mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge branch 'develop' into patch-1
This commit is contained in:
+5
-12
@@ -29,12 +29,6 @@ mode: {}
|
||||
splunk_api_username: null
|
||||
post_test_behavior: pause_on_failure
|
||||
apps:
|
||||
# - uid: 263
|
||||
# title: Splunk Enterprise Security
|
||||
# appid: SplunkEnterpriseSecuritySuite
|
||||
# version: 7.3.1
|
||||
# description: description of app
|
||||
# hardcoded_path: apps/splunk-enterprise-security_731.spl
|
||||
- uid: 1621
|
||||
title: Splunk Common Information Model (CIM)
|
||||
appid: Splunk_SA_CIM
|
||||
@@ -142,10 +136,10 @@ apps:
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-amazon-kinesis-firehose_132.tgz
|
||||
- uid: 1876
|
||||
title: Splunk Add-on for AWS
|
||||
appid: Splunk_TA_aws
|
||||
version: 7.7.1
|
||||
appid: Splunk_TA_aws
|
||||
version: 7.8.0
|
||||
description: description of app
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-amazon-web-services-aws_771.tgz
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-amazon-web-services-aws_780.tgz
|
||||
- uid: 3088
|
||||
title: Splunk Add-on for Google Cloud Platform
|
||||
appid: SPLUNK_ADD_ON_FOR_GOOGLE_CLOUD_PLATFORM
|
||||
@@ -185,9 +179,9 @@ apps:
|
||||
- uid: 6207
|
||||
title: Splunk Add-on for Microsoft Security
|
||||
appid: Splunk_TA_MS_Security
|
||||
version: 2.3.0
|
||||
version: 2.4.0
|
||||
description: description of app
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-security_230.tgz
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-security_240.tgz
|
||||
- uid: 2734
|
||||
title: URL Toolbox
|
||||
appid: URL_TOOLBOX
|
||||
@@ -207,4 +201,3 @@ apps:
|
||||
description: description of app
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/crowdstrike-falcon-event-streams-technical-add-on_321.tgz
|
||||
githash: d6fac80e6d50ae06b40f91519a98489d4ce3a3fd
|
||||
|
||||
|
||||
@@ -9,7 +9,7 @@ sourcetype: aws:cloudfront:accesslogs
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,4 +10,4 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- apiVersion
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- apiVersion
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- apiVersion
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- apiVersion
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -9,7 +9,7 @@ sourcetype: aws:cloudwatchlogs:vpcflow
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
fields:
|
||||
- _raw
|
||||
|
||||
@@ -9,7 +9,7 @@ sourcetype: aws:securityhub:finding
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.7.1
|
||||
version: 7.8.0
|
||||
fields:
|
||||
- _time
|
||||
- AwsAccountId
|
||||
|
||||
@@ -9,7 +9,7 @@ sourcetype: ms365:defender:incident:alerts
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Security
|
||||
url: https://splunkbase.splunk.com/app/6207
|
||||
version: 2.3.0
|
||||
version: 2.4.0
|
||||
fields:
|
||||
- actorName
|
||||
- alertId
|
||||
|
||||
@@ -9,7 +9,7 @@ sourcetype: ms:defender:atp:alerts
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Security
|
||||
url: https://splunkbase.splunk.com/app/6207
|
||||
version: 2.3.0
|
||||
version: 2.4.0
|
||||
fields:
|
||||
- column
|
||||
- accountName
|
||||
|
||||
@@ -0,0 +1,61 @@
|
||||
name: Windows Event Log Microsoft Windows TerminalServices RDPClient 1024
|
||||
id: 2490537e-5e0c-46f7-9209-f56f852aa217
|
||||
version: 1
|
||||
date: '2024-11-21'
|
||||
author: Michael Haag, Splunk
|
||||
description: Data source object for Windows Event Microsoft Windows TerminalServices RDPClient 1024
|
||||
source: WinEventLog:Microsoft-Windows-TerminalServices-RDPClient/Operational
|
||||
sourcetype: WinEventLog
|
||||
separator: EventCode
|
||||
supported_TA: []
|
||||
fields:
|
||||
- _time
|
||||
- Channel
|
||||
- Computer
|
||||
- EventCode
|
||||
- EventData
|
||||
- EventID
|
||||
- EventRecordID
|
||||
- EventType
|
||||
- Keywords
|
||||
- Level
|
||||
- Message
|
||||
- Opcode
|
||||
- ProcessID
|
||||
- RecordNumber
|
||||
- Security_ID
|
||||
- Src
|
||||
- Src_Host
|
||||
- Src_NT_Domain
|
||||
- Src_User
|
||||
- System_TimeCreated
|
||||
- Task
|
||||
- ThreadID
|
||||
- Type
|
||||
- User
|
||||
- UserID
|
||||
- Version
|
||||
- dest
|
||||
- dvc
|
||||
- event_id
|
||||
- host
|
||||
- source
|
||||
- sourcetype
|
||||
- tag
|
||||
- user
|
||||
example_log:
|
||||
11/21/2024 06:09:16 PM
|
||||
LogName=Microsoft-Windows-TerminalServices-RDPClient/Operational
|
||||
EventCode=1024
|
||||
EventType=4
|
||||
ComputerName=ar-win-5.attackrange.local
|
||||
User=NOT_TRANSLATED
|
||||
Sid=S-1-5-21-1731938146-2314223186-1848411941-500
|
||||
SidType=0
|
||||
SourceName=Microsoft-Windows-TerminalServices-ClientActiveXCore
|
||||
Type=Information
|
||||
RecordNumber=95
|
||||
Keywords=None
|
||||
TaskCategory=Connection Sequence
|
||||
OpCode=This event is raised during the connection process
|
||||
Message=RDP ClientActiveX is trying to connect to the server (34.221.50.57)
|
||||
@@ -1,18 +1,40 @@
|
||||
name: Add or Set Windows Defender Exclusion
|
||||
id: 773b66fe-4dd9-11ec-8289-acde48001122
|
||||
version: 4
|
||||
date: '2024-09-30'
|
||||
version: '5'
|
||||
date: '2024-11-28'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the use of commands to add or set exclusions in Windows Defender. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions involving "Add-MpPreference" or "Set-MpPreference" with exclusion parameters. This activity is significant because adversaries often use it to bypass Windows Defender, allowing malicious code to execute undetected. If confirmed malicious, this behavior could enable attackers to evade antivirus detection, maintain persistence, and execute further malicious activities without interference from Windows Defender.
|
||||
description: The following analytic detects the use of commands to add or set exclusions
|
||||
in Windows Defender. It leverages data from Endpoint Detection and Response (EDR)
|
||||
agents, focusing on command-line executions involving "Add-MpPreference" or "Set-MpPreference"
|
||||
with exclusion parameters. This activity is significant because adversaries often
|
||||
use it to bypass Windows Defender, allowing malicious code to execute undetected.
|
||||
If confirmed malicious, this behavior could enable attackers to evade antivirus
|
||||
detection, maintain persistence, and execute further malicious activities without
|
||||
interference from Windows Defender.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process = "*Add-MpPreference *" OR Processes.process = "*Set-MpPreference *") AND Processes.process="*-exclusion*" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `add_or_set_windows_defender_exclusion_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Admin or user may choose to use this windows features. Filter as needed.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.process = "*Add-MpPreference
|
||||
*" OR Processes.process = "*Set-MpPreference *") AND Processes.process="*-exclusion*"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name
|
||||
Processes.process_name Processes.original_file_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `add_or_set_windows_defender_exclusion_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Admin or user may choose to use this windows features. Filter
|
||||
as needed.
|
||||
references:
|
||||
- https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html
|
||||
- https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/
|
||||
@@ -23,18 +45,24 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- CISA AA22-320A
|
||||
- AgentTesla
|
||||
- Remcos
|
||||
- Windows Defense Evasion Tactics
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
- Windows Defense Evasion Tactics
|
||||
- Remcos
|
||||
- Data Destruction
|
||||
- CISA AA22-320A
|
||||
- ValleyRAT
|
||||
- Compromised Windows Host
|
||||
- AgentTesla
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
|
||||
@@ -1,18 +1,40 @@
|
||||
name: Attacker Tools On Endpoint
|
||||
id: a51bfe1a-94f0-48cc-b4e4-16a110145893
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of tools commonly exploited by cybercriminals, such as those used for unauthorized access, network scanning, or data exfiltration. It leverages process activity data from Endpoint Detection and Response (EDR) agents, focusing on known attacker tool names. This activity is significant because it serves as an early warning system for potential security incidents, enabling prompt response. If confirmed malicious, this activity could lead to unauthorized access, data theft, or further network compromise, posing a severe threat to the organization's security infrastructure.
|
||||
description: The following analytic detects the execution of tools commonly exploited
|
||||
by cybercriminals, such as those used for unauthorized access, network scanning,
|
||||
or data exfiltration. It leverages process activity data from Endpoint Detection
|
||||
and Response (EDR) agents, focusing on known attacker tool names. This activity
|
||||
is significant because it serves as an early warning system for potential security
|
||||
incidents, enabling prompt response. If confirmed malicious, this activity could
|
||||
lead to unauthorized access, data theft, or further network compromise, posing a
|
||||
severe threat to the organization's security infrastructure.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process) as process values(Processes.parent_process) as parent_process from datamodel=Endpoint.Processes where Processes.dest!=unknown Processes.user!=unknown by Processes.dest Processes.user Processes.process_name Processes.process | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name(Processes)` | lookup attacker_tools attacker_tool_names AS process_name OUTPUT description | search description !=false| `attacker_tools_on_endpoint_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Some administrator activity can be potentially triggered, please add those users to the filter macro.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime values(Processes.process) as process values(Processes.parent_process)
|
||||
as parent_process from datamodel=Endpoint.Processes where Processes.dest!=unknown
|
||||
Processes.user!=unknown by Processes.dest Processes.user Processes.process_name
|
||||
Processes.process | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `drop_dm_object_name(Processes)` | lookup attacker_tools attacker_tool_names AS
|
||||
process_name OUTPUT description | search description !=false| `attacker_tools_on_endpoint_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Some administrator activity can be potentially triggered, please
|
||||
add those users to the filter macro.
|
||||
references: []
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$user$" and "$dest$"
|
||||
@@ -20,20 +42,27 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Monitor for Unauthorized Software
|
||||
- XMRig
|
||||
- SamSam Ransomware
|
||||
- Monitor for Unauthorized Software
|
||||
- Unusual Processes
|
||||
- SamSam Ransomware
|
||||
- CISA AA22-264A
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
message: An attacker tool $process_name$,listed in attacker_tools.csv is executed on host $dest$ by User $user$. This process $process_name$ is known to do- $description$
|
||||
message: An attacker tool $process_name$,listed in attacker_tools.csv is executed
|
||||
on host $dest$ by User $user$. This process $process_name$ is known to do- $description$
|
||||
mitre_attack_id:
|
||||
- T1036.005
|
||||
- T1036
|
||||
|
||||
@@ -1,17 +1,40 @@
|
||||
name: Attempted Credential Dump From Registry via Reg exe
|
||||
id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911
|
||||
version: 10
|
||||
date: '2024-09-30'
|
||||
version: '11'
|
||||
date: '2024-11-28'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of reg.exe with parameters that export registry keys containing hashed credentials. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions involving reg.exe or cmd.exe with specific registry paths. This activity is significant because exporting these keys can allow attackers to obtain hashed credentials, which they may attempt to crack offline. If confirmed malicious, this could lead to unauthorized access to sensitive accounts, enabling further compromise and lateral movement within the network.
|
||||
description: The following analytic detects the execution of reg.exe with parameters
|
||||
that export registry keys containing hashed credentials. It leverages data from
|
||||
Endpoint Detection and Response (EDR) agents, focusing on command-line executions
|
||||
involving reg.exe or cmd.exe with specific registry paths. This activity is significant
|
||||
because exporting these keys can allow attackers to obtain hashed credentials, which
|
||||
they may attempt to crack offline. If confirmed malicious, this could lead to unauthorized
|
||||
access to sensitive accounts, enabling further compromise and lateral movement within
|
||||
the network.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=reg* OR Processes.process_name=cmd* Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\System* OR Processes.process=*HKLM\\Security* OR Processes.process=*HKLM\\System* OR Processes.process=*HKLM\\SAM*) by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=reg*
|
||||
OR Processes.process_name=cmd* Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\Security*
|
||||
OR Processes.process=*HKEY_LOCAL_MACHINE\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\System*
|
||||
OR Processes.process=*HKLM\\Security* OR Processes.process=*HKLM\\System* OR Processes.process=*HKLM\\SAM*)
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `attempted_credential_dump_from_registry_via_reg_exe_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: None identified.
|
||||
references:
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets
|
||||
@@ -21,21 +44,28 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- Windows Registry Abuse
|
||||
- Credential Dumping
|
||||
- CISA AA23-347A
|
||||
- DarkSide Ransomware
|
||||
- Industroyer2
|
||||
- Data Destruction
|
||||
- CISA AA23-347A
|
||||
- Windows Registry Abuse
|
||||
- Compromised Windows Host
|
||||
- Credential Dumping
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 90
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to export the registry keys.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to export the registry keys.
|
||||
mitre_attack_id:
|
||||
- T1003.002
|
||||
- T1003
|
||||
|
||||
@@ -1,16 +1,42 @@
|
||||
name: Batch File Write to System32
|
||||
id: 503d17cb-9eab-4cf8-a20e-01d5c6987ae3
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
version: '7'
|
||||
date: '2024-11-28'
|
||||
author: Steven Dick, Michael Haag, Rico Valdez, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the creation of a batch file (.bat) within the Windows system directory tree, specifically in the System32 or SysWOW64 folders. It leverages data from the Endpoint datamodel, focusing on process and filesystem events to identify this behavior. This activity is significant because writing batch files to system directories can be indicative of malicious intent, such as persistence mechanisms or system manipulation. If confirmed malicious, this could allow an attacker to execute arbitrary commands with elevated privileges, potentially compromising the entire system.
|
||||
description: The following analytic detects the creation of a batch file (.bat) within
|
||||
the Windows system directory tree, specifically in the System32 or SysWOW64 folders.
|
||||
It leverages data from the Endpoint datamodel, focusing on process and filesystem
|
||||
events to identify this behavior. This activity is significant because writing batch
|
||||
files to system directories can be indicative of malicious intent, such as persistence
|
||||
mechanisms or system manipulation. If confirmed malicious, this could allow an attacker
|
||||
to execute arbitrary commands with elevated privileges, potentially compromising
|
||||
the entire system.
|
||||
data_source:
|
||||
- Sysmon EventID 1 AND Sysmon EventID 11
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=* by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | join process_guid [| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\system32\\*", "*\\syswow64\\*") Filesystem.file_name="*.bat" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid | `drop_dm_object_name(Filesystem)`] | table dest user file_create_time, file_name, file_path, process_name, firstTime, lastTime | dedup file_create_time | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `batch_file_write_to_system32_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: It is possible for this search to generate a notable event for a batch file write to a path that includes the string "system32", but is not the actual Windows system directory. As such, you should confirm the path of the batch file identified by the search. In addition, a false positive may be generated by an administrator copying a legitimate batch file in this directory tree. You should confirm that the activity is legitimate and modify the search to add exclusions, as necessary.
