diff --git a/detections/cloud/azure_ad_azurehound_useragent_detected.yml b/detections/cloud/azure_ad_azurehound_useragent_detected.yml index 62d1f62095..7f8e4abc5b 100644 --- a/detections/cloud/azure_ad_azurehound_useragent_detected.yml +++ b/detections/cloud/azure_ad_azurehound_useragent_detected.yml @@ -59,6 +59,5 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://github.com/splunk/contentctl/wiki - sourcetype: UPDATE SOURCETYPE - source: UPDATE SOURCE + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.004/azurehound/azurehound.log + sourcetype: azure:monitor:aad diff --git a/detections/cloud/azure_ad_service_principal_enumeration.yml b/detections/cloud/azure_ad_service_principal_enumeration.yml index 15ac90e51e..98b4101d28 100644 --- a/detections/cloud/azure_ad_service_principal_enumeration.yml +++ b/detections/cloud/azure_ad_service_principal_enumeration.yml @@ -63,6 +63,5 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://github.com/splunk/contentctl/wiki - sourcetype: UPDATE SOURCETYPE - source: UPDATE SOURCE + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1087.004/azurehound/azurehound.log + sourcetype: azure:monitor:aad diff --git a/detections/cloud/azure_ad_service_principal_privilege_escalation.yml b/detections/cloud/azure_ad_service_principal_privilege_escalation.yml index b2a0b698f8..0b8b5fbd36 100644 --- a/detections/cloud/azure_ad_service_principal_privilege_escalation.yml +++ b/detections/cloud/azure_ad_service_principal_privilege_escalation.yml @@ -23,6 +23,9 @@ known_false_positives: Unknown references: - https://splunkbase.splunk.com/app/3110 - https://docs.splunk.com/Documentation/AddOns/released/MSCloudServices/Install +- https://github.com/mvelazc0/BadZure +- https://www.splunk.com/en_us/blog/security/hunting-m365-invaders-navigating-the-shadows-of-midnight-blizzard.html +- https://posts.specterops.io/microsoft-breach-what-happened-what-should-azure-admins-do-da2b7e674ebc tags: analytic_story: - Azure Active Directory Privilege Escalation @@ -31,7 +34,7 @@ tags: impact: 100 message: Service Principal $servicePrincipal$ has elevated privileges by adding themself to app role $appRole$ mitre_attack_id: - - T1098.001 + - T1098.003 - T1098 observable: - name: servicePrincipal @@ -63,6 +66,5 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://github.com/splunk/contentctl/wiki - sourcetype: UPDATE SOURCETYPE - source: UPDATE SOURCE + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/azure_ad_spn_privesc/azure_ad_spn_privesc.log + sourcetype: azure:monitor:aad diff --git a/detections/cloud/azure_intune_new_device_health_script_created.yml b/detections/cloud/azure_intune_new_device_health_script_created.yml deleted file mode 100644 index 53314fdeb2..0000000000 --- a/detections/cloud/azure_intune_new_device_health_script_created.yml +++ /dev/null @@ -1,49 +0,0 @@ -name: Azure Intune New Device Health Script Created -id: 6fe42e07-15b1-4caa-b547-7885666cb1bd -version: 1 -date: '2025-01-06' -author: Dean Luxton -data_sources: [] -type: Hunting -status: production -description: Intune Remediation Scripts can be used to move laterally to intune managed devices. This detection identifies when a new device health script has been created. -search: >- - `azure_monitor_activity` operationName="createDeviceHealthScript DeviceHealthScript" - | rename identity as user, properties.TargetObjectIds{} as TargetObjectId - | table _time correlationId resultType user TargetObjectId - | `azure_intune_new_device_health_script_created_filter` -how_to_implement: The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest In-Tune audit logs via Azure EventHub. To configure this logging, visit Intune > Tenant administration > Diagnostic settings > Add diagnostic setting & send events to the activity audit event hub. -known_false_positives: False positives are expected from this detection. -references: -- https://posts.specterops.io/death-from-above-lateral-movement-from-azure-to-on-prem-ad-d18cb3959d4d -tags: - analytic_story: - - Azure Active Directory Account Takeover - asset_type: Azure Tenant - confidence: 20 - impact: 100 - message: Intune device health script $TargetObjectId$ was created by user $user$ - mitre_attack_id: - - T1072 - - T1021.007 - observable: - - name: user - type: User - role: - - Attacker - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - operationName - - identity - - properties.TargetObjectIds{} - risk_score: 20 - security_domain: audit -tests: -- name: True Positive Test - attack_data: - - data: https://github.com/splunk/contentctl/wiki - sourcetype: UPDATE SOURCETYPE - source: UPDATE SOURCE diff --git a/detections/cloud/microsoft_intune_device_health_scripts.yml b/detections/cloud/microsoft_intune_device_health_scripts.yml new file mode 100644 index 0000000000..f0856e8e7b --- /dev/null +++ b/detections/cloud/microsoft_intune_device_health_scripts.yml @@ -0,0 +1,62 @@ +name: Microsoft Intune Device Health Scripts +id: 6fe42e07-15b1-4caa-b547-7885666cb1bd +version: 1 +date: '2025-01-06' +author: Dean Luxton +data_sources: [] +type: Hunting +status: production +description: >- + Microsoft Intune device remediation scripts are a tool administrators can use to remotely manage devices, this functionality can also be abused for SYSTEM level code execution and lateral movement to intune managed devices. + This detection identifies when a new device health script has been added, updated or deleted. +search: >- + `azure_monitor_activity` operationName="*DeviceHealthScript*" + | rename identity as user, properties.TargetObjectIds{} as TargetObjectId, properties.TargetDisplayNames{} as TargetDisplayName, properties.Actor.IsDelegatedAdmin as user_isDelegatedAdmin + | rex field="operationName" "^(?P\w+?)DeviceHealthScript" | replace "patch" with "updated", "create" with "created", "delete", with "deleted", "assign", with "assigned" IN action + | table _time operationName action user user_type user_isDelegatedAdmin TargetDisplayName TargetObjectId status tenantId correlationId + | `microsoft_intune_device_health_scripts_filter` +how_to_implement: >- + The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest In-Tune audit logs via Azure EventHub. + To configure this logging, visit Intune > Tenant administration > Diagnostic settings > Add diagnostic settings & send events to the activity audit event hub. + Deploy as a risk based alerting rule for quick deployment or perform baselining & tune accordingly. +known_false_positives: Legitimate adminstrative usage of this functionality will trigger this detection. +references: +- https://posts.specterops.io/death-from-above-lateral-movement-from-azure-to-on-prem-ad-d18cb3959d4d +- https://securityintelligence.com/x-force/detecting-intune-lateral-movement/ +- https://posts.specterops.io/maestro-9ed71d38d546 +tags: + analytic_story: + - Azure Active Directory Account Takeover + asset_type: Azure Tenant + confidence: 40 + impact: 100 + message: Intune device health script $TargetObjectId$ was $action$ by user $user$ + mitre_attack_id: + - T1072 + - T1021.007 + - T1202 + - T1105 + observable: + - name: user + type: User + role: + - Attacker + - name: TargetObjectId + type: TargetObjectId + role: + - Object + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - operationName + - identity + - properties.TargetObjectIds{} + risk_score: 40 + security_domain: audit +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1072/intune/intune.log + sourcetype: azure:monitor:activity \ No newline at end of file diff --git a/detections/cloud/microsoft_intune_devicemanagementconfigurationpolicies.yml b/detections/cloud/microsoft_intune_devicemanagementconfigurationpolicies.yml new file mode 100644 index 0000000000..847aab8897 --- /dev/null +++ b/detections/cloud/microsoft_intune_devicemanagementconfigurationpolicies.yml @@ -0,0 +1,65 @@ +name: Microsoft Intune DeviceManagementConfigurationPolicies +id: 3c49e5ed-625c-408c-a2c7-8e2b524efb2c +version: 1 +date: '2025-01-07' +author: Dean Luxton +data_sources: [] +type: Hunting +status: production +description: >- + Microsoft Intune device management configuration policies are a tool administrators can use to remotely manage policies and settings on intune managed devices. + This functionality can also be abused to disable defences & evade detection. + This detection identifies when a new device management configuration policy has been created. +search: >- + `azure_monitor_activity` operationName="* DeviceManagementConfigurationPolicy*" + | rename identity as user, properties.TargetObjectIds{} as TargetObjectId, properties.TargetDisplayNames{} as TargetDisplayName, properties.Actor.IsDelegatedAdmin as user_isDelegatedAdmin + | eval details=mvzip('properties.Targets{}.ModifiedProperties{}.Name','properties.Targets{}.ModifiedProperties{}.New',": ") + | rex field="operationName" "^(?P\w+)\s" | replace "Patch" with "updated", "Create" with "created", "Delete", with "deleted", "assign", with "assigned" IN action + | eval action=if(match(operationName ,"Assignment$"),"assigned",'action') + | table _time operationName action user user_type user_isDelegatedAdmin TargetDisplayName TargetObjectId details status tenantId correlationId | `microsoft_intune_devicemanagementconfigurationpolicies_filter` +how_to_implement: >- + The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest In-Tune audit logs via Azure EventHub. + To configure this logging, visit Intune > Tenant administration > Diagnostic settings > Add diagnostic settings & send events to the activity audit event hub. + Deploy as a risk based alerting rule for quick deployment or perform baselining & tune accordingly. +known_false_positives: Legitimate adminstrative usage of this functionality will trigger this detection. +references: +- https://posts.specterops.io/death-from-above-lateral-movement-from-azure-to-on-prem-ad-d18cb3959d4d +- https://securityintelligence.com/x-force/detecting-intune-lateral-movement/ +- https://posts.specterops.io/maestro-9ed71d38d546 +tags: + analytic_story: + - Azure Active Directory Account Takeover + asset_type: Azure Tenant + confidence: 40 + impact: 100 + message: Intune device management policy $TargetObjectId$ has been $action$ by user $user$ + mitre_attack_id: + - T1072 + - T1484 + - T1021.007 + - T1562.001 + - T1562.004 + observable: + - name: user + type: User + role: + - Attacker + - name: TargetObjectId + type: TargetObjectId + role: + - Object + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - operationName + - identity + - properties.TargetObjectIds{} + risk_score: 40 + security_domain: audit +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1072/intune/intune.log + sourcetype: azure:monitor:activity diff --git a/detections/cloud/microsoft_intune_manual_device_management.yml b/detections/cloud/microsoft_intune_manual_device_management.yml new file mode 100644 index 0000000000..401345194e --- /dev/null +++ b/detections/cloud/microsoft_intune_manual_device_management.yml @@ -0,0 +1,63 @@ +name: Microsoft Intune Manual Device Management +id: 5ca7ebee-4ee7-4cf2-b3be-0ea26a00d822 +version: 1 +date: '2025-01-07' +author: Dean Luxton +data_sources: [] +type: Hunting +status: production +description: >- + Microsoft Intune device management configuration policies, scripts & apps are a all tools administrators can use to remotely manage intune managed devices. + Instead of waiting for the devices to poll for changes to polciies, the policies can be manually pushed to expidite delivery. + This may be useful in a pinch, it may also be a sign of an impatient attacker trying to speed up the delivery of their payload. + This detection identifies when a device management configuration policy sync events, on-demand remediation scripts are triggered or when devices are remotely restarted. +search: >- + `azure_monitor_activity` operationName="*ManagedDevice*" + | rename identity as user, properties.TargetObjectIds{} as TargetObjectId, properties.TargetDisplayNames{} as TargetDisplayName, properties.Actor.IsDelegatedAdmin as user_isDelegatedAdmin + | rex field="operationName" "^(?P\w+)\s" + | table _time operationName action user user_type user_isDelegatedAdmin TargetDisplayName TargetObjectId status tenantId correlationId + | `microsoft_intune_manual_device_management_filter` +how_to_implement: >- + The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest In-Tune audit logs via Azure EventHub. + To configure this logging, visit Intune > Tenant administration > Diagnostic settings > Add diagnostic settings & send events to the activity audit event hub. + Deploy as a risk based alerting rule for quick deployment or perform baselining & tune accordingly. +known_false_positives: Legitimate adminstrative usage of this functionality will trigger this detection. +references: +- https://posts.specterops.io/death-from-above-lateral-movement-from-azure-to-on-prem-ad-d18cb3959d4d +- https://securityintelligence.com/x-force/detecting-intune-lateral-movement/ +- https://posts.specterops.io/maestro-9ed71d38d546 +tags: + analytic_story: + - Azure Active Directory Account Takeover + asset_type: Azure Tenant + confidence: 70 + impact: 20 + message: Microsoft Intune device management configuration policy action $action$ was performed on $TargetObjectId$ by user $user$ + mitre_attack_id: + - T1021.007 + - T1072 + - T1529 + observable: + - name: user + type: User + role: + - Attacker + - name: TargetObjectId + type: TargetObjectId + role: + - Object + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - operationName + - identity + - properties.TargetObjectIds{} + risk_score: 14 + security_domain: audit +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1072/intune/intune.log + sourcetype: azure:monitor:activity diff --git a/detections/cloud/microsoft_intune_mobile_apps.yml