mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge branch 'develop' into firewall_win_events
This commit is contained in:
@@ -74,18 +74,18 @@ rba:
|
||||
type: process_name
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ingress Tool Transfer
|
||||
- Data Destruction
|
||||
- Malicious PowerShell
|
||||
- China-Nexus Threat Activity
|
||||
- Crypto Stealer
|
||||
- Hermetic Wiper
|
||||
- DarkCrystal RAT
|
||||
- Malicious PowerShell
|
||||
- Earth Estries
|
||||
- Phemedrone Stealer
|
||||
- Braodo Stealer
|
||||
- PXA Stealer
|
||||
- Data Destruction
|
||||
- Log4Shell CVE-2021-44228
|
||||
- Salt Typhoon
|
||||
- Braodo Stealer
|
||||
- Crypto Stealer
|
||||
- Ingress Tool Transfer
|
||||
- PHP-CGI RCE Attack on Japanese Organizations
|
||||
asset_type: Endpoint
|
||||
cve:
|
||||
|
||||
@@ -68,12 +68,12 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- SnappyBee
|
||||
- Rhysida Ransomware
|
||||
- China-Nexus Threat Activity
|
||||
- Crypto Stealer
|
||||
- Earth Estries
|
||||
- Unusual Processes
|
||||
- SnappyBee
|
||||
- Salt Typhoon
|
||||
- Rhysida Ransomware
|
||||
- Crypto Stealer
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1204
|
||||
|
||||
@@ -42,18 +42,18 @@ references:
|
||||
- https://redcanary.com/blog/threat-hunting-psexec-lateral-movement/
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- BlackByte Ransomware
|
||||
- HAFNIUM Group
|
||||
- DHS Report TA18-074A
|
||||
- CISA AA22-320A
|
||||
- DarkSide Ransomware
|
||||
- Active Directory Lateral Movement
|
||||
- DarkGate Malware
|
||||
- Sandworm Tools
|
||||
- Rhysida Ransomware
|
||||
- Earth Estries
|
||||
- SamSam Ransomware
|
||||
- BlackByte Ransomware
|
||||
- CISA AA22-320A
|
||||
- China-Nexus Threat Activity
|
||||
- Salt Typhoon
|
||||
- DarkGate Malware
|
||||
- Active Directory Lateral Movement
|
||||
- HAFNIUM Group
|
||||
- DarkSide Ransomware
|
||||
- Rhysida Ransomware
|
||||
- DHS Report TA18-074A
|
||||
- VanHelsing Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
|
||||
@@ -42,9 +42,9 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- CISA AA22-277A
|
||||
- Collection and Staging
|
||||
- Earth Estries
|
||||
- CISA AA22-277A
|
||||
- Salt Typhoon
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1560.001
|
||||
|
||||
@@ -63,48 +63,48 @@ rba:
|
||||
type: file_name
|
||||
tags:
|
||||
analytic_story:
|
||||
- BlackByte Ransomware
|
||||
- Brute Ratel C4
|
||||
- Trickbot
|
||||
- Snake Keylogger
|
||||
- Graceful Wipe Out Attack
|
||||
- PlugX
|
||||
- Handala Wiper
|
||||
- Earth Estries
|
||||
- Warzone RAT
|
||||
- ValleyRAT
|
||||
- NjRAT
|
||||
- LockBit Ransomware
|
||||
- Double Zero Destructor
|
||||
- Swift Slicer
|
||||
- DarkCrystal RAT
|
||||
- AsyncRAT
|
||||
- Volt Typhoon
|
||||
- Chaos Ransomware
|
||||
- Hermetic Wiper
|
||||
- Derusbi
|
||||
- XMRig
|
||||
- AgentTesla
|
||||
- WinDealer RAT
|
||||
- RedLine Stealer
|
||||
- Remcos
|
||||
- Rhysida Ransomware
|
||||
- China-Nexus Threat Activity
|
||||
- Crypto Stealer
|
||||
- Qakbot
|
||||
- IcedID
|
||||
- Meduza Stealer
|
||||
- AcidPour
|
||||
- MoonPeak
|
||||
- CISA AA23-347A
|
||||
- DarkGate Malware
|
||||
- Industroyer2
|
||||
- Azorult
|
||||
- Data Destruction
|
||||
- Amadey
|
||||
- SnappyBee
|
||||
- WhisperGate
|
||||
- SystemBC
|
||||
- Snake Keylogger
|
||||
- China-Nexus Threat Activity
|
||||
- Remcos
|
||||
- LockBit Ransomware
|
||||
- AsyncRAT
|
||||
- DarkCrystal RAT
|
||||
- Derusbi
|
||||
- WinDealer RAT
|
||||
- DarkGate Malware
|
||||
- Crypto Stealer
|
||||
- ValleyRAT
|
||||
- AcidPour
|
||||
- PlugX
|
||||
- Data Destruction
|
||||
- Qakbot
|
||||
- CISA AA23-347A
|
||||
- Hermetic Wiper
|
||||
- Volt Typhoon
|
||||
- Double Zero Destructor
|
||||
- NjRAT
|
||||
- Trickbot
|
||||
- AgentTesla
|
||||
- Meduza Stealer
|
||||
- SnappyBee
|
||||
- Azorult
|
||||
- WhisperGate
|
||||
- Warzone RAT
|
||||
- Swift Slicer
|
||||
- Rhysida Ransomware
|
||||
- Brute Ratel C4
|
||||
- BlackByte Ransomware
|
||||
- Graceful Wipe Out Attack
|
||||
- Chaos Ransomware
|
||||
- Handala Wiper
|
||||
- RedLine Stealer
|
||||
- Salt Typhoon
|
||||
- XMRig
|
||||
- MoonPeak
|
||||
- Industroyer2
|
||||
- Amadey
|
||||
- IcedID
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1036
|
||||
|
||||
@@ -60,47 +60,47 @@ rba:
|
||||
type: file_name
|
||||
tags:
|
||||
analytic_story:
|
||||
- Chaos Ransomware
|
||||
- Trickbot
|
||||
- Snake Keylogger
|
||||
- CISA AA23-347A
|
||||
- Industroyer2
|
||||
- WinDealer RAT
|
||||
- Qakbot
|
||||
- Warzone RAT
|
||||
- IcedID
|
||||
- ValleyRAT
|
||||
- Azorult
|
||||
- Handala Wiper
|
||||
- LockBit Ransomware
|
||||
- Meduza Stealer
|
||||
- Brute Ratel C4
|
||||
- AsyncRAT
|
||||
- AcidPour
|
||||
- Derusbi
|
||||
- DarkGate Malware
|
||||
- Graceful Wipe Out Attack
|
||||
- NjRAT
|
||||
- WhisperGate
|
||||
- Data Destruction
|
||||
- BlackByte Ransomware
|
||||
- AgentTesla
|
||||
- Swift Slicer
|
||||
- Crypto Stealer
|
||||
- Hermetic Wiper
|
||||
- MoonPeak
|
||||
- Double Zero Destructor
|
||||
- XMRig
|
||||
- PlugX
|
||||
- Amadey
|
||||
- DarkCrystal RAT
|
||||
- Remcos
|
||||
- China-Nexus Threat Activity
|
||||
- Earth Estries
|
||||
- Rhysida Ransomware
|
||||
- RedLine Stealer
|
||||
- Remcos
|
||||
- LockBit Ransomware
|
||||
- AsyncRAT
|
||||
- DarkCrystal RAT
|
||||
- Derusbi
|
||||
- WinDealer RAT
|
||||
- DarkGate Malware
|
||||
- AcidPour
|
||||
