mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge pull request #3332 from splunk/haagsqldb
🎪 Haag's SQL Server Story Time: Tales of SQLCMD and Suspicious Queries 📚
This commit is contained in:
@@ -0,0 +1,99 @@
|
||||
name: Windows Event Log Application 15457
|
||||
id: 4491537e-520c-46f7-9209-f56f852aa237
|
||||
version: 1
|
||||
date: '2025-03-04'
|
||||
author: Michael Haag, Splunk
|
||||
description: Data source object for Windows Event Log Application 15457
|
||||
source: XmlWinEventLog:Application
|
||||
sourcetype: XmlWinEventLog
|
||||
separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- CategoryString
|
||||
- Channel
|
||||
- Computer
|
||||
- Error_Code
|
||||
- EventCode
|
||||
- EventData_Xml
|
||||
- EventID
|
||||
- EventRecordID
|
||||
- Guid
|
||||
- Image_File_Name
|
||||
- Keywords
|
||||
- Level
|
||||
- Name
|
||||
- Opcode
|
||||
- ProcessID
|
||||
- Qualifiers
|
||||
- RecordNumber
|
||||
- RenderingInfo_Xml
|
||||
- SourceName
|
||||
- SubStatus
|
||||
- SystemTime
|
||||
- System_Props_Xml
|
||||
- Task
|
||||
- TaskCategory
|
||||
- ThreadID
|
||||
- UserData_Xml
|
||||
- UserID
|
||||
- Version
|
||||
- _bkt
|
||||
- _cd
|
||||
- _eventtype_color
|
||||
- _indextime
|
||||
- _raw
|
||||
- _serial
|
||||
- _si
|
||||
- _sourcetype
|
||||
- _subsecond
|
||||
- _time
|
||||
- action
|
||||
- category
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- dvc_nt_host
|
||||
- event_id
|
||||
- eventtype
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- linecount
|
||||
- name
|
||||
- parent_process
|
||||
- process_name
|
||||
- punct
|
||||
- result
|
||||
- service
|
||||
- service_id
|
||||
- service_name
|
||||
- severity
|
||||
- severity_id
|
||||
- signature
|
||||
- signature_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- splunk_server_group
|
||||
- status
|
||||
- subject
|
||||
- tag
|
||||
- tag::action
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user_group_id
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='MSSQLSERVER'/><EventID Qualifiers='16384'>15457</EventID><Version>0</Version><Level>4</Level><Task>2</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime='2025-02-04T19:46:19.5339693Z'/><EventRecordID>15827</EventRecordID><Correlation/><Execution ProcessID='0' ThreadID='0'/><Channel>Application</Channel><Computer>ar-win-2.attackrange.local</Computer><Security/></System><EventData><Data>show advanced options</Data><Data>1</Data><Data>0</Data><Binary>613C00000A00000009000000610072002D00770069006E002D0032000000070000006D00610073007400650072000000</Binary></EventData></Event>
|
||||
|
||||
@@ -0,0 +1,96 @@
|
||||
name: Windows Event Log Application 17135
|
||||
id: 4491537e-520c-46f7-9209-f56f852aa231
|
||||
version: 1
|
||||
date: '2025-02-26'
|
||||
author: Michael Haag, Splunk
|
||||
description: Data source object for Windows Event Log Application 17135
|
||||
source: XmlWinEventLog:Application
|
||||
sourcetype: XmlWinEventLog
|
||||
separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- CategoryString
|
||||
- Channel
|
||||
- Computer
|
||||
- Error_Code
|
||||
- EventCode
|
||||
- EventData_Xml
|
||||
- EventID
|
||||
- EventRecordID
|
||||
- Image_File_Name
|
||||
- Keywords
|
||||
- Level
|
||||
- Name
|
||||
- Opcode
|
||||
- ProcessID
|
||||
- Qualifiers
|
||||
- RecordNumber
|
||||
- RenderingInfo_Xml
|
||||
- SourceName
|
||||
- SubStatus
|
||||
- SystemTime
|
||||
- System_Props_Xml
|
||||
- Task
|
||||
- TaskCategory
|
||||
- ThreadID
|
||||
- Version
|
||||
- _bkt
|
||||
- _cd
|
||||
- _eventtype_color
|
||||
- _indextime
|
||||
- _raw
|
||||
- _serial
|
||||
- _si
|
||||
- _sourcetype
|
||||
- _subsecond
|
||||
- _time
|
||||
- action
|
||||
- category
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- dvc_nt_host
|
||||
- event_id
|
||||
- eventtype
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- linecount
|
||||
- name
|
||||
- parent_process
|
||||
- process_name
|
||||
- punct
|
||||
- result
|
||||
- service
|
||||
- service_id
|
||||
- service_name
|
||||
- severity
|
||||
- severity_id
|
||||
- signature
|
||||
- signature_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- splunk_server_group
|
||||
- status
|
||||
- subject
|
||||
- tag
|
||||
- tag::action
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user_group_id
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='MSSQLSERVER'/><EventID Qualifiers='16384'>17135</EventID><Version>0</Version><Level>4</Level><Task>2</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime='2025-02-10T16:38:42.6969829Z'/><EventRecordID>16509</EventRecordID><Correlation/><Execution ProcessID='0' ThreadID='0'/><Channel>Application</Channel><Computer>ar-win-2.attackrange.local</Computer><Security/></System><EventData><Data>sp_add_sysadmin</Data><Binary>EF4200000A00000009000000610072002D00770069006E002D0032000000070000006D00610073007400650072000000</Binary></EventData></Event>
|
||||
|
||||
@@ -0,0 +1,88 @@
|
||||
name: Windows Event Log Application 8128
|
||||
id: 4491537e-5e0c-46f7-9209-f56f852aa237
|
||||
version: 1
|
||||
date: '2025-02-26'
|
||||
author: Michael Haag, Splunk
|
||||
description: Data source object for Windows Event Log Application 8128
|
||||
source: XmlWinEventLog:Application
|
||||
sourcetype: XmlWinEventLog
|
||||
separator: EventCode
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Windows
|
||||
url: https://splunkbase.splunk.com/app/742
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- CategoryString
|
||||
- Channel
|
||||
- Computer
|
||||
- Error_Code
|
||||
- EventCode
|
||||
- EventData_Xml
|
||||
- EventID
|
||||
- EventRecordID
|
||||
- EventSourceName
|
||||
- Guid
|
||||
- Image_File_Name
|
||||
- Keywords
|
||||