b/detections/cloud/microsoft_intune_mobile_apps.yml new file mode 100644 index 0000000000..6df133b455 --- /dev/null +++ b/detections/cloud/microsoft_intune_mobile_apps.yml @@ -0,0 +1,62 @@ +name: Microsoft Intune Mobile Apps +id: 98e6b389-2806-4426-a580-8a92cb0d9710 +version: 1 +date: '2025-01-07' +author: Dean Luxton +data_sources: [] +type: Hunting +status: experimental +description: >- + Microsoft Intune supports deploying packaged applications to support software deployment, this functionality can also be abused for deploying malicious payloads to intune managed devices. + This detection identifies when a new packaged application has been added, updated or deleted. +search: >- + `azure_monitor_activity` operationName="*MobileApp*" + | rename identity as user, properties.TargetObjectIds{} as TargetObjectId, properties.TargetDisplayNames{} as TargetDisplayName, properties.Actor.IsDelegatedAdmin as user_isDelegatedAdmin + | rex field="operationName" "^(?P\w+)\s" | replace "Patch" with "updated", "Create" with "created", "Delete", with "deleted", "assign", with "assigned" IN action + | table _time operationName action user user_type user_isDelegatedAdmin TargetDisplayName TargetObjectId status tenantId correlationId + | `microsoft_intune_mobile_apps_filter` +how_to_implement: >- + The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest In-Tune audit logs via Azure EventHub. + To configure this logging, visit Intune > Tenant administration > Diagnostic settings > Add diagnostic settings & send events to the activity audit event hub. + Deploy as a risk based alerting rule for quick deployment or perform baselining & tune accordingly. +known_false_positives: Legitimate adminstrative usage of this functionality will trigger this detection. +references: +- https://posts.specterops.io/death-from-above-lateral-movement-from-azure-to-on-prem-ad-d18cb3959d4d +- https://securityintelligence.com/x-force/detecting-intune-lateral-movement/ +- https://posts.specterops.io/maestro-9ed71d38d546 +tags: + analytic_story: + - Azure Active Directory Account Takeover + asset_type: Azure Tenant + confidence: 40 + impact: 100 + message: Intune packed application $TargetDisplayName$ $TargetObjectId$ was $action$ by user $user$ + mitre_attack_id: + - T1072 + - T1021.007 + - T1202 + - T1105 + observable: + - name: user + type: User + role: + - Attacker + - name: TargetObjectId + type: TargetObjectId + role: + - Object + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - operationName + - identity + - properties.TargetObjectIds{} + risk_score: 40 + security_domain: audit +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1072/intune/intune.log + sourcetype: azure:monitor:activity diff --git a/detections/cloud/o365_service_principal_privilege_escalation.yml b/detections/cloud/o365_service_principal_privilege_escalation.yml index 219b18d33b..0bcb538d01 100644 --- a/detections/cloud/o365_service_principal_privilege_escalation.yml +++ b/detections/cloud/o365_service_principal_privilege_escalation.yml @@ -15,19 +15,24 @@ search: >- | spath input=targetServicePrincipal path=NewValue output=targetServicePrincipal | where servicePrincipal=targetServicePrincipal | table _time Operation servicePrincipal servicePrincipalId appRole targetAppContext user_agent tenant_id InterSystemsId + | `o365_service_principal_privilege_escalation_filter how_to_implement: The Splunk Add-on for Microsoft Office 365 add-on is required to ingest EntraID audit logs via the 365 API. See references for links for further details on how to onboard this log source. known_false_positives: Unknown references: - https://splunkbase.splunk.com/app/4055 +- https://github.com/mvelazc0/BadZure +- https://www.splunk.com/en_us/blog/security/hunting-m365-invaders-navigating-the-shadows-of-midnight-blizzard.html +- https://posts.specterops.io/microsoft-breach-what-happened-what-should-azure-admins-do-da2b7e674ebc tags: analytic_story: - Azure Active Directory Privilege Escalation + - Office 365 Account Takeover asset_type: Azure Tenant confidence: 100 impact: 100 message: Service Principal $servicePrincipal$ has elevated privileges by adding themself to app role $appRole$ mitre_attack_id: - - T1098.001 + - T1098.003 - T1098 observable: - name: servicePrincipal @@ -56,6 +61,5 @@ tags: tests: - name: True Positive Test attack_data: - - data: https://github.com/splunk/contentctl/wiki - sourcetype: UPDATE SOURCETYPE - source: UPDATE SOURCE + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/o365_spn_privesc/o365_spn_privesc.log + sourcetype: o365:management:activity