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
where Processes.process_name=* by _time span=1h Processes.process_guid Processes.process_name
|
||||
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | join process_guid
|
||||
[| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\system32\\*",
|
||||
"*\\syswow64\\*") Filesystem.file_name="*.bat" by _time span=1h Filesystem.dest
|
||||
Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid
|
||||
| `drop_dm_object_name(Filesystem)`] | table dest user file_create_time, file_name,
|
||||
file_path, process_name, firstTime, lastTime | dedup file_create_time | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `batch_file_write_to_system32_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: It is possible for this search to generate a notable event
|
||||
for a batch file write to a path that includes the string "system32", but is not
|
||||
the actual Windows system directory. As such, you should confirm the path of the
|
||||
batch file identified by the search. In addition, a false positive may be generated
|
||||
by an administrator copying a legitimate batch file in this directory tree. You
|
||||
should confirm that the activity is legitimate and modify the search to add exclusions,
|
||||
as necessary.
|
||||
references: []
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$user$" and "$dest$"
|
||||
@@ -18,16 +44,23 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- SamSam Ransomware
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 70
|
||||
message: A file - $file_name$ was written to system32 has occurred on endpoint $dest$ by user $user$.
|
||||
message: A file - $file_name$ was written to system32 has occurred on endpoint $dest$
|
||||
by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1204
|
||||
- T1204.002
|
||||
|
||||
@@ -1,17 +1,37 @@
|
||||
name: BCDEdit Failure Recovery Modification
|
||||
id: 809b31d2-5462-11eb-ae93-0242ac130002
|
||||
version: 4
|
||||
date: '2024-09-30'
|
||||
version: '5'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects modifications to the Windows error recovery boot configurations using bcdedit.exe with flags such as "recoveryenabled" and "no". It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names, parent processes, and command-line executions. This activity is significant because ransomware often disables recovery options to prevent system restoration, making it crucial for SOC analysts to investigate. If confirmed malicious, this could hinder recovery efforts, allowing ransomware to cause extensive damage and complicate remediation.
|
||||
description: The following analytic detects modifications to the Windows error recovery
|
||||
boot configurations using bcdedit.exe with flags such as "recoveryenabled" and "no".
|
||||
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on
|
||||
process names, parent processes, and command-line executions. This activity is significant
|
||||
because ransomware often disables recovery options to prevent system restoration,
|
||||
making it crucial for SOC analysts to investigate. If confirmed malicious, this
|
||||
could hinder recovery efforts, allowing ransomware to cause extensive damage and
|
||||
complicate remediation.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = bcdedit.exe Processes.process="*recoveryenabled*" (Processes.process="* no*") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `bcdedit_failure_recovery_modification_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = bcdedit.exe
|
||||
Processes.process="*recoveryenabled*" (Processes.process="* no*") by Processes.process_name
|
||||
Processes.process Processes.parent_process_name Processes.dest Processes.user |
|
||||
`drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `bcdedit_failure_recovery_modification_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Administrators may modify the boot configuration.
|
||||
references:
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md#atomic-test-4---windows---disable-windows-recovery-console-repair
|
||||
@@ -21,17 +41,25 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ryuk Ransomware
|
||||
- Ransomware
|
||||
- Compromised Windows Host
|
||||
- Ryuk Ransomware
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 100
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting disable the ability to recover the endpoint.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting disable the ability to recover the
|
||||
endpoint.
|
||||
mitre_attack_id:
|
||||
- T1490
|
||||
observable:
|
||||
|
||||
@@ -1,18 +1,40 @@
|
||||
name: CertUtil Download With URLCache and Split Arguments
|
||||
id: 415b4306-8bfb-11eb-85c4-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
version: '7'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the use of certutil.exe to download files using the `-urlcache` and `-split` arguments. It leverages Endpoint Detection and Response (EDR) data, focusing on command-line executions that include these specific arguments. This activity is significant because certutil.exe is typically used for certificate services, and its use to download files from remote locations is uncommon and potentially malicious. If confirmed, this behavior could indicate an attempt to download and execute malicious payloads, leading to potential system compromise and unauthorized data access.
|
||||
description: The following analytic detects the use of certutil.exe to download files
|
||||
using the `-urlcache` and `-split` arguments. It leverages Endpoint Detection and
|
||||
Response (EDR) data, focusing on command-line executions that include these specific
|
||||
arguments. This activity is significant because certutil.exe is typically used for
|
||||
certificate services, and its use to download files from remote locations is uncommon
|
||||
and potentially malicious. If confirmed, this behavior could indicate an attempt
|
||||
to download and execute malicious payloads, leading to potential system compromise
|
||||
and unauthorized data access.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_certutil` (Processes.process=*urlcache* Processes.process=*split*) OR Processes.process=*urlcache* by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.original_file_name Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `certutil_download_with_urlcache_and_split_arguments_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_certutil` (Processes.process=*urlcache*
|
||||
Processes.process=*split*) OR Processes.process=*urlcache* by Processes.dest Processes.user
|
||||
Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process
|
||||
Processes.process_id Processes.original_file_name Processes.parent_process_id |
|
||||
`drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `certutil_download_with_urlcache_and_split_arguments_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Limited false positives in most environments, however tune
|
||||
as needed based on parent-child relationship or network connection.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1105/
|
||||
- https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats
|
||||
@@ -23,22 +45,29 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ingress Tool Transfer
|
||||
- DarkSide Ransomware
|
||||
- Living Off The Land
|
||||
- ProxyNotShell
|
||||
- CISA AA22-277A
|
||||
- Flax Typhoon
|
||||
- Living Off The Land
|
||||
- DarkSide Ransomware
|
||||
- Forest Blizzard
|
||||
- Flax Typhoon
|
||||
- Ingress Tool Transfer
|
||||
- Compromised Windows Host
|
||||
- CISA AA22-277A
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 90
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to download a file.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to download a file.
|
||||
mitre_attack_id:
|
||||
- T1105
|
||||
observable:
|
||||
|
||||
@@ -1,18 +1,40 @@
|
||||
name: CertUtil Download With VerifyCtl and Split Arguments
|
||||
id: 801ad9e4-8bfb-11eb-8b31-acde48001122
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
version: '7'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the use of `certutil.exe` to download files using the `-VerifyCtl` and `-split` arguments. This behavior is identified by monitoring command-line executions for these specific arguments via Endpoint Detection and Response (EDR) telemetry. This activity is significant because `certutil.exe` is a legitimate tool often abused by attackers to download and execute malicious payloads. If confirmed malicious, this could allow an attacker to download and execute arbitrary files, potentially leading to code execution, data exfiltration, or further compromise of the system.
|
||||
description: The following analytic detects the use of `certutil.exe` to download
|
||||
files using the `-VerifyCtl` and `-split` arguments. This behavior is identified
|
||||
by monitoring command-line executions for these specific arguments via Endpoint
|
||||
Detection and Response (EDR) telemetry. This activity is significant because `certutil.exe`
|
||||
is a legitimate tool often abused by attackers to download and execute malicious
|
||||
payloads. If confirmed malicious, this could allow an attacker to download and execute
|
||||
arbitrary files, potentially leading to code execution, data exfiltration, or further
|
||||
compromise of the system.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_certutil` (Processes.process=*verifyctl* Processes.process=*split*) OR Processes.process=*verifyctl* by Processes.dest Processes.user Processes.original_file_name Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `certutil_download_with_verifyctl_and_split_arguments_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_certutil` (Processes.process=*verifyctl*
|
||||
Processes.process=*split*) OR Processes.process=*verifyctl* by Processes.dest Processes.user
|
||||
Processes.original_file_name Processes.parent_process Processes.parent_process_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `certutil_download_with_verifyctl_and_split_arguments_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Limited false positives in most environments, however tune
|
||||
as needed based on parent-child relationship or network connection.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1105/
|
||||
- https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/
|
||||
@@ -24,18 +46,25 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ingress Tool Transfer
|
||||
- DarkSide Ransomware
|
||||
- Compromised Windows Host
|
||||
- Living Off The Land
|
||||
- Ingress Tool Transfer
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 90
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to download a file.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to download a file.
|
||||
mitre_attack_id:
|
||||
- T1105
|
||||
observable:
|
||||
|
||||
@@ -1,18 +1,40 @@
|
||||
name: Certutil exe certificate extraction
|
||||
id: 337a46be-600f-11eb-ae93-0242ac130002
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Rod Soto, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies the use of certutil.exe with arguments indicating the manipulation or extraction of certificates. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant because extracting certificates can allow attackers to sign new authentication tokens, particularly in federated environments like Windows ADFS. If confirmed malicious, this could enable attackers to forge authentication tokens, potentially leading to unauthorized access and privilege escalation within the network.
|
||||
description: The following analytic identifies the use of certutil.exe with arguments
|
||||
indicating the manipulation or extraction of certificates. It leverages data from
|
||||
Endpoint Detection and Response (EDR) agents, focusing on process names and command-line
|
||||
arguments. This activity is significant because extracting certificates can allow
|
||||
attackers to sign new authentication tokens, particularly in federated environments
|
||||
like Windows ADFS. If confirmed malicious, this could enable attackers to forge
|
||||
authentication tokens, potentially leading to unauthorized access and privilege
|
||||
escalation within the network.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process = "*-exportPFX*" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `certutil_exe_certificate_extraction_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Unless there are specific use cases, manipulating or exporting certificates using certutil is uncommon. Extraction of certificate has been observed during attacks such as Golden SAML and other campaigns targeting Federated services.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe
|
||||
Processes.process = "*-exportPFX*" by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.parent_process_name Processes.process_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `certutil_exe_certificate_extraction_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Unless there are specific use cases, manipulating or exporting
|
||||
certificates using certutil is uncommon. Extraction of certificate has been observed
|
||||
during attacks such as Golden SAML and other campaigns targeting Federated services.
|
||||
references:
|
||||
- https://blog.sygnia.co/detection-and-hunting-of-golden-saml-attack
|
||||
- https://strontic.github.io/xcyclopedia/library/certutil.exe-09A8A29BAA3A451713FD3D07943B4A43.html
|
||||
@@ -22,19 +44,26 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Persistence Techniques
|
||||
- Cloud Federated Credential Abuse
|
||||
- Living Off The Land
|
||||
- Cloud Federated Credential Abuse
|
||||
- Compromised Windows Host
|
||||
- Windows Certificate Services
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 90
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting export a certificate.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting export a certificate.
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
@@ -1,17 +1,36 @@
|
||||
name: Clear Unallocated Sector Using Cipher App
|
||||
id: cd80a6ac-c9d9-11eb-8839-acde48001122
|
||||
version: 4
|
||||
date: '2024-09-30'
|
||||
version: '5'
|
||||
date: '2024-11-28'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of `cipher.exe` with the `/w` flag to clear unallocated sectors on a disk. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names, command-line arguments, and parent processes. This activity is significant because it is a technique used by ransomware to prevent forensic recovery of deleted files. If confirmed malicious, this action could hinder incident response efforts by making it impossible to recover critical data, thereby complicating the investigation and remediation process.
|
||||
description: The following analytic detects the execution of `cipher.exe` with the
|
||||
`/w` flag to clear unallocated sectors on a disk. It leverages data from Endpoint
|
||||
Detection and Response (EDR) agents, focusing on process names, command-line arguments,
|
||||
and parent processes. This activity is significant because it is a technique used
|
||||
by ransomware to prevent forensic recovery of deleted files. If confirmed malicious,
|
||||
this action could hinder incident response efforts by making it impossible to recover
|
||||
critical data, thereby complicating the investigation and remediation process.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "cipher.exe" Processes.process = "*/w:*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `clear_unallocated_sector_using_cipher_app_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "cipher.exe"
|
||||
Processes.process = "*/w:*" by Processes.parent_process_name Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id
|
||||
Processes.process_guid | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `clear_unallocated_sector_using_cipher_app_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: administrator may execute this app to manage disk
|
||||
references:
|
||||
- https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/3/
|
||||
@@ -22,16 +41,24 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ransomware
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 100
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to clear the unallocated sectors of a specific disk.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to clear the unallocated sectors
|
||||
of a specific disk.
|
||||
mitre_attack_id:
|
||||
- T1070.004
|
||||
- T1070
|
||||
|
||||
@@ -1,17 +1,37 @@
|
||||
name: Clop Common Exec Parameter
|
||||
id: 5a8a2a72-8322-11eb-9ee9-acde48001122
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies the execution of CLOP ransomware variants using specific arguments ("runrun" or "temp.dat") to trigger their malicious activities. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. Monitoring this activity is crucial as it indicates potential ransomware behavior, which can lead to file encryption on network shares or local machines. If confirmed malicious, this activity could result in significant data loss and operational disruption due to encrypted files, highlighting the need for immediate investigation and response.
|
||||
description: The following analytic identifies the execution of CLOP ransomware variants
|
||||
using specific arguments ("runrun" or "temp.dat") to trigger their malicious activities.
|
||||
This detection leverages data from Endpoint Detection and Response (EDR) agents,
|
||||
focusing on process names and command-line arguments. Monitoring this activity is
|
||||
crucial as it indicates potential ransomware behavior, which can lead to file encryption
|
||||
on network shares or local machines. If confirmed malicious, this activity could
|
||||
result in significant data loss and operational disruption due to encrypted files,
|
||||
highlighting the need for immediate investigation and response.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name != "*temp.dat*" Processes.process = "*runrun*" OR Processes.process = "*temp.dat*" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `clop_common_exec_parameter_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name != "*temp.dat*"
|
||||
Processes.process = "*runrun*" OR Processes.process = "*temp.dat*" by Processes.dest
|
||||
Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `clop_common_exec_parameter_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Operators can execute third party tools using these parameters.