- Level
|
||||
- Name
|
||||
- Opcode
|
||||
- ProcessID
|
||||
- Qualifiers
|
||||
- RecordNumber
|
||||
- RenderingInfo_Xml
|
||||
- SourceName
|
||||
- SubStatus
|
||||
- SystemTime
|
||||
- System_Props_Xml
|
||||
- Task
|
||||
- TaskCategory
|
||||
- ThreadID
|
||||
- UserID
|
||||
- Version
|
||||
- _bkt
|
||||
- _cd
|
||||
- _eventtype_color
|
||||
- _indextime
|
||||
- _raw
|
||||
- _serial
|
||||
- _si
|
||||
- _sourcetype
|
||||
- _time
|
||||
- action
|
||||
- category
|
||||
- dest
|
||||
- dvc
|
||||
- dvc_nt_host
|
||||
- event_id
|
||||
- eventtype
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- linecount
|
||||
- name
|
||||
- parent_process
|
||||
- process_name
|
||||
- punct
|
||||
- result
|
||||
- service
|
||||
- service_id
|
||||
- service_name
|
||||
- severity
|
||||
- severity_id
|
||||
- signature
|
||||
- signature_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- splunk_server_group
|
||||
- status
|
||||
- subject
|
||||
- tag
|
||||
- tag::action
|
||||
- tag::eventtype
|
||||
- user_group_id
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='MSSQLSERVER'/><EventID Qualifiers='16384'>8128</EventID><Version>0</Version><Level>4</Level><Task>2</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime='2025-02-10T20:03:14.2006851Z'/><EventRecordID>16635</EventRecordID><Correlation/><Execution ProcessID='0' ThreadID='0'/><Channel>Application</Channel><Computer>ar-win-2.attackrange.local</Computer><Security/></System><EventData><Data>odsole70.dll</Data><Data>2022.160.1000</Data><Data>sp_OACreate</Data><Binary>C01F00000A00000009000000610072002D00770069006E002D0032000000050000006D007300640062000000</Binary></EventData></Event>
|
||||
|
||||
@@ -0,0 +1,130 @@
|
||||
name: Windows PowerShell Invoke-Sqlcmd Execution
|
||||
id: 5eb76fe2-a869-4865-8c4c-8cff424b18a1
|
||||
version: 1
|
||||
date: '2025-02-03'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
description: This detection identifies potentially suspicious usage of Invoke-Sqlcmd PowerShell cmdlet, which can be used for database operations and potential data exfiltration. The detection looks for suspicious parameter combinations and query patterns that may indicate unauthorized database access, data theft, or malicious database operations. Threat actors may prefer using PowerShell Invoke-Sqlcmd over sqlcmd.exe as it provides a more flexible programmatic interface and can better evade detection.
|
||||
data_source:
|
||||
- Powershell Script Block Logging 4104
|
||||
search: '`powershell` EventCode=4104 ScriptBlockText="*invoke-sqlcmd*"
|
||||
| eval script_lower=lower(ScriptBlockText)
|
||||
| eval
|
||||
has_query=case(
|
||||
match(script_lower, "(?i)-query\\s+"), 1,
|
||||
match(script_lower, "(?i)-q\\s+"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_input_file=case(
|
||||
match(script_lower, "(?i)-inputfile\\s+"), 1,
|
||||
match(script_lower, "(?i)-i\\s+"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_url_input=case(
|
||||
match(script_lower, "(?i)-inputfile\\s+https?://"), 1,
|
||||
match(script_lower, "(?i)-i\\s+https?://"), 1,
|
||||
match(script_lower, "(?i)-inputfile\\s+ftp://"), 1,
|
||||
match(script_lower, "(?i)-i\\s+ftp://"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_admin_conn=case(
|
||||
match(script_lower, "(?i)-dedicatedadministratorconnection"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_suspicious_auth=case(
|
||||
match(script_lower, "(?i)-username\\s+sa\\b"), 1,
|
||||
match(script_lower, "(?i)-u\\s+sa\\b"), 1,
|
||||
match(script_lower, "(?i)-username\\s+admin\\b"), 1,
|
||||
match(script_lower, "(?i)-u\\s+admin\\b"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_suspicious_query=case(
|
||||
match(script_lower, "(?i)(xp_cmdshell|sp_oacreate|sp_execute_external|openrowset|bulk\\s+insert)"), 1,
|
||||
match(script_lower, "(?i)(master\\.\\.\\.sysdatabases|msdb\\.\\.\\.backuphistory|sysadmin|securityadmin)"), 1,
|
||||
match(script_lower, "(?i)(select.*from.*sys\\.|select.*password|dump\\s+database)"), 1,
|
||||
match(script_lower, "(?i)(sp_addextendedproc|sp_makewebtask|sp_addsrvrolemember)"), 1,
|
||||
match(script_lower, "(?i)(sp_configure.*show\\s+advanced|reconfigure|enable_xp_cmdshell)"), 1,
|
||||
match(script_lower, "(?i)(exec.*master\\.dbo\\.|exec.*msdb\\.dbo\\.)"), 1,
|
||||
match(script_lower, "(?i)(sp_password|sp_control_dbmasterkey_password|sp_dropextendedproc)"), 1,
|
||||
match(script_lower, "(?i)(powershell|cmd\\.exe|rundll32|regsvr32|certutil)"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_data_exfil=case(
|
||||
match(script_lower, "(?i)-outputas\\s+(dataset|datatables)"), 1,
|
||||
match(script_lower, "(?i)-as\\s+(dataset|datatables)"), 1,
|
||||
match(script_lower, "(?i)(for\\s+xml|for\\s+json)"), 1,
|
||||
match(script_lower, "(?i)(select.*into.*from|select.*into.*outfile)"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_cert_bypass=case(
|
||||
match(script_lower, "(?i)-trustservercertificate"), 1,
|
||||
true(), 0
|
||||
)
|
||||
|
||||
| eval risk_score=0
|
||||
| eval risk_score=case(
|
||||
has_suspicious_query=1 AND has_data_exfil=1, risk_score + 90,
|
||||
has_url_input=1, risk_score + 80,
|
||||
has_suspicious_query=1, risk_score + 60,
|
||||
has_data_exfil=1, risk_score + 60,
|
||||
has_admin_conn=1, risk_score + 50,
|
||||
has_suspicious_auth=1, risk_score + 40,
|
||||
has_cert_bypass=1, risk_score + 20,
|
||||
true(), risk_score
|
||||
)
|
||||
|
||||
| eval command_type=case(
|
||||
match(script_lower, "xp_cmdshell"), "xp_cmdshell abuse",
|
||||
match(script_lower, "https?://"), "Remote file execution",
|
||||
match(script_lower, "sys\\.server_principals"), "System enumeration",
|
||||
match(script_lower, "fn_my_permissions"), "Permission enumeration",
