From 0219203fa9a55cb7fbf763814fa2246f15c91800 Mon Sep 17 00:00:00 2001 From: josehelps Date: Tue, 18 Oct 2022 12:48:18 -0400 Subject: [PATCH 1/5] adding 9 BA lolbas detection --- .../output/lolbas_file_path.csv | 528 ++++++++---------- .../output/ssa___acccheckconsole_exe.yml | 4 +- .../output/ssa___adplus_exe.yml | 4 +- .../output/ssa___advpack_dll.yml | 4 +- .../output/ssa___agentexecutor_exe.yml | 4 +- .../output/ssa___appinstaller_exe.yml | 4 +- .../output/ssa___appvlp_exe.yml | 4 +- .../output/ssa___aspnet_compiler_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___at_exe.yml | 4 +- .../output/ssa___atbroker_exe.yml | 4 +- .../output/ssa___bash_exe.yml | 4 +- .../output/ssa___bitsadmin_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___cdb_exe.yml | 4 +- .../output/ssa___certoc_exe.yml | 4 +- .../output/ssa___certreq_exe.yml | 4 +- .../output/ssa___certutil_exe.yml | 4 +- .../output/ssa___cl_invocation_ps1.yml | 4 +- .../output/ssa___cl_loadassembly_ps1.yml | 4 +- .../output/ssa___cl_mutexverifiers_ps1.yml | 4 +- bin/lolba_enrichment/output/ssa___cmd_exe.yml | 4 +- .../output/ssa___cmdkey_exe.yml | 4 +- .../output/ssa___cmdl32_exe.yml | 4 +- .../output/ssa___cmstp_exe.yml | 4 +- .../output/ssa___comsvcs_dll.yml | 4 +- .../output/ssa___configsecuritypolicy_exe.yml | 4 +- .../output/ssa___conhost_exe.yml | 4 +- .../output/ssa___control_exe.yml | 4 +- .../output/ssa___coregen_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___csc_exe.yml | 4 +- .../output/ssa___cscript_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___csi_exe.yml | 4 +- .../output/ssa___datasvcutil_exe.yml | 4 +- .../output/ssa___defaultpack_exe.yml | 4 +- .../output/ssa___desk_cpl.yml | 4 +- .../output/ssa___desktopimgdownldr_exe.yml | 4 +- .../output/ssa___devtoolslauncher_exe.yml | 4 +- .../output/ssa___dfshim_dll.yml | 4 +- .../output/ssa___dfsvc_exe.yml | 4 +- .../output/ssa___diantz_exe.yml | 4 +- .../output/ssa___diskshadow_exe.yml | 4 +- .../output/ssa___dnscmd_exe.yml | 4 +- .../output/ssa___dotnet_exe.yml | 4 +- .../output/ssa___dump64_exe.yml | 4 +- .../output/ssa___dxcap_exe.yml | 4 +- .../output/ssa___esentutl_exe.yml | 4 +- .../output/ssa___eventvwr_exe.yml | 4 +- .../output/ssa___excel_exe.yml | 4 +- .../output/ssa___expand_exe.yml | 4 +- .../output/ssa___explorer_exe.yml | 4 +- .../output/ssa___extexport_exe.yml | 4 +- .../output/ssa___extrac32_exe.yml | 4 +- .../output/ssa___findstr_exe.yml | 4 +- .../output/ssa___finger_exe.yml | 4 +- .../output/ssa___fltmc_exe.yml | 4 +- .../output/ssa___forfiles_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___fsi_exe.yml | 4 +- .../output/ssa___fsianycpu_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___ftp_exe.yml | 4 +- .../output/ssa___gfxdownloadwrapper_exe.yml | 4 +- .../output/ssa___gpscript_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___hh_exe.yml | 4 +- .../output/ssa___ie4uinit_exe.yml | 4 +- .../output/ssa___ieadvpack_dll.yml | 4 +- .../output/ssa___ieexec_exe.yml | 4 +- .../output/ssa___ieframe_dll.yml | 4 +- .../output/ssa___ilasm_exe.yml | 4 +- .../output/ssa___imewdbld_exe.yml | 4 +- .../output/ssa___infdefaultinstall_exe.yml | 4 +- .../output/ssa___installutil_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___jsc_exe.yml | 4 +- .../output/ssa___makecab_exe.yml | 4 +- .../output/ssa___manage-bde_wsf.yml | 4 +- .../output/ssa___mavinject_exe.yml | 4 +- .../output/ssa___mftrace_exe.yml | 4 +- .../ssa___microsoft_workflow_compiler_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___mmc_exe.yml | 4 +- .../output/ssa___mpcmdrun_exe.yml | 4 +- .../output/ssa___msbuild_exe.yml | 4 +- .../output/ssa___msconfig_exe.yml | 4 +- .../output/ssa___msdeploy_exe.yml | 4 +- .../output/ssa___msdt_exe.yml | 4 +- .../output/ssa___mshta_exe.yml | 4 +- .../output/ssa___mshtml_dll.yml | 4 +- .../output/ssa___msiexec_exe.yml | 4 +- .../output/ssa___netsh_exe.yml | 4 +- .../output/ssa___ntdsutil_exe.yml | 4 +- .../output/ssa___odbcconf_exe.yml | 4 +- .../output/ssa___offlinescannershell_exe.yml | 4 +- .../output/ssa___pcalua_exe.yml | 4 +- .../output/ssa___pcwrun_exe.yml | 4 +- .../output/ssa___pcwutl_dll.yml | 4 +- .../output/ssa___pester_bat.yml | 4 +- .../output/ssa___pktmon_exe.yml | 4 +- .../output/ssa___pnputil_exe.yml | 4 +- .../output/ssa___powerpnt_exe.yml | 4 +- .../output/ssa___presentationhost_exe.yml | 4 +- .../output/ssa___print_exe.yml | 4 +- .../output/ssa___printbrm_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___psr_exe.yml | 4 +- .../output/ssa___pubprn_vbs.yml | 4 +- .../output/ssa___rasautou_exe.yml | 4 +- .../output/ssa___rdrleakdiag_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___reg_exe.yml | 4 +- .../output/ssa___regasm_exe.yml | 4 +- .../output/ssa___regedit_exe.yml | 4 +- .../output/ssa___regini_exe.yml | 4 +- .../output/ssa___register-cimprovider_exe.yml | 4 +- .../output/ssa___regsvcs_exe.yml | 4 +- .../output/ssa___regsvr32_exe.yml | 4 +- .../output/ssa___remote_exe.yml | 4 +- .../output/ssa___replace_exe.yml | 4 +- .../output/ssa___rpcping_exe.yml | 4 +- .../output/ssa___rundll32_exe.yml | 4 +- .../output/ssa___runonce_exe.yml | 4 +- .../output/ssa___runscripthelper_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___sc_exe.yml | 4 +- .../output/ssa___schtasks_exe.yml | 4 +- .../output/ssa___scriptrunner_exe.yml | 4 +- .../output/ssa___settingsynchost_exe.yml | 4 +- .../output/ssa___setupapi_dll.yml | 4 +- .../output/ssa___shdocvw_dll.yml | 4 +- .../output/ssa___shell32_dll.yml | 4 +- .../output/ssa___sqldumper_exe.yml | 4 +- .../output/ssa___sqlps_exe.yml | 4 +- .../output/ssa___sqltoolsps_exe.yml | 4 +- .../output/ssa___stordiag_exe.yml | 4 +- .../ssa___syncappvpublishingserver_exe.yml | 4 +- .../ssa___syncappvpublishingserver_vbs.yml | 4 +- .../output/ssa___syssetup_dll.yml | 4 +- .../output/ssa___ttdinject_exe.yml | 4 +- .../output/ssa___tttracer_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___url_dll.yml | 4 +- .../output/ssa___utilityfunctions_ps1.yml | 4 +- bin/lolba_enrichment/output/ssa___vbc_exe.yml | 4 +- .../output/ssa___verclsid_exe.yml | 4 +- .../ssa___visualuiaverifynative_exe.yml | 4 +- .../output/ssa___vsiisexelauncher_exe.yml | 4 +- .../output/ssa___vsjitdebugger_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___wab_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___wfc_exe.yml | 4 +- .../output/ssa___winrm_vbs.yml | 4 +- .../output/ssa___winword_exe.yml | 4 +- .../output/ssa___wlrmdr_exe.yml | 4 +- .../output/ssa___wmic_exe.test.yml | 13 + .../output/ssa___wmic_exe.yml | 77 +++ .../output/ssa___workfolders_exe.yml | 4 +- .../output/ssa___wscript_exe.yml | 4 +- bin/lolba_enrichment/output/ssa___wsl_exe.yml | 4 +- .../output/ssa___wsreset_exe.yml | 4 +- .../output/ssa___wuauclt_exe.yml | 4 +- .../output/ssa___xwizard_exe.yml | 4 +- .../output/ssa___zipfldr_dll.yml | 4 +- .../ssa___acccheckconsole_exe.test.yml | 15 + .../endpoint/ssa___acccheckconsole_exe.yml | 78 +++ detections/endpoint/ssa___adplus_exe.yml | 78 +++ detections/endpoint/ssa___advpack_dll.yml | 77 +++ .../endpoint/ssa___agentexecutor_exe.yml | 77 +++ .../endpoint/ssa___appinstaller_exe.yml | 78 +++ detections/endpoint/ssa___appvlp_exe.yml | 78 +++ .../endpoint/ssa___aspnet_compiler_exe.yml | 78 +++ detections/endpoint/ssa___at_exe.yml | 77 +++ detections/endpoint/ssa___atbroker_exe.yml | 77 +++ tests/endpoint/ssa___adplus_exe.test.yml | 14 + tests/endpoint/ssa___advpack_dll.test.yml | 14 + .../endpoint/ssa___agentexecutor_exe.test.yml | 14 + .../endpoint/ssa___appinstaller_exe.test.yml | 14 + tests/endpoint/ssa___appvlp_exe.test.yml | 14 + .../ssa___aspnet_compiler_exe.test.yml | 15 + tests/endpoint/ssa___at_exe.test.yml | 13 + tests/endpoint/ssa___atbroker_exe.test.yml | 14 + 170 files changed, 1454 insertions(+), 585 deletions(-) create mode 100644 bin/lolba_enrichment/output/ssa___wmic_exe.test.yml create mode 100644 bin/lolba_enrichment/output/ssa___wmic_exe.yml create mode 100644 detections/endpoint/ssa___acccheckconsole_exe.test.yml create mode 100644 detections/endpoint/ssa___acccheckconsole_exe.yml create mode 100644 detections/endpoint/ssa___adplus_exe.yml create mode 100644 detections/endpoint/ssa___advpack_dll.yml create mode 100644 detections/endpoint/ssa___agentexecutor_exe.yml create mode 100644 detections/endpoint/ssa___appinstaller_exe.yml create mode 100644 detections/endpoint/ssa___appvlp_exe.yml create mode 100644 detections/endpoint/ssa___aspnet_compiler_exe.yml create mode 100644 detections/endpoint/ssa___at_exe.yml create mode 100644 detections/endpoint/ssa___atbroker_exe.yml create mode 100644 tests/endpoint/ssa___adplus_exe.test.yml create mode 100644 tests/endpoint/ssa___advpack_dll.test.yml create mode 100644 tests/endpoint/ssa___agentexecutor_exe.test.yml create mode 100644 tests/endpoint/ssa___appinstaller_exe.test.yml create mode 100644 tests/endpoint/ssa___appvlp_exe.test.yml create mode 100644 tests/endpoint/ssa___aspnet_compiler_exe.test.yml create mode 100644 tests/endpoint/ssa___at_exe.test.yml create mode 100644 tests/endpoint/ssa___atbroker_exe.test.yml diff --git a/bin/lolba_enrichment/output/lolbas_file_path.csv b/bin/lolba_enrichment/output/lolbas_file_path.csv index 121a2e4d7d..12682573e3 100644 --- a/bin/lolba_enrichment/output/lolbas_file_path.csv +++ b/bin/lolba_enrichment/output/lolbas_file_path.csv @@ -1,92 +1,57 @@ lolbas_file_name,lolbas_file_path,description -regsvcs.exe,c:\windows\system32\*,Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies -regsvcs.exe,c:\windows\syswow64\*,Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies -ftp.exe,c:\windows\system32\*,A binary designed for connecting to FTP servers -ftp.exe,c:\windows\syswow64\*,A binary designed for connecting to FTP servers -dfsvc.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,ClickOnce engine in Windows used by .NET -dfsvc.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,ClickOnce engine in Windows used by .NET -dfsvc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,ClickOnce engine in Windows used by .NET -dfsvc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,ClickOnce engine in Windows used by .NET -offlinescannershell.exe,c:\program files\windows defender\offline\*,Windows Defender Offline Shell +eventvwr.exe,c:\windows\system32\*,Displays Windows Event Logs in a GUI window. +eventvwr.exe,c:\windows\syswow64\*,Displays Windows Event Logs in a GUI window. rasautou.exe,c:\windows\system32\*,Windows Remote Access Dialer -schtasks.exe,c:\windows\system32\*,Schedule periodic tasks -schtasks.exe,c:\windows\syswow64\*,Schedule periodic tasks -certreq.exe,c:\windows\system32\*,Used for requesting and managing certificates -certreq.exe,c:\windows\syswow64\*,Used for requesting and managing certificates -pktmon.exe,c:\windows\system32\*,Capture Network Packets on the windows 10 with October 2018 Update or later. -pktmon.exe,c:\windows\syswow64\*,Capture Network Packets on the windows 10 with October 2018 Update or later. -unregmp2.exe,c:\windows\system32\*,Microsoft Windows Media Player Setup Utility -unregmp2.exe,c:\windows\syswow64\*,Microsoft Windows Media Player Setup Utility -wlrmdr.exe,c:\windows\system32\*,Windows Logon Reminder executable -xwizard.exe,c:\windows\system32\*,Execute custom class that has been added to the registry or download a file with Xwizard.exe -xwizard.exe,c:\windows\syswow64\*,Execute custom class that has been added to the registry or download a file with Xwizard.exe -findstr.exe,c:\windows\system32\*,"Write to ADS, discover, or download files with Findstr.exe" -findstr.exe,c:\windows\syswow64\*,"Write to ADS, discover, or download files with Findstr.exe" -esentutl.exe,c:\windows\system32\*,Binary for working with Microsoft Joint Engine Technology (JET) database -esentutl.exe,c:\windows\syswow64\*,Binary for working with Microsoft Joint Engine Technology (JET) database -cscript.exe,c:\windows\system32\*,Binary used to execute scripts in Windows -cscript.exe,c:\windows\syswow64\*,Binary used to execute scripts in Windows -reg.exe,c:\windows\system32\*,Used to manipulate the registry -reg.exe,c:\windows\syswow64\*,Used to manipulate the registry -imewdbld.exe,c:\windows\system32\ime\shared\*,Microsoft IME Open Extended Dictionary Module -csc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Binary file used by .NET to compile C# code -csc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used by .NET to compile C# code -pnputil.exe,c:\windows\system32\*,Used for installing drivers -atbroker.exe,c:\windows\system32\*,Helper binary for Assistive Technology (AT) -atbroker.exe,c:\windows\syswow64\*,Helper binary for Assistive Technology (AT) -datasvcutil.exe,c:\windows\microsoft.net\framework64\v3.5\*,DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application. -appinstaller.exe,c:\program files\windowsapps\microsoft.desktopappinstaller_1.11.2521.0_x64__8wekyb3d8bbwe\*,Tool used for installation of AppX/MSIX applications on Windows 10 -print.exe,c:\windows\system32\*,Used by Windows to send files to the printer -print.exe,c:\windows\syswow64\*,Used by Windows to send files to the printer -winget.exe,c:\users\user\appdata\local\microsoft\windowsapps\*,Windows Package Manager tool -pcwrun.exe,c:\windows\system32\*,Program Compatibility Wizard -vbc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used for compile vbs code -vbc.exe,c:\windows\microsoft.net\framework64\v3.5\*,Binary file used for compile vbs code -diantz.exe,c:\windows\system32\*,Binary that package existing files into a cabinet (.cab) file -diantz.exe,c:\windows\syswow64\*,Binary that package existing files into a cabinet (.cab) file -rpcping.exe,c:\windows\system32\*,Used to verify rpc connection -rpcping.exe,c:\windows\syswow64\*,Used to verify rpc connection -wsreset.exe,c:\windows\system32\*,Used to reset Windows Store settings according to its manifest file -ttdinject.exe,c:\windows\system32\*,Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe) -ttdinject.exe,c:\windows\syswow64\*,Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe) -ilasm.