From 0b8ccaf23a1a84b67432e9d928416b7bb96e80ca Mon Sep 17 00:00:00 2001 From: root Date: Fri, 12 Feb 2021 19:30:06 +0000 Subject: [PATCH] Added detection testing service results inDetect Regasm Spawning a Process --- .../detect_regasm_spawning_a_process.yml | 24 +++++++++++-------- 1 file changed, 14 insertions(+), 10 deletions(-) diff --git a/detections/endpoint/detect_regasm_spawning_a_process.yml b/detections/endpoint/detect_regasm_spawning_a_process.yml index de6c6c3d3f..1078a7c4ef 100644 --- a/detections/endpoint/detect_regasm_spawning_a_process.yml +++ b/detections/endpoint/detect_regasm_spawning_a_process.yml @@ -2,10 +2,14 @@ name: Detect Regasm Spawning a Process id: 72170ec5-f7d2-42f5-aefb-2b8be6aad15f version: 1 date: '2021-02-12' -description: The following analytic identifies regasm.exe spawning a process. - This particular technique has been used in the wild to bypass application control products. Regasm.exe and Regsvcs.exe are signed by Microsoft. Spawning of a child process is rare from either process and should be investigated further. - During investigation, identify and retrieve the content being loaded. Review parallel processes for additional suspicious behavior. Gather any other file modifications and review accordingly. - regsvcs.exe and regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. +description: The following analytic identifies regasm.exe spawning a process. This + particular technique has been used in the wild to bypass application control products. + Regasm.exe and Regsvcs.exe are signed by Microsoft. Spawning of a child process + is rare from either process and should be investigated further. During investigation, + identify and retrieve the content being loaded. Review parallel processes for additional + suspicious behavior. Gather any other file modifications and review accordingly. + regsvcs.exe and regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe + and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. @@ -19,12 +23,11 @@ author: Michael Haag, Splunk search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=regasm.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name - Processes.process Processes.process_id Processes.parent_process_id - | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `detect_regasm_spawning_a_process_filter`' -known_false_positives: Although unlikely, limited instances of regasm.exe or regsvcs.exe may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage. + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_regasm_spawning_a_process_filter`' +known_false_positives: Although unlikely, limited instances of regasm.exe or regsvcs.exe + may cause a false positive. Filter based endpoint usage, command line arguments, + or process lineage. tags: analytic_story: - Suspicious Regasm Regsvcs Activity @@ -45,3 +48,4 @@ tags: asset_type: Endpoint dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.009/atomic_red_team/windows-sysmon.log + automated_detection_testing: passed