|
||||
match(script_lower, "username\\s+sa\\b"), "SA account usage",
|
||||
match(script_lower, "show\\s+advanced\\s+options"), "Configuration change attempt",
|
||||
match(script_lower, "select.*from\\s+customers"), "Large data export",
|
||||
match(script_lower, "select.*password"), "Sensitive data query",
|
||||
match(script_lower, "sp_configure.*xp_cmdshell"), "Enable xp_cmdshell",
|
||||
1=1, "General database access"
|
||||
)
|
||||
|
||||
| eval risk_factors=mvappend(
|
||||
if(has_suspicious_query=1 AND has_data_exfil=1, "High-risk query with data extraction: ".command_type, null()),
|
||||
if(has_url_input=1, "Remote file input detected in command", null()),
|
||||
if(has_suspicious_query=1, "Suspicious SQL query pattern: ".command_type, null()),
|
||||
if(has_data_exfil=1, "Potential data exfiltration using ".command_type, null()),
|
||||
if(has_admin_conn=1, "Administrative database connection", null()),
|
||||
if(has_suspicious_auth=1, "Suspicious authentication method used", null()),
|
||||
if(has_cert_bypass=1, "Certificate validation bypassed", null())
|
||||
)
|
||||
| eval risk_message="PowerShell Invoke-Sqlcmd execution with risk factors: ".mvjoin(risk_factors, ", ")
|
||||
|
||||
| where risk_score >= 30
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText UserID Computer risk_message risk_score command_type
|
||||
| rename Computer as dest, UserID as user
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_powershell_invoke_sqlcmd_execution_filter`'
|
||||
how_to_implement: To successfully implement this detection, you need to be ingesting PowerShell logs with Script Block Logging and Module Logging enabled. The detection looks for Invoke-Sqlcmd usage in PowerShell scripts and evaluates the parameters and queries for suspicious patterns. Configure your PowerShell logging to capture script block execution and ensure the logs are mapped to the PowerShell node of the Endpoint data model. The analytic will need to be tuned based on organization specific data. Currently, set to hunting to allow for tuning. Invoke-Sqlcmd is a legitimate tool for database management and scripting tasks within enterprise environments.
|
||||
known_false_positives: Database administrators and developers frequently use Invoke-Sqlcmd as a legitimate tool for various database management tasks. This includes running automated database maintenance scripts, performing ETL (Extract, Transform, Load) processes, executing data migration jobs, implementing database deployment and configuration scripts, and running monitoring and reporting tasks. To effectively manage false positives in your environment, consider implementing several mitigation strategies. First, establish a whitelist of known administrator and service accounts that regularly perform these operations. Second, create exceptions for approved script paths where legitimate database operations typically occur. Additionally, it's important to baseline your environment's normal PowerShell database interaction patterns and implement monitoring for any deviations from these established patterns. Finally, consider adjusting the risk score thresholds based on your specific environment and security requirements to achieve an optimal balance between security and operational efficiency.
|
||||
references:
|
||||
- https://learn.microsoft.com/en-us/powershell/module/sqlserver/invoke-sqlcmd
|
||||
- https://attack.mitre.org/techniques/T1059.001/
|
||||
- https://attack.mitre.org/techniques/T1059.003/
|
||||
tags:
|
||||
analytic_story:
|
||||
- SQL Server Abuse
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1059.001
|
||||
- T1059.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/atomic_red_team/invokesqlcmd_powershell.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
|
||||
sourcetype: XmlWinEventLog
|
||||
@@ -0,0 +1,51 @@
|
||||
name: Windows SQL Server Configuration Option Hunt
|
||||
id: 8dc9efd5-805a-460e-889e-bc79e5477af9
|
||||
version: 1
|
||||
date: '2025-02-06'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
description: This detection helps hunt for changes to SQL Server configuration options that could indicate malicious activity. It monitors for modifications to any SQL Server configuration settings, allowing analysts to identify potentially suspicious changes that may be part of an attack, such as enabling dangerous features or modifying security-relevant settings.
|
||||
data_source:
|
||||
- Windows Event Log Application 15457
|
||||
search: '`wineventlog_application` EventCode=15457
|
||||
| rex field=EventData_Xml "<Data>(?<config_name>[^<]+)</Data><Data>(?<new_value>[^<]+)</Data><Data>(?<old_value>[^<]+)</Data>"
|
||||
| rename host as dest
|
||||
| eval change_type=case(
|
||||
old_value="0" AND new_value="1", "enabled",
|
||||
old_value="1" AND new_value="0", "disabled",
|
||||
true(), "modified"
|
||||
)
|
||||
| eval risk_score=case(
|
||||
change_type="enabled", 90,
|
||||
change_type="disabled", 60,
|
||||
true(), 70
|
||||
)
|
||||
| eval risk_message="SQL Server ".config_name." was ".change_type." on host ".dest
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by dest EventCode config_name change_type risk_message risk_score
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_sql_server_configuration_option_hunt_filter`'
|
||||
how_to_implement: To successfully implement this detection, you need to be ingesting Windows Application Event Logs from SQL Server instances. The detection specifically looks for EventID 15457 which indicates configuration changes to SQL Server settings. Ensure proper logging is enabled for SQL Server configuration changes and that the logs are being forwarded to your SIEM.