|
||||
references:
|
||||
- https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft
|
||||
@@ -22,16 +42,24 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Compromised Windows Host
|
||||
- Clop Ransomware
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 100
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting using arguments to execute its main code or feature of its code related to Clop ransomware.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting using arguments to execute its main
|
||||
code or feature of its code related to Clop ransomware.
|
||||
mitre_attack_id:
|
||||
- T1204
|
||||
observable:
|
||||
|
||||
@@ -1,15 +1,27 @@
|
||||
name: Clop Ransomware Known Service Name
|
||||
id: 07e08a12-870c-11eb-b5f9-acde48001122
|
||||
version: 4
|
||||
date: '2024-09-30'
|
||||
version: '5'
|
||||
date: '2024-11-28'
|
||||
author: Teoderick Contreras
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies the creation of a service with a known name used by CLOP ransomware for persistence and high-privilege code execution. It detects this activity by monitoring Windows Event Logs (EventCode 7045) for specific service names ("SecurityCenterIBM", "WinCheckDRVs"). This activity is significant because the creation of such services is a common tactic used by ransomware to maintain control over infected systems. If confirmed malicious, this could allow attackers to execute code with elevated privileges, maintain persistence, and potentially disrupt or encrypt critical data.
|
||||
description: The following analytic identifies the creation of a service with a known
|
||||
name used by CLOP ransomware for persistence and high-privilege code execution.
|
||||
It detects this activity by monitoring Windows Event Logs (EventCode 7045) for specific
|
||||
service names ("SecurityCenterIBM", "WinCheckDRVs"). This activity is significant
|
||||
because the creation of such services is a common tactic used by ransomware to maintain
|
||||
control over infected systems. If confirmed malicious, this could allow attackers
|
||||
to execute code with elevated privileges, maintain persistence, and potentially
|
||||
disrupt or encrypt critical data.
|
||||
data_source:
|
||||
- Windows Event Log System 7045
|
||||
search: '`wineventlog_system` EventCode=7045 ServiceName IN ("SecurityCenterIBM", "WinCheckDRVs") | stats count min(_time) as firstTime max(_time) as lastTime by Computer EventCode ServiceName StartType ServiceType | rename Computer as dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `clop_ransomware_known_service_name_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints.
|
||||
search: '`wineventlog_system` EventCode=7045 ServiceName IN ("SecurityCenterIBM",
|
||||
"WinCheckDRVs") | stats count min(_time) as firstTime max(_time) as lastTime by
|
||||
Computer EventCode ServiceName StartType ServiceType | rename Computer as dest |
|
||||
`security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `clop_ransomware_known_service_name_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the Service name, Service File Name Service Start type, and Service Type
|
||||
from your endpoints.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft
|
||||
@@ -20,11 +32,17 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Compromised Windows Host
|
||||
- Clop Ransomware
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
|
||||
@@ -1,18 +1,39 @@
|
||||
name: CMD Echo Pipe - Escalation
|
||||
id: eb277ba0-b96b-11eb-b00e-acde48001122
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies the use of named-pipe impersonation for privilege escalation, commonly associated with Cobalt Strike and similar frameworks. It detects command-line executions where `cmd.exe` uses `echo` to write to a named pipe, such as `cmd.exe /c echo 4sgryt3436 > \\.\Pipe\5erg53`. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and command-line telemetry. This activity is significant as it indicates potential privilege escalation attempts. If confirmed malicious, attackers could gain elevated privileges, enabling further compromise and persistence within the environment.
|
||||
description: The following analytic identifies the use of named-pipe impersonation
|
||||
for privilege escalation, commonly associated with Cobalt Strike and similar frameworks.
|
||||
It detects command-line executions where `cmd.exe` uses `echo` to write to a named
|
||||
pipe, such as `cmd.exe /c echo 4sgryt3436 > \\.\Pipe\5erg53`. This detection leverages
|
||||
data from Endpoint Detection and Response (EDR) agents, focusing on process and
|
||||
command-line telemetry. This activity is significant as it indicates potential privilege
|
||||
escalation attempts. If confirmed malicious, attackers could gain elevated privileges,
|
||||
enabling further compromise and persistence within the environment.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` OR Processes.process=*%comspec%* (Processes.process=*echo* AND Processes.process=*pipe*) by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `cmd_echo_pipe___escalation_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Unknown. It is possible filtering may be required to ensure fidelity.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_cmd` OR Processes.process=*%comspec%*
|
||||
(Processes.process=*echo* AND Processes.process=*pipe*) by Processes.dest Processes.user
|
||||
Processes.parent_process Processes.parent_process_name Processes.process_name Processes.original_file_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `cmd_echo_pipe___escalation_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Unknown. It is possible filtering may be required to ensure
|
||||
fidelity.
|
||||
references:
|
||||
- https://redcanary.com/threat-detection-report/threats/cobalt-strike/
|
||||
- https://github.com/rapid7/meterpreter/blob/master/source/extensions/priv/server/elevate/namedpipe.c
|
||||
@@ -22,18 +43,26 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- BlackByte Ransomware
|
||||
- Cobalt Strike
|
||||
- Graceful Wipe Out Attack
|
||||
- Cobalt Strike
|
||||
- Compromised Windows Host
|
||||
- BlackByte Ransomware
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ potentially performing privilege escalation using named pipes related to Cobalt Strike and other frameworks.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ potentially performing privilege escalation
|
||||
using named pipes related to Cobalt Strike and other frameworks.
|
||||
mitre_attack_id:
|
||||
- T1059
|
||||
- T1059.003
|
||||
|
||||
@@ -1,16 +1,32 @@
|
||||
name: ConnectWise ScreenConnect Path Traversal Windows SACL
|
||||
id: 4e127857-1fc9-4c95-9d69-ba24c91d52d7
|
||||
version: 3
|
||||
date: '2024-09-30'
|
||||
version: '4'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
data_source:
|
||||
- Windows Event Log Security 4663
|
||||
type: TTP
|
||||
status: production
|
||||
description: The following analytic detects attempts to exploit the ConnectWise ScreenConnect CVE-2024-1708 vulnerability using Windows SACL EventCode 4663. It identifies path traversal attacks by monitoring file system events related to the ScreenConnect service. This activity is significant as it allows unauthorized access to sensitive files and directories, potentially leading to data exfiltration or arbitrary code execution. If confirmed malicious, attackers could gain unauthorized access to critical data or execute harmful code, compromising the integrity and security of the affected system. Immediate remediation by updating to version 23.9.8 or above is recommended.
|
||||
search: '`wineventlog_security` EventCode=4663 ProcessName=*\\ScreenConnect.Service.exe file_path IN ("*\\ScreenConnect\\App_Extensions\\*") file_name IN ("*.aspx","*.ashx") | stats count min(_time) as firstTime max(_time) as lastTime by ObjectName ObjectType ProcessName AccessMask process_id EventCode Computer Caller_User_Name | rename Computer as dest Caller_User_Name as user ProcessName as process_name | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `connectwise_screenconnect_path_traversal_windows_sacl_filter`'
|
||||
how_to_implement: To implement the following query, enable SACL auditing for the ScreenConnect directory(ies). With this data, the following analytic will work correctly. A GIST is provided in the references to assist with enabling SACL Auditing.
|
||||
known_false_positives: False positives should be limited as the analytic is specific to ScreenConnect path traversal attempts. Tune as needed, or restrict to specific hosts if false positives are encountered.
|
||||
description: The following analytic detects attempts to exploit the ConnectWise ScreenConnect
|
||||
CVE-2024-1708 vulnerability using Windows SACL EventCode 4663. It identifies path
|
||||
traversal attacks by monitoring file system events related to the ScreenConnect
|
||||
service. This activity is significant as it allows unauthorized access to sensitive
|
||||
files and directories, potentially leading to data exfiltration or arbitrary code
|
||||
execution. If confirmed malicious, attackers could gain unauthorized access to critical
|
||||
data or execute harmful code, compromising the integrity and security of the affected
|
||||
system. Immediate remediation by updating to version 23.9.8 or above is recommended.
|
||||
search: '`wineventlog_security` EventCode=4663 ProcessName=*\\ScreenConnect.Service.exe
|
||||
file_path IN ("*\\ScreenConnect\\App_Extensions\\*") file_name IN ("*.aspx","*.ashx")
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by ObjectName ObjectType
|
||||
ProcessName AccessMask process_id EventCode Computer Caller_User_Name | rename Computer
|
||||
as dest Caller_User_Name as user ProcessName as process_name | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `connectwise_screenconnect_path_traversal_windows_sacl_filter`'
|
||||
how_to_implement: To implement the following query, enable SACL auditing for the ScreenConnect
|
||||
directory(ies). With this data, the following analytic will work correctly. A GIST
|
||||
is provided in the references to assist with enabling SACL Auditing.
|
||||
known_false_positives: False positives should be limited as the analytic is specific
|
||||
to ScreenConnect path traversal attempts. Tune as needed, or restrict to specific
|
||||
hosts if false positives are encountered.
|
||||
references:
|
||||
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4663
|
||||
- https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
|
||||
@@ -22,12 +38,18 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- ConnectWise ScreenConnect Vulnerabilities
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 100
|
||||
|
||||
@@ -1,18 +1,40 @@
|
||||
name: Conti Common Exec parameter
|
||||
id: 624919bc-c382-11eb-adcc-acde48001122
|
||||
version: 4
|
||||
date: '2024-09-30'
|
||||
version: '5'
|
||||
date: '2024-11-28'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of suspicious command-line arguments commonly associated with Conti ransomware, specifically targeting local drives and network shares for encryption. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution logs that include command-line details. This activity is significant because it indicates a potential ransomware attack, which can lead to widespread data encryption and operational disruption. If confirmed malicious, the impact could be severe, resulting in data loss, system downtime, and potential ransom demands.
|
||||
description: The following analytic detects the execution of suspicious command-line
|
||||
arguments commonly associated with Conti ransomware, specifically targeting local
|
||||
drives and network shares for encryption. It leverages data from Endpoint Detection
|
||||
and Response (EDR) agents, focusing on process execution logs that include command-line
|
||||
details. This activity is significant because it indicates a potential ransomware
|
||||
attack, which can lead to widespread data encryption and operational disruption.
|
||||
If confirmed malicious, the impact could be severe, resulting in data loss, system
|
||||
downtime, and potential ransom demands.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*-m local*" OR Processes.process = "*-m net*" OR Processes.process = "*-m all*" OR Processes.process = "*-nomutex*" by Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.dest Processes.user Processes.process_id Processes.process_guid | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `conti_common_exec_parameter_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: 3rd party tool may have commandline parameter that can trigger this detection.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process = "*-m local*"
|
||||
OR Processes.process = "*-m net*" OR Processes.process = "*-m all*" OR Processes.process
|
||||
= "*-nomutex*" by Processes.process_name Processes.process Processes.parent_process_name
|
||||
Processes.parent_process Processes.dest Processes.user Processes.process_id Processes.process_guid
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `conti_common_exec_parameter_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: 3rd party tool may have commandline parameter that can trigger
|
||||
this detection.
|
||||
references:
|
||||
- https://malpedia.caad.fkie.fraunhofer.de/details/win.conti
|
||||
drilldown_searches:
|
||||
@@ -21,16 +43,24 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ransomware
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ executing specific Conti Ransomware related parameters.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ executing specific Conti Ransomware related
|
||||
parameters.
|
||||
mitre_attack_id:
|
||||
- T1204
|
||||
observable:
|
||||
|
||||
@@ -1,18 +1,41 @@
|
||||
name: Control Loading from World Writable Directory
|
||||
id: 10423ac4-10c9-11ec-8dc4-acde48001122
|
||||
version: 4
|
||||
date: '2024-09-30'
|
||||
version: '5'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies instances of control.exe loading a .cpl or .inf file from a writable directory, which is related to CVE-2021-40444. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions mapped to the `Processes` node of the `Endpoint` data model. This activity is significant as it may indicate an attempt to exploit a known vulnerability, potentially leading to unauthorized code execution. If confirmed malicious, this could allow an attacker to gain control over the affected system, leading to further compromise.
|
||||
description: The following analytic identifies instances of control.exe loading a
|
||||
.cpl or .inf file from a writable directory, which is related to CVE-2021-40444.
|
||||
This detection leverages data from Endpoint Detection and Response (EDR) agents,
|
||||
focusing on process names and command-line executions mapped to the `Processes`
|
||||
node of the `Endpoint` data model. This activity is significant as it may indicate
|
||||
an attempt to exploit a known vulnerability, potentially leading to unauthorized
|
||||
code execution. If confirmed malicious, this could allow an attacker to gain control
|
||||
over the affected system, leading to further compromise.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=control.exe OR Processes.original_file_name=CONTROL.EXE) AND Processes.process IN ("*\\appdata\\*", "*\\windows\\temp\\*", "*\\programdata\\*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `control_loading_from_world_writable_directory_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Limited false positives will be present as control.exe does not natively load from writable paths as defined. One may add .cpl or .inf to the command-line if there is any false positives. Tune as needed.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=control.exe
|
||||
OR Processes.original_file_name=CONTROL.EXE) AND Processes.process IN ("*\\appdata\\*",
|
||||
"*\\windows\\temp\\*", "*\\programdata\\*") by Processes.dest Processes.user Processes.parent_process_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `control_loading_from_world_writable_directory_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Limited false positives will be present as control.exe does
|
||||
not natively load from writable paths as defined. One may add .cpl or .inf to the
|
||||
command-line if there is any false positives. Tune as needed.
|
||||
references:
|
||||
- https://strontic.github.io/xcyclopedia/library/rundll32.exe-111474C61232202B5B588D2B512CBB25.html
|
||||
- https://app.any.run/tasks/36c14029-9df8-439c-bba0-45f2643b0c70/
|
||||
@@ -25,19 +48,26 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Microsoft MSHTML Remote Code Execution CVE-2021-40444
|
||||
- Living Off The Land
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2021-40444
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to load a suspicious file from disk.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.002
|
||||
|
||||
@@ -1,18 +1,40 @@
|
||||
name: Creation of Shadow Copy
|
||||
id: eb120f5f-b879-4a63-97c1-93352b5df844
|
||||
version: 4
|
||||
date: '2024-09-30'
|
||||
version: '5'
|
||||
date: '2024-11-28'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the creation of shadow copies using Vssadmin or Wmic. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution logs that include command-line details. This activity is significant because creating shadow copies can be a precursor to ransomware attacks or data exfiltration, allowing attackers to bypass file locks and access sensitive data. If confirmed malicious, this behavior could enable attackers to maintain persistence, recover deleted files, or prepare for further malicious activities, posing a significant risk to the integrity and confidentiality of the system.