- ValleyRAT
|
||||
- Crypto Stealer
|
||||
- PlugX
|
||||
- Data Destruction
|
||||
- Qakbot
|
||||
- CISA AA23-347A
|
||||
- Hermetic Wiper
|
||||
- Volt Typhoon
|
||||
- Double Zero Destructor
|
||||
- NjRAT
|
||||
- Trickbot
|
||||
- Meduza Stealer
|
||||
- AgentTesla
|
||||
- SnappyBee
|
||||
- Azorult
|
||||
- WhisperGate
|
||||
- Warzone RAT
|
||||
- Swift Slicer
|
||||
- Rhysida Ransomware
|
||||
- Brute Ratel C4
|
||||
- BlackByte Ransomware
|
||||
- Graceful Wipe Out Attack
|
||||
- Chaos Ransomware
|
||||
- Handala Wiper
|
||||
- RedLine Stealer
|
||||
- Salt Typhoon
|
||||
- XMRig
|
||||
- MoonPeak
|
||||
- Industroyer2
|
||||
- Amadey
|
||||
- IcedID
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1036
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
name: Linux Auditd File Permission Modification Via Chmod
|
||||
id: 5f1d2ea7-eec0-4790-8b24-6875312ad492
|
||||
version: 9
|
||||
date: '2025-02-24'
|
||||
author: Teoderick Contreras, Splunk, Ivar Nygård
|
||||
version: '10'
|
||||
date: '2025-03-19'
|
||||
author: "Teoderick Contreras, Splunk, Ivar Nyg\xE5rd"
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic detects suspicious file permission modifications
|
||||
@@ -15,12 +15,10 @@ description: The following analytic detects suspicious file permission modificat
|
||||
actions on the system.
|
||||
data_source:
|
||||
- Linux Auditd Proctitle
|
||||
search: '`linux_auditd` proctitle="*chmod*" AND proctitle IN ("* 777 *", "* 755 *", "*+*x*", "* 754 *")
|
||||
| rename host as dest
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by proctitle dest
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `linux_auditd_file_permission_modification_via_chmod_filter`'
|
||||
search: '`linux_auditd` proctitle="*chmod*" AND proctitle IN ("* 777 *", "* 755 *",
|
||||
"*+*x*", "* 754 *") | rename host as dest | stats count min(_time) as firstTime
|
||||
max(_time) as lastTime by proctitle dest | `security_content_ctime(firstTime)` |
|
||||
`security_content_ctime(lastTime)` | `linux_auditd_file_permission_modification_via_chmod_filter`'
|
||||
how_to_implement: To implement this detection, the process begins by ingesting auditd
|
||||
data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
|
||||
command-line executions and process details on Unix/Linux systems. These logs should
|
||||
@@ -58,13 +56,13 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Linux Persistence Techniques
|
||||
- XorDDos
|
||||
- Linux Privilege Escalation
|
||||
- Compromised Linux Host
|
||||
- China-Nexus Threat Activity
|
||||
- Linux Living Off The Land
|
||||
- Earth Estries
|
||||
- XorDDos
|
||||
- Salt Typhoon
|
||||
- Linux Privilege Escalation
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1222.002
|
||||
@@ -76,8 +74,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chmod_exec_attrib/auditd_proctitle_chmod.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.002/linux_auditd_chmod_exec_attrib/auditd_proctitle_chmod.log
|
||||
source: auditd
|
||||
sourcetype: auditd
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Auditd Nopasswd Entry In Sudoers File
|
||||
id: 651df959-ad17-4b73-a323-90cb96d5fa1b
|
||||
version: 6
|
||||
date: '2025-02-24'
|
||||
version: '7'
|
||||
date: '2025-03-19'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -14,11 +14,9 @@ description: The following analytic detects the addition of NOPASSWD entries to
|
||||
and potential compromise of sensitive data and system integrity.
|
||||
data_source:
|
||||
- Linux Auditd Proctitle
|
||||
search: '`linux_auditd` proctitle = "*NOPASSWD*"
|
||||
| rename host as dest
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by proctitle dest
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `linux_auditd_nopasswd_entry_in_sudoers_file_filter`'
|
||||
search: '`linux_auditd` proctitle = "*NOPASSWD*" | rename host as dest | stats count
|
||||
min(_time) as firstTime max(_time) as lastTime by proctitle dest | `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)` | `linux_auditd_nopasswd_entry_in_sudoers_file_filter`'
|
||||
how_to_implement: To implement this detection, the process begins by ingesting auditd
|
||||
data, that consist SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line
|
||||
executions and process details on Unix/Linux systems. These logs should be ingested
|
||||
@@ -57,11 +55,11 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Linux Persistence Techniques
|
||||
- Linux Privilege Escalation
|
||||
- Compromised Linux Host
|
||||
- Earth Estries
|
||||
- China-Nexus Threat Activity
|
||||
- Salt Typhoon
|
||||
- Linux Privilege Escalation
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1548.003
|
||||
@@ -73,8 +71,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_nopasswd/linux_auditd_nopasswd2.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_nopasswd/linux_auditd_nopasswd2.log
|
||||
source: auditd
|
||||
sourcetype: auditd
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Auditd Possible Access To Credential Files
|
||||
id: 0419cb7a-57ea-467b-974f-77c303dfe2a3
|
||||
version: 7
|
||||
date: '2025-02-24'
|
||||
version: '8'
|
||||
date: '2025-03-19'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -14,11 +14,10 @@ description: The following analytic detects attempts to access or dump the conte
|
||||
offline cracking, leading to unauthorized access and potential system compromise.