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,used for compile c# code into dll or exe. -ilasm.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,used for compile c# code into dll or exe. -rdrleakdiag.exe,c:\windows\system32\*,Microsoft Windows resource leak diagnostic tool -rdrleakdiag.exe,c:\windows\syswow64\*,Microsoft Windows resource leak diagnostic tool -certutil.exe,c:\windows\system32\*,Windows binary used for handling certificates -certutil.exe,c:\windows\syswow64\*,Windows binary used for handling certificates -replace.exe,c:\windows\system32\*,Used to replace file with another file -replace.exe,c:\windows\syswow64\*,Used to replace file with another file -mshta.exe,c:\windows\system32\*,Used by Windows to execute html applications. (.hta) -mshta.exe,c:\windows\syswow64\*,Used by Windows to execute html applications. (.hta) -bitsadmin.exe,c:\windows\system32\*,Used for managing background intelligent transfer -bitsadmin.exe,c:\windows\syswow64\*,Used for managing background intelligent transfer -wscript.exe,c:\windows\system32\*,Used by Windows to execute scripts -wscript.exe,c:\windows\syswow64\*,Used by Windows to execute scripts -certoc.exe,c:\windows\system32\*,Used for installing certificates -certoc.exe,c:\windows\syswow64\*,Used for installing certificates -ssh.exe,c:\windows\system32\openssh\*,Ssh.exe is the OpenSSH compatible client can be used to connect to Windows 10 (build 1809 and later) and Windows Server 2019 devices. -ieexec.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL. -ieexec.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL. -cmd.exe,c:\windows\system32\*,The command-line interpreter in Windows -cmd.exe,c:\windows\syswow64\*,The command-line interpreter in Windows -microsoft.workflow.compiler.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,A utility included with .NET that is capable of compiling and executing C# or VB.net code. -cmdl32.exe,c:\windows\system32\*,Microsoft Connection Manager Auto-Download -cmdl32.exe,c:\windows\syswow64\*,Microsoft Connection Manager Auto-Download -runscripthelper.exe,c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\*,Execute target PowerShell script -runscripthelper.exe,c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\*,Execute target PowerShell script -printbrm.exe,c:\windows\system32\spool\tools\*,Printer Migration Command-Line Tool -makecab.exe,c:\windows\system32\*,Binary to package existing files into a cabinet (.cab) file -makecab.exe,c:\windows\syswow64\*,Binary to package existing files into a cabinet (.cab) file -customshellhost.exe,c:\windows\system32\*,A host process that is used by custom shells when using Windows in Kiosk mode. -forfiles.exe,c:\windows\system32\*,Selects and executes a command on a file or set of files. This command is useful for batch processing. -forfiles.exe,c:\windows\syswow64\*,Selects and executes a command on a file or set of files. This command is useful for batch processing. -devicecredentialdeployment.exe,c:\windows\system32\*,Device Credential Deployment -desktopimgdownldr.exe,c:\windows\system32\*,Windows binary used to configure lockscreen/desktop image -aspnet_compiler.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,ASP.NET Compilation Tool -aspnet_compiler.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,ASP.NET Compilation Tool +regedit.exe,c:\windows\system32\*,Used by Windows to manipulate registry +regedit.exe,c:\windows\syswow64\*,Used by Windows to manipulate registry +regsvr32.exe,c:\windows\system32\*,Used by Windows to register dlls +regsvr32.exe,c:\windows\syswow64\*,Used by Windows to register dlls control.exe,c:\windows\system32\*,Binary used to launch controlpanel items in Windows control.exe,c:\windows\syswow64\*,Binary used to launch controlpanel items in Windows +configsecuritypolicy.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender. you can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads. +scriptrunner.exe,c:\windows\system32\*,Execute binary through proxy binary to evade defensive counter measures +scriptrunner.exe,c:\windows\syswow64\*,Execute binary through proxy binary to evade defensive counter measures +offlinescannershell.exe,c:\program files\windows defender\offline\*,Windows Defender Offline Shell +atbroker.exe,c:\windows\system32\*,Helper binary for Assistive Technology (AT) +atbroker.exe,c:\windows\syswow64\*,Helper binary for Assistive Technology (AT) +mmc.exe,c:\windows\system32\*,Load snap-ins to locally and remotely manage Windows systems +mmc.exe,c:\windows\syswow64\*,Load snap-ins to locally and remotely manage Windows systems +mavinject.exe,c:\windows\system32\*,Used by App-v in Windows +mavinject.exe,c:\windows\syswow64\*,Used by App-v in Windows +ftp.exe,c:\windows\system32\*,A binary designed for connecting to FTP servers +ftp.exe,c:\windows\syswow64\*,A binary designed for connecting to FTP servers +ttdinject.exe,c:\windows\system32\*,Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe) +ttdinject.exe,c:\windows\syswow64\*,Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe) +certoc.exe,c:\windows\system32\*,Used for installing certificates +certoc.exe,c:\windows\syswow64\*,Used for installing certificates +at.exe,c:\windows\system32\*,Schedule periodic tasks +at.exe,c:\windows\syswow64\*,Schedule periodic tasks +netsh.exe,c:\windows\system32\*,Netsh is a Windows tool used to manipulate network interface settings. +netsh.exe,c:\windows\syswow64\*,Netsh is a Windows tool used to manipulate network interface settings. +pnputil.exe,c:\windows\system32\*,Used for installing drivers +ie4uinit.exe,c:\windows\system32\*,Executes commands from a specially prepared ie4uinit.inf file. +ie4uinit.exe,c:\windows\syswow64\*,Executes commands from a specially prepared ie4uinit.inf file. +infdefaultinstall.exe,c:\windows\system32\*,Binary used to perform installation based on content inside inf files +infdefaultinstall.exe,c:\windows\syswow64\*,Binary used to perform installation based on content inside inf files +forfiles.exe,c:\windows\system32\*,Selects and executes a command on a file or set of files. This command is useful for batch processing. +forfiles.exe,c:\windows\syswow64\*,Selects and executes a command on a file or set of files. This command is useful for batch processing. +register-cimprovider.exe,c:\windows\system32\*,Used to register new wmi providers +register-cimprovider.exe,c:\windows\syswow64\*,Used to register new wmi providers +tttracer.exe,c:\windows\system32\*,Used by Windows 1809 and newer to Debug Time Travel +tttracer.exe,c:\windows\syswow64\*,Used by Windows 1809 and newer to Debug Time Travel +xwizard.exe,c:\windows\system32\*,Execute custom class that has been added to the registry or download a file with Xwizard.exe +xwizard.exe,c:\windows\syswow64\*,Execute custom class that has been added to the registry or download a file with Xwizard.exe +pcalua.exe,c:\windows\system32\*,Program Compatibility Assistant +print.exe,c:\windows\system32\*,Used by Windows to send files to the printer +print.exe,c:\windows\syswow64\*,Used by Windows to send files to the printer +runscripthelper.exe,c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\*,Execute target PowerShell script +runscripthelper.exe,c:\windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\*,Execute target PowerShell script +regasm.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Part of .NET +regasm.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Part of .NET +regasm.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Part of .NET +regasm.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Part of .NET +cmd.exe,c:\windows\system32\*,The command-line interpreter in Windows +cmd.exe,c:\windows\syswow64\*,The command-line interpreter in Windows msbuild.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Used to compile and execute code msbuild.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Used to compile and execute code msbuild.exe,c:\windows\microsoft.net\framework\v3.5\*,Used to compile and execute code @@ -94,69 +59,18 @@ msbuild.exe,c:\windows\microsoft.net\framework64\v3.5\*,Used to compile and exec msbuild.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Used to compile and execute code msbuild.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Used to compile and execute code msbuild.exe,c:\program files (x86)\msbuild\14.0\bin\*,Used to compile and execute code -register-cimprovider.exe,c:\windows\system32\*,Used to register new wmi providers -register-cimprovider.exe,c:\windows\syswow64\*,Used to register new wmi providers -fltmc.exe,c:\windows\system32\*,Filter Manager Control Program used by Windows -tttracer.exe,c:\windows\system32\*,Used by Windows 1809 and newer to Debug Time Travel -tttracer.exe,c:\windows\syswow64\*,Used by Windows 1809 and newer to Debug Time Travel -ie4uinit.exe,c:\windows\system32\*,Executes commands from a specially prepared ie4uinit.inf file. -ie4uinit.exe,c:\windows\syswow64\*,Executes commands from a specially prepared ie4uinit.inf file. -fsutil.exe,c:\windows\system32\*,File System Utility -fsutil.exe,c:\windows\syswow64\*,File System Utility -sc.exe,c:\windows\system32\*,Used by Windows to manage services -sc.exe,c:\windows\syswow64\*,Used by Windows to manage services -conhost.exe,c:\windows\system32\*,Console Window host -bash.exe,c:\windows\system32\*,File used by Windows subsystem for Linux -bash.exe,c:\windows\syswow64\*,File used by Windows subsystem for Linux -hh.exe,c:\windows\*,Binary used for processing chm files in Windows -hh.exe,c:\windows\syswow64\*,Binary used for processing chm files in Windows -settingsynchost.exe,c:\windows\system32\*,Host Process for Setting Synchronization -settingsynchost.exe,c:\windows\syswow64\*,Host Process for Setting Synchronization -finger.exe,c:\windows\system32\*,Displays information about a user or users on a specified remote computer that is running the Finger service or daemon -finger.exe,c:\windows\syswow64\*,Displays information about a user or users on a specified remote computer that is running the Finger service or daemon -cmstp.exe,c:\windows\system32\*,Installs or removes a Connection Manager service profile. -cmstp.exe,c:\windows\syswow64\*,Installs or removes a Connection Manager service profile. -mmc.exe,c:\windows\system32\*,Load snap-ins to locally and remotely manage Windows systems -mmc.exe,c:\windows\syswow64\*,Load snap-ins to locally and remotely manage Windows systems -jsc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Binary file used by .NET to compile javascript code to .exe or .dll format -jsc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used by .NET to compile javascript code to .exe or .dll format -jsc.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Binary file used by .NET to compile javascript code to .exe or .dll format -jsc.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Binary file used by .NET to compile javascript code to .exe or .dll format -configsecuritypolicy.exe,c:\program files\windows defender\*,Binary part of Windows Defender. Used to manage settings in Windows Defender. you can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads. -configsecuritypolicy.