diff --git a/detections/endpoint/cmd_carry_out_string_command_parameter.yml b/detections/endpoint/cmd_carry_out_string_command_parameter.yml index 0f2f344831..75ca92e6aa 100644 --- a/detections/endpoint/cmd_carry_out_string_command_parameter.yml +++ b/detections/endpoint/cmd_carry_out_string_command_parameter.yml @@ -39,6 +39,7 @@ tags: - Azorult - DarkCrystal RAT - ProxyNotShell + - Qakbot automated_detection_testing: passed confidence: 50 context: diff --git a/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml b/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml index b5650460c0..87f459fb4c 100644 --- a/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml +++ b/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml @@ -1,7 +1,7 @@ name: Cmdline Tool Not Executed In CMD Shell id: 6c3f7dd8-153c-11ec-ac2d-acde48001122 -version: 1 -date: '2021-09-14' +version: 2 +date: '2022-10-27' author: Teoderick Contreras, Splunk type: TTP datamodel: @@ -15,8 +15,10 @@ description: The following analytic identifies a non-standard parent process (no This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = "ipconfig.exe" - OR Processes.process_name = "systeminfo.exe") AND NOT (Processes.parent_process_name + as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = "ipconfig.exe" + OR Processes.process_name = "systeminfo.exe" OR Processes.process_name = "net.exe" OR Processes.process_name = "net1.exe" + OR Processes.process_name = "arp.exe" OR Processes.process_name = "nslookup.exe" OR Processes.process_name = "route.exe" + OR Processes.process_name = "netstat.exe" OR Processes.process_name = "whoami.exe") AND NOT (Processes.parent_process_name = "cmd.exe" OR Processes.parent_process_name = "powershell*" OR Processes.parent_process_name="pwsh.exe" OR Processes.parent_process_name = "explorer.exe") by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.original_file_name Processes.process_id @@ -38,6 +40,7 @@ tags: - FIN7 - Qakbot - CISA AA22-277A + - Qakbot confidence: 80 context: - Source:Endpoint diff --git a/detections/endpoint/create_remote_thread_in_shell_application.yml b/detections/endpoint/create_remote_thread_in_shell_application.yml index 68eeea1233..842f27d9c1 100644 --- a/detections/endpoint/create_remote_thread_in_shell_application.yml +++ b/detections/endpoint/create_remote_thread_in_shell_application.yml @@ -24,6 +24,7 @@ references: tags: analytic_story: - IcedID + - Qakbot confidence: 100 context: - Source:Endpoint diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml index 9934363177..f7ddc36c9d 100644 --- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml @@ -46,6 +46,7 @@ tags: - DarkCrystal RAT - Brute Ratel C4 - AgentTesla + - Qakbot automated_detection_testing: passed confidence: 50 context: diff --git a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml index de054f6693..87e4c99fa4 100644 --- a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml +++ b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml @@ -33,6 +33,7 @@ references: tags: analytic_story: - Spearphishing Attachments + - Qakbot asset_type: Endpoint cis20: - CIS 7 diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/endpoint/suspicious_process_file_path.yml index 4b9db6014b..6b4b5760a5 100644 --- a/detections/endpoint/suspicious_process_file_path.yml +++ b/detections/endpoint/suspicious_process_file_path.yml @@ -42,6 +42,7 @@ tags: - DarkCrystal RAT - Brute Ratel C4 - AgentTesla + - Qakbot automated_detection_testing: passed confidence: 50 context: diff --git a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml index ccf975cf98..7c32281b0d 100644 --- a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml +++ b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml @@ -39,6 +39,7 @@ tags: - Suspicious Regsvr32 Activity - Icedid - Living Off The Land + - Qakbot asset_type: Endpoint cis20: - CIS 8 diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml index d7991a1905..8647e3e4be 100644 --- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml +++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml @@ -37,6 +37,7 @@ tags: - Unusual Processes - Ransomware - Masquerading - Rename System Utilities + - Qakbot asset_type: Endpoint cis20: - CIS 8 diff --git a/detections/endpoint/system_user_discovery_with_whoami.yml b/detections/endpoint/system_user_discovery_with_whoami.yml index 9de024be13..230f140f70 100644 --- a/detections/endpoint/system_user_discovery_with_whoami.yml +++ b/detections/endpoint/system_user_discovery_with_whoami.yml @@ -24,6 +24,7 @@ references: tags: analytic_story: - Active Directory Discovery + - Qakbot confidence: 50 context: - Source:Endpoint diff --git a/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml b/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml index 19baae8d94..dc5eaf2ad7 100644 --- a/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml +++ b/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml @@ -29,6 +29,7 @@ references: tags: analytic_story: - Trickbot + - Qakbot confidence: 80 context: - Source:Endpoint diff --git a/detections/endpoint/windows_app_layer_protocol_wermgr_connect_to_namedpipe.yml b/detections/endpoint/windows_app_layer_protocol_wermgr_connect_to_namedpipe.yml new file mode 100644 index 0000000000..b2039a4980 --- /dev/null +++ b/detections/endpoint/windows_app_layer_protocol_wermgr_connect_to_namedpipe.yml @@ -0,0 +1,69 @@ +name: Windows App Layer Protocol Wermgr Connect To NamedPipe +id: 2f3a4092-548b-421c-9caa-84918e1787ef +version: 1 +date: '2022-10-28' +author: Teoderick Contreras, Splunk +type: Anomaly +datamodel: +- Endpoint +description: The following