mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -2,7 +2,7 @@ name: Excessive Usage of NSLOOKUP App
|
||||
id: 0a69fdaa-a2b8-11eb-b16d-acde48001122
|
||||
version: 1
|
||||
date: '2021-04-21'
|
||||
author: Teoderick Contreras, Splunk
|
||||
author: Teoderick Contreras, Stanislav Miskovic, Splunk
|
||||
type: batch
|
||||
datamodel:
|
||||
- Endpoint
|
||||
@@ -12,12 +12,12 @@ description: this search is to detect potential DNS exfiltration using nslookup
|
||||
use of nslookup where it tries to use specific record type (TXT, A, AAAA) that are
|
||||
commonly used by attacker and also the retry parameter which is designed to query
|
||||
C2 DNS multiple tries.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
values(Processes.process_id) as process_id values(Processes.parent_process) as parent_process
|
||||
count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.process_name = "nslookup.exe" by Processes.dest Processes.user Processes.process_name
|
||||
| where count >= 30 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`| `excessive_usage_of_nslookup_app_filter`'
|
||||
search: '`sysmon` EventCode = 1 process_name = "nslookup.exe" | bucket _time span=15m
|
||||
| stats count as numNsLookup by Computer, _time | eventstats avg(numNsLookup) as
|
||||
avgNsLookup, stdev(numNsLookup) as stdNsLookup, count as numSlots by Computer | eval
|
||||
upperThreshold=(avgNsLookup + stdNsLookup *3) | eval isOutlier=if(avgNsLookup >
|
||||
20 and avgNsLookup >= upperThreshold, 1, 0) | search isOutlier=1 | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `excessive_usage_of_nslookup_app_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
|
||||
@@ -9,7 +9,7 @@ datamodel:
|
||||
description: The following analytics identifies a big number of instance of ransomware
|
||||
notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This
|
||||
behavior is a good sensor if the ransomware note filename is quite new for security
|
||||
industry or the ransomware note filename is not in your lookup table list for monitoring.
|
||||
industry or the ransomware note filename is not in your ransomware lookup table list for monitoring.
|
||||
search: '`sysmon` EventCode=11 file_name IN ("*\.txt","*\.html","*\.hta") |bin _time
|
||||
span=10s | stats min(_time) as firstTime max(_time) as lastTime dc(TargetFilename)
|
||||
as unique_readme_path_count values(TargetFilename) as list_of_readme_path by Computer
|
||||
|
||||
Reference in New Issue
Block a user