|
||||
description: The following analytic detects the creation of shadow copies using Vssadmin
|
||||
or Wmic. It leverages data from Endpoint Detection and Response (EDR) agents, focusing
|
||||
on process execution logs that include command-line details. This activity is significant
|
||||
because creating shadow copies can be a precursor to ransomware attacks or data
|
||||
exfiltration, allowing attackers to bypass file locks and access sensitive data.
|
||||
If confirmed malicious, this behavior could enable attackers to maintain persistence,
|
||||
recover deleted files, or prepare for further malicious activities, posing a significant
|
||||
risk to the integrity and confidentiality of the system.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=vssadmin.exe Processes.process=*create* Processes.process=*shadow*) OR (Processes.process_name=wmic.exe Processes.process=*shadowcopy* Processes.process=*create*) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `creation_of_shadow_copy_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Legitimate administrator usage of Vssadmin or Wmic will create false positives.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=vssadmin.exe
|
||||
Processes.process=*create* Processes.process=*shadow*) OR (Processes.process_name=wmic.exe
|
||||
Processes.process=*shadowcopy* Processes.process=*create*) by Processes.dest Processes.user
|
||||
Processes.process_name Processes.process Processes.parent_process_name Processes.parent_process
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `creation_of_shadow_copy_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Legitimate administrator usage of Vssadmin or Wmic will create
|
||||
false positives.
|
||||
references:
|
||||
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
|
||||
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
|
||||
@@ -22,17 +44,25 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- Volt Typhoon
|
||||
- Compromised Windows Host
|
||||
- Credential Dumping
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 90
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to create a shadow copy to perform offline password cracking.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to create a shadow copy to perform
|
||||
offline password cracking.
|
||||
mitre_attack_id:
|
||||
- T1003.003
|
||||
- T1003
|
||||
|
||||
@@ -1,17 +1,37 @@
|
||||
name: Creation of Shadow Copy with wmic and powershell
|
||||
id: 2ed8b538-d284-449a-be1d-82ad1dbd186b
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the creation of shadow copies using "wmic" or "Powershell" commands. It leverages the Endpoint.Processes data model in Splunk to identify processes where the command includes "shadowcopy" and "create". This activity is significant because it may indicate an attacker attempting to manipulate or access data unauthorizedly, potentially leading to data theft or manipulation. If confirmed malicious, this behavior could allow attackers to backup and exfiltrate sensitive data or hide their tracks by restoring files to a previous state after an attack.
|
||||
description: The following analytic detects the creation of shadow copies using "wmic"
|
||||
or "Powershell" commands. It leverages the Endpoint.Processes data model in Splunk
|
||||
to identify processes where the command includes "shadowcopy" and "create". This
|
||||
activity is significant because it may indicate an attacker attempting to manipulate
|
||||
or access data unauthorizedly, potentially leading to data theft or manipulation.
|
||||
If confirmed malicious, this behavior could allow attackers to backup and exfiltrate
|
||||
sensitive data or hide their tracks by restoring files to a previous state after
|
||||
an attack.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` OR `process_powershell` Processes.process=*shadowcopy* Processes.process=*create* by Processes.user Processes.process_name Processes.original_file_name Processes.parent_process_name Processes.process Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `creation_of_shadow_copy_with_wmic_and_powershell_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_wmic` OR `process_powershell`
|
||||
Processes.process=*shadowcopy* Processes.process=*create* by Processes.user Processes.process_name
|
||||
Processes.original_file_name Processes.parent_process_name Processes.process Processes.dest
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `creation_of_shadow_copy_with_wmic_and_powershell_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Legtimate administrator usage of wmic to create a shadow copy.
|
||||
references:
|
||||
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
|
||||
@@ -22,18 +42,26 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- Living Off The Land
|
||||
- Volt Typhoon
|
||||
- Living Off The Land
|
||||
- Compromised Windows Host
|
||||
- Credential Dumping
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 90
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to create a shadow copy to perform offline password cracking.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to create a shadow copy to perform
|
||||
offline password cracking.
|
||||
mitre_attack_id:
|
||||
- T1003.003
|
||||
- T1003
|
||||
|
||||
@@ -1,17 +1,39 @@
|
||||
name: Credential Dumping via Copy Command from Shadow Copy
|
||||
id: d8c406fe-23d2-45f3-a983-1abe7b83ff3b
|
||||
version: 4
|
||||
date: '2024-09-30'
|
||||
version: '5'
|
||||
date: '2024-11-28'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the use of the copy command to dump credentials from a shadow copy. It leverages Endpoint Detection and Response (EDR) data to identify processes with command lines referencing critical files like "sam", "security", "system", and "ntds.dit" in system directories. This activity is significant as it indicates an attempt to extract credentials, a common technique for unauthorized access and privilege escalation. If confirmed malicious, this could lead to attackers gaining sensitive login information, escalating privileges, moving laterally within the network, or accessing sensitive data.
|
||||
description: The following analytic detects the use of the copy command to dump credentials
|
||||
from a shadow copy. It leverages Endpoint Detection and Response (EDR) data to identify
|
||||
processes with command lines referencing critical files like "sam", "security",
|
||||
"system", and "ntds.dit" in system directories. This activity is significant as
|
||||
it indicates an attempt to extract credentials, a common technique for unauthorized
|
||||
access and privilege escalation. If confirmed malicious, this could lead to attackers
|
||||
gaining sensitive login information, escalating privileges, moving laterally within
|
||||
the network, or accessing sensitive data.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` (Processes.process=*\\system32\\config\\sam* OR Processes.process=*\\system32\\config\\security* OR Processes.process=*\\system32\\config\\system* OR Processes.process=*\\windows\\ntds\\ntds.dit*) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.original_file_name Processes.process_id Processes.parent_process_id Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `credential_dumping_via_copy_command_from_shadow_copy_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_cmd` (Processes.process=*\\system32\\config\\sam*
|
||||
OR Processes.process=*\\system32\\config\\security* OR Processes.process=*\\system32\\config\\system*
|
||||
OR Processes.process=*\\windows\\ntds\\ntds.dit*) by Processes.dest Processes.user
|
||||
Processes.process_name Processes.process Processes.parent_process Processes.original_file_name
|
||||
Processes.process_id Processes.parent_process_id Processes.parent_process_name
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `credential_dumping_via_copy_command_from_shadow_copy_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
|
||||
@@ -21,16 +43,24 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Compromised Windows Host
|
||||
- Credential Dumping
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 90
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to copy SAM and NTDS.dit for offline password cracking.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to copy SAM and NTDS.dit for offline
|
||||
password cracking.
|
||||
mitre_attack_id:
|
||||
- T1003.003
|
||||
- T1003
|
||||
|
||||
@@ -1,17 +1,38 @@
|
||||
name: Credential Dumping via Symlink to Shadow Copy
|
||||
id: c5eac648-fae0-4263-91a6-773df1f4c903
|
||||
version: 4
|
||||
date: '2024-09-30'
|
||||
version: '5'
|
||||
date: '2024-11-28'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the creation of a symlink to a shadow copy, which may indicate credential dumping attempts. It leverages the Endpoint.Processes data model in Splunk to identify processes executing commands containing "mklink" and "HarddiskVolumeShadowCopy". This activity is significant because attackers often use this technique to manipulate or delete shadow copies, hindering system backup and recovery efforts. If confirmed malicious, this could prevent data restoration, complicate incident response, and lead to data loss or compromise. Analysts should review the process details, user, parent process, and any related artifacts to identify the attack source.
|
||||
description: The following analytic detects the creation of a symlink to a shadow
|
||||
copy, which may indicate credential dumping attempts. It leverages the Endpoint.Processes
|
||||
data model in Splunk to identify processes executing commands containing "mklink"
|
||||
and "HarddiskVolumeShadowCopy". This activity is significant because attackers often
|
||||
use this technique to manipulate or delete shadow copies, hindering system backup
|
||||
and recovery efforts. If confirmed malicious, this could prevent data restoration,
|
||||
complicate incident response, and lead to data loss or compromise. Analysts should
|
||||
review the process details, user, parent process, and any related artifacts to identify
|
||||
the attack source.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_cmd` Processes.process=*mklink* Processes.process=*HarddiskVolumeShadowCopy* by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.parent_process_name Processes.original_file_name Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `credential_dumping_via_symlink_to_shadow_copy_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_cmd` Processes.process=*mklink*
|
||||
Processes.process=*HarddiskVolumeShadowCopy* by Processes.dest Processes.user Processes.process_name
|
||||
Processes.process Processes.parent_process Processes.parent_process_name Processes.original_file_name
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `credential_dumping_via_symlink_to_shadow_copy_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf
|
||||
@@ -21,16 +42,24 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Compromised Windows Host
|
||||
- Credential Dumping
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 90
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to create symlink to a shadow copy to grab credentials.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to create symlink to a shadow copy
|
||||
to grab credentials.
|
||||
mitre_attack_id:
|
||||
- T1003.003
|
||||
- T1003
|
||||
|
||||
@@ -1,11 +1,18 @@
|
||||
name: Curl Download and Bash Execution
|
||||
id: 900bc324-59f3-11ec-9fb4-acde48001122
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk, DipsyTipsy
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the use of curl on Linux or MacOS systems to download a file from a remote source and pipe it directly to bash for execution. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names, command-line arguments, and parent processes. This activity is significant as it is commonly associated with malicious actions such as coinminers and exploitation of vulnerabilities like CVE-2021-44228 in Log4j. If confirmed malicious, this behavior could lead to unauthorized code execution, system compromise, and further exploitation within the environment.
|
||||
description: The following analytic detects the use of curl on Linux or MacOS systems
|
||||
to download a file from a remote source and pipe it directly to bash for execution.
|
||||
This detection leverages data from Endpoint Detection and Response (EDR) agents,
|
||||
focusing on process names, command-line arguments, and parent processes. This activity
|
||||
is significant as it is commonly associated with malicious actions such as coinminers
|
||||
and exploitation of vulnerabilities like CVE-2021-44228 in Log4j. If confirmed malicious,
|
||||
this behavior could lead to unauthorized code execution, system compromise, and
|
||||
further exploitation within the environment.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
@@ -38,20 +45,27 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ingress Tool Transfer
|
||||
- Compromised Windows Host
|
||||
- Log4Shell CVE-2021-44228
|
||||
- Linux Living Off The Land
|
||||
- Ingress Tool Transfer
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
impact: 80
|
||||
message: An instance of $process_name$ was identified on endpoint $dest$ attempting to download a remote file and run it with bash.
|
||||
message: An instance of $process_name$ was identified on endpoint $dest$ attempting
|
||||
to download a remote file and run it with bash.
|
||||
mitre_attack_id:
|
||||
- T1105
|
||||
observable:
|
||||
@@ -85,7 +99,9 @@ tags:
|
||||
- Processes.parent_process_id
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
manual_test: Due to current limitations in command line extraction capabilities with Sysmon for Linux, full CommandLine data cannot be collected for complete validation. Setting to manual test to prevent integration test failures.
|
||||
manual_test: Due to current limitations in command line extraction capabilities
|
||||
with Sysmon for Linux, full CommandLine data cannot be collected for complete
|
||||
validation. Setting to manual test to prevent integration test failures.
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
|
||||
@@ -1,18 +1,41 @@
|
||||
name: Deleting Shadow Copies
|
||||
id: b89919ed-ee5f-492c-b139-95dbb162039e
|
||||
version: 7
|
||||
date: '2024-09-30'
|
||||
version: '8'
|
||||
date: '2024-11-28'
|
||||
author: David Dorsey, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the deletion of shadow copies using the vssadmin.exe or wmic.exe utilities. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant because deleting shadow copies is a common tactic used by attackers to prevent recovery and hide their tracks. If confirmed malicious, this action could hinder incident response efforts and allow attackers to maintain persistence and cover their activities, making it crucial for security teams to investigate promptly.
|
||||
description: The following analytic detects the deletion of shadow copies using the
|
||||
vssadmin.exe or wmic.exe utilities. It leverages data from Endpoint Detection and
|
||||
Response (EDR) agents, focusing on process names and command-line arguments. This
|
||||
activity is significant because deleting shadow copies is a common tactic used by
|
||||
attackers to prevent recovery and hide their tracks. If confirmed malicious, this
|
||||
action could hinder incident response efforts and allow attackers to maintain persistence
|
||||
and cover their activities, making it crucial for security teams to investigate
|
||||
promptly.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=vssadmin.exe OR Processes.process_name=wmic.exe) Processes.process=*delete* Processes.process=*shadow* by Processes.user Processes.process_name Processes.parent_process_name Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `deleting_shadow_copies_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: vssadmin.exe and wmic.exe are standard applications shipped with modern versions of windows. They may be used by administrators to legitimately delete old backup copies, although this is typically rare.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process)
|
||||
as process values(Processes.parent_process) as parent_process min(_time) as firstTime
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=vssadmin.exe
|
||||
OR Processes.process_name=wmic.exe) Processes.process=*delete* Processes.process=*shadow*
|
||||
by Processes.user Processes.process_name Processes.parent_process_name Processes.dest |
|
||||
`drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `deleting_shadow_copies_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: vssadmin.exe and wmic.exe are standard applications shipped
|
||||
with modern versions of windows. They may be used by administrators to legitimately
|
||||
delete old backup copies, although this is typically rare.
|
||||
references:
|
||||
- https://blogs.vmware.com/security/2022/10/lockbit-3-0-also-known-as-lockbit-black.html
|
||||
drilldown_searches:
|
||||
@@ -21,25 +44,32 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Log Manipulation
|
||||
- SamSam Ransomware
|
||||
- Ransomware
|
||||
- Clop Ransomware
|
||||
- CISA AA22-264A
|
||||
- Prestige Ransomware
|
||||
- Chaos Ransomware
|
||||
- LockBit Ransomware
|
||||
- DarkGate Malware
|
||||
- Rhysida Ransomware
|
||||
- Windows Log Manipulation
|
||||
- Prestige Ransomware
|
||||
- Ransomware
|
||||
- SamSam Ransomware
|
||||
- CISA AA22-264A
|
||||
- DarkGate Malware
|
||||
- LockBit Ransomware
|
||||
- Compromised Windows Host
|
||||
- Clop Ransomware
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 90
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to delete shadow copies.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to delete shadow copies.
