From aa10dadc4f97dabe79c688e60b95d7f77836784d Mon Sep 17 00:00:00 2001 From: root Date: Wed, 8 Sep 2021 02:27:22 +0000 Subject: [PATCH] Added detection testing service results inGet-DomainTrust with PowerShell --- .../get_domaintrust_with_powershell.yml | 50 +++++++++++-------- 1 file changed, 29 insertions(+), 21 deletions(-) diff --git a/detections/endpoint/get_domaintrust_with_powershell.yml b/detections/endpoint/get_domaintrust_with_powershell.yml index bc7acac2ce..6d65303a08 100644 --- a/detections/endpoint/get_domaintrust_with_powershell.yml +++ b/detections/endpoint/get_domaintrust_with_powershell.yml @@ -6,24 +6,31 @@ author: Michael Haag, Splunk type: TTP datamodel: - Endpoint -description: 'This analytic identifies Get-DomainTrust from PowerView in order to gather domain trust information. - Typically, this is utilized within a script being executed and used to enumerate the domain trust information. This grants the adversary an understanding of how large or small the domain is. - During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity.' +description: This analytic identifies Get-DomainTrust from PowerView in order to gather + domain trust information. Typically, this is utilized within a script being executed + and used to enumerate the domain trust information. This grants the adversary an + understanding of how large or small the domain is. During triage, review parallel + processes using an EDR product or 4688 events. It will be important to understand + the timeline of events around this activity. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where Processes.process=*get-domaintrust* by Processes.dest Processes.user Processes.parent_process_name Processes.process_name - Processes.process Processes.process_id Processes.parent_process_id - | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `get_domaintrust_with_powershell_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. -known_false_positives: Limited false positives as this requires an active Administrator or adversary to bring in, import, and execute. + as lastTime from datamodel=Endpoint.Processes where Processes.process=*get-domaintrust* + by Processes.dest Processes.user Processes.parent_process_name Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `get_domaintrust_with_powershell_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Limited false positives as this requires an active Administrator + or adversary to bring in, import, and execute. references: - - http://www.harmj0y.net/blog/redteaming/a-guide-to-attacking-domain-trusts/ +- http://www.harmj0y.net/blog/redteaming/a-guide-to-attacking-domain-trusts/ tags: analytic_story: - Active Directory Discovery - dataset: [] + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-sysmon.log kill_chain_phases: - Reconnaissance mitre_attack_id: @@ -36,24 +43,24 @@ tags: - _time - Processes.dest - Processes.user - - Processes.parent_process_name #parent process name - - Processes.parent_process #parent cmdline + - Processes.parent_process_name + - Processes.parent_process - Processes.original_file_name - - Processes.process_name #process name - - Processes.process #process cmdline + - Processes.process_name + - Processes.process - Processes.process_id - Processes.parent_process_path - Processes.process_path - Processes.parent_process_id security_domain: endpoint - impact: 30 + impact: 30 confidence: 40 - # (impact * confidence)/100 risk_score: 12 context: - Source:Endpoint - Stage:Defense Evasion - message: Suspicious PowerShell Get-DomainTrust was identified on endpoint $dest$ by user $user$. + message: Suspicious PowerShell Get-DomainTrust was identified on endpoint $dest$ + by user $user$. observable: - name: user type: User @@ -62,4 +69,5 @@ tags: - name: dest type: Hostname role: - - Victim \ No newline at end of file + - Victim + automated_detection_testing: passed