|
||||
data_source:
|
||||
- Linux Auditd Proctitle
|
||||
search: '`linux_auditd` proctitle IN ("*shadow*", "*passwd*") AND proctitle IN ("*cat *", "*nano *", "*vim *", "*vi *")
|
||||
| rename host as dest
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by proctitle dest
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `linux_auditd_possible_access_to_credential_files_filter`'
|
||||
search: '`linux_auditd` proctitle IN ("*shadow*", "*passwd*") AND proctitle IN ("*cat
|
||||
*", "*nano *", "*vim *", "*vi *") | rename host as dest | stats count min(_time)
|
||||
as firstTime max(_time) as lastTime by proctitle dest | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `linux_auditd_possible_access_to_credential_files_filter`'
|
||||
how_to_implement: To implement this detection, the process begins by ingesting auditd
|
||||
data, that consist SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line
|
||||
executions and process details on Unix/Linux systems. These logs should be ingested
|
||||
@@ -48,8 +47,8 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: A [$proctitle$] event occurred on host - [$dest$] to access or dump
|
||||
the contents of /etc/passwd and /etc/shadow files.
|
||||
message: A [$proctitle$] event occurred on host - [$dest$] to access or dump the
|
||||
contents of /etc/passwd and /etc/shadow files.
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: system
|
||||
@@ -57,11 +56,11 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Linux Persistence Techniques
|
||||
- Linux Privilege Escalation
|
||||
- Compromised Linux Host
|
||||
- Earth Estries
|
||||
- China-Nexus Threat Activity
|
||||
- Salt Typhoon
|
||||
- Linux Privilege Escalation
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1003.008
|
||||
@@ -73,7 +72,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/linux_auditd_access_credential/auditd_proctitle_access_cred.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.008/linux_auditd_access_credential/auditd_proctitle_access_cred.log
|
||||
source: auditd
|
||||
sourcetype: auditd
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Auditd Possible Access To Sudoers File
|
||||
id: 8be88f46-f7e8-4ae6-b15e-cf1b13392834
|
||||
version: 7
|
||||
date: '2025-02-24'
|
||||
version: '8'
|
||||
date: '2025-03-19'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -56,11 +56,11 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Linux Persistence Techniques
|
||||
- Linux Privilege Escalation
|
||||
- Compromised Linux Host
|
||||
- Earth Estries
|
||||
- China-Nexus Threat Activity
|
||||
- Salt Typhoon
|
||||
- Linux Privilege Escalation
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1548.003
|
||||
@@ -72,8 +72,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudoers_access/linux_auditd_sudoers_access.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/linux_auditd_sudoers_access/linux_auditd_sudoers_access.log
|
||||
source: auditd
|
||||
sourcetype: auditd
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Auditd Preload Hijack Library Calls
|
||||
id: 35c50572-a70b-452f-afa9-bebdf3c3ce36
|
||||
version: 7
|
||||
date: '2025-02-24'
|
||||
version: '8'
|
||||
date: '2025-03-19'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -15,13 +15,10 @@ description: The following analytic detects the use of the LD_PRELOAD environmen
|
||||
access to the system.
|
||||
data_source:
|
||||
- Linux Auditd Execve
|
||||
search: '`linux_auditd` execve_command = "*LD_PRELOAD*"
|
||||
| rename host as dest
|
||||
| rename comm as process_name
|
||||
| rename exe as process
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by argc execve_command dest
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `linux_auditd_preload_hijack_library_calls_filter`'
|
||||
search: '`linux_auditd` execve_command = "*LD_PRELOAD*" | rename host as dest | rename
|
||||
comm as process_name | rename exe as process | stats count min(_time) as firstTime
|
||||
max(_time) as lastTime by argc execve_command dest | `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)` | `linux_auditd_preload_hijack_library_calls_filter`'
|
||||
how_to_implement: To implement this detection, the process begins by ingesting auditd
|
||||
data, that consists of SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures
|
||||
command-line executions and process details on Unix/Linux systems. These logs should
|
||||
@@ -59,11 +56,11 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Linux Persistence Techniques
|
||||
- Linux Privilege Escalation
|
||||
- Compromised Linux Host
|
||||
- Earth Estries
|
||||
- China-Nexus Threat Activity
|
||||
- Salt Typhoon
|
||||
- Linux Privilege Escalation
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1574.006
|
||||
@@ -75,8 +72,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/linux_auditd_ldpreload/auditd_execve_ldpreload.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1574.006/linux_auditd_ldpreload/auditd_execve_ldpreload.log
|
||||
source: auditd
|
||||
sourcetype: auditd
|
||||
|
||||
|
||||
@@ -48,11 +48,11 @@ references:
|
||||
- https://github.com/microsoft/MSTIC-Sysmon/blob/main/linux/configs/attack-based/privilege_escalation/T1548.001_ElevationControl_CommonProcesses.xml
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Linux Persistence Techniques
|
||||
- Linux Privilege Escalation
|
||||
- China-Nexus Threat Activity
|
||||
- Linux Living Off The Land
|
||||
- Earth Estries
|
||||
- Salt Typhoon
|
||||
- Linux Privilege Escalation
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1548.001
|
||||
|
||||