|
||||
mitre_attack_id:
|
||||
- T1490
|
||||
observable:
|
||||
|
||||
@@ -1,17 +1,36 @@
|
||||
name: Detect AzureHound Command-Line Arguments
|
||||
id: 26f02e96-c300-11eb-b611-acde48001122
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of the `Invoke-AzureHound` command-line argument, commonly used by the AzureHound tool. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant because AzureHound is often used for reconnaissance in Azure environments, potentially exposing sensitive information. If confirmed malicious, this activity could allow an attacker to map out Azure Active Directory structures, aiding in further attacks and privilege escalation.
|
||||
description: The following analytic detects the execution of the `Invoke-AzureHound`
|
||||
command-line argument, commonly used by the AzureHound tool. It leverages data from
|
||||
Endpoint Detection and Response (EDR) agents, focusing on process names and command-line
|
||||
executions. This activity is significant because AzureHound is often used for reconnaissance
|
||||
in Azure environments, potentially exposing sensitive information. If confirmed
|
||||
malicious, this activity could allow an attacker to map out Azure Active Directory
|
||||
structures, aiding in further attacks and privilege escalation.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*invoke-azurehound*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.parent_process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_azurehound_command_line_arguments_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("*invoke-azurehound*")
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.parent_process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_azurehound_command_line_arguments_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Unknown.
|
||||
references:
|
||||
- https://attack.mitre.org/software/S0521/
|
||||
@@ -24,16 +43,23 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Discovery Techniques
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ using AzureHound to enumerate AzureAD.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ using AzureHound to enumerate AzureAD.
|
||||
mitre_attack_id:
|
||||
- T1087.002
|
||||
- T1069.001
|
||||
|
||||
@@ -1,17 +1,39 @@
|
||||
name: Detect Certify Command Line Arguments
|
||||
id: e6d2dc61-a8b9-4b03-906c-da0ca75d71b8
|
||||
version: 3
|
||||
date: '2024-09-30'
|
||||
version: '4'
|
||||
date: '2024-11-28'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the use of Certify or Certipy tools to enumerate Active Directory Certificate Services (AD CS) environments. It leverages Endpoint Detection and Response (EDR) data, focusing on specific command-line arguments associated with these tools. This activity is significant because it indicates potential reconnaissance or exploitation attempts targeting AD CS, which could lead to unauthorized access or privilege escalation. If confirmed malicious, attackers could gain insights into the AD CS infrastructure, potentially compromising sensitive certificates and escalating their privileges within the network.
|
||||
description: The following analytic detects the use of Certify or Certipy tools to
|
||||
enumerate Active Directory Certificate Services (AD CS) environments. It leverages
|
||||
Endpoint Detection and Response (EDR) data, focusing on specific command-line arguments
|
||||
associated with these tools. This activity is significant because it indicates potential
|
||||
reconnaissance or exploitation attempts targeting AD CS, which could lead to unauthorized
|
||||
access or privilege escalation. If confirmed malicious, attackers could gain insights
|
||||
into the AD CS infrastructure, potentially compromising sensitive certificates and
|
||||
escalating their privileges within the network.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("* find *","* auth *","* request *","* req *","* download *",) AND Processes.process IN ("* /vulnerable*","* /enrolleeSuppliesSubject *","* /json /outfile*","* /ca*", "* -username *","* -u *") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `detect_certify_command_line_arguments_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("* find
|
||||
*","* auth *","* request *","* req *","* download *",) AND Processes.process IN
|
||||
("* /vulnerable*","* /enrolleeSuppliesSubject *","* /json /outfile*","* /ca*", "*
|
||||
-username *","* -u *") by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|
|
||||
`detect_certify_command_line_arguments_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Unknown
|
||||
references:
|
||||
- https://github.com/GhostPack/Certify
|
||||
@@ -23,11 +45,17 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Compromised Windows Host
|
||||
- Windows Certificate Services
|
||||
- Ingress Tool Transfer
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -1,16 +1,38 @@
|
||||
name: Detect Exchange Web Shell
|
||||
id: 8c14eeee-2af1-4a4b-bda8-228da0f4862a
|
||||
version: 7
|
||||
date: '2024-09-30'
|
||||
version: '8'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Shannon Davis, David Dorsey, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies the creation of suspicious .aspx files in known drop locations for Exchange exploitation, specifically targeting paths associated with HAFNIUM group and vulnerabilities like ProxyShell and ProxyNotShell. It leverages data from the Endpoint datamodel, focusing on process and filesystem events. This activity is significant as it may indicate a web shell deployment, a common method for persistent access and remote code execution. If confirmed malicious, attackers could gain unauthorized access, execute arbitrary commands, and potentially escalate privileges within the Exchange environment.
|
||||
description: The following analytic identifies the creation of suspicious .aspx files
|
||||
in known drop locations for Exchange exploitation, specifically targeting paths
|
||||
associated with HAFNIUM group and vulnerabilities like ProxyShell and ProxyNotShell.
|
||||
It leverages data from the Endpoint datamodel, focusing on process and filesystem
|
||||
events. This activity is significant as it may indicate a web shell deployment,
|
||||
a common method for persistent access and remote code execution. If confirmed malicious,
|
||||
attackers could gain unauthorized access, execute arbitrary commands, and potentially
|
||||
escalate privileges within the Exchange environment.
|
||||
data_source:
|
||||
- Sysmon EventID 1 AND Sysmon EventID 11
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=System by _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | join process_guid, _time [| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*", "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name IN( "*.aspx", "*.ashx") by _time span=1h Filesystem.user Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path | `drop_dm_object_name(Filesystem)` | fields _time dest user file_create_time file_name file_path process_name process_path process] | dedup file_create_time | table dest user file_create_time, file_name, file_path, process_name | `detect_exchange_web_shell_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node.
|
||||
known_false_positives: The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product.
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
where Processes.process_name=System by _time span=1h Processes.process_id Processes.process_name
|
||||
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | join process_guid,
|
||||
_time [| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*",
|
||||
"*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name
|
||||
IN( "*.aspx", "*.ashx") by _time span=1h Filesystem.user Filesystem.dest Filesystem.file_create_time
|
||||
Filesystem.file_name Filesystem.file_path | `drop_dm_object_name(Filesystem)` |
|
||||
fields _time dest user file_create_time file_name file_path process_name process_path
|
||||
process] | dedup file_create_time | table dest user file_create_time, file_name,
|
||||
file_path, process_name | `detect_exchange_web_shell_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem`
|
||||
node.
|
||||
known_false_positives: The query is structured in a way that `action` (read, create)
|
||||
is not defined. Review the results of this query, filter, and tune as necessary.
|
||||
It may be necessary to generate this query specific to your endpoint product.
|
||||
references:
|
||||
- https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Sample%20Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv
|
||||
- https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell
|
||||
@@ -22,20 +44,28 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- ProxyNotShell
|
||||
- ProxyShell
|
||||
- CISA AA22-257A
|
||||
- HAFNIUM Group
|
||||
- ProxyShell
|
||||
- Compromised Windows Host
|
||||
- BlackByte Ransomware
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 90
|
||||
message: A file - $file_name$ was written to disk that is related to IIS exploitation previously performed by HAFNIUM. Review further file modifications on endpoint $dest$ by user $user$.
|
||||
message: A file - $file_name$ was written to disk that is related to IIS exploitation
|
||||
previously performed by HAFNIUM. Review further file modifications on endpoint
|
||||
$dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1505
|
||||
- T1505.003
|
||||
|
||||
@@ -1,18 +1,39 @@
|
||||
name: Detect HTML Help Spawn Child Process
|
||||
id: 723716de-ee55-4cd4-9759-c44e7e55ba4b
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of hh.exe (HTML Help) spawning a child process, indicating the use of a Compiled HTML Help (CHM) file to execute Windows script code. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process creation events where hh.exe is the parent process. This activity is significant as it may indicate an attempt to execute malicious scripts via CHM files, a known technique for bypassing security controls. If confirmed malicious, this could lead to unauthorized code execution, potentially compromising the system.
|
||||
description: The following analytic detects the execution of hh.exe (HTML Help) spawning
|
||||
a child process, indicating the use of a Compiled HTML Help (CHM) file to execute
|
||||
Windows script code. This detection leverages data from Endpoint Detection and Response
|
||||
(EDR) agents, focusing on process creation events where hh.exe is the parent process.
|
||||
This activity is significant as it may indicate an attempt to execute malicious
|
||||
scripts via CHM files, a known technique for bypassing security controls. If confirmed
|
||||
malicious, this could lead to unauthorized code execution, potentially compromising
|
||||
the system.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=hh.exe by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_html_help_spawn_child_process_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, some legitimate applications (ex. web browsers) may spawn a child process. Filter as needed.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=hh.exe
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_html_help_spawn_child_process_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, some legitimate applications (ex. web browsers)
|
||||
may spawn a child process. Filter as needed.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1218/001/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md
|
||||
@@ -25,18 +46,26 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Compiled HTML Activity
|
||||
- Living Off The Land
|
||||
- AgentTesla
|
||||
- Living Off The Land
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ spawning a child process, typically not normal behavior.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ spawning a child process, typically not normal
|
||||
behavior.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.001
|
||||
|
||||
@@ -1,18 +1,38 @@
|
||||
name: Detect HTML Help URL in Command Line
|
||||
id: 8c5835b9-39d9-438b-817c-95f14c69a31e
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of hh.exe (HTML Help) loading a Compiled HTML Help (CHM) file from a remote URL. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions containing URLs. This activity is significant as it can indicate an attempt to execute malicious scripts via CHM files, potentially leading to unauthorized code execution. If confirmed malicious, this could allow an attacker to run scripts using engines like JScript or VBScript, leading to further system compromise or data exfiltration.
|
||||
description: The following analytic detects the execution of hh.exe (HTML Help) loading
|
||||
a Compiled HTML Help (CHM) file from a remote URL. This detection leverages data
|
||||
from Endpoint Detection and Response (EDR) agents, focusing on command-line executions
|
||||
containing URLs. This activity is significant as it can indicate an attempt to execute
|
||||
malicious scripts via CHM files, potentially leading to unauthorized code execution.
|
||||
If confirmed malicious, this could allow an attacker to run scripts using engines
|
||||
like JScript or VBScript, leading to further system compromise or data exfiltration.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_hh` Processes.process=*http* by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_html_help_url_in_command_line_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, some legitimate applications may retrieve a CHM remotely, filter as needed.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_hh` Processes.process=*http*
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process
|
||||
Processes.original_file_name Processes.process_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `detect_html_help_url_in_command_line_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, some legitimate applications may retrieve
|
||||
a CHM remotely, filter as needed.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1218/001/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md
|
||||
@@ -26,17 +46,25 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Compiled HTML Activity
|
||||
- Living Off The Land
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 90
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ contacting a remote destination to potentally download a malicious payload.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ contacting a remote destination to potentally
|
||||
download a malicious payload.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.001
|
||||
|
||||
@@ -1,18 +1,39 @@
|
||||
name: Detect HTML Help Using InfoTech Storage Handlers
|
||||
id: 0b2eefa5-5508-450d-b970-3dd2fb761aec
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of hh.exe (HTML Help) using InfoTech Storage Handlers to load Windows script code from a Compiled HTML Help (CHM) file. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant because it can be used to execute malicious scripts embedded within CHM files, potentially leading to code execution. If confirmed malicious, this technique could allow an attacker to execute arbitrary code, escalate privileges, or persist within the environment.
|
||||
description: The following analytic detects the execution of hh.exe (HTML Help) using
|
||||
InfoTech Storage Handlers to load Windows script code from a Compiled HTML Help
|
||||
(CHM) file. This detection leverages data from Endpoint Detection and Response (EDR)
|
||||
agents, focusing on process names and command-line executions. This activity is
|
||||
significant because it can be used to execute malicious scripts embedded within
|
||||
CHM files, potentially leading to code execution. If confirmed malicious, this technique
|
||||
could allow an attacker to execute arbitrary code, escalate privileges, or persist
|
||||
within the environment.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_hh` Processes.process IN ("*its:*", "*mk:@MSITStore:*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_html_help_using_infotech_storage_handlers_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: It is rare to see instances of InfoTech Storage Handlers being used, but it does happen in some legitimate instances. Filter as needed.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_hh` Processes.process
|
||||
IN ("*its:*", "*mk:@MSITStore:*") by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_html_help_using_infotech_storage_handlers_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: It is rare to see instances of InfoTech Storage Handlers being
|
||||
used, but it does happen in some legitimate instances. Filter as needed.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1218/001/
|
||||
- https://www.kb.cert.org/vuls/id/851869
|
||||
@@ -26,17 +47,24 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Compiled HTML Activity
|
||||
- Living Off The Land
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 80
|
||||
message: $process_name$ has been identified using Infotech Storage Handlers to load a specific file within a CHM on $dest$ under user $user$.
|
||||
message: $process_name$ has been identified using Infotech Storage Handlers to load
|
||||
a specific file within a CHM on $dest$ under user $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.001
|
||||
|
||||
@@ -1,18 +1,40 @@
|
||||
name: Detect mshta inline hta execution
|
||||
id: a0873b32-5b68-11eb-ae93-0242ac130002
|
||||
version: 9
|
||||
date: '2024-09-30'
|
||||
version: '10'
|
||||
date: '2024-11-28'
|
||||
author: Bhavin Patel, Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of "mshta.exe" with inline protocol handlers such as "JavaScript", "VBScript", and "About". It leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line arguments and process details. This activity is significant because mshta.exe can be exploited to execute malicious scripts, potentially leading to unauthorized code execution. If confirmed malicious, this could allow an attacker to execute arbitrary code, escalate privileges, or establish persistence within the environment, posing a severe security risk.
|
||||
description: The following analytic detects the execution of "mshta.exe" with inline
|
||||
protocol handlers such as "JavaScript", "VBScript", and "About". It leverages data
|
||||
from Endpoint Detection and Response (EDR) agents, focusing on command-line arguments
|
||||
and process details. This activity is significant because mshta.exe can be exploited
|
||||
to execute malicious scripts, potentially leading to unauthorized code execution.
