diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md new file mode 100644 index 0000000000..fb03d2ad8e --- /dev/null +++ b/.github/pull_request_template.md @@ -0,0 +1,10 @@ +# PR Template for new Detections + +For Authors: +1. Make sure that CI/CD [detection-testing and build-and-validate](https://github.com/splunk/security_content/actions) jobs passed ✔️. + +For Reviewers: +- [ ] Verify CI/CD jobs have passed without errors. +- [ ] Validate SPL logic. +- [ ] Validate tags, description, and how to implement. +- [ ] Validate name patches `__` diff --git a/detections/endpoint/rundll_loading_dll_by_ordinal.yml b/detections/deprecated/rundll_loading_dll_by_ordinal.yml similarity index 100% rename from detections/endpoint/rundll_loading_dll_by_ordinal.yml rename to detections/deprecated/rundll_loading_dll_by_ordinal.yml diff --git a/detections/endpoint/suspicious_rundll32_rename.yml b/detections/deprecated/suspicious_rundll32_rename.yml similarity index 95% rename from detections/endpoint/suspicious_rundll32_rename.yml rename to detections/deprecated/suspicious_rundll32_rename.yml index 459457a7d6..7fdc4f6525 100644 --- a/detections/endpoint/suspicious_rundll32_rename.yml +++ b/detections/deprecated/suspicious_rundll32_rename.yml @@ -1,12 +1,12 @@ name: Suspicious Rundll32 Rename id: 7360137f-abad-473e-8189-acbdaa34d114 -version: 3 -date: '2021-02-04' +version: 4 +date: '2022-02-01' author: Michael Haag, Splunk type: Hunting datamodel: - Endpoint -description: The following analytic identifies renamed instances of rundll32.exe executing. +description: The following hunting analytic identifies renamed instances of rundll32.exe executing. rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During investigation, validate it is the legitimate rundll32.exe executing and what script content it is loading. This query relies on the original filename or internal name diff --git a/detections/endpoint/linux_pkexec_privilege_escalation.yml b/detections/endpoint/linux_pkexec_privilege_escalation.yml new file mode 100644 index 0000000000..ab911111a3 --- /dev/null +++ b/detections/endpoint/linux_pkexec_privilege_escalation.yml @@ -0,0 +1,77 @@ +name: Linux pkexec Privilege Escalation +id: 03e22c1c-8086-11ec-ac2e-acde48001122 +version: 1 +date: '2022-01-28' +author: Michael Haag, Splunk +type: TTP +datamodel: + - Endpoint +description: 'The following analytic identifies `pkexec` spawning with no command-line arguments. A vulnerability in Polkit''s pkexec component identified as CVE-2021-4034 (PwnKit) which is present in the default configuration of all major Linux distributions and can be exploited to gain full root privileges on the system.' +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=pkexec by _time Processes.dest Processes.process_id Processes.parent_process_name Processes.process_name Processes.process Processes.process_path + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | regex process="(^.{1}$)" + | `linux_pkexec_privilege_escalation_filter`' +how_to_implement: 'Depending on the EDR product in use, there are multiple ways to "null" the command-line field, Processes.process. Two that may be useful `process="(^.{0}$)"` or `| where isnull(process)`. To generate data for this behavior, Sysmon for Linux was utilized. + To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.' +known_false_positives: False positives may be present, filter as needed. +references: + - https://www.reddit.com/r/crowdstrike/comments/sdfeig/20220126_cool_query_friday_hunting_pwnkit_local/ + - https://linux.die.net/man/1/pkexec + - https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/ + - https://access.redhat.com/security/security-updates/#/?q=polkit&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory&documentKind=PortalProduct +tags: + cve: + - CVE-2021-4034 + analytic_story: + - Linux Privilege Escalation + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/zoom_child_process/linux-sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1068 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name #parent process name + - Processes.parent_process #parent cmdline + - Processes.original_file_name + - Processes.process_name #process name + - Processes.process #process cmdline + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + security_domain: endpoint + impact: 80 + confidence: 70 + # (impact * confidence)/100 + risk_score: 56 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ related to a local privilege escalation in polkit pkexec. + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process \ No newline at end of file diff --git a/detections/endpoint/linux_setuid_using_chmod_utility.yml b/detections/endpoint/linux_setuid_using_chmod_utility.yml index ed5bffc077..9c0993d9d1 100644 --- a/detections/endpoint/linux_setuid_using_chmod_utility.yml +++ b/detections/endpoint/linux_setuid_using_chmod_utility.yml @@ -18,7 +18,7 @@ description: This analytic looks for suspicious chmod utility execution to enabl search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes WHERE (Processes.process_name = chmod OR Processes.process = "*chmod *") AND Processes.process IN("* g+s *", "* u+s *", - "* 4777 *", "* 4577 *", "* 777 *") by Processes.dest Processes.user Processes.parent_process_name + "* 4777 *", "* 4577 *") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `linux_setuid_using_chmod_utility_filter`' diff --git a/tests/endpoint/linux_pkexec_privilege_escalation.test.yml b/tests/endpoint/linux_pkexec_privilege_escalation.test.yml new file mode 100644 index 0000000000..13f788f251 --- /dev/null +++ b/tests/endpoint/linux_pkexec_privilege_escalation.test.yml @@ -0,0 +1,12 @@ +name: Linux pkexec Privilege Escalation Unit Test +tests: +- name: Linux pkexec Privilege Escalation + file: endpoint/linux_pkexec_privilege_escalation.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: linux-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/pkexec/linux-sysmon.log + source: Syslog:Linux-Sysmon/Operational + sourcetype: sysmon_linux \ No newline at end of file diff --git a/tests/endpoint/rundll_loading_dll_by_ordinal.test.yml b/tests/endpoint/rundll_loading_dll_by_ordinal.test.yml deleted file mode 100644 index 713662f1ea..0000000000 --- a/tests/endpoint/rundll_loading_dll_by_ordinal.test.yml +++ /dev/null @@ -1,12 +0,0 @@ -name: RunDLL Loading DLL By Ordinal Unit Test -tests: -- name: RunDLL Loading DLL By Ordinal - file: endpoint/rundll_loading_dll_by_ordinal.yml - pass_condition: '| stats count | where count > 0' - earliest_time: '-24h' - latest_time: 'now' - attack_data: - - file_name: windows-sysmon.log - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog diff --git a/tests/endpoint/suspicious_rundll32_rename.test.yml b/tests/endpoint/suspicious_rundll32_rename.test.yml deleted file mode 100644 index 67a20e4bc5..0000000000 --- a/tests/endpoint/suspicious_rundll32_rename.test.yml +++ /dev/null @@ -1,12 +0,0 @@ -name: Suspicious rundll32 rename unit test -tests: -- name: Detect Renamed rundll32.exe Rename - file: endpoint/suspicious_rundll32_rename.yml - pass_condition: '| stats count | where count > 0' - earliest_time: '-24h' - latest_time: 'now' - attack_data: - - file_name: windows-sysmon.log - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog \ No newline at end of file