@@ -61,10 +61,10 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Linux Persistence Techniques
|
||||
- China-Nexus Threat Activity
|
||||
- Salt Typhoon
|
||||
- Linux Privilege Escalation
|
||||
- Earth Estries
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1548.003
|
||||
|
||||
@@ -61,11 +61,11 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Linux Persistence Techniques
|
||||
- China-Nexus Threat Activity
|
||||
- XorDDos
|
||||
- Salt Typhoon
|
||||
- Linux Privilege Escalation
|
||||
- Earth Estries
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1003.008
|
||||
|
||||
@@ -61,10 +61,10 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Linux Persistence Techniques
|
||||
- China-Nexus Threat Activity
|
||||
- Salt Typhoon
|
||||
- Linux Privilege Escalation
|
||||
- Earth Estries
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1548.003
|
||||
|
||||
@@ -60,10 +60,10 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Linux Persistence Techniques
|
||||
- China-Nexus Threat Activity
|
||||
- Salt Typhoon
|
||||
- Linux Privilege Escalation
|
||||
- Earth Estries
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1574.006
|
||||
|
||||
@@ -53,10 +53,10 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Linux Persistence Techniques
|
||||
- China-Nexus Threat Activity
|
||||
- Salt Typhoon
|
||||
- Linux Privilege Escalation
|
||||
- Earth Estries
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1548.003
|
||||
|
||||
@@ -67,12 +67,12 @@ rba:
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- AsyncRAT
|
||||
- DarkCrystal RAT
|
||||
- Volt Typhoon
|
||||
- Salt Typhoon
|
||||
- HAFNIUM Group
|
||||
- DHS Report TA18-074A
|
||||
- DarkCrystal RAT
|
||||
- AsyncRAT
|
||||
- Earth Estries
|
||||
- Volt Typhoon
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1059.001
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Non Chrome Process Accessing Chrome Default Dir
|
||||
id: 81263de4-160a-11ec-944f-acde48001122
|
||||
version: '8'
|
||||
date: '2025-02-24'
|
||||
version: '9'
|
||||
date: '2025-03-19'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -49,20 +49,20 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- SnappyBee
|
||||
- Phemedrone Stealer
|
||||
- Snake Keylogger
|
||||
- NjRAT
|
||||
- CISA AA23-347A
|
||||
- 3CX Supply Chain Attack
|
||||
- FIN7
|
||||
- Earth Estries
|
||||
- Warzone RAT
|
||||
- China-Nexus Threat Activity
|
||||
- DarkGate Malware
|
||||
- Remcos
|
||||
- RedLine Stealer
|
||||
- AgentTesla
|
||||
- Snake Keylogger
|
||||
- CISA AA23-347A
|
||||
- China-Nexus Threat Activity
|
||||
- Remcos
|
||||
- FIN7
|
||||
- Phemedrone Stealer
|
||||
- SnappyBee
|
||||
- RedLine Stealer
|
||||
- Warzone RAT
|
||||
- Salt Typhoon
|
||||
- 3CX Supply Chain Attack
|
||||
- DarkGate Malware
|
||||
- NjRAT
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1555.003
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Non Firefox Process Access Firefox Profile Dir
|
||||
id: e6fc13b0-1609-11ec-b533-acde48001122
|
||||
version: '7'
|
||||
date: '2025-02-13'
|
||||
version: '8'
|
||||
date: '2025-03-19'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -48,21 +48,21 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- SnappyBee
|
||||
- Phemedrone Stealer
|
||||
- Snake Keylogger
|
||||
- NjRAT
|
||||
- CISA AA23-347A
|
||||
- 3CX Supply Chain Attack
|
||||
- Azorult
|
||||
- China-Nexus Threat Activity
|
||||
- Warzone RAT
|
||||
- AgentTesla
|
||||
- RedLine Stealer
|
||||
- DarkGate Malware
|
||||
- Snake Keylogger
|
||||
- CISA AA23-347A
|
||||
- China-Nexus Threat Activity
|
||||
- Remcos
|
||||
- Earth Estries
|
||||
- FIN7
|
||||
- Phemedrone Stealer
|
||||
- SnappyBee
|
||||
- Azorult
|
||||
- RedLine Stealer
|
||||
- Warzone RAT
|
||||
- Salt Typhoon
|
||||
- 3CX Supply Chain Attack
|
||||
- DarkGate Malware
|
||||
- NjRAT
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1555.003
|
||||
|
||||
@@ -59,20 +59,20 @@ references:
|
||||
- https://adlumin.com/post/powerdrop-a-new-insidious-powershell-script-for-command-and-control-attacks-targets-u-s-aerospace-defense-industry/
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- CISA AA24-241A
|
||||
- Malicious PowerShell
|
||||
- Flax Typhoon
|
||||
- CISA AA23-347A
|
||||
- DarkGate Malware
|
||||
- Earth Estries
|
||||
- Cleo File Transfer Software
|
||||
- Braodo Stealer
|
||||
- Lumma Stealer
|
||||
- Rhysida Ransomware
|
||||
- Data Destruction
|
||||
- Hermetic Wiper
|
||||
- SystemBC
|
||||
- Data Destruction
|
||||
- Malicious PowerShell
|
||||
- China-Nexus Threat Activity
|
||||
- CISA AA23-347A
|
||||
- Cleo File Transfer Software
|
||||
- Lumma Stealer
|
||||
- CISA AA24-241A
|
||||
- Hermetic Wiper
|
||||
- Salt Typhoon
|
||||
- DarkGate Malware
|
||||
- Flax Typhoon
|
||||
- Braodo Stealer
|
||||
- Rhysida Ransomware
|
||||
- PHP-CGI RCE Attack on Japanese Organizations
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
|
||||
@@ -78,39 +78,38 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Amadey
|
||||
- AsyncRAT
|
||||
- Azorult
|
||||
- BlackByte Ransomware
|
||||
- BlackSuit Ransomware
|
||||
- Braodo Stealer
|
||||
- Chaos Ransomware
|
||||
- China-Nexus Threat Activity
|
||||
- CISA AA23-347A
|
||||
- DarkGate Malware
|
||||
- Derusbi
|
||||
- DHS Report TA18-074A
|
||||
- Earth Estries
|
||||
- Emotet Malware DHS Report TA18-201A
|
||||
- IcedID
|
||||
- MoonPeak
|
||||
- NjRAT
|
||||
- Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
|
||||
- Qakbot
|
||||
- Ransomware
|
||||
- RedLine Stealer
|
||||
- Remcos
|
||||
- PHP-CGI RCE Attack on Japanese Organizations