|
||||
If confirmed malicious, this could allow an attacker to execute arbitrary code,
|
||||
escalate privileges, or establish persistence within the environment, posing a severe
|
||||
security risk.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_mshta` (Processes.process=*vbscript* OR Processes.process=*javascript* OR Processes.process=*about*) by Processes.user Processes.process_name Processes.original_file_name Processes.parent_process_name Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_mshta_inline_hta_execution_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process)
|
||||
as process values(Processes.parent_process) as parent_process min(_time) as firstTime
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where `process_mshta` (Processes.process=*vbscript*
|
||||
OR Processes.process=*javascript* OR Processes.process=*about*) by Processes.user
|
||||
Processes.process_name Processes.original_file_name Processes.parent_process_name
|
||||
Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)` | `detect_mshta_inline_hta_execution_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, some legitimate applications may exhibit
|
||||
this behavior, triggering a false positive.
|
||||
references:
|
||||
- https://github.com/redcanaryco/AtomicTestHarnesses
|
||||
- https://redcanary.com/blog/introducing-atomictestharnesses/
|
||||
@@ -23,18 +45,26 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Gozi Malware
|
||||
- Suspicious MSHTA Activity
|
||||
- Living Off The Land
|
||||
- Gozi Malware
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 90
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ executing with inline HTA, indicative of defense evasion.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ executing with inline HTA, indicative of defense
|
||||
evasion.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.005
|
||||
|
||||
@@ -1,18 +1,38 @@
|
||||
name: Detect MSHTA Url in Command Line
|
||||
id: 9b3af1e6-5b68-11eb-ae93-0242ac130002
|
||||
version: 6
|
||||
date: '2024-11-20'
|
||||
version: '7'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the use of Microsoft HTML Application Host (mshta.exe) to make remote HTTP or HTTPS connections. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line arguments containing URLs. This activity is significant because adversaries often use mshta.exe to download and execute remote .hta files, bypassing security controls. If confirmed malicious, this behavior could allow attackers to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further network infiltration.
|
||||
description: The following analytic detects the use of Microsoft HTML Application
|
||||
Host (mshta.exe) to make remote HTTP or HTTPS connections. It leverages data from
|
||||
Endpoint Detection and Response (EDR) agents, focusing on command-line arguments
|
||||
containing URLs. This activity is significant because adversaries often use mshta.exe
|
||||
to download and execute remote .hta files, bypassing security controls. If confirmed
|
||||
malicious, this behavior could allow attackers to execute arbitrary code, potentially
|
||||
leading to system compromise, data exfiltration, or further network infiltration.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_mshta` (Processes.process="*http://*" OR Processes.process="*https://*") by Processes.user Processes.process_name Processes.parent_process_name Processes.original_file_name Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_mshta_url_in_command_line_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: It is possible legitimate applications may perform this behavior and will need to be filtered.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process)
|
||||
as process values(Processes.parent_process) as parent_process min(_time) as firstTime
|
||||
max(_time) as lastTime from datamodel=Endpoint.Processes where `process_mshta` (Processes.process="*http://*"
|
||||
OR Processes.process="*https://*") by Processes.user Processes.process_name Processes.parent_process_name
|
||||
Processes.original_file_name Processes.dest | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_mshta_url_in_command_line_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: It is possible legitimate applications may perform this behavior
|
||||
and will need to be filtered.
|
||||
references:
|
||||
- https://github.com/redcanaryco/AtomicTestHarnesses
|
||||
- https://redcanary.com/blog/introducing-atomictestharnesses/
|
||||
@@ -25,18 +45,26 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious MSHTA Activity
|
||||
- Living Off The Land
|
||||
- Lumma Stealer
|
||||
- Living Off The Land
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to access a remote destination to download an additional payload.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to access a remote destination to
|
||||
download an additional payload.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.005
|
||||
|
||||
@@ -1,18 +1,41 @@
|
||||
name: Detect Regasm Spawning a Process
|
||||
id: 72170ec5-f7d2-42f5-aefb-2b8be6aad15f
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
version: '7'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects regasm.exe spawning a child process. This behavior is identified using data from Endpoint Detection and Response (EDR) agents, focusing on process creation events where regasm.exe is the parent process. This activity is significant because regasm.exe spawning a process is rare and can indicate an attempt to bypass application control mechanisms. If confirmed malicious, this could allow an attacker to execute arbitrary code, potentially leading to privilege escalation or persistent access within the environment. Immediate investigation is recommended to determine the legitimacy of the spawned process and any associated activities.
|
||||
description: The following analytic detects regasm.exe spawning a child process. This
|
||||
behavior is identified using data from Endpoint Detection and Response (EDR) agents,
|
||||
focusing on process creation events where regasm.exe is the parent process. This
|
||||
activity is significant because regasm.exe spawning a process is rare and can indicate
|
||||
an attempt to bypass application control mechanisms. If confirmed malicious, this
|
||||
could allow an attacker to execute arbitrary code, potentially leading to privilege
|
||||
escalation or persistent access within the environment. Immediate investigation
|
||||
is recommended to determine the legitimacy of the spawned process and any associated
|
||||
activities.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=regasm.exe NOT (Processes.process_name IN ("conhost.exe")) by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_regasm_spawning_a_process_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, limited instances of regasm.exe or regsvcs.exe may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=regasm.exe
|
||||
NOT (Processes.process_name IN ("conhost.exe")) by Processes.dest Processes.user
|
||||
Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_regasm_spawning_a_process_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, limited instances of regasm.exe or regsvcs.exe
|
||||
may cause a false positive. Filter based endpoint usage, command line arguments,
|
||||
or process lineage.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1218/009/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md
|
||||
@@ -24,20 +47,28 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Regsvcs Regasm Activity
|
||||
- Living Off The Land
|
||||
- Handala Wiper
|
||||
- Compromised Windows Host
|
||||
- DarkGate Malware
|
||||
- Snake Keylogger
|
||||
- Handala Wiper
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ spawning a child process, typically not normal behavior for $parent_process_name$.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ spawning a child process, typically not normal
|
||||
behavior for $parent_process_name$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.009
|
||||
|
||||
@@ -1,18 +1,41 @@
|
||||
name: Detect Regsvcs Spawning a Process
|
||||
id: bc477b57-5c21-4ab6-9c33-668772e7f114
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies regsvcs.exe spawning a child process. This behavior is detected using Endpoint Detection and Response (EDR) telemetry, focusing on process creation events where the parent process is regsvcs.exe. This activity is significant because regsvcs.exe rarely spawns child processes, and such behavior can indicate an attempt to bypass application control mechanisms. If confirmed malicious, this could allow an attacker to execute arbitrary code, potentially leading to privilege escalation or persistent access within the environment. Immediate investigation is recommended to determine the legitimacy of the spawned process and any associated suspicious activities.
|
||||
description: The following analytic identifies regsvcs.exe spawning a child process.
|
||||
This behavior is detected using Endpoint Detection and Response (EDR) telemetry,
|
||||
focusing on process creation events where the parent process is regsvcs.exe. This
|
||||
activity is significant because regsvcs.exe rarely spawns child processes, and such
|
||||
behavior can indicate an attempt to bypass application control mechanisms. If confirmed
|
||||
malicious, this could allow an attacker to execute arbitrary code, potentially leading
|
||||
to privilege escalation or persistent access within the environment. Immediate investigation
|
||||
is recommended to determine the legitimacy of the spawned process and any associated
|
||||
suspicious activities.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=regsvcs.exe by Processes.parent_process_name Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_regsvcs_spawning_a_process_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, limited instances of regasm.exe or regsvcs.exe may cause a false positive. Filter based endpoint usage, command line arguments, or process lineage.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=regsvcs.exe
|
||||
by Processes.parent_process_name Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_regsvcs_spawning_a_process_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, limited instances of regasm.exe or regsvcs.exe
|
||||
may cause a false positive. Filter based endpoint usage, command line arguments,
|
||||
or process lineage.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1218/009/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md
|
||||
@@ -23,17 +46,24 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Regsvcs Regasm Activity
|
||||
- Living Off The Land
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ typically not normal for this process.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ typically not normal for this process.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.009
|
||||
|
||||
@@ -1,18 +1,39 @@
|
||||
name: Detect Regsvr32 Application Control Bypass
|
||||
id: 070e9b80-6252-11eb-ae93-0242ac130002
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies the abuse of Regsvr32.exe to proxy execution of malicious code, specifically detecting the loading of "scrobj.dll" by Regsvr32.exe. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process creation events and command-line executions. This activity is significant because Regsvr32.exe is a trusted, signed Microsoft binary, often used in "Squiblydoo" attacks to bypass application control mechanisms. If confirmed malicious, this technique could allow an attacker to execute arbitrary code, potentially leading to system compromise and persistent access.
|
||||
description: The following analytic identifies the abuse of Regsvr32.exe to proxy
|
||||
execution of malicious code, specifically detecting the loading of "scrobj.dll"
|
||||
by Regsvr32.exe. This detection leverages data from Endpoint Detection and Response
|
||||
(EDR) agents, focusing on process creation events and command-line executions. This
|
||||
activity is significant because Regsvr32.exe is a trusted, signed Microsoft binary,
|
||||
often used in "Squiblydoo" attacks to bypass application control mechanisms. If
|
||||
confirmed malicious, this technique could allow an attacker to execute arbitrary
|
||||
code, potentially leading to system compromise and persistent access.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` Processes.process=*scrobj* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.parent_process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_regsvr32_application_control_bypass_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Limited false positives related to third party software registering .DLL's.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` Processes.process=*scrobj*
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.parent_process_name Processes.process Processes.original_file_name Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)` | `detect_regsvr32_application_control_bypass_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Limited false positives related to third party software registering
|
||||
.DLL's.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1218/010/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md
|
||||
@@ -24,20 +45,28 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Living Off The Land
|
||||
- Cobalt Strike
|
||||
- BlackByte Ransomware
|
||||
- Graceful Wipe Out Attack
|
||||
- Suspicious Regsvr32 Activity
|
||||
- Graceful Wipe Out Attack
|
||||
- Cobalt Strike
|
||||
- Compromised Windows Host
|
||||
- BlackByte Ransomware
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ in an attempt to bypass detection and preventative controls was identified on endpoint $dest$ by user $user$.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ in an attempt
|
||||
to bypass detection and preventative controls was identified on endpoint $dest$
|
||||
by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.010
|
||||
|
||||
@@ -1,18 +1,39 @@
|
||||
name: Detect Rundll32 Application Control Bypass - advpack
|
||||
id: 4aefadfe-9abd-4bf8-b3fd-867e9ef95bf8
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of rundll32.exe loading advpack.dll or ieadvpack.dll via the LaunchINFSection function. This method is identified using Endpoint Detection and Response (EDR) telemetry, focusing on command-line executions and process details. This activity is significant as it indicates a potential application control bypass, allowing script code execution from a file. If confirmed malicious, an attacker could execute arbitrary code, potentially leading to privilege escalation, persistence, or further network compromise. Investigate script content, network connections, and any spawned child processes for further context.
|
||||
description: The following analytic detects the execution of rundll32.exe loading
|
||||
advpack.dll or ieadvpack.dll via the LaunchINFSection function. This method is identified
|
||||
using Endpoint Detection and Response (EDR) telemetry, focusing on command-line
|
||||
executions and process details. This activity is significant as it indicates a potential
|
||||
application control bypass, allowing script code execution from a file. If confirmed
|
||||
malicious, an attacker could execute arbitrary code, potentially leading to privilege
|
||||
escalation, persistence, or further network compromise. Investigate script content,
|
||||
network connections, and any spawned child processes for further context.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*advpack* by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_rundll32_application_control_bypass___advpack_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use advpack.dll or ieadvpack.dll, triggering a false positive.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*advpack*
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_rundll32_application_control_bypass___advpack_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use advpack.dll
|
||||
or ieadvpack.dll, triggering a false positive.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1218/011/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md
|
||||
@@ -25,17 +46,25 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Rundll32 Activity
|
||||
- Living Off The Land
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ loading advpack.dll and ieadvpack.dll by calling the LaunchINFSection function on the command line was identified on endpoint $dest$ by user $user$.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ loading advpack.dll
|
||||
and ieadvpack.dll by calling the LaunchINFSection function on the command line
|
||||
was identified on endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
|
||||
@@ -1,18 +1,39 @@
|
||||
name: Detect Rundll32 Application Control Bypass - setupapi
|
||||
id: 61e7b44a-6088-4f26-b788-9a96ba13b37a
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of rundll32.exe loading setupapi.dll and iesetupapi.dll via the LaunchINFSection function. This behavior is identified using Endpoint Detection and Response (EDR) telemetry, focusing on process creation events and command-line arguments. This activity is significant as it indicates a potential application control bypass, allowing an attacker to execute arbitrary script code. If confirmed malicious, this technique could enable code execution, privilege escalation, or persistence within the environment, posing a severe threat to system integrity and security.
|
||||
description: The following analytic detects the execution of rundll32.exe loading
|
||||
setupapi.dll and iesetupapi.dll via the LaunchINFSection function. This behavior
|
||||
is identified using Endpoint Detection and Response (EDR) telemetry, focusing on
|
||||
process creation events and command-line arguments. This activity is significant
|
||||
as it indicates a potential application control bypass, allowing an attacker to
|
||||
execute arbitrary script code. If confirmed malicious, this technique could enable
|
||||
code execution, privilege escalation, or persistence within the environment, posing
|
||||
a severe threat to system integrity and security.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*setupapi* by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_rundll32_application_control_bypass___setupapi_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use setupapi triggering a false positive.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*setupapi*
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_rundll32_application_control_bypass___setupapi_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use setupapi
|
||||
triggering a false positive.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1218/011/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md
|
||||
@@ -25,17 +46,25 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Rundll32 Activity
|
||||
- Living Off The Land
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ loading setupapi.dll and iesetupapi.dll by calling the LaunchINFSection function on the command line was identified on endpoint $dest$ by user $user$.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ loading setupapi.dll
|
||||
and iesetupapi.dll by calling the LaunchINFSection function on the command line
|
||||
was identified on endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
|
||||
@@ -1,18 +1,39 @@
|
||||
name: Detect Rundll32 Application Control Bypass - syssetup
|
||||
id: 71b9bf37-cde1-45fb-b899-1b0aa6fa1183
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of rundll32.exe loading syssetup.dll via the LaunchINFSection function. This method is identified through Endpoint Detection and Response (EDR) telemetry, focusing on command-line executions and process details. This activity is significant as it indicates a potential application control bypass, allowing script code execution from a file. If confirmed malicious, an attacker could execute arbitrary code, potentially leading to privilege escalation, persistence, or further network compromise. Investigate the script content, network connections, and any spawned child processes for further context.
