From 94787c626fd32d5fba3cf4e55e2d1df5e5cd30d0 Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Mon, 26 Sep 2022 13:00:17 -0600 Subject: [PATCH] New content --- ..._hijacking_inprocserver32_modification.yml | 64 ++++++++++++++ ..._hijacking_inprocserver32_modification.yml | 72 ++++++++++++++++ ...oxy_execution_syncappvpublishingserver.yml | 83 +++++++++++++++++++ ...cking_inprocserver32_modification.test.yml | 14 ++++ ...cking_inprocserver32_modification.test.yml | 13 +++ ...xecution_syncappvpublishingserver.test.yml | 13 +++ 6 files changed, 259 insertions(+) create mode 100644 detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml create mode 100644 detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml create mode 100644 detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml create mode 100644 tests/endpoint/powershell_com_hijacking_inprocserver32_modification.test.yml create mode 100644 tests/endpoint/windows_com_hijacking_inprocserver32_modification.test.yml create mode 100644 tests/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.test.yml diff --git a/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml b/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml new file mode 100644 index 0000000000..8d0a646b69 --- /dev/null +++ b/detections/endpoint/powershell_com_hijacking_inprocserver32_modification.yml @@ -0,0 +1,64 @@ +name: Powershell COM Hijacking InprocServer32 Modification +id: ea61e291-af05-4716-932a-67faddb6ae6f +version: 1 +date: '2022-09-26' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic utilizes PowerShell ScriptBlock Logging to identify a script that is attempting to modify or add a component object model to inprocserver32 path within the registry. +search: '`powershell` EventCode=4104 ScriptBlockText = "*Software\\Classes\\CLSID\\*\\InProcServer32*" | stats count min(_time) + as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer UserID | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `powershell_com_hijacking_inprocserver32_modification_filter`' +how_to_implement: The following analytic requires PowerShell operational logs + to be imported. Modify the PowerShell macro as needed to match the sourcetype or + add index. This analytic is specific to 4104, or PowerShell Script Block Logging. +known_false_positives: False positives will be present if any scripts are adding to inprocserver32. Filter as needed. +references: + - https://attack.mitre.org/techniques/T1546/015/ + - https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html + - https://blog.cluster25.duskrise.com/2022/09/23/in-the-footsteps-of-the-fancy-bear-powerpoint-graphite/ + - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1546.015/T1546.015.md +tags: + analytic_story: + - Malicious PowerShell + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.015/atomic_red_team/windows-powershell.log + impact: 80 + kill_chain_phases: + - Exploitation + - Installation + message: A PowerShell script has been identified with InProcServer32 within the script code on $Computer$. + mitre_attack_id: + - T1546.015 + - T1059 + - T1059.001 + nist: + - DE.CM + observable: + - name: Computer + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - ScriptBlockText + - Opcode + - Computer + - UserID + - EventCode + risk_score: 64 + security_domain: endpoint \ No newline at end of file diff --git a/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml b/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml new file mode 100644 index 0000000000..abb0f714ff --- /dev/null +++ b/detections/endpoint/windows_com_hijacking_inprocserver32_modification.yml @@ -0,0 +1,72 @@ +name: Windows COM Hijacking InprocServer32 Modification +id: b7bd83c0-92b5-4fc7-b286-23eccfa2c561 +version: 1 +date: '2022-09-26' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies the use of reg.exe performing an add to the InProcServer32, which is related to COM hijacking. + Adversaries can use the COM system to insert malicious code that can be executed in place of legitimate software through hijacking the COM references and relationships as a means for persistence. Hijacking a COM object requires a change in the Registry to replace a reference to a legitimate system component which may cause that component to not work when executed. When that system component is executed through normal system operation the adversary's code will be executed instead. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_reg` + Processes.process=*inprocserver32* by Processes.dest Processes.user Processes.parent_process_name Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_com_hijacking_inprocserver32_modification_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +known_false_positives: False positives may be present and some filtering may be required. +references: + - https://attack.mitre.org/techniques/T1546/015/ + - https://blog.cluster25.duskrise.com/2022/09/23/in-the-footsteps-of-the-fancy-bear-powerpoint-graphite/ + - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1546.015/T1546.015.md +tags: + analytic_story: + - Living Off The Land + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 80 + context: + - Source:Endpoint + - Stage:Execution + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.015/atomic_red_team/windows-sysmon.log + impact: 80 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to modify InProcServer32 within the registry. + mitre_attack_id: + - T1546.015 + - T1546 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - UPDATE + risk_score: 64 + security_domain: endpoint \ No newline at end of file diff --git a/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml b/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml new file mode 100644 index 0000000000..eb6677ab7a --- /dev/null +++ b/detections/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml @@ -0,0 +1,83 @@ +name: Windows System Script Proxy Execution Syncappvpublishingserver +id: 8dd73f89-682d-444c-8b41-8e679966ad3c +version: 1 +date: '2022-09-26' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies the abuse of Syncappvpublishingserver.vbs, which is a native script on Windows that may be utilized to download remote files or perform privilege escalation. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("wscript.exe","cscript.exe") + Processes.process="*syncappvpublishingserver.vbs*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_system_script_proxy_execution_syncappvpublishingserver_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +known_false_positives: False positives may be present if the vbscript syncappvpublishingserver is used for legitimate purposes. Filter as needed. Adding a n; to the command-line arguments may help reduce any noise. +references: + - https://lolbas-project.github.io/lolbas/Scripts/Syncappvpublishingserver/ + - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1216/T1216.md#atomic-test-1---syncappvpublishingserver-signed-script-powershell-command-execution +tags: + analytic_story: + - Living Off The Land + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 50 + context: + - Source:Endpoint + - Stage:Execution + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1216/atomic_red_team/windows-sysmon.log + impact: 60 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to download files or evade critical controls. + mitre_attack_id: + - T1216 + - T1218 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 30 + security_domain: endpoint + supported_tas: + - Splunk_TA_microsoft_sysmon \ No newline at end of file diff --git a/tests/endpoint/powershell_com_hijacking_inprocserver32_modification.test.yml b/tests/endpoint/powershell_com_hijacking_inprocserver32_modification.test.yml new file mode 100644 index 0000000000..a00c7a6792 --- /dev/null +++ b/tests/endpoint/powershell_com_hijacking_inprocserver32_modification.test.yml @@ -0,0 +1,14 @@ +name: Powershell COM Hijacking InprocServer32 Modification Unit + Test +tests: +- name: Powershell COM Hijacking InprocServer32 Modification + file: endpoint/powershell_com_hijacking_inprocserver32_modification.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-powershell.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.015/atomic_red_team/windows-powershell.log + source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_com_hijacking_inprocserver32_modification.test.yml b/tests/endpoint/windows_com_hijacking_inprocserver32_modification.test.yml new file mode 100644 index 0000000000..99f7fa7785 --- /dev/null +++ b/tests/endpoint/windows_com_hijacking_inprocserver32_modification.test.yml @@ -0,0 +1,13 @@ +name: Windows COM Hijacking InprocServer32 Modification Unit Test +tests: +- name: Windows COM Hijacking InprocServer32 Modification + file: endpoint/windows_com_hijacking_inprocserver32_modification.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.015/atomic_red_team/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.test.yml b/tests/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.test.yml new file mode 100644 index 0000000000..1892cb134a --- /dev/null +++ b/tests/endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.test.yml @@ -0,0 +1,13 @@ +name: Windows System Script Proxy Execution Syncappvpublishingserver Unit Test +tests: +- name: Windows System Script Proxy Execution Syncappvpublishingserver + file: endpoint/windows_system_script_proxy_execution_syncappvpublishingserver.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1216/atomic_red_team/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true