analytic identifies a suspicious wermgr.exe process creating or connecting to a named pipe. + Wermgr.exe is part of Windows OS Problem reporting application responsible for reporting problems, fault or error happen on + the Windows OS. This file is being abused by several Threat actors and malware such as Trickbot and Qakbot to execute their malicious + code. This anomaly detection can be a good pivot on possible wermgr.exe processes having injected malicious code that might be related to + qakbot infection that communicates via named pipe. +search: '`sysmon` EventCode IN (17, 18) Image= "*\\wermgr.exe" EventType IN ( "CreatePipe", "ConnectPipe") + | stats min(_time) as firstTime max(_time) as lastTime count by Image EventType ProcessGuid ProcessId PipeName SecurityID EventCode Computer UserID + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_app_layer_protocol_wermgr_connect_to_namedpipe_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, pipename, processguid and named pipe event type from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: unknown +references: +- https://strontic.github.io/xcyclopedia/library/wermgr.exe-0F652BF7ADA772981E8AAB0D108FCC92.html +- https://www.trellix.com/en-us/about/newsroom/stories/research/demystifying-qbot-malware.html +tags: + analytic_story: + - Qakbot + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Command And Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_wermgr2/sysmon_wermgr2.log + impact: 70 + kill_chain_phases: + - Exploitation + message: wermgr.exe process is creating or connecting to a named pipe $PipeName$ in $Computer$ + mitre_attack_id: + - T1071 + nist: + - DE.CM + observable: + - name: Computer + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Image + - EventType + - ProcessGuid + - ProcessId + - PipeName + - Computer + - UserID + - SecurityID + risk_score: 49 + security_domain: endpoint diff --git a/detections/endpoint/windows_command_shell_fetch_env_variables.yml b/detections/endpoint/windows_command_shell_fetch_env_variables.yml new file mode 100644 index 0000000000..90897cf03a --- /dev/null +++ b/detections/endpoint/windows_command_shell_fetch_env_variables.yml @@ -0,0 +1,75 @@ +name: Windows Command Shell Fetch Env Variables +id: 048839e4-1eaa-43ff-8a22-86d17f6fcc13 +version: 1 +date: '2022-10-27' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies a suspicious process command line fetching the environment variables with a non-shell parent process. + This technique was seen in qakbot malware where it fetches the environment variable in the target or compromised host. This TTP detection is a good pivot + of possible malicious behavior since the command line is executed by a common non-shell process like cmd.exe , powershell.exe and many more. + This can also be a good sign that the parent process has a malicious code injected to it to execute this command. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where Processes.process = "*cmd /c set" OR Processes.process = "*cmd.exe /c set" AND NOT (Processes.parent_process_name = "cmd.exe" + OR Processes.parent_process_name = "powershell*" OR Processes.parent_process_name="pwsh.exe" OR Processes.parent_process_name = "explorer.exe") + by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id + Processes.parent_process_id Processes.original_file_name + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_command_shell_fetch_env_variables_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: shell process that are not included in this search may cause False positive. Filter is needed. +references: +- https://twitter.com/pr0xylife/status/1585612370441031680?s=46&t=Dc3CJi4AnM-8rNoacLbScg +tags: + analytic_story: + - Qakbot + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_wermgr/sysmon_wermgr.log + impact: 80 + kill_chain_phases: + - Exploitation + message: non-shell parent process has a child process $process_name$ with a commandline $process$ to fetch env variables in $dest$ + mitre_attack_id: + - T1055 + nist: + - DE.CM + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 56 + security_domain: endpoint diff --git a/detections/endpoint/windows_dll_side_loading_in_calc.yml b/detections/endpoint/windows_dll_side_loading_in_calc.yml new file mode 100644 index 0000000000..32a556f0b3 --- /dev/null +++ b/detections/endpoint/windows_dll_side_loading_in_calc.yml @@ -0,0 +1,63 @@ +name: Windows DLL Side-Loading In Calc +id: af01f6db-26ac-440e-8d89-2793e303f137 +version: 1 +date: '2022-10-24' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies suspicious DLL modules loaded by calc.exe that are not in windows %systemroot%\system32 or %systemroot%\sysWoW64 folder. + This technique is well used by Qakbot malware to execute its malicious DLL file via dll side loading technique in calc process execution. + This TTP detection is a good indicator that a suspicious dll was loaded in a public or non-common installation folder of Windows Operating System that needs further investigation. +search: '`sysmon` EventCode=7 Image = "*\calc.exe" AND NOT (Image IN ("*:\\windows\\system32\\*", "*:\\windows\\sysWow64\\*")) AND NOT(ImageLoaded IN("*:\\windows\\system32\\*", "*:\\windows\\sysWow64\\*", "*:\\windows\\WinSXS\\*")) + | stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded OriginalFileName Product process_name Computer EventCode Signed ProcessId + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_dll_side_loading_in_calc_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on processes that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` + node. In addition, confirm the latest CIM App 4.20 or