|
||||
description: The following analytic detects the execution of rundll32.exe loading
|
||||
syssetup.dll via the LaunchINFSection function. This method is identified through
|
||||
Endpoint Detection and Response (EDR) telemetry, focusing on command-line executions
|
||||
and process details. This activity is significant as it indicates a potential application
|
||||
control bypass, allowing script code execution from a file. If confirmed malicious,
|
||||
an attacker could execute arbitrary code, potentially leading to privilege escalation,
|
||||
persistence, or further network compromise. Investigate the script content, network
|
||||
connections, and any spawned child processes for further context.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*syssetup* by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_rundll32_application_control_bypass___syssetup_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use syssetup.dll, triggering a false positive.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*syssetup*
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.original_file_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_rundll32_application_control_bypass___syssetup_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Although unlikely, some legitimate applications may use syssetup.dll,
|
||||
triggering a false positive.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1218/011/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md
|
||||
@@ -25,17 +46,25 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Rundll32 Activity
|
||||
- Living Off The Land
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ loading syssetup.dll by calling the LaunchINFSection function on the command line was identified on endpoint $dest$ by user $user$.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ loading syssetup.dll
|
||||
by calling the LaunchINFSection function on the command line was identified on
|
||||
endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
- T1218.011
|
||||
|
||||
@@ -1,18 +1,46 @@
|
||||
name: Detect Webshell Exploit Behavior
|
||||
id: 22597426-6dbd-49bd-bcdc-4ec19857192f
|
||||
version: 4
|
||||
date: '2024-09-30'
|
||||
version: '5'
|
||||
date: '2024-11-28'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies the execution of suspicious processes typically associated with webshell activity on web servers. It detects when processes like `cmd.exe`, `powershell.exe`, or `bash.exe` are spawned by web server processes such as `w3wp.exe` or `nginx.exe`. This behavior is significant as it may indicate an adversary exploiting a web application vulnerability to install a webshell, providing persistent access and command execution capabilities. If confirmed malicious, this activity could allow attackers to maintain control over the compromised server, execute arbitrary commands, and potentially escalate privileges or exfiltrate sensitive data.
|
||||
description: The following analytic identifies the execution of suspicious processes
|
||||
typically associated with webshell activity on web servers. It detects when processes
|
||||
like `cmd.exe`, `powershell.exe`, or `bash.exe` are spawned by web server processes
|
||||
such as `w3wp.exe` or `nginx.exe`. This behavior is significant as it may indicate
|
||||
an adversary exploiting a web application vulnerability to install a webshell, providing
|
||||
persistent access and command execution capabilities. If confirmed malicious, this
|
||||
activity could allow attackers to maintain control over the compromised server,
|
||||
execute arbitrary commands, and potentially escalate privileges or exfiltrate sensitive
|
||||
data.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count max(_time) as lastTime, min(_time) as firstTime from datamodel=Endpoint.Processes where (Processes.process_name IN ("arp.exe","at.exe","bash.exe","bitsadmin.exe","certutil.exe","cmd.exe","cscript.exe", "dsget.exe","dsquery.exe","find.exe","findstr.exe","fsutil.exe","hostname.exe","ipconfig.exe","ksh.exe","nbstat.exe", "net.exe","net1.exe","netdom.exe","netsh.exe","netstat.exe","nltest.exe","nslookup.exe","ntdsutil.exe","pathping.exe", "ping.exe","powershell.exe","pwsh.exe","qprocess.exe","query.exe","qwinsta.exe","reg.exe","rundll32.exe","sc.exe", "scrcons.exe","schtasks.exe","sh.exe","systeminfo.exe","tasklist.exe","tracert.exe","ver.exe","vssadmin.exe", "wevtutil.exe","whoami.exe","wmic.exe","wscript.exe","wusa.exe","zsh.exe") AND Processes.parent_process_name IN ("w3wp.exe", "http*.exe", "nginx*.exe", "php*.exe", "php-cgi*.exe","tomcat*.exe")) by Processes.dest,Processes.user,Processes.parent_process,Processes.parent_process_name,Processes.process,Processes.process_name | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_webshell_exploit_behavior_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Legitimate OS functions called by vendor applications, baseline the environment and filter before enabling. Recommend throttle by dest/process_name
|
||||
search: '| tstats `security_content_summariesonly` count max(_time) as lastTime, min(_time)
|
||||
as firstTime from datamodel=Endpoint.Processes where (Processes.process_name IN
|
||||
("arp.exe","at.exe","bash.exe","bitsadmin.exe","certutil.exe","cmd.exe","cscript.exe",
|
||||
"dsget.exe","dsquery.exe","find.exe","findstr.exe","fsutil.exe","hostname.exe","ipconfig.exe","ksh.exe","nbstat.exe",
|
||||
"net.exe","net1.exe","netdom.exe","netsh.exe","netstat.exe","nltest.exe","nslookup.exe","ntdsutil.exe","pathping.exe",
|
||||
"ping.exe","powershell.exe","pwsh.exe","qprocess.exe","query.exe","qwinsta.exe","reg.exe","rundll32.exe","sc.exe",
|
||||
"scrcons.exe","schtasks.exe","sh.exe","systeminfo.exe","tasklist.exe","tracert.exe","ver.exe","vssadmin.exe",
|
||||
"wevtutil.exe","whoami.exe","wmic.exe","wscript.exe","wusa.exe","zsh.exe") AND Processes.parent_process_name
|
||||
IN ("w3wp.exe", "http*.exe", "nginx*.exe", "php*.exe", "php-cgi*.exe","tomcat*.exe"))
|
||||
by Processes.dest,Processes.user,Processes.parent_process,Processes.parent_process_name,Processes.process,Processes.process_name
|
||||
| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_webshell_exploit_behavior_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Legitimate OS functions called by vendor applications, baseline
|
||||
the environment and filter before enabling. Recommend throttle by dest/process_name
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1505/003/
|
||||
- https://github.com/nsacyber/Mitigating-Web-Shells
|
||||
@@ -23,25 +51,32 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- ProxyNotShell
|
||||
- ProxyShell
|
||||
- CISA AA22-257A
|
||||
- HAFNIUM Group
|
||||
- BlackByte Ransomware
|
||||
- CISA AA22-264A
|
||||
- Citrix ShareFile RCE CVE-2023-24489
|
||||
- ProxyShell
|
||||
- Flax Typhoon
|
||||
- WS FTP Server Critical Vulnerabilities
|
||||
- CISA AA22-264A
|
||||
- SysAid On-Prem Software CVE-2023-47246 Vulnerability
|
||||
- Compromised Windows Host
|
||||
- WS FTP Server Critical Vulnerabilities
|
||||
- BlackByte Ransomware
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 100
|
||||
message: Webshell Exploit Behavior - $parent_process_name$ spawned $process_name$ on $dest$.
|
||||
message: Webshell Exploit Behavior - $parent_process_name$ spawned $process_name$
|
||||
on $dest$.
|
||||
mitre_attack_id:
|
||||
- T1505
|
||||
- T1505.003
|
||||
|
||||
@@ -1,17 +1,39 @@
|
||||
name: DNS Exfiltration Using Nslookup App
|
||||
id: 2452e632-9e0d-11eb-bacd-acde48001122
|
||||
version: 5
|
||||
date: '2024-10-23'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Teoderick Contreras, Splunk, Wouter Jansen
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies potential DNS exfiltration using the nslookup application. It detects specific command-line parameters such as query type (TXT, A, AAAA) and retry options, which are commonly used by attackers to exfiltrate data. The detection leverages Endpoint Detection and Response (EDR) telemetry, focusing on process execution logs. This activity is significant as it may indicate an attempt to communicate with a Command and Control (C2) server or exfiltrate sensitive data. If confirmed malicious, this could lead to data breaches and unauthorized access to critical information.
|
||||
description: The following analytic identifies potential DNS exfiltration using the
|
||||
nslookup application. It detects specific command-line parameters such as query
|
||||
type (TXT, A, AAAA) and retry options, which are commonly used by attackers to exfiltrate
|
||||
data. The detection leverages Endpoint Detection and Response (EDR) telemetry, focusing
|
||||
on process execution logs. This activity is significant as it may indicate an attempt
|
||||
to communicate with a Command and Control (C2) server or exfiltrate sensitive data.
|
||||
If confirmed malicious, this could lead to data breaches and unauthorized access
|
||||
to critical information.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id values(Processes.parent_process) as parent_process count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "nslookup.exe" Processes.process = "*-querytype=*" OR Processes.process="*-qt=*" OR Processes.process="*-q=*" OR Processes.process="*-type=*" OR Processes.process="*-retry=*" by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `dns_exfiltration_using_nslookup_app_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
values(Processes.process_id) as process_id values(Processes.parent_process) as parent_process
|
||||
count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.process_name = "nslookup.exe" Processes.process = "*-querytype=*"
|
||||
OR Processes.process="*-qt=*" OR Processes.process="*-q=*" OR Processes.process="*-type=*"
|
||||
OR Processes.process="*-retry=*" by Processes.dest Processes.user Processes.process_name
|
||||
Processes.process Processes.parent_process_name | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `dns_exfiltration_using_nslookup_app_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: admin nslookup usage
|
||||
references:
|
||||
- https://www.mandiant.com/resources/fin7-spear-phishing-campaign-targets-personnel-involved-sec-filings
|
||||
@@ -23,7 +45,12 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
@@ -32,10 +59,12 @@ tags:
|
||||
- Dynamic DNS
|
||||
- Data Exfiltration
|
||||
- Command And Control
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 90
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ performing activity related to DNS exfiltration.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ performing activity related to DNS exfiltration.
|
||||
mitre_attack_id:
|
||||
- T1048
|
||||
observable:
|
||||
|
||||
@@ -1,18 +1,39 @@
|
||||
name: DSQuery Domain Discovery
|
||||
id: cc316032-924a-11eb-91a2-acde48001122
|
||||
version: 4
|
||||
date: '2024-09-30'
|
||||
version: '5'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the execution of "dsquery.exe" with arguments targeting `TrustedDomain` queries directly from the command line. This behavior is identified using Endpoint Detection and Response (EDR) telemetry, focusing on process names and command-line arguments. This activity is significant as it often indicates domain trust discovery, a common step in lateral movement or privilege escalation by adversaries. If confirmed malicious, this could allow attackers to map domain trusts, potentially leading to further exploitation and unauthorized access to trusted domains.
|
||||
description: The following analytic detects the execution of "dsquery.exe" with arguments
|
||||
targeting `TrustedDomain` queries directly from the command line. This behavior
|
||||
is identified using Endpoint Detection and Response (EDR) telemetry, focusing on
|
||||
process names and command-line arguments. This activity is significant as it often
|
||||
indicates domain trust discovery, a common step in lateral movement or privilege
|
||||
escalation by adversaries. If confirmed malicious, this could allow attackers to
|
||||
map domain trusts, potentially leading to further exploitation and unauthorized
|
||||
access to trusted domains.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=dsquery.exe Processes.process=*trustedDomain* by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `dsquery_domain_discovery_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: Limited false positives. If there is a true false positive, filter based on command-line or parent process.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=dsquery.exe
|
||||
Processes.process=*trustedDomain* by Processes.dest Processes.user Processes.parent_process_name
|
||||
Processes.parent_process Processes.process_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `dsquery_domain_discovery_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: Limited false positives. If there is a true false positive,
|
||||
filter based on command-line or parent process.
|
||||
references:
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1482/T1482.md
|
||||
- https://blog.harmj0y.net/redteaming/a-guide-to-attacking-domain-trusts/
|
||||
@@ -24,17 +45,24 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Domain Trust Discovery
|
||||
- Active Directory Discovery
|
||||
- Domain Trust Discovery
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified performing domain discovery on endpoint $dest$ by user $user$.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
performing domain discovery on endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1482
|
||||
observable:
|
||||
|
||||
@@ -1,17 +1,37 @@
|
||||
name: Dump LSASS via comsvcs DLL
|
||||
id: 8943b567-f14d-4ee8-a0bb-2121d4ce3184
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the behavior of dumping credentials from memory by exploiting the Local Security Authority Subsystem Service (LSASS) using the comsvcs.dll and MiniDump via rundll32. This detection leverages process information from Endpoint Detection and Response (EDR) logs, focusing on specific command-line executions. This activity is significant because it indicates potential credential theft, which can lead to broader system compromise, persistence, lateral movement, and privilege escalation. If confirmed malicious, attackers could gain unauthorized access to sensitive information, leading to data theft, ransomware attacks, or other damaging outcomes.
|
||||
description: The following analytic detects the behavior of dumping credentials from
|
||||
memory by exploiting the Local Security Authority Subsystem Service (LSASS) using
|
||||
the comsvcs.dll and MiniDump via rundll32. This detection leverages process information
|
||||
from Endpoint Detection and Response (EDR) logs, focusing on specific command-line
|
||||
executions. This activity is significant because it indicates potential credential
|
||||
theft, which can lead to broader system compromise, persistence, lateral movement,
|
||||
and privilege escalation. If confirmed malicious, attackers could gain unauthorized
|
||||
access to sensitive information, leading to data theft, ransomware attacks, or other
|
||||
damaging outcomes.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*comsvcs.dll* Processes.process=*MiniDump* by Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `dump_lsass_via_comsvcs_dll_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_rundll32` Processes.process=*comsvcs.dll*
|
||||
Processes.process=*MiniDump* by Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.original_file_name Processes.process Processes.dest | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `dump_lsass_via_comsvcs_dll_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: None identified.