|
||||
- Snake Keylogger
|
||||
- SnappyBee
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
- Suspicious MSHTA Activity
|
||||
- Suspicious Windows Registry Activities
|
||||
- SystemBC
|
||||
- Warzone RAT
|
||||
- WinDealer RAT
|
||||
- Snake Keylogger
|
||||
- China-Nexus Threat Activity
|
||||
- Remcos
|
||||
- AsyncRAT
|
||||
- Windows Persistence Techniques
|
||||
- Derusbi
|
||||
- WinDealer RAT
|
||||
- Suspicious MSHTA Activity
|
||||
- DarkGate Malware
|
||||
- Suspicious Windows Registry Activities
|
||||
- Qakbot
|
||||
- CISA AA23-347A
|
||||
- Ransomware
|
||||
- NjRAT
|
||||
- Emotet Malware DHS Report TA18-201A
|
||||
- Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
- SnappyBee
|
||||
- Azorult
|
||||
- Warzone RAT
|
||||
- BlackByte Ransomware
|
||||
- Chaos Ransomware
|
||||
- RedLine Stealer
|
||||
- BlackSuit Ransomware
|
||||
- Windows Registry Abuse
|
||||
- Amadey
|
||||
- Salt Typhoon
|
||||
- MoonPeak
|
||||
- Braodo Stealer
|
||||
- DHS Report TA18-074A
|
||||
- IcedID
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1547.001
|
||||
|
||||
@@ -69,12 +69,12 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- CISA AA23-347A
|
||||
- China-Nexus Threat Activity
|
||||
- Ransomware
|
||||
- Active Directory Lateral Movement
|
||||
- CISA AA23-347A
|
||||
- Suspicious WMI Use
|
||||
- Earth Estries
|
||||
- Salt Typhoon
|
||||
- Active Directory Lateral Movement
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1047
|
||||
|
||||
@@ -71,32 +71,32 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- DHS Report TA18-074A
|
||||
- Trickbot
|
||||
- NOBELIUM Group
|
||||
- Prestige Ransomware
|
||||
- Earth Estries
|
||||
- ShrinkLocker
|
||||
- NjRAT
|
||||
- CISA AA24-241A
|
||||
- DarkCrystal RAT
|
||||
- Sandworm Tools
|
||||
- Living Off The Land
|
||||
- AsyncRAT
|
||||
- Scheduled Tasks
|
||||
- AgentTesla
|
||||
- Windows Persistence Techniques
|
||||
- RedLine Stealer
|
||||
- Rhysida Ransomware
|
||||
- Winter Vivern
|
||||
- China-Nexus Threat Activity
|
||||
- CISA AA24-241A
|
||||
- AsyncRAT
|
||||
- DarkCrystal RAT
|
||||
- Windows Persistence Techniques
|
||||
- Scheduled Tasks
|
||||
- Qakbot
|
||||
- CISA AA22-257A
|
||||
- MoonPeak
|
||||
- CISA AA23-347A
|
||||
- NjRAT
|
||||
- Trickbot
|
||||
- AgentTesla
|
||||
- Living Off The Land
|
||||
- Winter Vivern
|
||||
- Phemedrone Stealer
|
||||
- Azorult
|
||||
- CISA AA22-257A
|
||||
- Rhysida Ransomware
|
||||
- Prestige Ransomware
|
||||
- NOBELIUM Group
|
||||
- ShrinkLocker
|
||||
- RedLine Stealer
|
||||
- Amadey
|
||||
- Salt Typhoon
|
||||
- MoonPeak
|
||||
- DHS Report TA18-074A
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1053.005
|
||||
|
||||
@@ -76,13 +76,13 @@ rba:
|
||||
type: process_name
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- IcedID
|
||||
- Qakbot
|
||||
- Derusbi
|
||||
- Living Off The Land
|
||||
- Earth Estries
|
||||
- Qakbot
|
||||
- China-Nexus Threat Activity
|
||||
- Derusbi
|
||||
- Salt Typhoon
|
||||
- Suspicious Regsvr32 Activity
|
||||
- IcedID
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1218.010
|
||||
|
||||
@@ -69,19 +69,19 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Crypto Stealer
|
||||
- Ransomware
|
||||
- MoonPeak
|
||||
- DarkCrystal RAT
|
||||
- CISA AA24-241A
|
||||
- CISA AA23-347A
|
||||
- Windows Persistence Techniques
|
||||
- Living Off The Land
|
||||
- Azorult
|
||||
- China-Nexus Threat Activity
|
||||
- CISA AA23-347A
|
||||
- Ryuk Ransomware
|
||||
- CISA AA24-241A
|
||||
- Windows Persistence Techniques
|
||||
- DarkCrystal RAT
|
||||
- Ransomware
|
||||
- Azorult
|
||||
- Scheduled Tasks
|
||||
- Earth Estries
|
||||
- Salt Typhoon
|
||||
- MoonPeak
|
||||
- Crypto Stealer
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1053.005
|
||||
|
||||
@@ -56,18 +56,18 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Meduza Stealer
|
||||
- PlugX
|
||||
- CISA AA23-347A
|
||||
- China-Nexus Threat Activity
|
||||
- AsyncRAT
|
||||
- SnappyBee
|
||||
- Derusbi
|
||||
- WinDealer RAT
|
||||
- Salt Typhoon
|
||||
- DarkGate Malware
|
||||
- ValleyRAT
|
||||
- Brute Ratel C4
|
||||
- WinDealer RAT
|
||||
- Meduza Stealer
|
||||
- CISA AA23-347A
|
||||
- AsyncRAT
|
||||
- Derusbi
|
||||
- PlugX
|
||||
- China-Nexus Threat Activity
|
||||
- DarkGate Malware
|
||||
- Earth Estries
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1134.002
|
||||
|
||||
@@ -1,23 +1,35 @@
|
||||
name: Windows Anonymous Pipe Activity
|
||||
id: ee301e1e-cd81-4011-a911-e5f049b9e3d5
|
||||
version: 1
|
||||
date: '2025-02-11'
|
||||
version: '2'
|
||||
date: '2025-03-19'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
description: The following analytic detects the creation or connection of anonymous pipes for inter-process communication (IPC) within a Windows environment. Anonymous pipes are commonly used by legitimate system processes, services, and applications to transfer data between related processes. However, adversaries frequently abuse anonymous pipes to facilitate stealthy process injection, command-and-control (C2) communication, credential theft, or privilege escalation. This detection monitors for unusual anonymous pipe activity, particularly involving non-system processes, unsigned executables, or unexpected parent-child process relationships. While legitimate use cases exist—such as Windows services, software installers, or security tools—unusual or high-frequency anonymous pipe activity should be investigated for potential malware, persistence mechanisms, or lateral movement techniques.