higher is installed and the + latest TA for the endpoint product. +known_false_positives: unknown +references: +- https://www.bitdefender.com/blog/hotforsecurity/new-qakbot-malware-strain-replaces-windows-calculator-dll-to-infected-pcs/ +tags: + analytic_story: + - Qakbot + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot2/sysmon.log + impact: 90 + kill_chain_phases: + - Exploitation + message: a dll modules is loaded by calc.exe in $ImageLoaded$ that are not in common windows OS installation folder in $Computer$ + mitre_attack_id: + - T1574.002 + - T1574 + observable: + - name: Computer + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Image + - ImageLoaded + - OriginalFileName + - Product + - process_name + - Computer + - EventCode + - Signed + - ProcessId + risk_score: 90 + security_domain: endpoint + asset_type: Endpoint diff --git a/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml b/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml new file mode 100644 index 0000000000..73573735bd --- /dev/null +++ b/detections/endpoint/windows_dll_side_loading_process_child_of_calc.yml @@ -0,0 +1,75 @@ +name: Windows DLL Side-Loading Process Child Of Calc +id: 295ca9ed-e97b-4520-90f7-dfb6469902e1 +version: 1 +date: '2022-10-20' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies the suspicious child process of calc.exe due to dll side loading technique to execute another executable. + This technique was seen in qakbot malware that uses dll side loading technique to calc applications to load its malicious dll code. The malicious dll that abuses + dll side loading technique will load the actual qakbot loader dll using regsvr32.exe application. + This TTP is a good indicator of qakbot since the calc.exe will not load other child processes aside from win32calc.exe. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where (Processes.parent_process_name = "calc.exe") AND Processes.process_name != "win32calc.exe" + by Processes.parent_process Processes.process_name Processes.process_id Processes.process_guid Processes.process Processes.user Processes.dest + | `drop_dm_object_name("Processes")` + | `security_content_ctime(firstTime)` + |`security_content_ctime(lastTime)` + | `windows_dll_side_loading_process_child_of_calc_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process + that include the name of the process responsible for the changes from your endpoints into the `Endpoint` + datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and + the latest TA for the endpoint product. +known_false_positives: unknown +references: +- https://malpedia.caad.fkie.fraunhofer.de/details/win.qakbot +tags: + analytic_story: + - Qakbot + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 90 + context: + - Source:Endpoint + - Stage:Persistence + - Stage:Privilege Escalation + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/sysmon.log + impact: 90 + kill_chain_phases: + - Exploitation + message: calc.exe has a child process $process_name$ in $dest$ + mitre_attack_id: + - T1574.002 + - T1574 + nist: + - DE.CM + observable: + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name #parent process name + - Processes.parent_process #parent cmdline + - Processes.original_file_name + - Processes.process_name #process name + - Processes.process #process cmdline + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 81 + security_domain: endpoint diff --git a/detections/endpoint/windows_masquerading_explorer_as_child_process.yml b/detections/endpoint/windows_masquerading_explorer_as_child_process.yml new file mode 100644 index 0000000000..c529d94add --- /dev/null +++ b/detections/endpoint/windows_masquerading_explorer_as_child_process.yml @@ -0,0 +1,73 @@ +name: Windows Masquerading Explorer As Child Process +id: 61490da9-52a1-4855-a0c5-28233c88c481 +version: 1 +date: '2022-10-20' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies a suspicious parent process of explorer.exe. + Explorer is usually executed by userinit.exe that will exit after execution that causes the main explorer.exe no parent process. + Some malware like qakbot spawn another explorer.exe to inject its code. This TTP detection is a good indicator that a process spawning explorer.exe + might inject code or masquerading its parent child process to evade detections. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where Processes.parent_process_name IN("cmd.exe", "powershell.exe", "regsvr32.exe") AND Processes.process_name = "explorer.exe" + by Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process_id Processes.process_guid Processes.process Processes.user Processes.dest Processes.parent_process_id + | `drop_dm_object_name("Processes")` + | `security_content_ctime(firstTime)` + |`security_content_ctime(lastTime)` + | `windows_masquerading_explorer_as_child_process_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process + that include the name of the process responsible for the changes from your endpoints into the `Endpoint` + datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and + the latest TA for the endpoint product. +known_false_positives: unknown +references: +- https://malpedia.caad.fkie.fraunhofer.de/details/win.qakbot +tags: + analytic_story: + - Qakbot + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 90 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/sysmon.log + impact: 90 + kill_chain_phases: + - Exploitation + message: explorer.exe hash a suspicious parent process $parent_process_name$ in $dest$ + mitre_attack_id: + - T1574.002 + - T1574 + nist: + - DE.CM + observable: + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name #parent process name + - Processes.parent_process #parent cmdline + - Processes.original_file_name + - Processes.process_name #process name + - Processes.process #process cmdline + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 81 + security_domain: endpoint \ No newline at end of file diff --git a/detections/endpoint/windows_modify_registry_qakbot_binary_data_registry.yml b/detections/endpoint/windows_modify_registry_qakbot_binary_data_registry.yml new file mode 100644 index 0000000000..c8752f24d6 --- /dev/null +++ b/detections/endpoint/windows_modify_registry_qakbot_binary_data_registry.yml @@ -0,0 +1,89 @@ +name: Windows Modify Registry Qakbot Binary Data Registry +id: 2e768497-04e0-4188-b800-70dd2be0e30d +version: 1 +date: '2022-10-21' +author: Teoderick Contreras, Bhavin Patel, Splunk +type: Anomaly +datamodel: +- Endpoint +description: The following analytic identifies a suspicious registry entry created by Qakbot malware as part of its malicious execution. + This "Binary Data" Registry was created by newly spawn explorer.exe where its malicious code is injected to it. The registry consist of 8 random registry value name + with encrypted binary data on its registry value data. This anomaly detections can be a good pivot for possible Qakbot malware infection or other malware that uses registry + to save or store there config or malicious code on the registry data stream. +search: '| tstats `security_content_summariesonly` count dc(registry_value_name) as registry_value_name_count FROM datamodel=Endpoint.Registry + where Registry.registry_path="*\\SOFTWARE\\Microsoft\\*" AND Registry.registry_value_data = "Binary Data" + by _time span=1m Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.process_id Registry.registry_key_name + | `drop_dm_object_name(Registry)` + | rename process_guid as proc_guid + | eval registry_key_name_len = len(registry_key_name) + | eval registry_value_name_len = len(registry_value_name) + | regex registry_value_name="^[0-9a-fA-F]{8}" + | where registry_key_name_len < 80 AND registry_value_name_len == 8 + | join proc_guid, _time + [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + where Processes.process_name IN ("explorer.exe", "wermgr.exe","dxdiag.exe") + by _time span=1m Processes.process_id Processes.process_name Processes.process Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid Processes.process_path + | `drop_dm_object_name(Processes)` + | rename process_guid as proc_guid + | fields _time dest user parent_process_name parent_process process_name process_path process proc_guid registry_path registry_value_name registry_value_data process_id registry_key_name registry_value_name_count] + | stats min(_time) as firstTime max(_time) as lastTime values(registry_value_name) as registry_value_name dc(registry_value_name) as registry_value_name_count + by process_path registry_key_name registry_value_data proc_guid registry_key_name_len registry_value_name_len + | where registry_value_name_count >= 5 + | `windows_modify_registry_qakbot_binary_data_registry_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure + that this registry was included in your config files ex. sysmon config to be monitored. +known_false_positives: unknown +references: +- https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/decrypting-qakbots-encrypted-registry-keys/ +tags: + analytic_story: + - Qakbot + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot2/sysmon.log + impact: 70 + kill_chain_phases: + - Exploitation + message: registry with binary data $registry_path$ created by $process_name$ in $dest$ + mitre_attack_id: + - T1112 + nist: + - DE.CM + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - dest + - user + - parent_process_name + - parent_process + - process_name + - process_path + - process + - proc_guid + - registry_path + - registry_value_name + - registry_value_data + - process_id + - registry_key_name + - registry_key_name_len + - registry_value_name_len + risk_score: 49 + security_domain: endpoint diff --git a/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml b/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml new file mode 100644 index 0000000000..fbd319894c --- /dev/null +++ b/detections/endpoint/windows_process_injection_of_wermgr_to_known_browser.yml @@ -0,0 +1,71 @@ +name: Windows Process Injection Of Wermgr to Known Browser +id: aec755a5-3a2c-4be0-ab34-6540e68644e9 +version: 1 +date: '2022-10-28' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic identifies the suspicious Remote Thread execution of wermgr.exe process to "firefox.exe", "chrome.exe" and other known browsers. + This technique was seen in Qakbot malware that executes its malicious code by injecting its code in legitimate Windows Operating System processes such as wermgr.exe + to steal information in the compromised host. This TTP detection can be a good pivot to detect wermgr.exe process injected with qakbot code that tries to + remote thread code execution in known browsers like firefox and edge which is not a common behavior of this wermgr.exe application. +search: '`sysmon` EventCode=8 SourceImage = "*\\wermgr.exe" TargetImage IN ("*\\firefox.exe", "*\\chrome.exe", "*\\iexplore.exe","*\\microsoftedgecp.exe") + | stats count min(_time) as firstTime max(_time) as lastTime by SourceImage TargetImage SourceProcessGuid SourceProcessId StartAddress StartFunction TargetProcessGuid TargetProcessId EventCode Computer + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_process_injection_of_wermgr_to_known_browser_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the SourceImage, TargetImage, and EventCode