|
||||
references:
|
||||
- https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/
|
||||
@@ -23,26 +43,33 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- HAFNIUM Group
|
||||
- CISA AA22-264A
|
||||
- Prestige Ransomware
|
||||
- Credential Dumping
|
||||
- CISA AA22-257A
|
||||
- Living Off The Land
|
||||
- Suspicious Rundll32 Activity
|
||||
- Data Destruction
|
||||
- CISA AA22-257A
|
||||
- Volt Typhoon
|
||||
- HAFNIUM Group
|
||||
- Prestige Ransomware
|
||||
- Suspicious Rundll32 Activity
|
||||
- Industroyer2
|
||||
- Data Destruction
|
||||
- Flax Typhoon
|
||||
- CISA AA22-264A
|
||||
- Compromised Windows Host
|
||||
- Credential Dumping
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified accessing credentials using comsvcs.dll on endpoint $dest$ by user $user$.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
accessing credentials using comsvcs.dll on endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1003.001
|
||||
- T1003
|
||||
|
||||
@@ -1,17 +1,37 @@
|
||||
name: Dump LSASS via procdump
|
||||
id: 3742ebfe-64c2-11eb-ae93-0242ac130002
|
||||
version: 6
|
||||
date: '2024-09-30'
|
||||
version: '7'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the use of procdump.exe to dump the LSASS process, specifically looking for the -mm and -ma command-line arguments. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names, command-line executions, and parent processes. This activity is significant because dumping LSASS can expose sensitive credentials, posing a severe security risk. If confirmed malicious, an attacker could obtain credentials, escalate privileges, and move laterally within the network, leading to potential data breaches and further compromise of the environment.
|
||||
description: The following analytic detects the use of procdump.exe to dump the LSASS
|
||||
process, specifically looking for the -mm and -ma command-line arguments. It leverages
|
||||
data from Endpoint Detection and Response (EDR) agents, focusing on process names,
|
||||
command-line executions, and parent processes. This activity is significant because
|
||||
dumping LSASS can expose sensitive credentials, posing a severe security risk. If
|
||||
confirmed malicious, an attacker could obtain credentials, escalate privileges,
|
||||
and move laterally within the network, leading to potential data breaches and further
|
||||
compromise of the environment.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_procdump` (Processes.process=*-ma* OR Processes.process=*-mm*) Processes.process=*lsass* by Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.original_file_name Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `dump_lsass_via_procdump_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_procdump` (Processes.process=*-ma*
|
||||
OR Processes.process=*-mm*) Processes.process=*lsass* by Processes.user Processes.parent_process_name
|
||||
Processes.process_name Processes.process Processes.original_file_name Processes.dest
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `dump_lsass_via_procdump_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: None identified.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1003/001/
|
||||
@@ -24,18 +44,25 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- HAFNIUM Group
|
||||
- CISA AA22-257A
|
||||
- HAFNIUM Group
|
||||
- Compromised Windows Host
|
||||
- Credential Dumping
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified attempting to dump lsass.exe on endpoint $dest$ by user $user$.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
attempting to dump lsass.exe on endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1003.001
|
||||
- T1003
|
||||
|
||||
@@ -1,15 +1,27 @@
|
||||
name: Enumerate Users Local Group Using Telegram
|
||||
id: fcd74532-ae54-11eb-a5ab-acde48001122
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects a Telegram process enumerating all network users in a local group. It leverages EventCode 4798, which is generated when a process enumerates a user's security-enabled local groups on a computer or device. This activity is significant as it may indicate an attempt to gather information on user accounts, a common precursor to further malicious actions. If confirmed malicious, this behavior could allow an attacker to map out user accounts, potentially leading to privilege escalation or lateral movement within the network.
|
||||
description: The following analytic detects a Telegram process enumerating all network
|
||||
users in a local group. It leverages EventCode 4798, which is generated when a process
|
||||
enumerates a user's security-enabled local groups on a computer or device. This
|
||||
activity is significant as it may indicate an attempt to gather information on user
|
||||
accounts, a common precursor to further malicious actions. If confirmed malicious,
|
||||
this behavior could allow an attacker to map out user accounts, potentially leading
|
||||
to privilege escalation or lateral movement within the network.
|
||||
data_source:
|
||||
- Windows Event Log Security 4798
|
||||
search: '`wineventlog_security` EventCode=4798 CallerProcessName = "*\\telegram.exe" | stats count min(_time) as firstTime max(_time) as lastTime by user Computer EventCode CallerProcessName ProcessID SubjectUserSid SubjectDomainName SubjectLogonId | rename Computer as dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `enumerate_users_local_group_using_telegram_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting logs with the Task Schedule (Exa. Security Log EventCode 4798) endpoints. Tune and filter known instances of process like logonUI used in your environment.
|
||||
search: '`wineventlog_security` EventCode=4798 CallerProcessName = "*\\telegram.exe"
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by user Computer EventCode
|
||||
CallerProcessName ProcessID SubjectUserSid SubjectDomainName SubjectLogonId |
|
||||
rename Computer as dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `enumerate_users_local_group_using_telegram_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the Task Schedule (Exa. Security Log EventCode 4798) endpoints. Tune and
|
||||
filter known instances of process like logonUI used in your environment.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
|
||||
@@ -20,16 +32,23 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- XMRig
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
message: The Telegram application has been identified enumerating local groups on $dest$ by $user$.
|
||||
message: The Telegram application has been identified enumerating local groups on
|
||||
$dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1087
|
||||
observable:
|
||||
|
||||
@@ -1,18 +1,39 @@
|
||||
name: Excel Spawning PowerShell
|
||||
id: 42d40a22-9be3-11eb-8f08-acde48001122
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects Microsoft Excel spawning PowerShell, an uncommon and suspicious behavior. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process creation events where the parent process is "excel.exe" and the child process is PowerShell. This activity is significant because it is often associated with spearphishing attacks, where malicious attachments execute encoded PowerShell commands. If confirmed malicious, this behavior could allow an attacker to execute arbitrary code, potentially leading to data exfiltration, privilege escalation, or persistent access within the environment.
|
||||
description: The following analytic detects Microsoft Excel spawning PowerShell, an
|
||||
uncommon and suspicious behavior. This detection leverages data from Endpoint Detection
|
||||
and Response (EDR) agents, focusing on process creation events where the parent
|
||||
process is "excel.exe" and the child process is PowerShell. This activity is significant
|
||||
because it is often associated with spearphishing attacks, where malicious attachments
|
||||
execute encoded PowerShell commands. If confirmed malicious, this behavior could
|
||||
allow an attacker to execute arbitrary code, potentially leading to data exfiltration,
|
||||
privilege escalation, or persistent access within the environment.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process) min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="excel.exe" `process_powershell` by Processes.parent_process Processes.parent_process_name Processes.process_name Processes.user Processes.dest Processes.original_file_name | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)` | `excel_spawning_powershell_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: False positives should be limited, but if any are present, filter as needed.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process)
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.parent_process_name="excel.exe" `process_powershell` by Processes.parent_process
|
||||
Processes.parent_process_name Processes.process_name Processes.user Processes.dest
|
||||
Processes.original_file_name | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`
|
||||
| `excel_spawning_powershell_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: False positives should be limited, but if any are present,
|
||||
filter as needed.
|
||||
references:
|
||||
- https://redcanary.com/threat-detection-report/techniques/powershell/
|
||||
- https://attack.mitre.org/techniques/T1566/001/
|
||||
@@ -22,16 +43,23 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Spearphishing Attachments
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$, indicating potential suspicious macro execution.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$, indicating potential suspicious macro execution.
|
||||
mitre_attack_id:
|
||||
- T1003.002
|
||||
- T1003
|
||||
|
||||
@@ -1,18 +1,40 @@
|
||||
name: Excel Spawning Windows Script Host
|
||||
id: 57fe880a-9be3-11eb-9bf3-acde48001122
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies instances where Microsoft Excel spawns Windows Script Host processes (`cscript.exe` or `wscript.exe`). This behavior is detected using Endpoint Detection and Response (EDR) telemetry, focusing on process creation events where the parent process is `excel.exe`. This activity is significant because it is uncommon and often associated with malicious actions, such as spearphishing attacks. If confirmed malicious, this could allow an attacker to execute scripts, potentially leading to code execution, data exfiltration, or further system compromise. Immediate investigation and mitigation are recommended.
|
||||
description: The following analytic identifies instances where Microsoft Excel spawns
|
||||
Windows Script Host processes (`cscript.exe` or `wscript.exe`). This behavior is
|
||||
detected using Endpoint Detection and Response (EDR) telemetry, focusing on process
|
||||
creation events where the parent process is `excel.exe`. This activity is significant
|
||||
because it is uncommon and often associated with malicious actions, such as spearphishing
|
||||
attacks. If confirmed malicious, this could allow an attacker to execute scripts,
|
||||
potentially leading to code execution, data exfiltration, or further system compromise.
|
||||
Immediate investigation and mitigation are recommended.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process) min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="excel.exe" Processes.process_name IN ("cscript.exe", "wscript.exe") by Processes.parent_process Processes.parent_process_name Processes.process_name Processes.user Processes.dest | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)` | `excel_spawning_windows_script_host_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
|
||||
known_false_positives: False positives should be limited, but if any are present, filter as needed. In some instances, `cscript.exe` is used for legitimate business practices.
|
||||
search: '| tstats `security_content_summariesonly` count values(Processes.process)
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.parent_process_name="excel.exe" Processes.process_name IN ("cscript.exe",
|
||||
"wscript.exe") by Processes.parent_process Processes.parent_process_name Processes.process_name
|
||||
Processes.user Processes.dest | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`
|
||||
| `excel_spawning_windows_script_host_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
you must ingest logs that contain the process GUID, process name, and parent process.
|
||||
Additionally, you must ingest complete command-line executions. These logs must
|
||||
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
||||
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
||||
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
||||
names and speed up the data modeling process.
|
||||
known_false_positives: False positives should be limited, but if any are present,
|
||||
filter as needed. In some instances, `cscript.exe` is used for legitimate business
|
||||
practices.
|
||||
references:
|
||||
- https://app.any.run/tasks/8ecfbc29-03d0-421c-a5bf-3905d29192a2/
|
||||
- https://attack.mitre.org/techniques/T1566/001/
|
||||
@@ -22,16 +44,23 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$" and "$dest$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$",
|
||||
"$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk
|
||||
Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Spearphishing Attachments
|
||||
- Compromised Windows Host
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$, indicating potential suspicious macro execution.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$, indicating potential suspicious macro execution.
|
||||
mitre_attack_id:
|
||||
- T1003.002
|
||||
- T1003
|
||||
|
||||
@@ -1,16 +1,31 @@
|
||||
name: Executable File Written in Administrative SMB Share
|
||||
id: f63c34fe-a435-11eb-935a-acde48001122
|
||||
version: 5
|
||||
date: '2024-09-30'
|
||||
version: '6'
|
||||
date: '2024-11-28'
|
||||
author: Teoderick Contreras, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects executable files (.exe or .dll) being written to Windows administrative SMB shares (Admin$, IPC$, C$). It leverages Windows Security Event Logs with EventCode 5145 to identify this activity. This behavior is significant as it is commonly used by tools like PsExec/PaExec for staging binaries before creating and starting services on remote endpoints, a technique often employed for lateral movement and remote code execution. If confirmed malicious, this activity could allow an attacker to execute arbitrary code remotely, potentially compromising additional systems within the network.
|
||||
description: The following analytic detects executable files (.exe or .dll) being
|
||||
written to Windows administrative SMB shares (Admin$, IPC$, C$). It leverages Windows
|
||||
Security Event Logs with EventCode 5145 to identify this activity. This behavior
|
||||
is significant as it is commonly used by tools like PsExec/PaExec for staging binaries
|
||||
before creating and starting services on remote endpoints, a technique often employed
|
||||
for lateral movement and remote code execution. If confirmed malicious, this activity
|
||||
could allow an attacker to execute arbitrary code remotely, potentially compromising
|
||||
additional systems within the network.
|
||||
data_source:
|
||||
- Windows Event Log Security 5145
|
||||
search: '`wineventlog_security` EventCode=5145 RelativeTargetName IN ("*.exe","*.dll") ObjectType=File ShareName IN ("\\\\*\\C$","\\\\*\\IPC$","\\\\*\\admin$") AccessMask= "0x2" | stats min(_time) as firstTime max(_time) as lastTime count by EventCode ShareName RelativeTargetName ObjectType AccessMask src_user src_port IpAddress | `security_content_ctime(firstTime)` | `executable_file_written_in_administrative_smb_share_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting Windows Security Event Logs with 5145 EventCode enabled. The Windows TA is also required. Also enable the object Audit access success/failure in your group policy.
|
||||
known_false_positives: System Administrators may use looks like PsExec for troubleshooting or administrations tasks. However, this will typically come only from certain users and certain systems that can be added to an allow list.
|
||||
search: '`wineventlog_security` EventCode=5145 RelativeTargetName IN ("*.exe","*.dll")
|
||||
ObjectType=File ShareName IN ("\\\\*\\C$","\\\\*\\IPC$","\\\\*\\admin$") AccessMask=
|
||||
"0x2" | stats min(_time) as firstTime max(_time) as lastTime count by EventCode
|
||||
ShareName RelativeTargetName ObjectType AccessMask src_user src_port IpAddress |
|
||||
`security_content_ctime(firstTime)` | `executable_file_written_in_administrative_smb_share_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Windows Security Event Logs with 5145 EventCode enabled. The Windows TA is also
|
||||
required. Also enable the object Audit access success/failure in your group policy.
|
||||
known_false_positives: System Administrators may use looks like PsExec for troubleshooting
|
||||
or administrations tasks. However, this will typically come only from certain users
|
||||
and certain systems that can be added to an allow list.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1021/002/
|
||||
- https://www.rapid7.com/blog/post/2013/03/09/psexec-demystified/
|
||||
@@ -23,24 +38,31 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$src_user$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src_user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src_user$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Lateral Movement
|
||||
- Prestige Ransomware
|
||||
- Graceful Wipe Out Attack
|
||||
- Industroyer2
|
||||
- BlackSuit Ransomware
|
||||
- IcedID
|
||||
- Prestige Ransomware
|
||||
- Industroyer2
|
||||
- Data Destruction
|
||||
- Graceful Wipe Out Attack
|
||||
- Compromised Windows Host
|
||||
- Hermetic Wiper
|
||||
- Trickbot
|
||||
- BlackSuit Ransomware
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 70
|
||||
message: $src_user$ dropped or created an executable file in known sensitive SMB share. Share name=$ShareName$, Target name=$RelativeTargetName$, and Access mask=$AccessMask$
|
||||
message: $src_user$ dropped or created an executable file in known sensitive SMB
|
||||
share. Share name=$ShareName$, Target name=$RelativeTargetName$, and Access mask=$AccessMask$
|
||||
mitre_attack_id:
|
||||
- T1021
|
||||
- T1021.002
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user