|
||||
description: "The following analytic detects the creation or connection of anonymous\
|
||||
\ pipes for inter-process communication (IPC) within a Windows environment. Anonymous\
|
||||
\ pipes are commonly used by legitimate system processes, services, and applications\
|
||||
\ to transfer data between related processes. However, adversaries frequently abuse\
|
||||
\ anonymous pipes to facilitate stealthy process injection, command-and-control\
|
||||
\ (C2) communication, credential theft, or privilege escalation. This detection\
|
||||
\ monitors for unusual anonymous pipe activity, particularly involving non-system\
|
||||
\ processes, unsigned executables, or unexpected parent-child process relationships.\
|
||||
\ While legitimate use cases exist\u2014such as Windows services, software installers,\
|
||||
\ or security tools\u2014unusual or high-frequency anonymous pipe activity should\
|
||||
\ be investigated for potential malware, persistence mechanisms, or lateral movement\
|
||||
\ techniques."
|
||||
data_source:
|
||||
- Sysmon EventID 17
|
||||
- Sysmon EventID 18
|
||||
search: '`sysmon` EventCode IN (17,18) EventType IN ( "CreatePipe", "ConnectPipe") PipeName="*Anonymous Pipe*" NOT( Image IN ("*\\Program Files\\*"))
|
||||
| stats min(_time) as firstTime max(_time) as lastTime count by dest EventCode PipeName ProcessGuid ProcessId Image EventType
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
search: '`sysmon` EventCode IN (17,18) EventType IN ( "CreatePipe", "ConnectPipe")
|
||||
PipeName="*Anonymous Pipe*" NOT( Image IN ("*\\Program Files\\*")) | stats min(_time)
|
||||
as firstTime max(_time) as lastTime count by dest EventCode PipeName ProcessGuid
|
||||
ProcessId Image EventType | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `windows_anonymous_pipe_activity_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name and pipename from your endpoints. If you are using Sysmon,
|
||||
you must have at least version 6.0.4 of the Sysmon TA. .
|
||||
known_false_positives: Automation tool might use anonymous pipe for task orchestration or process communication.
|
||||
known_false_positives: Automation tool might use anonymous pipe for task orchestration
|
||||
or process communication.
|
||||
references:
|
||||
- https://www.trendmicro.com/en_nl/research/24/k/earth-estries.html
|
||||
drilldown_searches:
|
||||
@@ -36,9 +48,9 @@ drilldown_searches:
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- SnappyBee
|
||||
- Salt Typhoon
|
||||
- China-Nexus Threat Activity
|
||||
- Earth Estries
|
||||
- SnappyBee
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1559
|
||||
|
||||
@@ -64,8 +64,8 @@ rba:
|
||||
tags:
|
||||
analytic_story:
|
||||
- DarkGate Malware
|
||||
- Salt Typhoon
|
||||
- China-Nexus Threat Activity
|
||||
- Earth Estries
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1560.001
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Credential Access From Browser Password Store
|
||||
id: 72013a8e-5cea-408a-9d51-5585386b4d69
|
||||
version: '8'
|
||||
date: '2025-02-24'
|
||||
version: '9'
|
||||
date: '2025-03-19'
|
||||
author: Teoderick Contreras, Bhavin Patel Splunk
|
||||
data_source:
|
||||
- Windows Event Log Security 4663
|
||||
@@ -60,14 +60,14 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Meduza Stealer
|
||||
- Snake Keylogger
|
||||
- China-Nexus Threat Activity
|
||||
- SnappyBee
|
||||
- PXA Stealer
|
||||
- Salt Typhoon
|
||||
- MoonPeak
|
||||
- Braodo Stealer
|
||||
- Snake Keylogger
|
||||
- Meduza Stealer
|
||||
- PXA Stealer
|
||||
- China-Nexus Threat Activity
|
||||
- Earth Estries
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1012
|
||||
|
||||
+13
-13
@@ -1,7 +1,7 @@
|
||||
name: Windows Credentials from Password Stores Chrome LocalState Access
|
||||
id: 3b1d09a8-a26f-473e-a510-6c6613573657
|
||||
version: '8'
|
||||
date: '2025-02-24'
|
||||
version: '9'
|
||||
date: '2025-03-19'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -51,20 +51,20 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- SnappyBee
|
||||
- MoonPeak
|
||||
- Phemedrone Stealer
|
||||
- Braodo Stealer
|
||||
- Snake Keylogger
|
||||
- Meduza Stealer
|
||||
- NjRAT
|
||||
- Amadey
|
||||
- PXA Stealer
|
||||
- Warzone RAT
|
||||
- Snake Keylogger
|
||||
- China-Nexus Threat Activity
|
||||
- DarkGate Malware
|
||||
- Phemedrone Stealer
|
||||
- SnappyBee
|
||||
- PXA Stealer
|
||||
- RedLine Stealer
|
||||
- Earth Estries
|
||||
- Warzone RAT
|
||||
- Salt Typhoon
|
||||
- DarkGate Malware
|
||||
- MoonPeak
|
||||
- Braodo Stealer
|
||||
- Amadey
|
||||
- NjRAT
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1012
|
||||
|
||||
+13
-13
@@ -1,7 +1,7 @@
|
||||
name: Windows Credentials from Password Stores Chrome Login Data Access
|
||||
id: 0d32ba37-80fc-4429-809c-0ba15801aeaf
|
||||
version: '8'
|
||||
date: '2025-02-24'
|
||||
version: '9'
|
||||
date: '2025-03-19'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -52,20 +52,20 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- SnappyBee
|
||||
- MoonPeak
|
||||
- Phemedrone Stealer
|
||||
- Braodo Stealer
|
||||
- Snake Keylogger
|
||||
- Meduza Stealer
|
||||
- NjRAT
|
||||
- Amadey
|
||||
- PXA Stealer
|
||||
- Warzone RAT
|
||||
- Snake Keylogger
|
||||
- China-Nexus Threat Activity
|
||||
- DarkGate Malware
|
||||
- Phemedrone Stealer
|
||||
- SnappyBee
|
||||
- PXA Stealer
|
||||
- RedLine Stealer
|
||||
- Earth Estries
|
||||
- Warzone RAT
|
||||
- Salt Typhoon
|
||||
- DarkGate Malware
|
||||