executions from your endpoints + related to create remote thread or injecting codes. If you are using Sysmon, you + must have at least version 6.0.4 of the Sysmon TA. +known_false_positives: unknown +references: +- https://news.sophos.com/en-us/2022/03/10/qakbot-decoded/ +- https://www.trellix.com/en-us/about/newsroom/stories/research/demystifying-qbot-malware.html +tags: + analytic_story: + - Qakbot + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/remote_thread/sysmon_wermgr_remote.log + impact: 70 + kill_chain_phases: + - Exploitation + message: wermgr.exe process $SourceImage$ create a remote thread to a browser process $TargetImage$ in host $Computer$ + mitre_attack_id: + - T1055.001 + - T1055 + nist: + - DE.CM + observable: + - name: Computer + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - SourceImage + - TargetImage + - SourceProcessGuid + - SourceProcessId + - StartAddress + - StartFunction + - TargetProcessGuid + - TargetProcessId + - EventCode + - Computer + risk_score: 49 + security_domain: endpoint diff --git a/detections/endpoint/windows_process_injection_remote_thread.yml b/detections/endpoint/windows_process_injection_remote_thread.yml new file mode 100644 index 0000000000..004d3e9656 --- /dev/null +++ b/detections/endpoint/windows_process_injection_remote_thread.yml @@ -0,0 +1,78 @@ +name: Windows Process Injection Remote Thread +id: 8a618ade-ca8f-4d04-b972-2d526ba59924 +version: 1 +date: '2022-10-27' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies a suspicious remote thread execution in some process being abused by threat actor and malware like + qakbot. Qakbot is one of the malware using this technique to load its malicious dll module or malicious code in the targeted host. + This TTP can be a good pivot to verify what is the behavior of the targeted Image process after this detection trigger. + look for network connection, child process execution, file access and many more that helps to verify the indication of malware infection. +search: '`sysmon` EventCode=8 TargetImage IN ("*\\Taskmgr.exe", "*\\calc.exe", "*\\notepad.exe", "*\\rdpclip.exe", "*\\explorer.exe", "*\\wermgr.exe", "*\\ping.exe") + | stats count min(_time) as firstTime max(_time) as lastTime by TargetImage TargetProcessId SourceProcessId EventCode StartAddress SourceImage Computer + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_process_injection_remote_thread_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records process activity from your hosts like remote thread EventCode=8 of sysmon. + If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +known_false_positives: unknown +references: +- https://twitter.com/pr0xylife/status/1585612370441031680?s=46&t=Dc3CJi4AnM-8rNoacLbScg +tags: + analytic_story: + - Qakbot + asset_type: 80 + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_wermgr2/sysmon_wermgr2.log + impact: 80 + kill_chain_phases: + - Exploitation + message: process $SourceImage$ create a remote thread to process $TargetImage$ on host $Computer$ + mitre_attack_id: + - T1055 + - T1055.002 + nist: + - DE.CM + observable: + - name: Computer + type: Hostname + role: + - Victim + - name: SourceImage + type: Process + role: + - Attacker + - name: TargetImage + type: Process + role: + - Target + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - SourceImage + - TargetImage + - TargetProcessId + - SourceProcessId + - StartAddress + - EventCode + - Computer + - signature + - TargetProcessGuid + - SourceProcessGuid + - StartAddress + risk_score: 64 + security_domain: endpoint diff --git a/detections/endpoint/windows_process_injection_wermgr_child_process.yml b/detections/endpoint/windows_process_injection_wermgr_child_process.yml new file mode 100644 index 0000000000..afe3a2200a --- /dev/null +++ b/detections/endpoint/windows_process_injection_wermgr_child_process.yml @@ -0,0 +1,74 @@ +name: Windows Process Injection Wermgr Child Process +id: 360ae6b0-38b5-4328-9e2b-bc9436cddb17 +version: 1 +date: '2022-10-27' +author: Teoderick Contreras, Splunk +type: Anomaly +datamodel: +- Endpoint +description: The following analytic identifies a suspicious wermgr.exe parent process having a child process not related to error, fault or windows werfault event. + This technique was seen in Qakbot malware where it inject its malicious code in wermgr to evade detections and hide from the analyst to execute its + recon and its malicious behavior. This Anomaly detection can be a good pivot to start investigating a possible qakbot infection in the network. + The Wermgr.exe process is not known to have other child processes aside from itself or werfault.exe +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where Processes.parent_process_name = "wermgr.exe" AND NOT (Processes.process_name IN ("WerFaultSecure.exe", "wermgr.exe", "WerFault.exe")) + by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id + Processes.parent_process_id Processes.original_file_name + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_process_injection_wermgr_child_process_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: unknown +references: +- https://twitter.com/pr0xylife/status/1585612370441031680?s=46&t=Dc3CJi4AnM-8rNoacLbScg +tags: + analytic_story: + - Qakbot + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_wermgr/sysmon_wermgr.log + impact: 80 + kill_chain_phases: + - Exploitation + message: wermgr parent process has a child process $process_name$ in $dest$ + mitre_attack_id: + - T1055 + nist: + - DE.CM + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 56 + security_domain: endpoint diff --git a/detections/endpoint/windows_regsvr32_renamed_binary.yml