From 9058ee478b15cd9e94ea4b3e2deb3138cde58ac5 Mon Sep 17 00:00:00 2001 From: Lou Stella Date: Thu, 17 Feb 2022 15:41:45 -0600 Subject: [PATCH 1/6] SSA conversion --- ...a___windows_diskshadow_proxy_execution.yml | 63 +++++++++++++++++++ ...indows_diskshadow_proxy_execution.test.yml | 9 +++ 2 files changed, 72 insertions(+) create mode 100644 detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml create mode 100644 tests/endpoint/ssa___windows_diskshadow_proxy_execution.test.yml diff --git a/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml b/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml new file mode 100644 index 0000000000..375718e0a8 --- /dev/null +++ b/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml @@ -0,0 +1,63 @@ +name: BA Windows Diskshadow Proxy Execution +id: aa502688-9037-11ec-842d-acde48001122 +version: 1 +date: '2022-02-17' +author: Lou Stella, Splunk +type: Anomaly +datamodel: +- Endpoint_Process +description: DiskShadow.exe is a Microsoft Signed binary present on Windows Server. It has a scripting mode intended for complex scripted backup operations. This feature also allows for execution of arbitrary unsigned code. This analytic looks for the usage of the scripting mode flags in executions of DiskShadow. During triage, compare to known backup behavior in your environment and then review the scripts called by diskshadow. +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="diskshadow.exe" AND (like (cmd_line, "%-s%") OR like (cmd_line, "%/s%)) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search you need to be ingesting information on processes that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. +known_false_positives: Administrators using the DiskShadow tool in their infrastructure as a main backup tool with scripts will cause false positives +references: +- +tags: + analytic_story: + - Living Off The Land + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218/diskshadow/windows-security.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1218 + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + security_domain: endpoint + impact: 70 + confidence: 70 + risk_score: 49 + context: + - Source:Endpoint + - Stage:Execution + message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to run a script. + observable: + - name: dest_device_id + type: Hostname + role: + - Victim + - name: dest_user_id + type: User + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + nist: + - DE.CM + cis20: + - CIS 8 \ No newline at end of file diff --git a/tests/endpoint/ssa___windows_diskshadow_proxy_execution.test.yml b/tests/endpoint/ssa___windows_diskshadow_proxy_execution.test.yml new file mode 100644 index 0000000000..1b8c7d0d1b --- /dev/null +++ b/tests/endpoint/ssa___windows_diskshadow_proxy_execution.test.yml @@ -0,0 +1,9 @@ +name: BA Windows Diskshadow Proxy Execution Unit Test +tests: +- name: BA Windows Diskshadow Proxy Execution + file: endpoint/ssa___windows_diskshadow_proxy_execution.yml + pass_condition: '@count_gt(0)' + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218/diskshadow/windows-security.log + source: WinEventLog:Security From e297fcd8c7a3a6ec04fca58813ad6ae576c87392 Mon Sep 17 00:00:00 2001 From: Lou Stella Date: Thu, 17 Feb 2022 15:45:26 -0600 Subject: [PATCH 2/6] Datamodel name correction --- .../endpoint/ssa___windows_diskshadow_proxy_execution.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml b/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml index 375718e0a8..98fac23192 100644 --- a/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml +++ b/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml @@ -5,7 +5,7 @@ date: '2022-02-17' author: Lou Stella, Splunk type: Anomaly datamodel: -- Endpoint_Process +- Endpoint_Processes description: DiskShadow.exe is a Microsoft Signed binary present on Windows Server. It has a scripting mode intended for complex scripted backup operations. This feature also allows for execution of arbitrary unsigned code. This analytic looks for the usage of the scripting mode flags in executions of DiskShadow. During triage, compare to known backup behavior in your environment and then review the scripts called by diskshadow. search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="diskshadow.exe" AND (like (cmd_line, "%-s%") OR like (cmd_line, "%/s%)) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' how_to_implement: To successfully implement this search you need to be ingesting information on processes that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. From 6e56931b2e3d5948c7d83a20d2766f16cc418ab8 Mon Sep 17 00:00:00 2001 From: Lou Stella Date: Thu, 17 Feb 2022 15:46:47 -0600 Subject: [PATCH 3/6] Missing quote --- .../endpoint/ssa___windows_diskshadow_proxy_execution.