mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -0,0 +1,68 @@
|
||||
name: Windows Powershell RemoteSigned File
|
||||
id: f7f7456b-470d-4a95-9703-698250645ff4
|
||||
version: 1
|
||||
date: '2023-06-16'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
data_source:
|
||||
- Sysmon EventCode 1
|
||||
description: This analytic identifies the use of "remotesigned" execution policy for a file.
|
||||
This security setting determines whether PowerShell scripts can be executed on a computer.
|
||||
When the execution policy is set to "remotesigned," it allows locally created scripts to run without any restrictions,
|
||||
but scripts downloaded from the internet must have a digital signature from a trusted publisher.
|
||||
search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where `process_powershell` Processes.process="* remotesigned *" Processes.process="* -File *"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_powershell_remotesigned_file_filter`'
|
||||
how_to_implement: To successfully implement this analytic, you will need to enable
|
||||
PowerShell Script Block Logging on some or all endpoints. Additional setup here
|
||||
https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.
|
||||
known_false_positives: It is possible administrators or scripts may run these commands,
|
||||
filtering may be required.
|
||||
references:
|
||||
- https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/set-executionpolicy?view=powershell-7.3
|
||||
tags:
|
||||
analytic_story:
|
||||
- Amadey
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
message: A PowerShell commandline to remotesigned a powershell script in $dest$,
|
||||
mitre_attack_id:
|
||||
- T1059.001
|
||||
- T1059
|
||||
observable:
|
||||
- name: Computer
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
- name: User
|
||||
type: User
|
||||
role:
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
risk_score: 25
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process
|
||||
- Processes.process_name
|
||||
- Processes.original_file_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_id
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_remotesigned/remotesigned_sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
attackcti==0.3.9
|
||||
docker==6.1.3
|
||||
GitPython==3.1.31
|
||||
GitPython==3.1.32
|
||||
Jinja2==3.1.2
|
||||
jsonschema==4.17.3
|
||||
mock==4.0.3
|
||||
@@ -14,7 +14,7 @@ PyYAML>=5.4.1
|
||||
questionary==1.10.0
|
||||
requests==2.31.0
|
||||
six==1.16.0
|
||||
splunk-sdk==1.7.3
|
||||
splunk-sdk==1.7.4
|
||||
wrapt-timeout-decorator==1.3.12.2
|
||||
xmltodict==0.13.0
|
||||
|
||||
|
||||
Reference in New Issue
Block a user