- MoonPeak
|
||||
- Braodo Stealer
|
||||
- Amadey
|
||||
- NjRAT
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1012
|
||||
|
||||
@@ -73,13 +73,13 @@ rba:
|
||||
type: process_name
|
||||
tags:
|
||||
analytic_story:
|
||||
- Black Basta Ransomware
|
||||
- China-Nexus Threat Activity
|
||||
- Forest Blizzard
|
||||
- Compromised Windows Host
|
||||
- Salt Typhoon
|
||||
- Ingress Tool Transfer
|
||||
- IcedID
|
||||
- Forest Blizzard
|
||||
- Earth Estries
|
||||
- Black Basta Ransomware
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1105
|
||||
|
||||
@@ -67,8 +67,8 @@ rba:
|
||||
type: parent_process_name
|
||||
tags:
|
||||
analytic_story:
|
||||
- Salt Typhoon
|
||||
- China-Nexus Threat Activity
|
||||
- Earth Estries
|
||||
- SnappyBee
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Query Registry Browser List Application
|
||||
id: 45ebd21c-f4bf-4ced-bd49-d25b6526cebb
|
||||
version: '5'
|
||||
date: '2025-02-07'
|
||||
version: '6'
|
||||
date: '2025-03-19'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -51,10 +51,10 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- SnappyBee
|
||||
- RedLine Stealer
|
||||
- Earth Estries
|
||||
- China-Nexus Threat Activity
|
||||
- Salt Typhoon
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1012
|
||||
|
||||
@@ -62,12 +62,12 @@ rba:
|
||||
type: file_name
|
||||
tags:
|
||||
analytic_story:
|
||||
- NjRAT
|
||||
- PlugX
|
||||
- China-Nexus Threat Activity
|
||||
- Chaos Ransomware
|
||||
- Derusbi
|
||||
- PlugX
|
||||
- Earth Estries
|
||||
- Salt Typhoon
|
||||
- NjRAT
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1091
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Service Created with Suspicious Service Path
|
||||
id: 429141be-8311-11eb-adb6-acde48001122
|
||||
version: '13'
|
||||
date: '2025-02-24'
|
||||
version: '14'
|
||||
date: '2025-03-19'
|
||||
author: Teoderick Contreras, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -54,18 +54,18 @@ rba:
|
||||
type: service
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Crypto Stealer
|
||||
- Qakbot
|
||||
- Snake Malware
|
||||
- Brute Ratel C4
|
||||
- Derusbi
|
||||
- Active Directory Lateral Movement
|
||||
- Clop Ransomware
|
||||
- Flax Typhoon
|
||||
- CISA AA23-347A
|
||||
- PlugX
|
||||
- Earth Estries
|
||||
- Qakbot
|
||||
- China-Nexus Threat Activity
|
||||
- CISA AA23-347A
|
||||
- Flax Typhoon
|
||||
- Derusbi
|
||||
- Salt Typhoon
|
||||
- Active Directory Lateral Movement
|
||||
- Snake Malware
|
||||
- Clop Ransomware
|
||||
- Crypto Stealer
|
||||
- Brute Ratel C4
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1569.002
|
||||
|
||||
@@ -65,11 +65,11 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- SnappyBee
|
||||
- CISA AA23-347A
|
||||
- Active Directory Lateral Movement
|
||||
- China-Nexus Threat Activity
|
||||
- Earth Estries
|
||||
- CISA AA23-347A
|
||||
- SnappyBee
|
||||
- Salt Typhoon
|
||||
- Active Directory Lateral Movement
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1543.003
|
||||
|
||||
@@ -54,18 +54,18 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- SnappyBee
|
||||
- Windows Persistence Techniques
|
||||
- Brute Ratel C4
|
||||
- CISA AA23-347A
|
||||
- Suspicious Windows Registry Activities
|
||||
- China-Nexus Threat Activity
|
||||
- Derusbi
|
||||
- PlugX
|
||||
- CISA AA23-347A
|
||||
- China-Nexus Threat Activity
|
||||
- Windows Persistence Techniques
|
||||
- SnappyBee
|
||||
- Derusbi
|
||||
- Windows Registry Abuse
|
||||
- Salt Typhoon
|
||||
- Active Directory Lateral Movement
|
||||
- Suspicious Windows Registry Activities
|
||||
- Crypto Stealer
|
||||
- Earth Estries
|
||||
- Brute Ratel C4
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1574.011
|
||||
|
||||
@@ -57,9 +57,9 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- SnappyBee
|
||||
- Salt Typhoon
|
||||
- China-Nexus Threat Activity
|
||||
- Earth Estries
|
||||
- SnappyBee
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1112
|
||||
|
||||
@@ -74,44 +74,44 @@ rba:
|
||||
type: process_name
|
||||
tags:
|
||||
analytic_story:
|
||||
- Double Zero Destructor
|
||||
- Graceful Wipe Out Attack
|
||||
- AsyncRAT
|
||||
- WhisperGate
|
||||
- Prestige Ransomware
|
||||
- DarkGate Malware
|
||||
- AgentTesla
|
||||
- Brute Ratel C4
|
||||
- RedLine Stealer
|
||||
- Rhysida Ransomware
|
||||
- Swift Slicer
|
||||
- IcedID
|
||||
- DarkCrystal RAT
|
||||
- Chaos Ransomware
|
||||
- PlugX
|
||||
- Industroyer2
|
||||
- Azorult
|
||||
- Remcos
|
||||
- XMRig
|
||||
- Qakbot
|
||||
- Volt Typhoon
|
||||
- Hermetic Wiper
|
||||
- Warzone RAT
|
||||
- Trickbot
|
||||
- Amadey
|
||||
- BlackByte Ransomware
|
||||
- LockBit Ransomware
|
||||
- CISA AA23-347A
|
||||
- Data Destruction
|
||||
- Phemedrone Stealer
|
||||
- Handala Wiper
|
||||
- MoonPeak
|
||||
- ValleyRAT
|
||||
- Meduza Stealer
|
||||
- SystemBC
|
||||
- China-Nexus Threat Activity
|
||||
- Earth Estries
|
||||
- Remcos
|
||||
- LockBit Ransomware
|
||||
- AsyncRAT
|
||||
- DarkCrystal RAT
|
||||
- DarkGate Malware
|
||||
- ValleyRAT
|
||||
- PlugX
|
||||
- Data Destruction
|
||||
- Qakbot
|
||||
- CISA AA23-347A
|
||||
- Hermetic Wiper
|
||||
- Volt Typhoon
|
||||
- Double Zero Destructor
|
||||
- AgentTesla
|
||||
- Trickbot
|
||||
- Meduza Stealer
|
||||
- Phemedrone Stealer
|
||||
- SnappyBee
|
||||
- Azorult
|
||||
- WhisperGate
|
||||
- Warzone RAT
|
||||
- Swift Slicer
|
||||
- Rhysida Ransomware
|
||||
- Brute Ratel C4
|
||||
- Prestige Ransomware
|
||||
- BlackByte Ransomware