|
||||
known_false_positives: Database administrators frequently make legitimate configuration changes for maintenance, performance tuning, and security hardening. To reduce false positives, establish a baseline of normal configuration changes, document approved configuration modifications, implement change control procedures, and maintain an inventory of expected settings.
|
||||
references:
|
||||
- https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/server-configuration-options-sql-server
|
||||
- https://attack.mitre.org/techniques/T1505/001/
|
||||
- https://www.netspi.com/blog/technical/network-penetration-testing/sql-server-persistence-part-1-startup-stored-procedures/
|
||||
tags:
|
||||
analytic_story:
|
||||
- SQL Server Abuse
|
||||
asset_type: Windows
|
||||
mitre_attack_id:
|
||||
- T1505.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
security_domain: endpoint
|
||||
cve: []
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.001/simulation/windows-application.log
|
||||
sourcetype: XmlWinEventLog
|
||||
source: XmlWinEventLog:Application
|
||||
@@ -0,0 +1,79 @@
|
||||
name: Windows SQL Server Critical Procedures Enabled
|
||||
id: d0434864-b043-41e3-8c08-30e53605e9cb
|
||||
version: 1
|
||||
date: '2025-02-06'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: This detection identifies when critical SQL Server configuration options are modified, including "Ad Hoc Distributed Queries", "external scripts enabled", "Ole Automation Procedures", "clr enabled", and "clr strict security". These features can be abused by attackers for various malicious purposes - Ad Hoc Distributed Queries enables Active Directory reconnaissance through ADSI provider, external scripts and Ole Automation allow execution of arbitrary code, and CLR features can be used to run custom assemblies. Enabling these features could indicate attempts to gain code execution or perform reconnaissance through SQL Server.
|
||||
data_source:
|
||||
- Windows Event Log Application 15457
|
||||
search: '`wineventlog_application` EventCode=15457
|
||||
| rex field=EventData_Xml "<Data>(?<config_name>[^<]+)</Data><Data>(?<new_value>[^<]+)</Data><Data>(?<old_value>[^<]+)</Data>"
|
||||
| where config_name IN ("Ad Hoc Distributed Queries", "external scripts enabled", "Ole Automation Procedures", "clr enabled", "clr strict security")
|
||||
| rename host as dest
|
||||
| eval change_type=case(
|
||||
old_value="0" AND new_value="1", "enabled",
|
||||
old_value="1" AND new_value="0", "disabled",
|
||||
true(), "modified"
|
||||
)
|
||||
| eval risk_score=case(
|
||||
change_type="enabled", 90,
|
||||
change_type="disabled", 60,
|
||||
true(), 70
|
||||
)
|
||||
| eval risk_message="SQL Server critical procedure ".config_name." was ".change_type." on host ".dest.", which may indicate attempts to gain code execution or perform reconnaissance"
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by dest EventCode config_name change_type risk_message risk_score
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_sql_server_critical_procedures_enabled_filter`'
|
||||
how_to_implement: To successfully implement this detection, you need to be ingesting Windows Application Event Logs from SQL Server instances where SQL Server is installed. The detection specifically looks for EventID 15457 which indicates configuration changes to SQL Server features. Ensure proper logging is enabled for SQL Server configuration changes and that the logs are being forwarded to your SIEM.
|
||||
known_false_positives: Database administrators may legitimately enable these features for valid business purposes such as cross-database queries, custom CLR assemblies, automation scripts, or application requirements. To reduce false positives, document when these features are required, monitor for unauthorized changes, create change control procedures for configuration modifications, and consider alerting on the enabled state rather than configuration changes if preferred.
|
||||
references:
|
||||
- https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/ad-hoc-distributed-queries-server-configuration-option
|
||||
- https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/external-scripts-enabled-server-configuration-option
|
||||
- https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/ole-automation-procedures-server-configuration-option
|
||||
- https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/clr-enabled-server-configuration-option
|
||||
- https://www.netspi.com/blog/technical/network-penetration-testing/enumerating-domain-accounts-via-sql-server-using-adsi/
|
||||
- https://attack.mitre.org/techniques/T1505/001/
|
||||
- https://www.netspi.com/blog/technical-blog/adversary-simulation/attacking-sql-server-clr-assemblies/
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$dest$"
|
||||
search: '%original_detection_search% | search dest = "$dest$"'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: SQL Server critical procedure "$config_name$" was $change_type$ on host $dest$, which could indicate an attempt to gain code execution or perform reconnaissance
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: system
|
||||
score: 90
|
||||
- field: config_name
|
||||
type: other
|
||||
score: 90
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- SQL Server Abuse
|
||||
asset_type: Windows
|
||||
mitre_attack_id:
|
||||
- T1505.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.001/simulation/adhocdq_windows_application.log
|
||||
sourcetype: XmlWinEventLog
|
||||
source: XmlWinEventLog:Application
|
||||
@@ -0,0 +1,49 @@
|
||||
name: Windows SQL Server Extended Procedure DLL Loading Hunt
|
||||
id: 182ba99f-2dde-4cdb-8e5c-e3b1e251cb10
|
||||
version: 1
|
||||
date: '2025-02-10'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
description: This analytic detects when SQL Server loads DLLs to execute extended stored procedures. This is particularly important for security monitoring as it indicates the first-time use or version changes of potentially dangerous procedures like xp_cmdshell, sp_OACreate, and others. While this is a legitimate operation, adversaries may abuse these procedures for execution, discovery, or privilege escalation.