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender. you can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads. -stordiag.exe,c:\windows\system32\*,Storage diagnostic tool -stordiag.exe,c:\windows\syswow64\*,Storage diagnostic tool -scriptrunner.exe,c:\windows\system32\*,Execute binary through proxy binary to evade defensive counter measures -scriptrunner.exe,c:\windows\syswow64\*,Execute binary through proxy binary to evade defensive counter measures -odbcconf.exe,c:\windows\system32\*,Used in Windows for managing ODBC connections -odbcconf.exe,c:\windows\syswow64\*,Used in Windows for managing ODBC connections +certutil.exe,c:\windows\system32\*,Windows binary used for handling certificates +certutil.exe,c:\windows\syswow64\*,Windows binary used for handling certificates +vbc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used for compile vbs code +vbc.exe,c:\windows\microsoft.net\framework64\v3.5\*,Binary file used for compile vbs code +psr.exe,c:\windows\system32\*,"Windows Problem Steps Recorder, used to record screen and clicks." +psr.exe,c:\windows\syswow64\*,"Windows Problem Steps Recorder, used to record screen and clicks." extexport.exe,c:\program files\internet explorer\*,Load a DLL located in the c:\test folder with a specific name. extexport.exe,c:\program files (x86)\internet explorer\*,Load a DLL located in the c:\test folder with a specific name. +rpcping.exe,c:\windows\system32\*,Used to verify rpc connection +rpcping.exe,c:\windows\syswow64\*,Used to verify rpc connection msdt.exe,c:\windows\system32\*,Microsoft diagnostics tool msdt.exe,c:\windows\syswow64\*,Microsoft diagnostics tool -workfolders.exe,c:\windows\system32\*,Work Folders -diskshadow.exe,c:\windows\system32\*,Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS). -diskshadow.exe,c:\windows\syswow64\*,Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS). -extrac32.exe,c:\windows\system32\*,"Extract to ADS, copy or overwrite a file with Extrac32.exe" -extrac32.exe,c:\windows\syswow64\*,"Extract to ADS, copy or overwrite a file with Extrac32.exe" -eventvwr.exe,c:\windows\system32\*,Displays Windows Event Logs in a GUI window. -eventvwr.exe,c:\windows\syswow64\*,Displays Windows Event Logs in a GUI window. -mavinject.exe,c:\windows\system32\*,Used by App-v in Windows -mavinject.exe,c:\windows\syswow64\*,Used by App-v in Windows -regasm.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Part of .NET -regasm.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Part of .NET -regasm.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Part of .NET -regasm.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Part of .NET -gpscript.exe,c:\windows\system32\*,Used by group policy to process scripts -gpscript.exe,c:\windows\syswow64\*,Used by group policy to process scripts -rundll32.exe,c:\windows\system32\*,Used by Windows to execute dll files -rundll32.exe,c:\windows\syswow64\*,Used by Windows to execute dll files -regsvr32.exe,c:\windows\system32\*,Used by Windows to register dlls -regsvr32.exe,c:\windows\syswow64\*,Used by Windows to register dlls -regedit.exe,c:\windows\system32\*,Used by Windows to manipulate registry -regedit.exe,c:\windows\syswow64\*,Used by Windows to manipulate registry -msiexec.exe,c:\windows\system32\*,Used by Windows to execute msi files -msiexec.exe,c:\windows\syswow64\*,Used by Windows to execute msi files gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\64kb6472.inf_amd64_3daef03bbe98572b\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path." gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_0e9c57ae3396e055\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path." gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\cui_comp.inf_amd64_209bd95d56b1ac2d\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path." @@ -313,133 +227,184 @@ gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132544.i gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132574.inf_amd64_54c9b905b975ee55\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path." gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\ki132869.inf_amd64_052eb72d070df60f\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path." gfxdownloadwrapper.exe,c:\windows\system32\driverstore\filerepository\kit126731.inf_amd64_1905c9d5f38631d9\*,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path." -wuauclt.exe,c:\windows\system32\*,Windows Update Client -presentationhost.exe,c:\windows\system32\*,File is used for executing Browser applications -presentationhost.exe,c:\windows\syswow64\*,File is used for executing Browser applications -regini.exe,c:\windows\system32\*,Used to manipulate the registry -regini.exe,c:\windows\syswow64\*,Used to manipulate the registry +dnscmd.exe,c:\windows\system32\*,A command-line interface for managing DNS servers +dnscmd.exe,c:\windows\syswow64\*,A command-line interface for managing DNS servers +wab.exe,c:\program files\windows mail\*,Windows address book manager +wab.exe,c:\program files (x86)\windows mail\*,Windows address book manager +msconfig.exe,c:\windows\system32\*,"MSConfig is a troubleshooting tool which is used to temporarily disable or re-enable software, device drivers or Windows services that run during startup process to help the user determine the cause of a problem with Windows" +wscript.exe,c:\windows\system32\*,Used by Windows to execute scripts +wscript.exe,c:\windows\syswow64\*,Used by Windows to execute scripts +makecab.exe,c:\windows\system32\*,Binary to package existing files into a cabinet (.cab) file +makecab.exe,c:\windows\syswow64\*,Binary to package existing files into a cabinet (.cab) file +datasvcutil.exe,c:\windows\microsoft.net\framework64\v3.5\*,DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application. +cmdl32.exe,c:\windows\system32\*,Microsoft Connection Manager Auto-Download +cmdl32.exe,c:\windows\syswow64\*,Microsoft Connection Manager Auto-Download +mshta.exe,c:\windows\system32\*,Used by Windows to execute html applications. (.hta) +mshta.exe,c:\windows\syswow64\*,Used by Windows to execute html applications. (.hta) +cmdkey.exe,c:\windows\system32\*,"creates, lists, and deletes stored user names and passwords or credentials." +cmdkey.exe,c:\windows\syswow64\*,"creates, lists, and deletes stored user names and passwords or credentials." +ilasm.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,used for compile c# code into dll or exe. +ilasm.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,used for compile c# code into dll or exe. +rdrleakdiag.exe,c:\windows\system32\*,Microsoft Windows resource leak diagnostic tool +rdrleakdiag.exe,c:\windows\syswow64\*,Microsoft Windows resource leak diagnostic tool mpcmdrun.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.4-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender mpcmdrun.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.7-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender mpcmdrun.exe,c:\programdata\microsoft\windows defender\platform\4.18.2008.9-0\*,Binary part of Windows Defender. Used to manage settings in Windows Defender -wmic.exe,c:\windows\system32\wbem\*,The WMI command-line (WMIC) utility provides a command-line interface for WMI -wmic.exe,c:\windows\syswow64\wbem\*,The WMI command-line (WMIC) utility provides a command-line interface for WMI +jsc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Binary file used by .NET to compile javascript code to .exe or .dll format +jsc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used by .NET to compile javascript code to .exe or .dll format +jsc.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,Binary file used by .NET to compile javascript code to .exe or .dll format +jsc.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,Binary file used by .NET to compile javascript code to .exe or .dll format +cmstp.exe,c:\windows\system32\*,Installs or removes a Connection Manager service profile. +cmstp.exe,c:\windows\syswow64\*,Installs or removes a Connection Manager service profile. +stordiag.exe,c:\windows\system32\*,Storage diagnostic tool +stordiag.exe,c:\windows\syswow64\*,Storage diagnostic tool +odbcconf.exe,c:\windows\system32\*,Used in Windows for managing ODBC connections +odbcconf.exe,c:\windows\syswow64\*,Used in Windows for managing ODBC connections +wlrmdr.exe,c:\windows\system32\*,Windows Logon Reminder executable +printbrm.exe,c:\windows\system32\spool\tools\*,Printer Migration Command-Line Tool +dfsvc.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,ClickOnce engine in Windows used by .NET +dfsvc.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,ClickOnce engine in Windows used by .NET +dfsvc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,ClickOnce engine in Windows used by .NET +dfsvc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,ClickOnce engine in Windows used by .NET +extrac32.exe,c:\windows\system32\*,"Extract to ADS, copy or overwrite a file with Extrac32.exe" +extrac32.exe,c:\windows\syswow64\*,"Extract to ADS, copy or overwrite a file with Extrac32.exe" +rundll32.exe,c:\windows\system32\*,Used by Windows to execute dll files +rundll32.exe,c:\windows\syswow64\*,Used by Windows to execute dll files runonce.exe,c:\windows\system32\*,Executes a Run Once Task that has been configured in the registry runonce.exe,c:\windows\syswow64\*,Executes a Run Once Task that has been configured in the registry -syncappvpublishingserver.exe,c:\windows\system32\*,Used by App-v to get App-v server lists -syncappvpublishingserver.exe,c:\windows\syswow64\*,Used by App-v to get App-v server lists -verclsid.exe,c:\windows\system32\*,Used to verify a COM object before it is instantiated by Windows Explorer -verclsid.exe,c:\windows\syswow64\*,Used to verify a COM object before it is instantiated by Windows Explorer -psr.exe,c:\windows\system32\*,"Windows Problem Steps Recorder, used to record screen and clicks." -psr.exe,c:\windows\syswow64\*,"Windows Problem Steps Recorder, used to record screen and clicks." -infdefaultinstall.exe,c:\windows\system32\*,Binary used to perform installation based on content inside inf files -infdefaultinstall.exe,c:\windows\syswow64\*,Binary used to perform installation based on content inside inf files explorer.exe,c:\windows\*,Binary used for managing files and system components within Windows explorer.exe,c:\windows\syswow64\*,Binary used for managing files and system components within Windows +wuauclt.exe,c:\windows\system32\*,Windows Update Client +wsreset.exe,c:\windows\system32\*,Used to reset Windows Store settings according to its manifest file +finger.exe,c:\windows\system32\*,Displays information about a user or users on a specified remote computer that is running the Finger service or daemon +finger.exe,c:\windows\syswow64\*,Displays information about a user or users on a specified remote computer that is running the Finger service or daemon +regini.exe,c:\windows\system32\*,Used to manipulate the registry +regini.exe,c:\windows\syswow64\*,Used to manipulate the registry +reg.exe,c:\windows\system32\*,Used to manipulate the registry +reg.exe,c:\windows\syswow64\*,Used to manipulate the registry +syncappvpublishingserver.exe,c:\windows\system32\*,Used by App-v to get App-v server lists +syncappvpublishingserver.exe,c:\windows\syswow64\*,Used by App-v to get App-v server lists +bitsadmin.exe,c:\windows\system32\*,Used for managing background intelligent transfer +bitsadmin.exe,c:\windows\syswow64\*,Used for managing background intelligent transfer +msiexec.exe,c:\windows\system32\*,Used by Windows to execute msi files +msiexec.exe,c:\windows\syswow64\*,Used by Windows to execute msi files +regsvcs.exe,c:\windows\system32\*,Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies +regsvcs.exe,c:\windows\syswow64\*,Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies +gpscript.exe,c:\windows\system32\*,Used by group policy to process scripts +gpscript.exe,c:\windows\syswow64\*,Used by group policy to process scripts +diskshadow.exe,c:\windows\system32\*,Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS). +diskshadow.exe,c:\windows\syswow64\*,Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS). +ieexec.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL. +ieexec.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL. +diantz.exe,c:\windows\system32\*,Binary that package existing files into a cabinet (.cab) file +diantz.exe,c:\windows\syswow64\*,Binary that package existing files into a cabinet (.cab) file +desktopimgdownldr.exe,c:\windows\system32\*,Windows binary used to configure lockscreen/desktop image +appinstaller.exe,c:\program files\windowsapps\microsoft.desktopappinstaller_1.11.2521.0_x64__8wekyb3d8bbwe\*,Tool used for installation of AppX/MSIX applications on Windows 10 +sc.exe,c:\windows\system32\*,Used by Windows to manage services +sc.exe,c:\windows\syswow64\*,Used by Windows to manage services +replace.exe,c:\windows\system32\*,Used to replace file with another file +replace.exe,c:\windows\syswow64\*,Used to replace file with another file +schtasks.exe,c:\windows\system32\*,Schedule periodic tasks +schtasks.exe,c:\windows\syswow64\*,Schedule periodic tasks +microsoft.workflow.compiler.