|
||||
- Graceful Wipe Out Attack
|
||||
- Chaos Ransomware
|
||||
- Handala Wiper
|
||||
- RedLine Stealer
|
||||
- Salt Typhoon
|
||||
- XMRig
|
||||
- MoonPeak
|
||||
- Industroyer2
|
||||
- Amadey
|
||||
- IcedID
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1543
|
||||
|
||||
@@ -54,11 +54,11 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Warzone RAT
|
||||
- NjRAT
|
||||
- China-Nexus Threat Activity
|
||||
- Derusbi
|
||||
- Earth Estries
|
||||
- Warzone RAT
|
||||
- Salt Typhoon
|
||||
- NjRAT
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1574.002
|
||||
|
||||
@@ -56,12 +56,12 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Derusbi
|
||||
- DarkGate Malware
|
||||
- PlugX
|
||||
- Earth Estries
|
||||
- China-Nexus Threat Activity
|
||||
- SnappyBee
|
||||
- Derusbi
|
||||
- Salt Typhoon
|
||||
- DarkGate Malware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1574.002
|
||||
|
||||
@@ -68,8 +68,8 @@ tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- Derusbi
|
||||
- Salt Typhoon
|
||||
- APT29 Diplomatic Deceptions with WINELOADER
|
||||
- Earth Estries
|
||||
group:
|
||||
- APT29
|
||||
- Cozy Bear
|
||||
|
||||
@@ -65,9 +65,9 @@ rba:
|
||||
type: process_name
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- DarkGate Malware
|
||||
- Earth Estries
|
||||
- Salt Typhoon
|
||||
- China-Nexus Threat Activity
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1036.009
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: WinEvent Scheduled Task Created to Spawn Shell
|
||||
id: 203ef0ea-9bd8-11eb-8201-acde48001122
|
||||
version: '11'
|
||||
date: '2025-02-25'
|
||||
version: '12'
|
||||
date: '2025-03-19'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -54,17 +54,17 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- SystemBC
|
||||
- China-Nexus Threat Activity
|
||||
- CISA AA22-257A
|
||||
- Ryuk Ransomware
|
||||
- Winter Vivern
|
||||
- Windows Persistence Techniques
|
||||
- Ransomware
|
||||
- Windows Error Reporting Service Elevation of Privilege Vulnerability
|
||||
- Compromised Windows Host
|
||||
- Ransomware
|
||||
- Windows Persistence Techniques
|
||||
- Ryuk Ransomware
|
||||
- Scheduled Tasks
|
||||
- Earth Estries
|
||||
- Winter Vivern
|
||||
- SystemBC
|
||||
- Salt Typhoon
|
||||
- CISA AA22-257A
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1053.005
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: WinEvent Scheduled Task Created Within Public Path
|
||||
id: 5d9c6eee-988c-11eb-8253-acde48001122
|
||||
version: '11'
|
||||
date: '2025-02-28'
|
||||
version: '12'
|
||||
date: '2025-03-19'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -54,23 +54,23 @@ rba:
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- China-Nexus Threat Activity
|
||||
- IcedID
|
||||
- CISA AA22-257A
|
||||
- Compromised Windows Host
|
||||
- Ransomware
|
||||
- Active Directory Lateral Movement
|
||||
- CISA AA23-347A
|
||||
- Windows Persistence Techniques
|
||||
- Earth Estries
|
||||
- Prestige Ransomware
|
||||
- Industroyer2
|
||||
- Ryuk Ransomware
|
||||
- AsyncRAT
|
||||
- Scheduled Tasks
|
||||
- Data Destruction
|
||||
- Winter Vivern
|
||||
- SystemBC
|
||||
- Data Destruction
|
||||
- China-Nexus Threat Activity
|
||||
- CISA AA23-347A
|
||||
- Ryuk Ransomware
|
||||
- Winter Vivern
|
||||
- Windows Persistence Techniques
|
||||
- AsyncRAT
|
||||
- Ransomware
|
||||
- Compromised Windows Host
|
||||
- Scheduled Tasks
|
||||
- Salt Typhoon
|
||||
- Active Directory Lateral Movement
|
||||
- CISA AA22-257A
|
||||
- Industroyer2
|
||||
- IcedID
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1053.005
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
name: Salt Typhoon
|
||||
id: 7df800b1-af23-4f65-ac36-abe87374ee72
|
||||
version: 1
|
||||
date: '2025-03-19'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
description: Leverage searches that allow you to detect and investigate unusual activities that might relate to Salt Typhoon, a sophisticated threat actor targeting various sectors with espionage-focused campaigns. Monitor for indicators such as spear-phishing emails, unauthorized access attempts, and lateral movement within your network. Investigate anomalous data exfiltration patterns and command-and-control (C2) traffic consistent with known tactics, techniques, and procedures (TTPs) of this group. Combining threat intelligence with advanced monitoring tools helps identify potential Salt Typhoon activity early, enabling swift response to mitigate risks effectively.
|
||||
narrative: Salt Typhoon is a highly capable threat actor known for conducting targeted espionage campaigns against diverse sectors, including government, technology, and critical infrastructure. This group leverages sophisticated tactics such as spear-phishing, credential theft, and exploiting software vulnerabilities to gain initial access. Once inside a network, Salt Typhoon demonstrates expertise in lateral movement, privilege escalation, and covert data exfiltration. Their use of custom malware and command-and-control (C2) infrastructures highlights their adaptability. Detecting their activity requires robust threat intelligence and proactive monitoring of unusual behaviors and network anomalies.
|
||||
references:
|
||||
- https://www.trendmicro.com/en_nl/research/24/k/earth-estries.html
|
||||
tags:
|
||||
category:
|
||||
- Malware
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
usecase: Advanced Threat Detection
|
||||
Reference in New Issue
Block a user