|
||||
data_source:
|
||||
- Windows Event Log Application 8128
|
||||
search: '`wineventlog_application` EventCode=8128
|
||||
| rex field=EventData_Xml "<Data>(?<dll_name>[^<]+)</Data><Data>(?<dll_version>[^<]+)</Data><Data>(?<procedure_name>[^<]+)</Data>"
|
||||
| rename host as dest
|
||||
| eval dll_category=case(
|
||||
dll_name=="xpstar.dll", "Extended Procedures",
|
||||
dll_name=="odsole70.dll", "OLE Automation",
|
||||
dll_name=="xplog70.dll", "Logging Procedures",
|
||||
true(), "Other")
|
||||
| stats
|
||||
count as execution_count,
|
||||
values(procedure_name) as procedures_used,
|
||||
latest(_time) as last_seen
|
||||
by dest dll_name dll_category dll_version
|
||||
| sort - execution_count | `windows_sql_server_extended_procedure_dll_loading_hunt_filter`'
|
||||
how_to_implement: To successfully implement this detection, ensure Windows Event Log collection is enabled and collecting from the Application channel. SQL Server must be configured to log to the Windows Application log (enabled by default). The Splunk Windows TA is also required.
|
||||
known_false_positives: Legitimate administrative activity and normal database operations may trigger this detection. Common false positives include initial database startup and configuration, patch deployment and version updates, regular administrative tasks using extended stored procedures, and application servers that legitimately use OLE automation.
|
||||
references:
|
||||
- https://learn.microsoft.com/en-us/sql/relational-databases/system-stored-procedures/general-extended-stored-procedures-transact-sql
|
||||
- https://learn.microsoft.com/en-us/previous-versions/sql/sql-server-2008-r2/ms175543(v=sql.105)
|
||||
- https://learn.microsoft.com/en-us/sql/relational-databases/extended-stored-procedures-programming/using-extended-stored-procedures
|
||||
tags:
|
||||
analytic_story:
|
||||
- SQL Server Abuse
|
||||
asset_type: Windows
|
||||
mitre_attack_id:
|
||||
- T1505.001
|
||||
- T1059.009
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
security_domain: endpoint
|
||||
cve: []
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.001/simulation/dllprocedureload_windows-application.log
|
||||
sourcetype: XmlWinEventLog
|
||||
source: XmlWinEventLog:Application
|
||||
@@ -0,0 +1,68 @@
|
||||
name: Windows SQL Server Startup Procedure
|
||||
id: 7bec7c5c-2262-4adb-ba56-c8028512bc58
|
||||
version: 1
|
||||
date: '2025-02-06'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: This detection identifies when a startup procedure is registered or executed in SQL Server. Startup procedures automatically execute when SQL Server starts, making them an attractive persistence mechanism for attackers. The detection monitors for suspicious stored procedure names and patterns that may indicate malicious activity, such as attempts to execute operating system commands or gain elevated privileges.
|
||||
data_source:
|
||||
- Windows Event Log Application 17135
|
||||
search: '`wineventlog_application` EventCode=17135
|
||||
| rex field=EventData_Xml "<Data>(?<startup_procedure>[^<]+)</Data>"
|
||||
| rename host as dest
|
||||
| eval risk_score=case(
|
||||
match(lower(startup_procedure), "xp_|sp_|cmdshell|shell|exec"), 90,
|
||||
true(), 70
|
||||
)
|
||||
| eval risk_message="SQL Server startup procedure ''".startup_procedure."'' was launched on host ".dest
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by dest EventCode startup_procedure risk_message risk_score
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_sql_server_startup_procedure_filter`'
|
||||
how_to_implement: To successfully implement this detection, you need to be ingesting Windows Application Event Logs from SQL Server instances. The detection specifically looks for EventID 17135 which indicates startup procedure execution. Ensure proper logging is enabled for SQL Server startup events and that the logs are being forwarded to your SIEM.
|
||||
known_false_positives: Legitimate startup procedures may be used by database administrators for maintenance, monitoring, or application functionality. Common legitimate uses include database maintenance and cleanup jobs, performance monitoring and statistics collection, application initialization procedures, and system health checks. To reduce false positives, organizations should document approved startup procedures, maintain an inventory of expected startup procedures, monitor for changes to startup procedure configurations, and create exceptions for known good procedures.
|
||||
references:
|
||||
- https://learn.microsoft.com/en-us/sql/relational-databases/system-stored-procedures/sp-procoption-transact-sql
|
||||
- https://www.netspi.com/blog/technical-blog/network-penetration-testing/sql-server-persistence-part-1-startup-stored-procedures/
|
||||
- https://attack.mitre.org/techniques/T1505/001/
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$dest$"
|
||||
search: '%original_detection_search% | search dest = "$dest$"'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: A SQL Server startup procedure "$startup_procedure$" was executed on host $dest$, which could indicate an attempt to establish persistence
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: system
|
||||
score: 90
|
||||
- field: startup_procedure
|
||||
type: other
|
||||
score: 70
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- SQL Server Abuse
|
||||
asset_type: Windows
|
||||
mitre_attack_id:
|
||||
- T1505.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.001/simulation/sql_startupprocedure_widows-application.log
|
||||
sourcetype: XmlWinEventLog
|
||||
source: XmlWinEventLog:Application
|
||||
@@ -0,0 +1,80 @@
|
||||
name: Windows SQL Server xp_cmdshell Config Change
|
||||
id: 5eb76fe2-a869-4865-8c4c-8cff424b18b1
|
||||
version: 1
|
||||
date: '2025-02-04'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: This detection identifies when the xp_cmdshell configuration is modified in SQL Server. The xp_cmdshell extended stored procedure allows execution of operating system commands and programs from SQL Server, making it a high-risk feature commonly abused by attackers for privilege escalation and lateral movement.
|
||||
data_source:
|
||||
- Windows Event Log Application 15457
|
||||
search: '`wineventlog_application` EventCode=15457
|
||||
| rex field=EventData_Xml "<Data>(?<config_name>[^<]+)</Data><Data>(?<new_value>[^<]+)</Data><Data>(?<old_value>[^<]+)</Data>"
|
||||
| rename host as dest
|
||||
| where config_name="xp_cmdshell"
|
||||
| eval change_type=case(
|
||||
old_value="0" AND new_value="1", "enabled",
|
||||
old_value="1" AND new_value="0", "disabled",
|
||||
true(), "modified"
|
||||
)
|
||||
| eval risk_score=case(
|
||||
change_type="enabled", 90,
|
||||
change_type="disabled", 60,
|
||||
true(), 70
|
||||
)
|
||||
| eval risk_message="SQL Server xp_cmdshell was ".change_type." on host ".dest
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by dest EventCode config_name change_type risk_message risk_score
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_sql_server_xp_cmdshell_config_change_filter`'
|
||||
how_to_implement: To successfully implement this detection, you need to be ingesting Windows Application Event Logs from SQL Server instances where SQL Server is installed. The detection specifically looks for EventID 15457 which indicates configuration changes to extended stored procedures.