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,A utility included with .NET that is capable of compiling and executing C# or VB.net code. expand.exe,c:\windows\system32\*,Binary that expands one or more compressed files expand.exe,c:\windows\syswow64\*,Binary that expands one or more compressed files +conhost.exe,c:\windows\system32\*,Console Window host +bash.exe,c:\windows\system32\*,File used by Windows subsystem for Linux +bash.exe,c:\windows\syswow64\*,File used by Windows subsystem for Linux +pcwrun.exe,c:\windows\system32\*,Program Compatibility Wizard +fltmc.exe,c:\windows\system32\*,Filter Manager Control Program used by Windows +wmic.exe,c:\windows\system32\wbem\*,The WMI command-line (WMIC) utility provides a command-line interface for WMI +wmic.exe,c:\windows\syswow64\wbem\*,The WMI command-line (WMIC) utility provides a command-line interface for WMI +workfolders.exe,c:\windows\system32\*,Work Folders +settingsynchost.exe,c:\windows\system32\*,Host Process for Setting Synchronization +settingsynchost.exe,c:\windows\syswow64\*,Host Process for Setting Synchronization +pktmon.exe,c:\windows\system32\*,Capture Network Packets on the windows 10 with October 2018 Update or later. +pktmon.exe,c:\windows\syswow64\*,Capture Network Packets on the windows 10 with October 2018 Update or later. +aspnet_compiler.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,ASP.NET Compilation Tool +aspnet_compiler.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,ASP.NET Compilation Tool +cscript.exe,c:\windows\system32\*,Binary used to execute scripts in Windows +cscript.exe,c:\windows\syswow64\*,Binary used to execute scripts in Windows installutil.exe,c:\windows\microsoft.net\framework\v2.0.50727\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies installutil.exe,c:\windows\microsoft.net\framework64\v2.0.50727\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies installutil.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies installutil.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies -netsh.exe,c:\windows\system32\*,Netsh is a Windows tool used to manipulate network interface settings. -netsh.exe,c:\windows\syswow64\*,Netsh is a Windows tool used to manipulate network interface settings. -wab.exe,c:\program files\windows mail\*,Windows address book manager -wab.exe,c:\program files (x86)\windows mail\*,Windows address book manager -dnscmd.exe,c:\windows\system32\*,A command-line interface for managing DNS servers -dnscmd.exe,c:\windows\syswow64\*,A command-line interface for managing DNS servers -at.exe,c:\windows\system32\*,Schedule periodic tasks -at.exe,c:\windows\syswow64\*,Schedule periodic tasks -pcalua.exe,c:\windows\system32\*,Program Compatibility Assistant -cmdkey.exe,c:\windows\system32\*,"creates, lists, and deletes stored user names and passwords or credentials." -cmdkey.exe,c:\windows\syswow64\*,"creates, lists, and deletes stored user names and passwords or credentials." -msconfig.exe,c:\windows\system32\*,"MSConfig is a troubleshooting tool which is used to temporarily disable or re-enable software, device drivers or Windows services that run during startup process to help the user determine the cause of a problem with Windows" -ldifde.exe,c:\windows\system32\*,"Creates, modifies, and deletes LDAP directory objects." -ldifde.exe,c:\windows\syswow64\*,"Creates, modifies, and deletes LDAP directory objects." +esentutl.exe,c:\windows\system32\*,Binary for working with Microsoft Joint Engine Technology (JET) database +esentutl.exe,c:\windows\syswow64\*,Binary for working with Microsoft Joint Engine Technology (JET) database +hh.exe,c:\windows\*,Binary used for processing chm files in Windows +hh.exe,c:\windows\syswow64\*,Binary used for processing chm files in Windows +findstr.exe,c:\windows\system32\*,"Write to ADS, discover, or download files with Findstr.exe" +findstr.exe,c:\windows\syswow64\*,"Write to ADS, discover, or download files with Findstr.exe" +verclsid.exe,c:\windows\system32\*,Used to verify a COM object before it is instantiated by Windows Explorer +verclsid.exe,c:\windows\syswow64\*,Used to verify a COM object before it is instantiated by Windows Explorer +certreq.exe,c:\windows\system32\*,Used for requesting and managing certificates +certreq.exe,c:\windows\syswow64\*,Used for requesting and managing certificates +csc.exe,c:\windows\microsoft.net\framework\v4.0.30319\*,Binary file used by .NET to compile C# code +csc.exe,c:\windows\microsoft.net\framework64\v4.0.30319\*,Binary file used by .NET to compile C# code +imewdbld.exe,c:\windows\system32\ime\shared\*,Microsoft IME Open Extended Dictionary Module +presentationhost.exe,c:\windows\system32\*,File is used for executing Browser applications +presentationhost.exe,c:\windows\syswow64\*,File is used for executing Browser applications +shell32.dll,c:\windows\system32\*,Windows Shell Common Dll +shell32.dll,c:\windows\syswow64\*,Windows Shell Common Dll +zipfldr.dll,c:\windows\system32\*,Compressed Folder library +zipfldr.dll,c:\windows\syswow64\*,Compressed Folder library +desk.cpl,c:\windows\system32\*,Desktop Settings Control Panel +desk.cpl,c:\windows\syswow64\*,Desktop Settings Control Panel +comsvcs.dll,c:\windows\system32\*,COM+ Services +setupapi.dll,c:\windows\system32\*,Windows Setup Application Programming Interface +setupapi.dll,c:\windows\syswow64\*,Windows Setup Application Programming Interface +mshtml.dll,c:\windows\system32\*,Microsoft HTML Viewer +mshtml.dll,c:\windows\syswow64\*,Microsoft HTML Viewer +advpack.dll,c:\windows\system32\*,Utility for installing software and drivers with rundll32.exe +advpack.dll,c:\windows\syswow64\*,Utility for installing software and drivers with rundll32.exe +pcwutl.dll,c:\windows\system32\*,Microsoft HTML Viewer +pcwutl.dll,c:\windows\syswow64\*,Microsoft HTML Viewer +shdocvw.dll,c:\windows\system32\*,Shell Doc Object and Control Library. +shdocvw.dll,c:\windows\syswow64\*,Shell Doc Object and Control Library. +ieframe.dll,c:\windows\system32\*,Internet Browser DLL for translating HTML code. +ieframe.dll,c:\windows\syswow64\*,Internet Browser DLL for translating HTML code. dfshim.dll,c:\windows\microsoft.net\framework\v2.0.50727\*,ClickOnce engine in Windows used by .NET dfshim.dll,c:\windows\microsoft.net\framework64\v2.0.50727\*,ClickOnce engine in Windows used by .NET dfshim.dll,c:\windows\microsoft.net\framework\v4.0.30319\*,ClickOnce engine in Windows used by .NET dfshim.dll,c:\windows\microsoft.net\framework64\v4.0.30319\*,ClickOnce engine in Windows used by .NET -pcwutl.dll,c:\windows\system32\*,Microsoft HTML Viewer -pcwutl.dll,c:\windows\syswow64\*,Microsoft HTML Viewer url.dll,c:\windows\system32\*,Internet Shortcut Shell Extension DLL. url.dll,c:\windows\syswow64\*,Internet Shortcut Shell Extension DLL. -zipfldr.dll,c:\windows\system32\*,Compressed Folder library -zipfldr.dll,c:\windows\syswow64\*,Compressed Folder library ieadvpack.dll,c:\windows\system32\*,INF installer for Internet Explorer. Has much of the same functionality as advpack.dll. ieadvpack.dll,c:\windows\syswow64\*,INF installer for Internet Explorer. Has much of the same functionality as advpack.dll. -ieframe.dll,c:\windows\system32\*,Internet Browser DLL for translating HTML code. -ieframe.dll,c:\windows\syswow64\*,Internet Browser DLL for translating HTML code. -advpack.dll,c:\windows\system32\*,Utility for installing software and drivers with rundll32.exe -advpack.dll,c:\windows\syswow64\*,Utility for installing software and drivers with rundll32.exe syssetup.dll,c:\windows\system32\*,Windows NT System Setup syssetup.dll,c:\windows\syswow64\*,Windows NT System Setup -shell32.dll,c:\windows\system32\*,Windows Shell Common Dll -shell32.dll,c:\windows\syswow64\*,Windows Shell Common Dll -setupapi.dll,c:\windows\system32\*,Windows Setup Application Programming Interface -setupapi.dll,c:\windows\syswow64\*,Windows Setup Application Programming Interface -shdocvw.dll,c:\windows\system32\*,Shell Doc Object and Control Library. -shdocvw.dll,c:\windows\syswow64\*,Shell Doc Object and Control Library. -desk.cpl,c:\windows\system32\*,Desktop Settings Control Panel -desk.cpl,c:\windows\syswow64\*,Desktop Settings Control Panel -mshtml.dll,c:\windows\system32\*,Microsoft HTML Viewer -mshtml.dll,c:\windows\syswow64\*,Microsoft HTML Viewer -comsvcs.dll,c:\windows\system32\*,COM+ Services -cl_invocation.ps1,c:\windows\diagnostics\system\aero\*,Aero diagnostics script -cl_invocation.ps1,c:\windows\diagnostics\system\audio\*,Aero diagnostics script -cl_invocation.ps1,c:\windows\diagnostics\system\windowsupdate\*,Aero diagnostics script winrm.vbs,c:\windows\system32\*,Script used for manage Windows RM settings winrm.vbs,c:\windows\syswow64\*,Script used for manage Windows RM settings +manage-bde.wsf,c:\windows\system32\*,Script for managing BitLocker cl_mutexverifiers.ps1,c:\windows\diagnostics\system\windowsupdate\*,Proxy execution with CL_Mutexverifiers.ps1 cl_mutexverifiers.ps1,c:\windows\diagnostics\system\audio\*,Proxy execution with CL_Mutexverifiers.ps1 cl_mutexverifiers.ps1,c:\windows\diagnostics\system\video\*,Proxy execution with CL_Mutexverifiers.ps1 cl_mutexverifiers.ps1,c:\windows\diagnostics\system\speech\*,Proxy execution with CL_Mutexverifiers.ps1 -utilityfunctions.ps1,c:\windows\diagnostics\system\networking\*,PowerShell Diagnostic Script -syncappvpublishingserver.vbs,c:\windows\system32\*,Script used related to app-v and publishing server -pester.bat,c:\program files\windowspowershell\modules\pester\3.4.0\bin\*,Used as part of the Powershell pester -pester.bat,c:\program files\windowspowershell\modules\pester\*\bin\*,Used as part of the Powershell pester -manage-bde.wsf,c:\windows\system32\*,Script for managing BitLocker -cl_loadassembly.ps1,c:\windows\diagnostics\system\audio\*,PowerShell Diagnostic Script pubprn.vbs,c:\windows\system32\printing_admin_scripts\en-us\*,Proxy execution with Pubprn.vbs pubprn.vbs,c:\windows\syswow64\printing_admin_scripts\en-us\*,Proxy execution with Pubprn.vbs -mftrace.exe,c:\program files (x86)\windows kits\10\bin\10.0.16299.0\*,Trace log generation tool for Media Foundation Tools. -mftrace.exe,c:\program files (x86)\windows kits\10\bin\*,Trace log generation tool for Media Foundation Tools. -dotnet.exe,c:\program files\dotnet\*,dotnet.exe comes with .NET Framework -createdump.exe,c:\program files\dotnet\shared\microsoft.netcore.app\*\*,Microsoft .NET Runtime Crash Dump Generator (included in .NET Core) -vsiisexelauncher.exe,c:\program files (x86)\microsoft visual studio\2019\community\common7\ide\extensions\microsoft\web tools\projectsystem\*,Binary will execute specified binary. Part of VS/VScode installation. -sqltoolsps.exe,c:\program files (x86)\microsoft sql server\130\tools\binn\*,Tool included with Microsoft SQL that loads SQL Server cmdlts. A replacement for sqlps.exe. Successor to sqlps.exe in SQL Server 2016+. -dxcap.exe,c:\windows\system32\*,DirectX diagnostics/debugger included with Visual Studio. -dxcap.exe,c:\windows\syswow64\*,DirectX diagnostics/debugger included with Visual Studio. -appvlp.exe,c:\program files\microsoft office\root\client\*,Application Virtualization Utility Included with Microsoft Office 2016 -appvlp.exe,c:\program files (x86)\microsoft office\root\client\*,Application Virtualization Utility Included with Microsoft Office 2016 -mspub.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Publisher -mspub.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Publisher -mspub.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Publisher -mspub.exe,c:\program files\microsoft office\office16\*,Microsoft Publisher -mspub.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Publisher -mspub.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Publisher -mspub.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Publisher -mspub.exe,c:\program files\microsoft office\office15\*,Microsoft Publisher -mspub.exe,c:\program files (x86)\microsoft office 14\clientx86\root\office14\*,Microsoft Publisher -mspub.exe,c:\program files\microsoft office 14\clientx64\root\office14\*,Microsoft Publisher -mspub.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Publisher -mspub.exe,c:\program files\microsoft office\office14\*,Microsoft Publisher +pester.bat,c:\program files\windowspowershell\modules\pester\3.4.0\bin\*,Used as part of the Powershell pester +pester.bat,c:\program files\windowspowershell\modules\pester\*\bin\*,Used as part of the Powershell pester +cl_loadassembly.ps1,c:\windows\diagnostics\system\audio\*,PowerShell Diagnostic Script +syncappvpublishingserver.vbs,c:\windows\system32\*,Script used related to app-v and publishing server +cl_invocation.ps1,c:\windows\diagnostics\system\aero\*,Aero diagnostics script +cl_invocation.ps1,c:\windows\diagnostics\system\audio\*,Aero diagnostics script +cl_invocation.ps1,c:\windows\diagnostics\system\windowsupdate\*,Aero diagnostics script +utilityfunctions.ps1,c:\windows\diagnostics\system\networking\*,PowerShell Diagnostic Script +coregen.exe,c:\program files\microsoft silverlight\5.1.50918.0\*,"Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within ""C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\"" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight." +coregen.exe,c:\program files (x86)\microsoft silverlight\5.1.50918.0\*,"Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within ""C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\"" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight." +fsi.exe,c:\program files\dotnet\sdk\[sdk version]\fsharp\*,64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK. +fsi.exe,c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\*,64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK. visualuiaverifynative.exe,c:\program files (x86)\windows kits\10\bin\[sdk version]\arm64\uiaverify\*,A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls. visualuiaverifynative.exe,c:\program files (x86)\windows kits\10\bin\[sdk version]\x64\uiaverify\*,A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls. visualuiaverifynative.exe,c:\program files (x86)\windows kits\10\bin\[sdk version]\uiaverify\*,A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls. -powerpnt.