b/detections/endpoint/windows_regsvr32_renamed_binary.yml new file mode 100644 index 0000000000..39fde777ef --- /dev/null +++ b/detections/endpoint/windows_regsvr32_renamed_binary.yml @@ -0,0 +1,76 @@ +name: Windows Regsvr32 Renamed Binary +id: 7349a9e9-3cf6-4171-bb0c-75607a8dcd1a +version: 1 +date: '2022-10-27' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: The following hunting analytic identifies renamed instances of regsv32.exe executing. + regsv32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. + During investigation, validate if it is the legitimate regsv32.exe executing and what dll module content it is loading. + This query relies on the original filename or internal name from the PE meta data. + Expand the query as needed by looking for specific command line arguments outlined in other analytics. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where Processes.process_name != regsvr32.exe AND Processes.original_file_name=regsvr32.exe + by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id + Processes.parent_process_id Processes.original_file_name + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_regsvr32_renamed_binary_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: unknown +references: +- https://twitter.com/pr0xylife/status/1585612370441031680?s=46&t=Dc3CJi4AnM-8rNoacLbScg +tags: + analytic_story: + - Qakbot + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_3/sysmon.log + impact: 80 + kill_chain_phases: + - Exploitation + message: regsvr32 was renamed as $process_name$ in $dest$ + mitre_attack_id: + - T1218.010 + - T1218 + nist: + - DE.CM + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 64 + security_domain: endpoint diff --git a/detections/endpoint/windows_system_discovery_using_ldap_nslookup.yml b/detections/endpoint/windows_system_discovery_using_ldap_nslookup.yml new file mode 100644 index 0000000000..0d8efa2499 --- /dev/null +++ b/detections/endpoint/windows_system_discovery_using_ldap_nslookup.yml @@ -0,0 +1,74 @@ +name: Windows System Discovery Using ldap Nslookup +id: 2418780f-7c3e-4c45-b8b4-996ea850cd49 +version: 1 +date: '2022-10-21' +author: Teoderick Contreras, Splunk +type: Hunting +datamodel: +- Endpoint +description: The following analytic identifies the execution of nslookup.exe tool to get domain information. + Nslookup.exe is a command-line tool that can display information to diagnose domain name systems. This Nslookup feature is being abused + by Qakbot malware to gather domain information such as SRV service location records, server name and many more. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where (Processes.process_name = "nslookup.exe" OR Processes.original_file_name = "nslookup.exe") AND Processes.process = "*_ldap._tcp.dc._msdcs*" + by Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process_id Processes.process_guid Processes.process Processes.user Processes.dest Processes.parent_process_id Processes.original_file_name + | `drop_dm_object_name("Processes")` + | `security_content_ctime(firstTime)` + |`security_content_ctime(lastTime)` + | `windows_system_discovery_using_ldap_nslookup_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: dministrator may execute this commandline tool for auditing purposes. Filter as needed. +references: +- https://securelist.com/qakbot-technical-analysis/103931/ +- https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/verify-srv-dns-records-have-been-created +tags: + analytic_story: + - Qakbot + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 50 + context: + - Source:Endpoint + - Stage:Discovery + - Stage:Recon + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/qakbot_discovery_cmdline/sysmon.log + impact: 50 + kill_chain_phases: + - Reconnaissance + message: System nslookup domain discovery on $dest$ + mitre_attack_id: + - T1033 + nist: + - DE.CM + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 25 + security_domain: endpoint \ No newline at end of file diff --git a/detections/endpoint/windows_system_discovery_using_qwinsta.yml b/detections/endpoint/windows_system_discovery_using_qwinsta.yml new file mode 100644 index 0000000000..2d3e3410ef --- /dev/null +++ b/detections/endpoint/windows_system_discovery_using_qwinsta.yml @@ -0,0 +1,75 @@ +name: Windows System Discovery Using Qwinsta +id: 2e765c1b-144a-49f0-93d0-1df4287cca04 +version: 1 +date: '2022-10-21' +author: Teoderick Contreras, Splunk +type: Hunting +datamodel: +- Endpoint +description: The following analytic identifies the execution of qwinsta.exe executable in Windows Operating System. + This Windows executable file can display information about sessions on a remote desktop session host server. The information + includes servername, sessionname, username and many more. This tool is being abused of Qakbot malware + to gather information to the targeted or compromised host that will be send back to its Command and control server. