Branch was auto-updated.

This commit is contained in:
srv-rr-gh-researchbt
2023-08-02 08:53:13 -07:00
committed by GitHub
2 changed files with 70 additions and 2 deletions
@@ -0,0 +1,68 @@
name: Windows Powershell RemoteSigned File
id: f7f7456b-470d-4a95-9703-698250645ff4
version: 1
date: '2023-06-16'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
data_source:
- Sysmon EventCode 1
description: This analytic identifies the use of "remotesigned" execution policy for a file.
This security setting determines whether PowerShell scripts can be executed on a computer.
When the execution policy is set to "remotesigned," it allows locally created scripts to run without any restrictions,
but scripts downloaded from the internet must have a digital signature from a trusted publisher.
search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where `process_powershell` Processes.process="* remotesigned *" Processes.process="* -File *"
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_powershell_remotesigned_file_filter`'
how_to_implement: To successfully implement this analytic, you will need to enable
PowerShell Script Block Logging on some or all endpoints. Additional setup here
https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.
known_false_positives: It is possible administrators or scripts may run these commands,
filtering may be required.
references:
- https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/set-executionpolicy?view=powershell-7.3
tags:
analytic_story:
- Amadey
asset_type: Endpoint
confidence: 50
impact: 50
message: A PowerShell commandline to remotesigned a powershell script in $dest$,
mitre_attack_id:
- T1059.001
- T1059
observable:
- name: Computer
type: Hostname
role:
- Victim
- name: User
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 25
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process
- Processes.process_name
- Processes.original_file_name
- Processes.process
- Processes.process_id
- Processes.parent_process_id
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_remotesigned/remotesigned_sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
+2 -2
View File
@@ -1,6 +1,6 @@
attackcti==0.3.9
docker==6.1.3
GitPython==3.1.31
GitPython==3.1.32
Jinja2==3.1.2
jsonschema==4.17.3
mock==4.0.3
@@ -14,7 +14,7 @@ PyYAML>=5.4.1
questionary==1.10.0
requests==2.31.0
six==1.16.0
splunk-sdk==1.7.3
splunk-sdk==1.7.4
wrapt-timeout-decorator==1.3.12.2
xmltodict==0.13.0