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary. -powerpnt.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office binary. -powerpnt.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Office binary. -powerpnt.exe,c:\program files\microsoft office\office16\*,Microsoft Office binary. -powerpnt.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Office binary. -powerpnt.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Office binary. -powerpnt.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Office binary. -powerpnt.exe,c:\program files\microsoft office\office15\*,Microsoft Office binary. -powerpnt.exe,c:\program files (x86)\microsoft office 14\clientx86\root\office14\*,Microsoft Office binary. -powerpnt.exe,c:\program files\microsoft office 14\clientx64\root\office14\*,Microsoft Office binary. -powerpnt.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office binary. -powerpnt.exe,c:\program files\microsoft office\office14\*,Microsoft Office binary. -powerpnt.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office binary. -powerpnt.exe,c:\program files\microsoft office\office12\*,Microsoft Office binary. +ntdsutil.exe,c:\windows\system32\*,Command line utility used to export Active Directory. +sqltoolsps.exe,c:\program files (x86)\microsoft sql server\130\tools\binn\*,Tool included with Microsoft SQL that loads SQL Server cmdlts. A replacement for sqlps.exe. Successor to sqlps.exe in SQL Server 2016+. +dump64.exe,c:\program files (x86)\microsoft visual studio\installer\feedback\*,Memory dump tool that comes with Microsoft Visual Studio +wsl.exe,c:\windows\system32\*,Windows subsystem for Linux executable +csi.exe,c:\program files (x86)\microsoft visual studio\2017\community\msbuild\15.0\bin\roslyn\*,Command line interface included with Visual Studio. +csi.exe,c:\program files (x86)\microsoft web tools\packages\microsoft.net.compilers.x.y.z\tools\*,Command line interface included with Visual Studio. +mftrace.exe,c:\program files (x86)\windows kits\10\bin\10.0.16299.0\*,Trace log generation tool for Media Foundation Tools. +mftrace.exe,c:\program files (x86)\windows kits\10\bin\*,Trace log generation tool for Media Foundation Tools. adplus.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools adplus.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools excel.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary @@ -456,9 +421,44 @@ excel.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office bi excel.exe,c:\program files\microsoft office\office14\*,Microsoft Office binary excel.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office binary excel.exe,c:\program files\microsoft office\office12\*,Microsoft Office binary +dotnet.exe,c:\program files\dotnet\*,dotnet.exe comes with .NET Framework +sqlps.exe,c:\program files (x86)\microsoft sql server\100\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons." +sqlps.exe,c:\program files (x86)\microsoft sql server\110\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons." +sqlps.exe,c:\program files (x86)\microsoft sql server\120\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons." +sqlps.exe,c:\program files (x86)\microsoft sql server\130\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons." +sqlps.exe,c:\program files (x86)\microsoft sql server\150\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons." +acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x86\accchecker\*,Verifies UI accessibility requirements +acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x64\accchecker\*,Verifies UI accessibility requirements +acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm\accchecker\*,Verifies UI accessibility requirements +acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm64\accchecker\*,Verifies UI accessibility requirements +powerpnt.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary. +powerpnt.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office binary. +powerpnt.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Office binary. +powerpnt.exe,c:\program files\microsoft office\office16\*,Microsoft Office binary. +powerpnt.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Office binary. +powerpnt.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Office binary. +powerpnt.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Office binary. +powerpnt.exe,c:\program files\microsoft office\office15\*,Microsoft Office binary. +powerpnt.exe,c:\program files (x86)\microsoft office 14\clientx86\root\office14\*,Microsoft Office binary. +powerpnt.exe,c:\program files\microsoft office 14\clientx64\root\office14\*,Microsoft Office binary. +powerpnt.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office binary. +powerpnt.exe,c:\program files\microsoft office\office14\*,Microsoft Office binary. +powerpnt.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office binary. +powerpnt.exe,c:\program files\microsoft office\office12\*,Microsoft Office binary. +sqldumper.exe,c:\program files\microsoft sql server\90\shared\*,Debugging utility included with Microsoft SQL. +sqldumper.exe,c:\program files (x86)\microsoft office\root\vfs\programfilesx86\microsoft analysis\as oledb\140\*,Debugging utility included with Microsoft SQL. +remote.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools +remote.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools +appvlp.exe,c:\program files\microsoft office\root\client\*,Application Virtualization Utility Included with Microsoft Office 2016 +appvlp.exe,c:\program files (x86)\microsoft office\root\client\*,Application Virtualization Utility Included with Microsoft Office 2016 +agentexecutor.exe,c:\program files (x86)\*,Intune Management Extension included on Intune Managed Devices +dxcap.exe,c:\windows\system32\*,DirectX diagnostics/debugger included with Visual Studio. +dxcap.exe,c:\windows\syswow64\*,DirectX diagnostics/debugger included with Visual Studio. +cdb.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools. +cdb.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools. +defaultpack.exe,c:\program files (x86)\microsoft\defaultpack\*,This binary can be downloaded along side multiple software downloads on the microsoft website. It gets downloaded when the user forgets to uncheck the option to set Bing as the default search provider. devtoolslauncher.exe,c:\windows\system32\*,Binary will execute specified binary. Part of VS/VScode installation. -wsl.exe,c:\windows\system32\*,Windows subsystem for Linux executable -vsjitdebugger.exe,c:\windows\system32\*,Just-In-Time (JIT) debugger included with Visual Studio +vsiisexelauncher.exe,c:\program files (x86)\microsoft visual studio\2019\community\common7\ide\extensions\microsoft\web tools\projectsystem\*,Binary will execute specified binary. Part of VS/VScode installation. winword.exe,c:\program files\microsoft office\root\office16\*,Microsoft Office binary winword.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary winword.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office binary @@ -474,53 +474,7 @@ winword.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office winword.exe,c:\program files\microsoft office\office14\*,Microsoft Office binary winword.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office binary winword.exe,c:\program files\microsoft office\office12\*,Microsoft Office binary -agentexecutor.exe,c:\program files (x86)\*,Intune Management Extension included on Intune Managed Devices -fsi.exe,c:\program files\dotnet\sdk\[sdk version]\fsharp\*,64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK. -fsi.exe,c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\*,64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK. -sqlps.exe,c:\program files (x86)\microsoft sql server\100\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons." -sqlps.exe,c:\program files (x86)\microsoft sql server\110\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons." -sqlps.exe,c:\program files (x86)\microsoft sql server\120\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons." -sqlps.exe,c:\program files (x86)\microsoft sql server\130\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons." -sqlps.exe,c:\program files (x86)\microsoft sql server\150\tools\binn\*,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons." -wfc.exe,c:\program files (x86)\microsoft sdks\windows\v10.0a\bin\netfx 4.8 tools\*,The Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK). -msohtmed.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office component -msohtmed.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office component -msohtmed.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Office component -msohtmed.exe,c:\program files\microsoft office\office16\*,Microsoft Office component -msohtmed.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Office component -msohtmed.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Office component -msohtmed.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Office component -msohtmed.exe,c:\program files\microsoft office\office15\*,Microsoft Office component -msohtmed.exe,c:\program files (x86)\microsoft office 14\clientx86\root\office14\*,Microsoft Office component -msohtmed.exe,c:\program files\microsoft office 14\clientx64\root\office14\*,Microsoft Office component -msohtmed.exe,c:\program files (x86)\microsoft office\office14\*,Microsoft Office component -msohtmed.exe,c:\program files\microsoft office\office14\*,Microsoft Office component -msohtmed.exe,c:\program files (x86)\microsoft office\office12\*,Microsoft Office component -msohtmed.exe,c:\program files\microsoft office\office12\*,Microsoft Office component -remote.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools -remote.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools fsianycpu.exe,c:\program files (x86)\microsoft visual studio\2019\professional\common7\ide\commonextensions\microsoft\fsharp\*,32/64-bit FSharp (F#) Interpreter included with Visual Studio. -defaultpack.exe,c:\program files (x86)\microsoft\defaultpack\*,This binary can be downloaded along side multiple software downloads on the microsoft website. It gets downloaded when the user forgets to uncheck the option to set Bing as the default search provider. +vsjitdebugger.exe,c:\windows\system32\*,Just-In-Time (JIT) debugger included with Visual Studio +wfc.exe,c:\program files (x86)\microsoft sdks\windows\v10.0a\bin\netfx 4.8 tools\*,The Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK). msdeploy.exe,c:\program files (x86)\iis\microsoft web deploy v3\*,Microsoft tool used to deploy Web Applications. -acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x86\accchecker\*,Verifies UI accessibility requirements -acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\x64\accchecker\*,Verifies UI accessibility requirements -acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm\accchecker\*,Verifies UI accessibility requirements -acccheckconsole.exe,c:\program files (x86)\windows kits\10\bin\10.0.22000.0\arm64\accchecker\*,Verifies UI accessibility requirements -sqldumper.exe,c:\program files\microsoft sql server\90\shared\*,Debugging utility included with Microsoft SQL. -sqldumper.exe,c:\program files (x86)\microsoft office\root\vfs\programfilesx86\microsoft analysis\as oledb\140\*,Debugging utility included with Microsoft SQL. -dump64.exe,c:\program files (x86)\microsoft visual studio\installer\feedback\*,Memory dump tool that comes with Microsoft Visual Studio -protocolhandler.exe,c:\program files (x86)\microsoft office 16\clientx86\root\office16\*,Microsoft Office binary -protocolhandler.exe,c:\program files\microsoft office 16\clientx64\root\office16\*,Microsoft Office binary -protocolhandler.exe,c:\program files (x86)\microsoft office\office16\*,Microsoft Office binary -protocolhandler.exe,c:\program files\microsoft office\office16\*,Microsoft Office