sep 17 00:00:00 2001 From: root Date: Mon, 30 Aug 2021 15:04:32 +0000 Subject: [PATCH 18/21] Added detection testing service results inGet DomainUser with PowerShell Script Block --- ...omainuser_with_powershell_script_block.yml | 29 +++++++++---------- 1 file changed, 14 insertions(+), 15 deletions(-) diff --git a/detections/endpoint/get_domainuser_with_powershell_script_block.yml b/detections/endpoint/get_domainuser_with_powershell_script_block.yml index fb18ca66c4..7dced17095 100644 --- a/detections/endpoint/get_domainuser_with_powershell_script_block.yml +++ b/detections/endpoint/get_domainuser_with_powershell_script_block.yml @@ -6,18 +6,18 @@ author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint -description: his search is to detect a powershell command Get-DomainUser to do user enumeration to the active directory. - This command is function seen in powerspoit and powerview tool that are designed to pentest active directory or domain controller for possible attack. - This is a good TTP for alerting SOC if there is a pentest or recon happening on the system. try to look for lateral movement technique or credential +description: his search is to detect a powershell command Get-DomainUser to do user + enumeration to the active directory. This command is function seen in powerspoit + and powerview tool that are designed to pentest active directory or domain controller + for possible attack. This is a good TTP for alerting SOC if there is a pentest or + recon happening on the system. try to look for lateral movement technique or credential dumping techniques in the system. -search: '`powershell` EventCode=4104 Message = "*Get-DomainUser*" - | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message ComputerName User - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `get_domainuser_with_powershell_script_block_filter`' -how_to_implement: The following Hunting analytic requires PowerShell operational logs to be imported. - Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, - or PowerShell Script Block Logging. +search: '`powershell` EventCode=4104 Message = "*Get-DomainUser*" | stats count min(_time) + as firstTime max(_time) as lastTime by EventCode Message ComputerName User | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `get_domainuser_with_powershell_script_block_filter`' +how_to_implement: The following Hunting analytic requires PowerShell operational logs + to be imported. Modify the powershell macro as needed to match the sourcetype or + add index. This analytic is specific to 4104, or PowerShell Script Block Logging. known_false_positives: unknown references: - https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainUser/ @@ -37,13 +37,12 @@ tags: required_fields: - _time - EventCode - - Message - - ComputerName + - Message + - ComputerName - User security_domain: endpoint impact: 50 confidence: 50 - # (impact * confidence)/100 risk_score: 25 context: - source:endpoint @@ -58,4 +57,4 @@ tags: type: User role: - Victim - \ No newline at end of file + automated_detection_testing: passed From 62b08792c9694cae0469c338e7507636561f51fc Mon Sep 17 00:00:00 2001 From: root Date: Mon, 30 Aug 2021 15:07:40 +0000 Subject: [PATCH 19/21] Added detection testing service results inGetWmiObject DS User with PowerShell From 322c804d876c7e9c2b64206af37b575d036ce4f4 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Tue, 31 Aug 2021 11:53:30 -0700 Subject: [PATCH 20/21] Update adsisearcher_account_discovery.yml --- detections/endpoint/adsisearcher_account_discovery.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/detections/endpoint/adsisearcher_account_discovery.yml b/detections/endpoint/adsisearcher_account_discovery.yml index fccf6eb36a..ba6b634aa0 100644 --- a/detections/endpoint/adsisearcher_account_discovery.yml +++ b/detections/endpoint/adsisearcher_account_discovery.yml @@ -59,3 +59,4 @@ tags: role: - Victim automated_detection_testing: passed + From 6cdc9a480979a9fcae53377aeaea583afffb0bda Mon Sep 17 00:00:00 2001 From: P4T12ICK Date: Mon, 6 Sep 2021 13:02:28 +0200 Subject: [PATCH 21/21] Update adsisearcher_account_discovery.yml --- detections/endpoint/adsisearcher_account_discovery.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/detections/endpoint/adsisearcher_account_discovery.yml b/detections/endpoint/adsisearcher_account_discovery.yml index ba6b634aa0..fccf6eb36a 100644 --- a/detections/endpoint/adsisearcher_account_discovery.yml +++ b/detections/endpoint/adsisearcher_account_discovery.yml @@ -59,4 +59,3 @@ tags: role: - Victim automated_detection_testing: passed -