|
||||
known_false_positives: Database administrators may legitimately enable xp_cmdshell for maintenance tasks, such as database maintenance scripts requiring OS-level operations, legacy applications, or automated system management tasks; however, this feature should generally remain disabled in production environments due to security risks. To reduce false positives, document when xp_cmdshell is required, monitor for unauthorized changes, create change control procedures for xp_cmdshell modifications, and consider alerting on the enabled state rather than configuration changes if preferred.
|
||||
references:
|
||||
- https://learn.microsoft.com/en-us/sql/relational-databases/system-stored-procedures/xp-cmdshell-transact-sql
|
||||
- https://attack.mitre.org/techniques/T1505/003/
|
||||
- https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/xp-cmdshell-server-configuration-option
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$dest$"
|
||||
search: '%original_detection_search% | search dest = "$dest$"'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View all SQL Server configuration changes on this host in the last 7 days
|
||||
search: '`wineventlog_application` EventCode=15457 host="$dest$" | rex field=EventData_Xml "<Data>(?<config_name>[^<]+)</Data><Data>(?<new_value>[^<]+)</Data><Data>(?<old_value>[^<]+)</Data>" | stats count values(config_name) as "Changed Settings" values(new_value) as "New Values" by _time dest'
|
||||
earliest_offset: -7d
|
||||
latest_offset: now
|
||||
rba:
|
||||
message: SQL Server xp_cmdshell configuration was $change_type$ on host $dest$, which could indicate an attempt to gain operating system command execution capabilities
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: system
|
||||
score: 90
|
||||
- field: config_name
|
||||
type: other
|
||||
score: 90
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- SQL Server Abuse
|
||||
asset_type: Windows
|
||||
mitre_attack_id:
|
||||
- T1505.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.001/simulation/windows-application.log
|
||||
source: XmlWinEventLog:Application
|
||||
sourcetype: XmlWinEventLog
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows SQL Spawning CertUtil
|
||||
id: dfc18a5a-946e-44ee-a373-c0f60d06e676
|
||||
version: 7
|
||||
date: '2024-12-16'
|
||||
version: 8
|
||||
date: '2025-02-26'
|
||||
author: Michael Haag, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -53,6 +53,7 @@ rba:
|
||||
type: process_name
|
||||
tags:
|
||||
analytic_story:
|
||||
- SQL Server Abuse
|
||||
- Flax Typhoon
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
|
||||
@@ -0,0 +1,197 @@
|
||||
name: Windows SQLCMD Execution
|
||||
id: 4e7c2f85-8f02-4bd2-a48b-5ec98a2c5f72
|
||||
version: 1
|
||||
date: '2025-02-03'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
description: This detection identifies potentially suspicious usage of sqlcmd.exe, focusing on command patterns that may indicate data exfiltration, reconnaissance, or malicious database operations. The detection looks for both short-form (-X) and long-form (--flag) suspicious parameter combinations, which have been observed in APT campaigns targeting high-value organizations. For example, threat actors like CL-STA-0048 have been known to abuse sqlcmd.exe for data theft and exfiltration from compromised MSSQL servers. The detection monitors for suspicious authentication attempts, output redirection, and potentially malicious query patterns that could indicate unauthorized database access or data theft.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime
|
||||
from datamodel=Endpoint.Processes
|
||||
where `process_sqlcmd`
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| eval process_lower=lower(process)
|
||||
| eval
|
||||
is_help_check=case(
|
||||
match(process, "(?i)-[?]"), 1,
|
||||
match(process_lower, "(?i)--help"), 1,
|
||||
match(process_lower, "(?i)--version"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_parameters=if(match(process, "-[A-Za-z]"), 1, 0),
|
||||
has_query=case(
|
||||
match(process, "-[Qq]\\s+"), 1,
|
||||
match(process_lower, "--query\\s+"), 1,
|
||||
match(process_lower, "--initial-query\\s+"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_output=case(
|
||||
match(process, "-[oO]\\s+"), 1,
|
||||
match(process_lower, "--output-file\\s+"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_input=case(
|
||||
match(process, "-[iI]\\s+"), 1,
|
||||
match(process_lower, "--input-file\\s+"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_url_input=case(
|
||||
match(process, "-[iI]\\s+https?://"), 1,
|
||||
match(process_lower, "--input-file\\s+https?://"), 1,
|
||||
match(process, "-[iI]\\s+ftp://"), 1,
|
||||
match(process_lower, "--input-file\\s+ftp://"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_admin_conn=case(
|
||||
match(process, "-A"), 1,
|
||||
match(process_lower, "--dedicated-admin-connection"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_suspicious_auth=case(
|
||||
match(process, "-U\\s+sa\\b"), 1,
|
||||
match(process_lower, "--user-name\\s+sa\\b"), 1,
|
||||
match(process, "-U\\s+admin\\b"), 1,
|
||||
match(process_lower, "--user-name\\s+admin\\b"), 1,
|
||||
match(process, "-E\\b"), 1,
|
||||
match(process_lower, "--use-trusted-connection"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_local_server=case(
|
||||
match(process, "-S\\s+127\\.0\\.0\\.1"), 1,
|
||||
match(process_lower, "--server\\s+127\\.0\\.0\\.1"), 1,
|
||||
match(process, "-S\\s+localhost"), 1,
|
||||
match(process_lower, "--server\\s+localhost"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_suspicious_output=case(