binary -protocolhandler.exe,c:\program files (x86)\microsoft office 15\clientx86\root\office15\*,Microsoft Office binary -protocolhandler.exe,c:\program files\microsoft office 15\clientx64\root\office15\*,Microsoft Office binary -protocolhandler.exe,c:\program files (x86)\microsoft office\office15\*,Microsoft Office binary -protocolhandler.exe,c:\program files\microsoft office\office15\*,Microsoft Office binary -coregen.exe,c:\program files\microsoft silverlight\5.1.50918.0\*,"Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within ""C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\"" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight." -coregen.exe,c:\program files (x86)\microsoft silverlight\5.1.50918.0\*,"Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within ""C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\"" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight." -ntdsutil.exe,c:\windows\system32\*,Command line utility used to export Active Directory. -csi.exe,c:\program files (x86)\microsoft visual studio\2017\community\msbuild\15.0\bin\roslyn\*,Command line interface included with Visual Studio. -csi.exe,c:\program files (x86)\microsoft web tools\packages\microsoft.net.compilers.x.y.z\tools\*,Command line interface included with Visual Studio. -cdb.exe,c:\program files (x86)\windows kits\10\debuggers\x64\*,Debugging tool included with Windows Debugging Tools. -cdb.exe,c:\program files (x86)\windows kits\10\debuggers\x86\*,Debugging tool included with Windows Debugging Tools. diff --git a/bin/lolba_enrichment/output/ssa___acccheckconsole_exe.yml b/bin/lolba_enrichment/output/ssa___acccheckconsole_exe.yml index c86a1a103c..8c8144b809 100644 --- a/bin/lolba_enrichment/output/ssa___acccheckconsole_exe.yml +++ b/bin/lolba_enrichment/output/ssa___acccheckconsole_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Acccheckconsole exe LOLBAS in Non Standard Path -id: a8289f22-2df9-4d67-9913-de8fc0954d02 +id: c842931e-661f-42bc-a4df-0460d93cfb69 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___adplus_exe.yml b/bin/lolba_enrichment/output/ssa___adplus_exe.yml index dfc0558a8b..8552b8a3c1 100644 --- a/bin/lolba_enrichment/output/ssa___adplus_exe.yml +++ b/bin/lolba_enrichment/output/ssa___adplus_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Adplus exe LOLBAS in Non Standard Path -id: 32134938-37d4-4ec5-8714-46ca49769d20 +id: ecaaf956-c516-4980-b08e-8c01c19614ca version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___advpack_dll.yml b/bin/lolba_enrichment/output/ssa___advpack_dll.yml index 0ff9e03043..c557b3ba61 100644 --- a/bin/lolba_enrichment/output/ssa___advpack_dll.yml +++ b/bin/lolba_enrichment/output/ssa___advpack_dll.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Advpack dll LOLBAS in Non Standard Path -id: 56061a68-08af-4d8a-b0c3-e3e4477d2264 +id: 3284e4f4-67f7-49b6-ad5e-a8fcead2eef8 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___agentexecutor_exe.yml b/bin/lolba_enrichment/output/ssa___agentexecutor_exe.yml index 5b74807065..765e415cb4 100644 --- a/bin/lolba_enrichment/output/ssa___agentexecutor_exe.yml +++ b/bin/lolba_enrichment/output/ssa___agentexecutor_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Agentexecutor exe LOLBAS in Non Standard Path -id: 0327b45f-3531-4efc-9b51-46e716eb454a +id: e124f71f-11bc-47e4-9931-6046d256005d version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___appinstaller_exe.yml b/bin/lolba_enrichment/output/ssa___appinstaller_exe.yml index 19e417ac53..0c0c895bee 100644 --- a/bin/lolba_enrichment/output/ssa___appinstaller_exe.yml +++ b/bin/lolba_enrichment/output/ssa___appinstaller_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Appinstaller exe LOLBAS in Non Standard Path -id: 0f97913c-5aa4-443d-b111-676da584db6e +id: 057c06c7-ef31-4749-b5c9-199152e53a06 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___appvlp_exe.yml b/bin/lolba_enrichment/output/ssa___appvlp_exe.yml index bb743fb295..ad703a8861 100644 --- a/bin/lolba_enrichment/output/ssa___appvlp_exe.yml +++ b/bin/lolba_enrichment/output/ssa___appvlp_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Appvlp exe LOLBAS in Non Standard Path -id: da9de3e2-66ab-43ec-bbc8-4875d2115fec +id: 93862a89-abe0-4094-909a-08ec390aa5e3 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___aspnet_compiler_exe.yml b/bin/lolba_enrichment/output/ssa___aspnet_compiler_exe.yml index 440e79fcc4..efc87d96de 100644 --- a/bin/lolba_enrichment/output/ssa___aspnet_compiler_exe.yml +++ b/bin/lolba_enrichment/output/ssa___aspnet_compiler_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Aspnet_compiler exe LOLBAS in Non Standard Path -id: 41218a31-e6b8-4ea3-88dc-d588e1b45a5f +id: d75cc561-3828-4d0a-92c4-0eb93bfe0929 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___at_exe.yml b/bin/lolba_enrichment/output/ssa___at_exe.yml index 8a014e2b9f..c402402187 100644 --- a/bin/lolba_enrichment/output/ssa___at_exe.yml +++ b/bin/lolba_enrichment/output/ssa___at_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities At exe LOLBAS in Non Standard Path -id: 51fd491e-b38a-4657-b5c8-7f6410b9bbcf +id: 6401d583-0052-4dc5-a713-68b510826d2b version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___atbroker_exe.yml b/bin/lolba_enrichment/output/ssa___atbroker_exe.yml index 1f3c31ab77..ff6495644c 100644 --- a/bin/lolba_enrichment/output/ssa___atbroker_exe.yml +++ b/bin/lolba_enrichment/output/ssa___atbroker_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Atbroker exe LOLBAS in Non Standard Path -id: 09d6531d-b55b-4d46-8e7a-9b455563fd03 +id: b8da7ea5-8c16-4eff-9787-54ec271159e0 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___bash_exe.yml b/bin/lolba_enrichment/output/ssa___bash_exe.yml index d08353c7bf..c7e5240650 100644 --- a/bin/lolba_enrichment/output/ssa___bash_exe.yml +++ b/bin/lolba_enrichment/output/ssa___bash_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Bash exe LOLBAS in Non Standard Path -id: d47efd9c-2e31-4d38-ab95-c7db6908106b +id: 57bb8624-26b3-4d23-a35c-17d5b2fa03b2 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___bitsadmin_exe.yml b/bin/lolba_enrichment/output/ssa___bitsadmin_exe.yml index 08daf01d58..28c34ff8f6 100644 --- a/bin/lolba_enrichment/output/ssa___bitsadmin_exe.yml +++ b/bin/lolba_enrichment/output/ssa___bitsadmin_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Bitsadmin exe LOLBAS in Non Standard Path -id: 69e7e9bb-e08e-4972-9140-9adb08ebe199 +id: 919cfed5-71e3-4b56-8468-bfa0f8e48763 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___cdb_exe.yml b/bin/lolba_enrichment/output/ssa___cdb_exe.yml index f9954ffd75..2b30081933 100644 --- a/bin/lolba_enrichment/output/ssa___cdb_exe.yml +++ b/bin/lolba_enrichment/output/ssa___cdb_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Cdb exe LOLBAS in Non Standard Path -id: 4f0445e8-3d5a-470b-925c-b76f3eff60ee +id: 438a17bb-ffad-4540-a92b-c82177b6c584 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___certoc_exe.yml b/bin/lolba_enrichment/output/ssa___certoc_exe.yml index fd767a37b9..147ca4b649 100644 --- a/bin/lolba_enrichment/output/ssa___certoc_exe.yml +++ b/bin/lolba_enrichment/output/ssa___certoc_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Certoc exe LOLBAS in Non Standard Path -id: 6e8f20ff-265a-46b8-9681-e8442178b09c +id: 46e1d51f-2979-42e4-8397-63abb398fe71 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___certreq_exe.yml b/bin/lolba_enrichment/output/ssa___certreq_exe.yml index bbc9afbc20..6a3c312490 100644 --- a/bin/lolba_enrichment/output/ssa___certreq_exe.yml +++ b/bin/lolba_enrichment/output/ssa___certreq_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Certreq exe LOLBAS in Non Standard Path -id: 6c0ab09e-2be3-4fd0-b887-60240a68fb16 +id: 3b322498-f89c-4407-a43d-3218f5debbc5 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___certutil_exe.yml b/bin/lolba_enrichment/output/ssa___certutil_exe.yml index 4efb879969..6b8c2b9662 100644 --- a/bin/lolba_enrichment/output/ssa___certutil_exe.yml +++ b/bin/lolba_enrichment/output/ssa___certutil_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Certutil exe LOLBAS in Non Standard Path -id: 8402b60f-0a97-4d58-a927-bc4b1b04112c +id: 9de4a1d7-65bf-4a6f-b25f-c926570c6543 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___cl_invocation_ps1.yml b/bin/lolba_enrichment/output/ssa___cl_invocation_ps1.yml index 4a8106c174..3f2df5f68e 100644 --- a/bin/lolba_enrichment/output/ssa___cl_invocation_ps1.yml +++ b/bin/lolba_enrichment/output/ssa___cl_invocation_ps1.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Cl_invocation ps1 LOLBAS in Non Standard Path -id: 49630b63-7407-4a0b-b9c1-13741db4a2e4 +id: b84023f7-4fc9-429e-bb10-ab19095041f1 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___cl_loadassembly_ps1.yml b/bin/lolba_enrichment/output/ssa___cl_loadassembly_ps1.yml index 625600e26c..ecc26bbad8 100644 --- a/bin/lolba_enrichment/output/ssa___cl_loadassembly_ps1.yml +++ b/bin/lolba_enrichment/output/ssa___cl_loadassembly_ps1.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Cl_loadassembly ps1 LOLBAS in Non Standard Path -id: 80dae1e3-ed8e-4abf-b62b-b322d4d7eb3b +id: a32d2585-a516-4808-a130-92f480c55988 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___cl_mutexverifiers_ps1.yml b/bin/lolba_enrichment/output/ssa___cl_mutexverifiers_ps1.yml index 01465b7f3b..13a48df69d 100644 --- a/bin/lolba_enrichment/output/ssa___cl_mutexverifiers_ps1.yml +++ b/bin/lolba_enrichment/output/ssa___cl_mutexverifiers_ps1.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Cl_mutexverifiers ps1 LOLBAS in Non Standard Path -id: 4a98b0d1-88c0-4234-8d2a-44cbfe7f70b6 +id: 53c3b8a2-9e6c-4b34-8bf3-c76fd4fcacf3 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___cmd_exe.yml b/bin/lolba_enrichment/output/ssa___cmd_exe.yml index e2d4c67f11..eca2603dd2 100644 --- a/bin/lolba_enrichment/output/ssa___cmd_exe.yml +++ b/bin/lolba_enrichment/output/ssa___cmd_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Cmd exe LOLBAS in Non Standard Path -id: eddf68bb-7442-465f-aca6-d6be8c029781 +id: 90784ffc-3576-45d7-bb16-d62f6120c4e5 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___cmdkey_exe.yml b/bin/lolba_enrichment/output/ssa___cmdkey_exe.yml index e7f4558a2e..04b9786dcb 100644 --- a/bin/lolba_enrichment/output/ssa___cmdkey_exe.yml +++ b/bin/lolba_enrichment/output/ssa___cmdkey_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Cmdkey exe LOLBAS in Non Standard Path -id: 3a46ac20-f603-40e3-a4f3-a77aded3305b +id: 304b4002-dfad-422e-93b7-bb6e9a490513 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___cmdl32_exe.yml b/bin/lolba_enrichment/output/ssa___cmdl32_exe.yml index 4875c05dd7..9f4e8297c4 100644 --- a/bin/lolba_enrichment/output/ssa___cmdl32_exe.yml +++ b/bin/lolba_enrichment/output/ssa___cmdl32_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Cmdl32 exe LOLBAS in Non Standard Path -id: f9ea7424-1805-4b7c-828e-97564b96a08d +id: 10de5e76-a676-4149-a949-1132b117a11a version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___cmstp_exe.yml b/bin/lolba_enrichment/output/ssa___cmstp_exe.yml index 313ccb5a4b..4c1a4d3d6b 100644 --- a/bin/lolba_enrichment/output/ssa___cmstp_exe.yml +++ b/bin/lolba_enrichment/output/ssa___cmstp_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Cmstp exe LOLBAS in Non Standard Path -id: f473e060-a390-4567-9a4d-99cbde81da79 +id: c7cb13df-b234-4654-86c6-9a35c930de42 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___comsvcs_dll.yml b/bin/lolba_enrichment/output/ssa___comsvcs_dll.yml index 2f8d640e9e..79f6f17a2a 100644 --- a/bin/lolba_enrichment/output/ssa___comsvcs_dll.yml +++ b/bin/lolba_enrichment/output/ssa___comsvcs_dll.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Comsvcs dll LOLBAS in Non Standard Path -id: 8035fb1d-f610-4b54-9d1e-dcaca3ca06af +id: 3b4d71e9-ceb0-48ea-b1c1-a62dd66b9f66 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___configsecuritypolicy_exe.yml b/bin/lolba_enrichment/output/ssa___configsecuritypolicy_exe.yml index 14e5b277b2..6c8c4ca48b 100644 --- a/bin/lolba_enrichment/output/ssa___configsecuritypolicy_exe.yml +++ b/bin/lolba_enrichment/output/ssa___configsecuritypolicy_exe.