Branch was auto-updated.

This commit is contained in:
github-actions[bot]
2021-06-02 07:12:34 +00:00
committed by GitHub
2 changed files with 8 additions and 8 deletions
@@ -2,7 +2,7 @@ name: Excessive Usage of NSLOOKUP App
id: 0a69fdaa-a2b8-11eb-b16d-acde48001122
version: 1
date: '2021-04-21'
author: Teoderick Contreras, Splunk
author: Teoderick Contreras, Stanislav Miskovic, Splunk
type: batch
datamodel:
- Endpoint
@@ -12,12 +12,12 @@ description: this search is to detect potential DNS exfiltration using nslookup
use of nslookup where it tries to use specific record type (TXT, A, AAAA) that are
commonly used by attacker and also the retry parameter which is designed to query
C2 DNS multiple tries.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id values(Processes.parent_process) as parent_process
count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where Processes.process_name = "nslookup.exe" by Processes.dest Processes.user Processes.process_name
| where count >= 30 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`| `excessive_usage_of_nslookup_app_filter`'
search: '`sysmon` EventCode = 1 process_name = "nslookup.exe" | bucket _time span=15m
| stats count as numNsLookup by Computer, _time | eventstats avg(numNsLookup) as
avgNsLookup, stdev(numNsLookup) as stdNsLookup, count as numSlots by Computer | eval
upperThreshold=(avgNsLookup + stdNsLookup *3) | eval isOutlier=if(avgNsLookup >
20 and avgNsLookup >= upperThreshold, 1, 0) | search isOutlier=1 | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `excessive_usage_of_nslookup_app_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
@@ -9,7 +9,7 @@ datamodel:
description: The following analytics identifies a big number of instance of ransomware
notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This
behavior is a good sensor if the ransomware note filename is quite new for security
industry or the ransomware note filename is not in your lookup table list for monitoring.
industry or the ransomware note filename is not in your ransomware lookup table list for monitoring.
search: '`sysmon` EventCode=11 file_name IN ("*\.txt","*\.html","*\.hta") |bin _time
span=10s | stats min(_time) as firstTime max(_time) as lastTime dc(TargetFilename)
as unique_readme_path_count values(TargetFilename) as list_of_readme_path by Computer