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where Processes.process_name = "qwinsta.exe" OR Processes.original_file_name = "qwinsta.exe" + by Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process_id Processes.process_guid Processes.process Processes.user Processes.dest Processes.parent_process_id Processes.original_file_name + | `drop_dm_object_name("Processes")` + | `security_content_ctime(firstTime)` + |`security_content_ctime(lastTime)` + | `windows_system_discovery_using_qwinsta_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Administrator may execute this commandline tool for auditing purposes. Filter as needed. +references: +- https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/qwinsta +- https://securelist.com/qakbot-technical-analysis/103931/ +tags: + analytic_story: + - Qakbot + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 50 + context: + - Source:Endpoint + - Stage:Discovery + - Stage:Recon + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/qakbot_discovery_cmdline/sysmon.log + impact: 50 + kill_chain_phases: + - Reconnaissance + message: System qwinsta domain discovery on $dest$ + mitre_attack_id: + - T1033 + nist: + - DE.CM + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 25 + security_domain: endpoint diff --git a/detections/endpoint/windows_wmi_impersonate_token.yml b/detections/endpoint/windows_wmi_impersonate_token.yml new file mode 100644 index 0000000000..19a649a898 --- /dev/null +++ b/detections/endpoint/windows_wmi_impersonate_token.yml @@ -0,0 +1,71 @@ +name: Windows WMI Impersonate Token +id: cf192860-2d94-40db-9a51-c04a2e8a8f8b +version: 1 +date: '2022-10-24' +author: Teoderick Contreras, Splunk +type: Anomaly +datamodel: +- Endpoint +description: The following analytic identifies a possible wmi token impersonation activities in a process or command. + This technique was seen in Qakbot malware where it will execute a vbscript code contains wmi impersonation object to gain privilege escalation or + as defense evasion. This Anomaly detection looks for wmiprvse.exe SourceImage having a duplicate handle or full granted access in a target process. +search: '`sysmon` EventCode=10 SourceImage = "*\\wmiprvse.exe" GrantedAccess IN ("0x1478", "0x1fffff") + | stats count min(_time) as firstTime max(_time) as lastTime + by SourceImage TargetImage SourceProcessGUID TargetProcessGUID SourceProcessId TargetProcessId GrantedAccess CallTrace Computer + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_wmi_impersonate_token_filter`' +how_to_implement: This search requires Sysmon Logs and a Sysmon configuration, which + includes EventCode 10. This search uses an input macro named `sysmon`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition + with configurations for your Splunk environment. The search also uses a post-filter + macro designed to filter out known false positives. +known_false_positives: administrator may execute impersonate wmi object script for auditing. Filter is needed. +references: +- https://github.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/process-access.md +- https://www.joesandbox.com/analysis/278341/0/html +tags: + analytic_story: + - Qakbot + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 50 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/wmi_impersonate/sysmon.log + impact: 50 + kill_chain_phases: + - Exploitation + message: wmiprvse.exe process having a duplicate or full Granted Access $GrantedAccess$ to $TargetImage$ process in $dest$ + mitre_attack_id: + - T1047 + nist: + - DE.CM + observable: + - name: Computer + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - SourceImage + - TargetImage + - SourceProcessGUID + - TargetProcessGUID + - SourceProcessId + - TargetProcessId + - GrantedAccess + - CallTrace + - Computer + risk_score: 25 + security_domain: endpoint diff --git a/macros/process_wermgr.yml b/macros/process_wermgr.yml new file mode 100644 index 0000000000..d54429c003 --- /dev/null +++ b/macros/process_wermgr.yml @@ -0,0 +1,3 @@ +definition: (Processes.process_name=wermgr.exe OR Processes.original_file_name=wermgr.EXE) +description: Matches the process with its original file name, data for this macro came from https://strontic.github.io/ +name: process_wermgr \ No newline at end of file diff --git a/tests/endpoint/windows_app_layer_protocol_wermgr_connect_to_namedpipe.test.yml b/tests/endpoint/windows_app_layer_protocol_wermgr_connect_to_namedpipe.test.yml new file mode 100644 index 0000000000..77cfecd013 --- /dev/null +++ b/tests/endpoint/windows_app_layer_protocol_wermgr_connect_to_namedpipe.test.yml @@ -0,0 +1,13 @@ +name: Windows App Layer Protocol Wermgr Connect To NamedPipe Unit Test +tests: +- name: Windows App Layer Protocol Wermgr Connect To NamedPipe + file: endpoint/windows_app_layer_protocol_wermgr_connect_to_namedpipe.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon_wermgr2.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_wermgr2/sysmon_wermgr2.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_command_shell_fetch_env_variables.test.yml b/tests/endpoint/windows_command_shell_fetch_env_variables.test.yml new file mode 100644 index 0000000000..ef099fcd00 --- /dev/null +++ b/tests/endpoint/windows_command_shell_fetch_env_variables.test.yml @@ -0,0 +1,13 @@ +name: Windows Command Shell Fetch Env Variables Unit Test +tests: +- name: Windows Command Shell Fetch Env Variables + file: endpoint/windows_command_shell_fetch_env_variables.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon_wermgr.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_wermgr/sysmon_wermgr.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_dll_side_loading_in_calc.test.yml b/tests/endpoint/windows_dll_side_loading_in_calc.test.yml new file mode 100644 index 0000000000..4647bc8208 --- /dev/null +++ b/tests/endpoint/windows_dll_side_loading_in_calc.test.yml @@ -0,0 +1,13 @@ +name: Windows DLL Side-Loading In Calc Unit Test +tests: +- name: Windows DLL Side-Loading In Calc + file: endpoint/windows_dll_side_loading_in_calc.