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Configsecuritypolicy exe LOLBAS in Non Standard Path -id: 28427e48-405d-4d0d-8bb5-851dbe3a14f2 +id: 2212344c-5a19-4907-b561-b91832c54fa8 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___conhost_exe.yml b/bin/lolba_enrichment/output/ssa___conhost_exe.yml index 6802662c96..f70c714118 100644 --- a/bin/lolba_enrichment/output/ssa___conhost_exe.yml +++ b/bin/lolba_enrichment/output/ssa___conhost_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Conhost exe LOLBAS in Non Standard Path -id: 18c2d6d3-8712-49d2-b3ff-3950131ce8da +id: d1c99845-9762-4da4-b30e-7fbf05304baf version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___control_exe.yml b/bin/lolba_enrichment/output/ssa___control_exe.yml index 0d6ce8864d..f910bc9a2a 100644 --- a/bin/lolba_enrichment/output/ssa___control_exe.yml +++ b/bin/lolba_enrichment/output/ssa___control_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Control exe LOLBAS in Non Standard Path -id: de93877e-1926-4a57-93c7-ccc9110177ad +id: 8f4b0432-e5cd-434e-a87d-bffa2e936adb version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___coregen_exe.yml b/bin/lolba_enrichment/output/ssa___coregen_exe.yml index 4ca849f406..8e101dcfcd 100644 --- a/bin/lolba_enrichment/output/ssa___coregen_exe.yml +++ b/bin/lolba_enrichment/output/ssa___coregen_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Coregen exe LOLBAS in Non Standard Path -id: 3557c88c-e036-47b2-9516-cad111189568 +id: 5964991e-0c6e-4fb1-b9f3-acae15fd9858 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___csc_exe.yml b/bin/lolba_enrichment/output/ssa___csc_exe.yml index f447376cd6..bd59370849 100644 --- a/bin/lolba_enrichment/output/ssa___csc_exe.yml +++ b/bin/lolba_enrichment/output/ssa___csc_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Csc exe LOLBAS in Non Standard Path -id: acfeacea-5688-4f5a-b71a-572eccb9ea0b +id: ea783c88-d20f-461b-a295-cf1a87bd8502 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___cscript_exe.yml b/bin/lolba_enrichment/output/ssa___cscript_exe.yml index a54ddea9ab..12ed01dc0b 100644 --- a/bin/lolba_enrichment/output/ssa___cscript_exe.yml +++ b/bin/lolba_enrichment/output/ssa___cscript_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Cscript exe LOLBAS in Non Standard Path -id: afe8315c-ada9-4156-b26c-f64e7bcc6644 +id: dfcc58d1-4f59-42a6-85f9-7ea2085ae8fe version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___csi_exe.yml b/bin/lolba_enrichment/output/ssa___csi_exe.yml index 33ca2fe5ce..7c2ae92dda 100644 --- a/bin/lolba_enrichment/output/ssa___csi_exe.yml +++ b/bin/lolba_enrichment/output/ssa___csi_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Csi exe LOLBAS in Non Standard Path -id: d72eb4a1-d1bd-430e-ac81-54b85e62706b +id: 5258b32a-b811-4323-9e98-4701b8a6295c version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___datasvcutil_exe.yml b/bin/lolba_enrichment/output/ssa___datasvcutil_exe.yml index 76de49c891..08b502d187 100644 --- a/bin/lolba_enrichment/output/ssa___datasvcutil_exe.yml +++ b/bin/lolba_enrichment/output/ssa___datasvcutil_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Datasvcutil exe LOLBAS in Non Standard Path -id: 83f76c3f-8f26-4e75-9841-706b93550561 +id: cf1686f6-516f-4e58-ae86-524e162def2f version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___defaultpack_exe.yml b/bin/lolba_enrichment/output/ssa___defaultpack_exe.yml index 9867d62827..af1a399b05 100644 --- a/bin/lolba_enrichment/output/ssa___defaultpack_exe.yml +++ b/bin/lolba_enrichment/output/ssa___defaultpack_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Defaultpack exe LOLBAS in Non Standard Path -id: 1f0f4073-a44b-4d0a-831c-8678ad0ba107 +id: 640aa341-73f5-4958-8d44-7d4171af8862 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___desk_cpl.yml b/bin/lolba_enrichment/output/ssa___desk_cpl.yml index 546ca3923c..ac285e6ad9 100644 --- a/bin/lolba_enrichment/output/ssa___desk_cpl.yml +++ b/bin/lolba_enrichment/output/ssa___desk_cpl.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Desk cpl LOLBAS in Non Standard Path -id: e6b350d8-a238-4a31-8521-1353c9639aa0 +id: 7f6caf3f-0f0f-4c3e-ba8b-04664bc12771 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___desktopimgdownldr_exe.yml b/bin/lolba_enrichment/output/ssa___desktopimgdownldr_exe.yml index e01ef25618..273f045bb3 100644 --- a/bin/lolba_enrichment/output/ssa___desktopimgdownldr_exe.yml +++ b/bin/lolba_enrichment/output/ssa___desktopimgdownldr_exe.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Desktopimgdownldr exe LOLBAS in Non Standard Path -id: 3a77606b-d07b-4aff-8901-8337b72b1597 +id: c9f3d074-f077-4d98-9eec-f9e3629e5e58 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___devtoolslauncher_exe.yml b/bin/lolba_enrichment/output/ssa___devtoolslauncher_exe.yml index 2fcf7e51b1..8910c5970c 100644 --- a/bin/lolba_enrichment/output/ssa___devtoolslauncher_exe.yml +++ b/bin/lolba_enrichment/output/ssa___devtoolslauncher_exe.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Devtoolslauncher exe LOLBAS in Non Standard Path -id: c502882c-44ab-4556-ba3c-c9bec806ff3f +id: 989eef3d-36d4-4b83-a004-94f7f171e529 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___dfshim_dll.yml b/bin/lolba_enrichment/output/ssa___dfshim_dll.yml index aba55458b5..72a429597c 100644 --- a/bin/lolba_enrichment/output/ssa___dfshim_dll.yml +++ b/bin/lolba_enrichment/output/ssa___dfshim_dll.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Dfshim dll LOLBAS in Non Standard Path -id: 31d997d3-d28b-4bd5-b368-066fe410c699 +id: 2615f2e9-0f34-4106-b649-7a5ff5644f9f version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___dfsvc_exe.yml b/bin/lolba_enrichment/output/ssa___dfsvc_exe.yml index 6e731cdd5a..922e10f6f6 100644 --- a/bin/lolba_enrichment/output/ssa___dfsvc_exe.yml +++ b/bin/lolba_enrichment/output/ssa___dfsvc_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Dfsvc exe LOLBAS in Non Standard Path -id: 91272b91-c17a-4be7-a85e-6fae80ef124a +id: 0bf3fa5b-e25a-476b-8474-61ad82e4d82c version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___diantz_exe.yml b/bin/lolba_enrichment/output/ssa___diantz_exe.yml index beaee4c945..302f4fbb34 100644 --- a/bin/lolba_enrichment/output/ssa___diantz_exe.yml +++ b/bin/lolba_enrichment/output/ssa___diantz_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Diantz exe LOLBAS in Non Standard Path -id: 118c96e6-f3bf-4217-a2ee-9eba800eb91d +id: 09bcd983-9735-45e7-9bdd-a78f4557954d version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___diskshadow_exe.yml b/bin/lolba_enrichment/output/ssa___diskshadow_exe.yml index 41e2cef22a..677184699e 100644 --- a/bin/lolba_enrichment/output/ssa___diskshadow_exe.yml +++ b/bin/lolba_enrichment/output/ssa___diskshadow_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Diskshadow exe LOLBAS in Non Standard Path -id: 3c2a10c5-bb47-49f8-bc2e-1894291e2526 +id: 38ce0449-88f2-47c6-b6bd-0619f674a33d version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___dnscmd_exe.yml b/bin/lolba_enrichment/output/ssa___dnscmd_exe.yml index ead05a56d8..7d40b940bd 100644 --- a/bin/lolba_enrichment/output/ssa___dnscmd_exe.yml +++ b/bin/lolba_enrichment/output/ssa___dnscmd_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Dnscmd exe LOLBAS in Non Standard Path -id: ccdf5719-a825-4a66-8276-b6ef5c74cc3d +id: 9972c51f-0b1e-4dff-8341-678520c4ddf8 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___dotnet_exe.yml b/bin/lolba_enrichment/output/ssa___dotnet_exe.yml index 01810e19b4..d9e70b789e 100644 --- a/bin/lolba_enrichment/output/ssa___dotnet_exe.yml +++ b/bin/lolba_enrichment/output/ssa___dotnet_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Dotnet exe LOLBAS in Non Standard Path -id: 5ec76143-7216-4fdc-a4cc-3c9d6a7568ea +id: 083ee82a-4880-4561-b781-6aded01e73f1 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___dump64_exe.yml b/bin/lolba_enrichment/output/ssa___dump64_exe.yml index 9dae64ac1b..40ef943ec8 100644 --- a/bin/lolba_enrichment/output/ssa___dump64_exe.yml +++ b/bin/lolba_enrichment/output/ssa___dump64_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Dump64 exe LOLBAS in Non Standard Path -id: 76ffd818-0875-4a66-af22-f5593839b518 +id: c9742210-66ea-4ed1-a3c0-575bfa2ca17a version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___dxcap_exe.yml b/bin/lolba_enrichment/output/ssa___dxcap_exe.yml index 6d23635d2b..f2d71e4ba2 100644 --- a/bin/lolba_enrichment/output/ssa___dxcap_exe.yml +++ b/bin/lolba_enrichment/output/ssa___dxcap_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Dxcap exe LOLBAS in Non Standard Path -id: 200434f5-1166-4a81-ae29-b9896a2d0ad7 +id: 5078946b-8127-4250-8eab-8d57e3d7f098 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___esentutl_exe.yml b/bin/lolba_enrichment/output/ssa___esentutl_exe.yml index bdcee67fe5..e974da985f 100644 --- a/bin/lolba_enrichment/output/ssa___esentutl_exe.yml +++ b/bin/lolba_enrichment/output/ssa___esentutl_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Esentutl exe LOLBAS in Non Standard Path -id: 91324284-cad8-4f47-a740-749f12aafe55 +id: 3ca5f24f-44ef-466b-a5c6-6cdc873b0691 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___eventvwr_exe.yml b/bin/lolba_enrichment/output/ssa___eventvwr_exe.yml index bb331a9132..a36e98a37c 100644 --- a/bin/lolba_enrichment/output/ssa___eventvwr_exe.yml +++ b/bin/lolba_enrichment/output/ssa___eventvwr_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Eventvwr exe LOLBAS in Non Standard Path -id: 3510501d-efb0-4757-8f89-d36e803d32ba +id: a59816c5-c95a-4695-b9f9-654d7b36ebfb version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___excel_exe.yml b/bin/lolba_enrichment/output/ssa___excel_exe.yml index 9a7004daca..d0c87c6c35 100644 --- a/bin/lolba_enrichment/output/ssa___excel_exe.yml +++ b/bin/lolba_enrichment/output/ssa___excel_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Excel exe LOLBAS in Non Standard Path -id: c4a66592-3896-47e6-8727-7a769c171a2e +id: 3cb8bfea-8c07-4f69-8761-98700d3150e9 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___expand_exe.yml b/bin/lolba_enrichment/output/ssa___expand_exe.yml index c52403ef48..0ed712bedd 100644 --- a/bin/lolba_enrichment/output/ssa___expand_exe.yml +++ b/bin/lolba_enrichment/output/ssa___expand_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Expand exe LOLBAS in Non Standard Path -id: 6a93a1f4-4506-43ad-a235-10df7ac68827 +id: 1c8ccd46-9837-49b5-979e-f857d7d9ef03 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___explorer_exe.yml b/bin/lolba_enrichment/output/ssa___explorer_exe.yml index 0e04ecd9f6..28258fe4d1 100644 --- a/bin/lolba_enrichment/output/ssa___explorer_exe.yml +++ b/bin/lolba_enrichment/output/ssa___explorer_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Explorer exe LOLBAS in Non Standard Path -id: 1ffa5de9-97a8-4f22-af89-5f574a328207 +id: 1b95b89f-16cf-4cb6-b027-3a98c3bbfd9d version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___extexport_exe.yml b/bin/lolba_enrichment/output/ssa___extexport_exe.yml index 14ea16f956..2bec8442a7 100644 --- a/bin/lolba_enrichment/output/ssa___extexport_exe.yml +++ b/bin/lolba_enrichment/output/ssa___extexport_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Extexport exe LOLBAS in Non Standard Path -id: fb84ddd5-5736-4f41-8479-74484a45f050 +id: 6271e582-73b7-4eaa-8293-37cb70bf5082 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___extrac32_exe.yml b/bin/lolba_enrichment/output/ssa___extrac32_exe.yml index 5b7b98ab5c..3b38e12ba4 100644 --- a/bin/lolba_enrichment/output/ssa___extrac32_exe.yml +++ b/bin/lolba_enrichment/output/ssa___extrac32_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Extrac32 exe LOLBAS in Non Standard Path -id: 3e302ff2-d2c6-4a70-b9e0-3f4b4dead4e6 +id: 88e5cd66-11c0-49ca-ad84-e8207f2995fc version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___findstr_exe.yml b/bin/lolba_enrichment/output/ssa___findstr_exe.yml index 7c50ad602c..b5d7ed3f69 100644 --- a/bin/lolba_enrichment/output/ssa___findstr_exe.yml +++ b/bin/lolba_enrichment/output/ssa___findstr_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Findstr exe LOLBAS in Non Standard Path -id: f516a212-56ea-463e-bdf0-292699098d86 +id: a46647a3-97e4-40fb-84b0-09d5e3b00ad0 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___finger_exe.yml b/bin/lolba_enrichment/output/ssa___finger_exe.yml index a43103cccd..6842bb3bb2 100644 --- a/bin/lolba_enrichment/output/ssa___finger_exe.yml +++ b/bin/lolba_enrichment/output/ssa___finger_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Finger exe LOLBAS in Non Standard Path -id: b16dc603-5b05-4d67-81b8-d609edfa5cdf +id: 1d59e315-3933-4dba-8ada-dc7adc2043d4 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___fltmc_exe.yml b/bin/lolba_enrichment/output/ssa___fltmc_exe.yml index e63de55799..6b5ad3c45f 100644 --- a/bin/lolba_enrichment/output/ssa___fltmc_exe.yml +++ b/bin/lolba_enrichment/output/ssa___fltmc_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Fltmc exe LOLBAS in Non Standard Path -id: 84024943-d316-4992-9b0b-1e7cfd1f0524 +id: 3a47909d-b5b8-4ff2-83d6-04976fe889dd version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___forfiles_exe.yml b/bin/lolba_enrichment/output/ssa___forfiles_exe.yml index d8ac00867d..de3832e1c9 100644 --- a/bin/lolba_enrichment/output/ssa___forfiles_exe.yml +++ b/bin/lolba_enrichment/output/ssa___forfiles_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Forfiles exe LOLBAS in Non Standard Path -id: 5189854a-6766-45a3-8fd5-cc06c476f878 +id: 51687bfe-5c7a-4fbc-8a4a-4ae0322e2add version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___fsi_exe.yml b/bin/lolba_enrichment/output/ssa___fsi_exe.yml index 8546647315..efee0fc13d 100644 --- a/bin/lolba_enrichment/output/ssa___fsi_exe.yml +++ b/bin/lolba_enrichment/output/ssa___fsi_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Fsi exe LOLBAS in Non Standard Path -id: 40596539-81b1-43aa-85f1-6bb7bee45930 +id: 10219cc2-89a3-4566-b682-d7e01b6bdfb6 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___fsianycpu_exe.yml b/bin/lolba_enrichment/output/ssa___fsianycpu_exe.yml index 799f3d5f83..074cefbb91 100644 --- a/bin/lolba_enrichment/output/ssa___fsianycpu_exe.yml +++ b/bin/lolba_enrichment/output/ssa___fsianycpu_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Fsianycpu exe LOLBAS in Non Standard Path -id: 3ea3b7e3-ac4b-4c9e-b605-d7b3ef6091cb +id: c1c3eeaa-90a6-4ae7-b48d-1ae233a515fe version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___ftp_exe.yml b/bin/lolba_enrichment/output/ssa___ftp_exe.yml index e342424adb..9749c4b193 100644 --- a/bin/lolba_enrichment/output/ssa___ftp_exe.yml +++ b/bin/lolba_enrichment/output/ssa___ftp_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Ftp exe LOLBAS in Non Standard Path -id: 083d3948-85f8-4460-a613-afa5aa89c81a +id: 589f706c-bc5f-4fdd-9d48-c70c599236b5 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___gfxdownloadwrapper_exe.yml b/bin/lolba_enrichment/output/ssa___gfxdownloadwrapper_exe.yml index 5bc277f534..bc412d0c4d 100644 --- a/bin/lolba_enrichment/output/ssa___gfxdownloadwrapper_exe.yml +++ b/bin/lolba_enrichment/output/ssa___gfxdownloadwrapper_exe.