|
||||
match(process_lower, "-o\\s+.*\\.(txt|csv|dat)"), 1,
|
||||
match(process_lower, "--output-file\\s+.*\\.(txt|csv|dat)"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_cert_bypass=case(
|
||||
match(process, "-C"), 1,
|
||||
match(process_lower, "--trust-server-certificate"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_suspicious_query=case(
|
||||
match(process_lower, "(xp_cmdshell|sp_oacreate|sp_execute_external|openrowset|bulk\\s+insert)"), 1,
|
||||
match(process_lower, "(master\\.\\.\\.sysdatabases|msdb\\.\\.\\.backuphistory|sysadmin|securityadmin)"), 1,
|
||||
match(process_lower, "(select.*from.*sys\\.|select.*password|dump\\s+database)"), 1,
|
||||
match(process_lower, "(sp_addextendedproc|sp_makewebtask|sp_addsrvrolemember)"), 1,
|
||||
match(process_lower, "(sp_configure.*show\\s+advanced|reconfigure|enable_xp_cmdshell)"), 1,
|
||||
match(process_lower, "(exec.*master\\.dbo\\.|exec.*msdb\\.dbo\\.)"), 1,
|
||||
match(process_lower, "(sp_password|sp_control_dbmasterkey_password|sp_dropextendedproc)"), 1,
|
||||
match(process_lower, "(powershell|cmd\\.exe|rundll32|regsvr32|certutil)"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_suspicious_path=case(
|
||||
match(process_lower, "(\\\\temp\\\\|\\\\windows\\\\|\\\\public\\\\|\\\\users\\\\public\\\\|\\\\programdata\\\\)"), 1,
|
||||
match(process_lower, "(\\\\desktop\\\\.*\\.(zip|rar|7z|tar|gz))"), 1,
|
||||
match(process_lower, "(\\\\downloads\\\\.*\\.(dat|bin|tmp))"), 1,
|
||||
match(process_lower, "(\\\\appdata\\\\local\\\\temp\\\\|\\\\windows\\\\tasks\\\\)"), 1,
|
||||
match(process_lower, "(\\\\recycler\\\\|\\\\system32\\\\|\\\\system volume information\\\\)"), 1,
|
||||
match(process_lower, "(\\.vbs|\\.ps1|\\.bat|\\.cmd|\\.exe)$"), 1,
|
||||
true(), 0
|
||||
),
|
||||
has_suspicious_combo=case(
|
||||
match(process, "-E") AND match(process_lower, "(?i)xp_cmdshell"), 1,
|
||||
match(process, "-Q") AND match(process_lower, "(?i)exec\\s+master"), 1,
|
||||
has_local_server=1 AND has_suspicious_query=1, 1,
|
||||
true(), 0
|
||||
),
|
||||
has_obfuscation=case(
|
||||
match(process_lower, "(char\\(|convert\\(|cast\\(|declare\\s+@)"), 1,
|
||||
match(process_lower, "(exec\\s+\\(|exec\\s+@|;\\s*exec)"), 1,
|
||||
match(process, "\\^|\\%|\\+\\+|\\-\\-"), 1,
|
||||
len(process) > 500, 1,
|
||||
true(), 0
|
||||
),
|
||||
has_data_exfil=case(
|
||||
match(process_lower, "(for\\s+xml|for\\s+json)"), 1,
|
||||
match(process_lower, "(bulk\\s+insert.*from)"), 1,
|
||||
match(process_lower, "(bcp.*queryout|bcp.*out)"), 1,
|
||||
match(process_lower, "(select.*into.*from|select.*into.*outfile)"), 1,
|
||||
true(), 0
|
||||
)
|
||||
|
||||
| eval risk_score=0
|
||||
| eval risk_score=case(
|
||||
is_help_check=1, 0,
|
||||
has_parameters=0, 0,
|
||||
has_suspicious_combo=1, risk_score + 90,
|
||||
has_suspicious_query=1, risk_score + 60,
|
||||
has_suspicious_path=1, risk_score + 40,
|
||||
has_url_input=1 AND has_output=1, risk_score + 80,
|
||||
has_query=1 AND has_output=1, risk_score + 30,
|
||||
has_query=1 AND has_suspicious_output=1, risk_score + 40,
|
||||
has_admin_conn=1, risk_score + 50,
|
||||
has_suspicious_auth=1, risk_score + 40,
|
||||
has_local_server=1 AND has_query=1, risk_score + 30,
|
||||
has_cert_bypass=1, risk_score + 20,
|
||||
has_obfuscation=1, risk_score + 70,
|
||||
has_data_exfil=1, risk_score + 60,
|
||||
true(), risk_score
|
||||
)
|
||||
|
||||
| eval risk_factors=mvappend(
|
||||
if((is_help_check=0 AND has_parameters=0), null(),
|
||||
if(has_suspicious_combo=1, "High-risk command combination detected", null())),
|
||||
if((is_help_check=0 AND has_parameters=0), null(),
|
||||
if(has_suspicious_query=1, "Suspicious SQL query pattern", null())),
|
||||
if(has_suspicious_path=1, "Suspicious output path", null()),
|
||||
if(has_url_input=1 AND has_output=1, "File download attempt", null()),
|
||||
if(has_query=1 AND has_output=1, "Query output to file", null()),
|
||||
if(has_admin_conn=1, "Admin connection", null()),
|
||||
if(has_suspicious_auth=1, "Suspicious authentication", null()),
|
||||
if(has_local_server=1, "Local server connection", null()),
|
||||
if(has_cert_bypass=1, "Certificate validation bypass", null()),
|
||||
if(has_obfuscation=1, "Command obfuscation detected", null()),
|
||||
if(has_data_exfil=1, "Potential data exfiltration", null())
|
||||
)
|
||||
| eval risk_message="SQLCMD execution with risk factors: ".mvjoin(risk_factors, ", ")
|
||||
|
||||
| where is_help_check=0 AND (risk_score >= 30 OR (has_parameters=1 AND has_suspicious_query=1))
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_sqlcmd_execution_filter`'
|
||||
how_to_implement: The analytic will need to be tuned based on organization specific data. Currently, set to hunting to allow for tuning. SQLCmd is a legitimate tool for database management and scripting tasks within enterprise environments. The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: |
|
||||
Database administrators and developers commonly use sqlcmd.exe legitimately for database management and scripting tasks within enterprise environments. These legitimate activities often include database backups and restores, schema deployment scripts, automated database maintenance, and ETL processes. However, it's important to note that some organizations may have no sqlcmd.exe usage at all, making any detection highly suspicious. To effectively manage false positives, organizations should whitelist known administrator accounts, create exceptions for approved script paths and output locations, and add legitimate usage patterns to the filter macro as needed.