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot2/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_dll_side_loading_process_child_of_calc.test.yml b/tests/endpoint/windows_dll_side_loading_process_child_of_calc.test.yml new file mode 100644 index 0000000000..d001e93886 --- /dev/null +++ b/tests/endpoint/windows_dll_side_loading_process_child_of_calc.test.yml @@ -0,0 +1,13 @@ +name: Windows DLL Side-Loading Process Child Of Calc Unit Test +tests: +- name: Windows DLL Side-Loading Process Child Of Calc + file: endpoint/windows_dll_side_loading_process_child_of_calc.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_masquerading_explorer_as_child_process.test.yml b/tests/endpoint/windows_masquerading_explorer_as_child_process.test.yml new file mode 100644 index 0000000000..271c5d37b9 --- /dev/null +++ b/tests/endpoint/windows_masquerading_explorer_as_child_process.test.yml @@ -0,0 +1,13 @@ +name: Windows Masquerading Explorer As Child Process Unit Test +tests: +- name: Windows Masquerading Explorer As Child Process + file: endpoint/windows_masquerading_explorer_as_child_process.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_modify_registry_qakbot_binary_data_registry.test.yml b/tests/endpoint/windows_modify_registry_qakbot_binary_data_registry.test.yml new file mode 100644 index 0000000000..eefc2f110e --- /dev/null +++ b/tests/endpoint/windows_modify_registry_qakbot_binary_data_registry.test.yml @@ -0,0 +1,13 @@ +name: Windows Modify Registry Qakbot Binary Data Registry Unit Test +tests: +- name: Windows Modify Registry Qakbot Binary Data Registry + file: endpoint/windows_modify_registry_qakbot_binary_data_registry.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot2/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_process_injection_of_wermgr_to_known_browser.test.yml b/tests/endpoint/windows_process_injection_of_wermgr_to_known_browser.test.yml new file mode 100644 index 0000000000..ca930f37cf --- /dev/null +++ b/tests/endpoint/windows_process_injection_of_wermgr_to_known_browser.test.yml @@ -0,0 +1,13 @@ +name: Windows Process Injection Of Wermgr to Known Browser Unit Test +tests: +- name: Windows Process Injection Of Wermgr to Known Browser + file: endpoint/windows_process_injection_of_wermgr_to_known_browser.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon_wermgr_remote.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/remote_thread/sysmon_wermgr_remote.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_process_injection_remote_thread.test.yml b/tests/endpoint/windows_process_injection_remote_thread.test.yml new file mode 100644 index 0000000000..562984d710 --- /dev/null +++ b/tests/endpoint/windows_process_injection_remote_thread.test.yml @@ -0,0 +1,13 @@ +name: Windows Process Injection Remote Thread Unit Test +tests: +- name: Windows Process Injection Remote Thread + file: endpoint/windows_process_injection_remote_thread.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon_wermgr2.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_wermgr2/sysmon_wermgr2.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_process_injection_wermgr_child_process.test.yml b/tests/endpoint/windows_process_injection_wermgr_child_process.test.yml new file mode 100644 index 0000000000..10ef4c0db9 --- /dev/null +++ b/tests/endpoint/windows_process_injection_wermgr_child_process.test.yml @@ -0,0 +1,13 @@ +name: Windows Process Injection Wermgr Child Process Unit Test +tests: +- name: Windows Process Injection Wermgr Child Process + file: endpoint/windows_process_injection_wermgr_child_process.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon_wermgr.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_wermgr/sysmon_wermgr.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_regsvr32_renamed_binary.test.yml b/tests/endpoint/windows_regsvr32_renamed_binary.test.yml new file mode 100644 index 0000000000..0ef588ee42 --- /dev/null +++ b/tests/endpoint/windows_regsvr32_renamed_binary.test.yml @@ -0,0 +1,13 @@ +name: Windows Regsvr32 Renamed Binary Unit Test +tests: +- name: Windows Regsvr32 Renamed Binary + file: endpoint/windows_regsvr32_renamed_binary.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_3/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_system_discovery_using_ldap_nslookup.test.yml b/tests/endpoint/windows_system_discovery_using_ldap_nslookup.test.yml new file mode 100644 index 0000000000..a2efe1330f --- /dev/null +++ b/tests/endpoint/windows_system_discovery_using_ldap_nslookup.test.yml @@ -0,0 +1,13 @@ +name: Windows System Discovery Using ldap Nslookup Unit Test +tests: +- name: Windows System Discovery Using ldap Nslookup + file: endpoint/windows_system_discovery_using_ldap_nslookup.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/qakbot_discovery_cmdline/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_system_discovery_using_qwinsta.test.yml b/tests/endpoint/windows_system_discovery_using_qwinsta.test.yml new file mode 100644 index 0000000000..15cefdad56 --- /dev/null +++ b/tests/endpoint/windows_system_discovery_using_qwinsta.test.yml @@ -0,0 +1,13 @@ +name: Windows System Discovery Using Qwinsta Unit Test +tests: +- name: Windows System Discovery Using Qwinsta + file: endpoint/windows_system_discovery_using_qwinsta.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1033/qakbot_discovery_cmdline/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_wmi_impersonate_token.test.yml b/tests/endpoint/windows_wmi_impersonate_token.test.yml new file mode 100644 index 0000000000..9ce78d8504 --- /dev/null +++ b/tests/endpoint/windows_wmi_impersonate_token.test.yml @@ -0,0 +1,13 @@ +name: Windows WMI Impersonate Token Unit Test +tests: +- name: Windows WMI Impersonate Token + file: endpoint/windows_wmi_impersonate_token.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1047/wmi_impersonate/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true