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml b/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml index 98fac23192..a57382c3b5 100644 --- a/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml +++ b/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml @@ -7,7 +7,7 @@ type: Anomaly datamodel: - Endpoint_Processes description: DiskShadow.exe is a Microsoft Signed binary present on Windows Server. It has a scripting mode intended for complex scripted backup operations. This feature also allows for execution of arbitrary unsigned code. This analytic looks for the usage of the scripting mode flags in executions of DiskShadow. During triage, compare to known backup behavior in your environment and then review the scripts called by diskshadow. -search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="diskshadow.exe" AND (like (cmd_line, "%-s%") OR like (cmd_line, "%/s%)) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="diskshadow.exe" AND (like (cmd_line, "%-s%") OR like (cmd_line, "%/s%")) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' how_to_implement: To successfully implement this search you need to be ingesting information on processes that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. known_false_positives: Administrators using the DiskShadow tool in their infrastructure as a main backup tool with scripts will cause false positives references: From a47084d2e6e4c4fc1cd3e57915e976c75414fe96 Mon Sep 17 00:00:00 2001 From: Lou Stella Date: Thu, 17 Feb 2022 15:49:21 -0600 Subject: [PATCH 4/6] Missing reference --- .../endpoint/ssa___windows_diskshadow_proxy_execution.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml b/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml index a57382c3b5..c5c8181640 100644 --- a/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml +++ b/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml @@ -11,7 +11,7 @@ search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_data how_to_implement: To successfully implement this search you need to be ingesting information on processes that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. known_false_positives: Administrators using the DiskShadow tool in their infrastructure as a main backup tool with scripts will cause false positives references: -- +- https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/ tags: analytic_story: - Living Off The Land From b72643fe150b350c4e14ed02bf64f1a97ce83164 Mon Sep 17 00:00:00 2001 From: Lou Stella Date: Thu, 17 Feb 2022 16:39:39 -0600 Subject: [PATCH 5/6] Name tweak --- .../endpoint/ssa___windows_diskshadow_proxy_execution.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml b/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml index c5c8181640..ceea2b4278 100644 --- a/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml +++ b/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml @@ -1,4 +1,4 @@ -name: BA Windows Diskshadow Proxy Execution +name: Windows Diskshadow Proxy Execution id: aa502688-9037-11ec-842d-acde48001122 version: 1 date: '2022-02-17' From d4b0125a51863d14958d508a181cad5073a5e8dd Mon Sep 17 00:00:00 2001 From: Lou Stella Date: Tue, 22 Feb 2022 08:43:26 -0600 Subject: [PATCH 6/6] handling case sensitivity --- .../endpoint/ssa___windows_diskshadow_proxy_execution.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml b/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml index ceea2b4278..55a5e8feb3 100644 --- a/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml +++ b/detections/endpoint/ssa___windows_diskshadow_proxy_execution.yml @@ -7,7 +7,7 @@ type: Anomaly datamodel: - Endpoint_Processes description: DiskShadow.exe is a Microsoft Signed binary present on Windows Server. It has a scripting mode intended for complex scripted backup operations. This feature also allows for execution of arbitrary unsigned code. This analytic looks for the usage of the scripting mode flags in executions of DiskShadow. During triage, compare to known backup behavior in your environment and then review the scripts called by diskshadow. -search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="diskshadow.exe" AND (like (cmd_line, "%-s%") OR like (cmd_line, "%/s%")) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="diskshadow.exe" AND (like (cmd_line, "%-s%") OR like (cmd_line, "%/s%")) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' how_to_implement: To successfully implement this search you need to be ingesting information on processes that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. known_false_positives: Administrators using the DiskShadow tool in their infrastructure as a main backup tool with scripts will cause false positives references: @@ -60,4 +60,4 @@ tags: nist: - DE.CM cis20: - - CIS 8 \ No newline at end of file + - CIS 8