|
||||
Recommend running this detection first as a hunt to review usage patterns. Following, modify the risk score and false positive list as needed.
|
||||
references:
|
||||
- https://docs.microsoft.com/en-us/sql/tools/sqlcmd-utility
|
||||
- https://attack.mitre.org/techniques/T1078/
|
||||
- https://attack.mitre.org/techniques/T1213/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1105/T1105.md#atomic-test-32---file-download-with-sqlcmdexe
|
||||
- https://unit42.paloaltonetworks.com/espionage-campaign-targets-south-asian-entities/
|
||||
tags:
|
||||
analytic_story:
|
||||
- SQL Server Abuse
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1059.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
security_domain: endpoint
|
||||
cve: []
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/attack_techniques/T1059.003/atomic_red_team/sqlcmd_windows_sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: XmlWinEventLog
|
||||
@@ -0,0 +1,69 @@
|
||||
name: Windows Sqlservr Spawning Shell
|
||||
id: d33aac9f-030c-4830-8701-0c2dd75bb6cb
|
||||
version: 1
|
||||
date: '2025-02-04'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: This analytic detects instances where the sqlservr.exe process spawns a command shell (cmd.exe) or PowerShell process. This behavior is often indicative of command execution initiated from within the SQL Server process, potentially due to exploitation of SQL injection vulnerabilities or the use of extended stored procedures like xp_cmdshell.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="sqlservr.exe"
|
||||
`process_cmd` OR `process_powershell`
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.original_file_name
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_sqlservr_spawning_shell_filter`'
|
||||
how_to_implement: To implement this detection, you need to be ingesting endpoint data that captures process creation events, specifically the parent-child process relationships. Ensure that you are collecting Sysmon Event ID 1 or Windows Event Log Security 4688 events. The data should be mapped to the Endpoint data model in Splunk.
|
||||
known_false_positives: Legitimate administrative activities or monitoring tools might occasionally spawn command shells from sqlservr.exe. Review the process command-line arguments and consider filtering out known legitimate processes or users.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1505/001/
|
||||
- https://github.com/MHaggis/notes/tree/master/utilities/SQLSSTT
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$dest$" and "$process_name$"
|
||||
search: '%original_detection_search% | search dest = "$dest$" process_name = "$process_name$"'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$dest$" and "$user$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$",
|
||||
"$user$") starthoursago=168 | stats count min(_time)
|
||||
as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message)
|
||||
as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: A command shell was spawned by sqlservr.exe on host $dest$ by user $user$. This may indicate unauthorized command execution.
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: system
|
||||
score: 90
|
||||
- field: user
|
||||
type: user
|
||||
score: 90
|
||||
threat_objects:
|
||||
- field: parent_process_name
|
||||
type: parent_process_name
|
||||
- field: process_name
|
||||
type: process_name
|
||||
tags:
|
||||
analytic_story:
|
||||
- SQL Server Abuse
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1505.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
security_domain: endpoint
|
||||
cve: []
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.001/simulation/sqlservr-windows_sysmon.log
|
||||
sourcetype: XmlWinEventLog
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
@@ -0,0 +1,3 @@
|
||||
definition: (Processes.process_name=sqlcmd.exe OR Processes.original_file_name=sqlcmd.exe)
|
||||
description: Matches the process with its original file name, data for this macro came from https://strontic.github.io/
|
||||
name: process_sqlcmd
|
||||
@@ -0,0 +1,25 @@
|
||||
name: SQL Server Abuse
|
||||
id: e06d851e-774e-4c34-9813-6a26becccd71
|
||||
version: 1
|
||||
status: production
|
||||
date: '2025-02-04'
|
||||
author: Michael Haag, Splunk
|
||||
description: This analytic story addresses various techniques used by threat actors to abuse Microsoft SQL Server for maintaining persistence, executing malicious commands, and exfiltrating data. It focuses on detecting suspicious SQLCMD usage, startup procedure modifications, DLL procedure loads, and other SQL Server abuse patterns that may indicate compromise.
|
||||
narrative: Microsoft SQL Server is a common target for threat actors due to its widespread enterprise deployment and powerful capabilities. Attackers often abuse SQL Server features and components to achieve their objectives. Common attack patterns include using SQLCMD.exe for command execution and data exfiltration, modifying or creating startup procedures for persistence, and loading malicious DLLs through SQL Server procedures. Threat actors also frequently execute commands through xp_cmdshell and other extended stored procedures, leverage SQL Server Agent for scheduled task execution, and abuse trusted connections and elevated privileges.
|
||||
This story contains detections for various SQL Server abuse techniques. The detections focus on identifying suspicious SQLCMD.exe execution patterns and modifications to SQL Server startup procedures. They also monitor for unusual DLL loading through SQL Server, suspicious query patterns and command execution, anomalous authentication attempts, and potential data exfiltration indicators.
|
||||
Organizations should monitor SQL Server activity closely, especially usage of administrative features and extended stored procedures. A comprehensive security approach should include implementation of least privilege access principles, proper auditing mechanisms, and regular review of SQL Server configurations. These measures can help mitigate the risks posed by SQL Server abuse techniques commonly employed by threat actors.
|
||||
references:
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/10/03/defending-new-vectors-threat-actors-attempt-sql-server-to-cloud-lateral-movement/
|
||||
- https://www.netspi.com/blog/technical-blog/network-pentesting/hijacking-sql-server-credentials-with-agent-jobs-for-domain-privilege-escalation/
|
||||
- https://www.huntress.com/blog/attacking-mssql-servers
|
||||
- https://www.netspi.com/blog/technical-blog/network-pentesting/hacking-sql-server-stored-procedures-part-2-user-impersonation/
|
||||
- https://www.slideshare.net/slideshow/def-con-31-demo-labs-2023-abusing-microsoft-sql-server-with-sqlrecon-259778942/259778942#1
|
||||
tags:
|
||||
category:
|
||||
- Adversary Tactics
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
usecase: Advanced Threat Detection
|
||||
cve: []
|
||||
Reference in New Issue
Block a user