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Gfxdownloadwrapper exe LOLBAS in Non Standard Path -id: 7ef96cdf-d856-4ebc-8937-702d41158d79 +id: 3ed5ff81-7f18-4bf5-b6a9-38cf256d6217 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___gpscript_exe.yml b/bin/lolba_enrichment/output/ssa___gpscript_exe.yml index a6d0c9a9cf..9a712e7d58 100644 --- a/bin/lolba_enrichment/output/ssa___gpscript_exe.yml +++ b/bin/lolba_enrichment/output/ssa___gpscript_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Gpscript exe LOLBAS in Non Standard Path -id: 8dee5018-e8c5-4cbe-a031-7bd5e76de467 +id: 09326d45-46bd-4f26-8158-1b73b26e2c24 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___hh_exe.yml b/bin/lolba_enrichment/output/ssa___hh_exe.yml index b42e05d50d..11b8131659 100644 --- a/bin/lolba_enrichment/output/ssa___hh_exe.yml +++ b/bin/lolba_enrichment/output/ssa___hh_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Hh exe LOLBAS in Non Standard Path -id: f9a6eccb-a77c-4322-9263-cb587438f0ec +id: 1aa89968-690e-483d-8d76-1dd214185741 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___ie4uinit_exe.yml b/bin/lolba_enrichment/output/ssa___ie4uinit_exe.yml index 5c6b49af8d..a2c9f0aa97 100644 --- a/bin/lolba_enrichment/output/ssa___ie4uinit_exe.yml +++ b/bin/lolba_enrichment/output/ssa___ie4uinit_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Ie4uinit exe LOLBAS in Non Standard Path -id: 8e47e7fd-616a-49b8-b97d-3132f18cff02 +id: 09e2fffa-ad65-40ed-afff-433b80b4bd07 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___ieadvpack_dll.yml b/bin/lolba_enrichment/output/ssa___ieadvpack_dll.yml index 3d2471de33..277246f9fe 100644 --- a/bin/lolba_enrichment/output/ssa___ieadvpack_dll.yml +++ b/bin/lolba_enrichment/output/ssa___ieadvpack_dll.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Ieadvpack dll LOLBAS in Non Standard Path -id: befc38d7-5566-4b7a-aed3-7e77cda85a90 +id: ce1a96d5-64b3-465f-a300-e6d720157219 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___ieexec_exe.yml b/bin/lolba_enrichment/output/ssa___ieexec_exe.yml index 9f23587c09..a9f873008e 100644 --- a/bin/lolba_enrichment/output/ssa___ieexec_exe.yml +++ b/bin/lolba_enrichment/output/ssa___ieexec_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Ieexec exe LOLBAS in Non Standard Path -id: 9c442fca-d43f-4419-b9f7-e86706902e3d +id: 2e2c29d5-5f4b-4ad5-91b2-1c8d41b77277 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___ieframe_dll.yml b/bin/lolba_enrichment/output/ssa___ieframe_dll.yml index f76152f99e..50aca1b89e 100644 --- a/bin/lolba_enrichment/output/ssa___ieframe_dll.yml +++ b/bin/lolba_enrichment/output/ssa___ieframe_dll.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Ieframe dll LOLBAS in Non Standard Path -id: deb510e0-d338-499a-9333-ae6a92bbe1ee +id: 1a45dbdf-97f4-43cd-9620-5cac48faab8d version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___ilasm_exe.yml b/bin/lolba_enrichment/output/ssa___ilasm_exe.yml index 242e34d53d..5f1a941837 100644 --- a/bin/lolba_enrichment/output/ssa___ilasm_exe.yml +++ b/bin/lolba_enrichment/output/ssa___ilasm_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Ilasm exe LOLBAS in Non Standard Path -id: 754eb562-8a5a-44d5-a36d-b98304db0ddc +id: 1fbc75a1-33af-48e0-9199-e716b2bb29cc version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___imewdbld_exe.yml b/bin/lolba_enrichment/output/ssa___imewdbld_exe.yml index 7b19972e85..f254cfde18 100644 --- a/bin/lolba_enrichment/output/ssa___imewdbld_exe.yml +++ b/bin/lolba_enrichment/output/ssa___imewdbld_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Imewdbld exe LOLBAS in Non Standard Path -id: 65bc00f8-acd2-4c3a-8bc9-6b70067fe179 +id: d0a64b6d-7d06-4c04-99e9-04c497a94264 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___infdefaultinstall_exe.yml b/bin/lolba_enrichment/output/ssa___infdefaultinstall_exe.yml index 62909e9333..57d8d79d83 100644 --- a/bin/lolba_enrichment/output/ssa___infdefaultinstall_exe.yml +++ b/bin/lolba_enrichment/output/ssa___infdefaultinstall_exe.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Infdefaultinstall exe LOLBAS in Non Standard Path -id: ed336a3b-3940-4fa5-b2d3-1a70255b6b7e +id: d53987d7-ae11-4032-b958-fcc434d72ff9 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___installutil_exe.yml b/bin/lolba_enrichment/output/ssa___installutil_exe.yml index f3a7ca5495..5c617ab1ce 100644 --- a/bin/lolba_enrichment/output/ssa___installutil_exe.yml +++ b/bin/lolba_enrichment/output/ssa___installutil_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Installutil exe LOLBAS in Non Standard Path -id: 3940d2f5-34b5-4568-af6d-adae72fca9dc +id: 204af1e5-1473-4686-a2d4-5d5fd2a9b232 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___jsc_exe.yml b/bin/lolba_enrichment/output/ssa___jsc_exe.yml index dc6a3eb9ac..03c2b4a8c9 100644 --- a/bin/lolba_enrichment/output/ssa___jsc_exe.yml +++ b/bin/lolba_enrichment/output/ssa___jsc_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Jsc exe LOLBAS in Non Standard Path -id: 359b9d0d-3927-4bfd-ac25-83a47cd86c10 +id: 666474aa-ed53-47bc-a6f9-fb9e59fa2e2d version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___makecab_exe.yml b/bin/lolba_enrichment/output/ssa___makecab_exe.yml index e4bc2388a2..5c651d1f01 100644 --- a/bin/lolba_enrichment/output/ssa___makecab_exe.yml +++ b/bin/lolba_enrichment/output/ssa___makecab_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Makecab exe LOLBAS in Non Standard Path -id: 1be3fe66-eb96-40e9-ac6b-372c863411de +id: 6dee426a-b2d0-4bc7-aedc-405d0e7b1bf0 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___manage-bde_wsf.yml b/bin/lolba_enrichment/output/ssa___manage-bde_wsf.yml index d915766524..f483f73e5c 100644 --- a/bin/lolba_enrichment/output/ssa___manage-bde_wsf.yml +++ b/bin/lolba_enrichment/output/ssa___manage-bde_wsf.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Manage-bde wsf LOLBAS in Non Standard Path -id: 66a535f0-3de0-47a8-ad0f-351a31d1a765 +id: 54c4ee98-046c-42c8-b300-fd408f66b576 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___mavinject_exe.yml b/bin/lolba_enrichment/output/ssa___mavinject_exe.yml index ea1524ab95..cfa855e0b9 100644 --- a/bin/lolba_enrichment/output/ssa___mavinject_exe.yml +++ b/bin/lolba_enrichment/output/ssa___mavinject_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Mavinject exe LOLBAS in Non Standard Path -id: b75786ad-5306-4c7f-ad39-f1cc072c2114 +id: d9bc0697-fdd6-4f96-bf7b-563f31a0e7ba version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___mftrace_exe.yml b/bin/lolba_enrichment/output/ssa___mftrace_exe.yml index 8a69b725f4..a9af2f828a 100644 --- a/bin/lolba_enrichment/output/ssa___mftrace_exe.yml +++ b/bin/lolba_enrichment/output/ssa___mftrace_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Mftrace exe LOLBAS in Non Standard Path -id: 59b6dd12-ad92-4c23-9382-a71018dd49cd +id: 59698f8b-0dd3-4ec9-b0ed-4c277d9cd73f version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___microsoft_workflow_compiler_exe.yml b/bin/lolba_enrichment/output/ssa___microsoft_workflow_compiler_exe.yml index 7579c1f623..3c7d3c1982 100644 --- a/bin/lolba_enrichment/output/ssa___microsoft_workflow_compiler_exe.yml +++ b/bin/lolba_enrichment/output/ssa___microsoft_workflow_compiler_exe.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Microsoft workflow compiler exe LOLBAS in Non Standard Path -id: d91f6bc2-dea6-4e15-9794-eae0518c9b55 +id: 63fbf81a-f2a7-4ea6-98a3-54771f75d989 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___mmc_exe.yml b/bin/lolba_enrichment/output/ssa___mmc_exe.yml index 218a6634b8..523d428d45 100644 --- a/bin/lolba_enrichment/output/ssa___mmc_exe.yml +++ b/bin/lolba_enrichment/output/ssa___mmc_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Mmc exe LOLBAS in Non Standard Path -id: ea408a87-9613-4856-96ae-c87e77c2777d +id: 17e6ced3-8c95-4068-abb6-da08449c25d5 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___mpcmdrun_exe.yml b/bin/lolba_enrichment/output/ssa___mpcmdrun_exe.yml index c8a2559205..ad4a41e4c2 100644 --- a/bin/lolba_enrichment/output/ssa___mpcmdrun_exe.yml +++ b/bin/lolba_enrichment/output/ssa___mpcmdrun_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Mpcmdrun exe LOLBAS in Non Standard Path -id: a6de19ec-7aba-43d3-a692-d2257eaaa221 +id: 51639291-3360-497a-bd74-a776e6df0e2e version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___msbuild_exe.yml b/bin/lolba_enrichment/output/ssa___msbuild_exe.yml index 530eee184a..9db1f8e537 100644 --- a/bin/lolba_enrichment/output/ssa___msbuild_exe.yml +++ b/bin/lolba_enrichment/output/ssa___msbuild_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Msbuild exe LOLBAS in Non Standard Path -id: cb765ec2-f449-4e26-8852-ae5a068020bc +id: d2c831e7-d40c-4457-83d7-5b0c6b31ca6c version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___msconfig_exe.yml b/bin/lolba_enrichment/output/ssa___msconfig_exe.yml index e5435faaf6..346bbacc90 100644 --- a/bin/lolba_enrichment/output/ssa___msconfig_exe.yml +++ b/bin/lolba_enrichment/output/ssa___msconfig_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Msconfig exe LOLBAS in Non Standard Path -id: 0d42b215-dfd4-4f09-b6f8-cc51b94c726a +id: d35eb933-8473-4265-ad98-f5998e6f75d6 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___msdeploy_exe.yml b/bin/lolba_enrichment/output/ssa___msdeploy_exe.yml index 3024b2824f..258478efff 100644 --- a/bin/lolba_enrichment/output/ssa___msdeploy_exe.yml +++ b/bin/lolba_enrichment/output/ssa___msdeploy_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Msdeploy exe LOLBAS in Non Standard Path -id: 942dcb56-8f11-4e26-afea-5f3c795723e2 +id: 0ac4bd64-94d1-4dc7-82ce-ce2fe424cb0e version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___msdt_exe.yml b/bin/lolba_enrichment/output/ssa___msdt_exe.yml index a9bb72da2e..62b4b9784a 100644 --- a/bin/lolba_enrichment/output/ssa___msdt_exe.yml +++ b/bin/lolba_enrichment/output/ssa___msdt_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Msdt exe LOLBAS in Non Standard Path -id: c5056ba2-6b1f-4272-a92b-2dca08a8f98a +id: 363d3d99-a83f-4108-992c-c059e93573ad version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___mshta_exe.yml b/bin/lolba_enrichment/output/ssa___mshta_exe.yml index 3214952646..8d18dfc13b 100644 --- a/bin/lolba_enrichment/output/ssa___mshta_exe.yml +++ b/bin/lolba_enrichment/output/ssa___mshta_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Mshta exe LOLBAS in Non Standard Path -id: d1c46649-8b38-4b8a-9149-320c9ab7dd3f +id: 8a6ed35c-b70f-4f8f-8220-6dc93dc837a1 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___mshtml_dll.yml b/bin/lolba_enrichment/output/ssa___mshtml_dll.yml index ee7f1d402a..7950052e85 100644 --- a/bin/lolba_enrichment/output/ssa___mshtml_dll.yml +++ b/bin/lolba_enrichment/output/ssa___mshtml_dll.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Mshtml dll LOLBAS in Non Standard Path -id: 8e2051c3-8af9-408e-92f9-e1bac4dc6077 +id: 716484b0-ca55-4f93-9ba8-0e7de3f354fc version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___msiexec_exe.yml b/bin/lolba_enrichment/output/ssa___msiexec_exe.yml index c760671a7e..f9811f955b 100644 --- a/bin/lolba_enrichment/output/ssa___msiexec_exe.yml +++ b/bin/lolba_enrichment/output/ssa___msiexec_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Msiexec exe LOLBAS in Non Standard Path -id: 7fb47baf-fc9d-48ff-8a11-90696b9a10e1 +id: 5141dbfe-f28f-43c4-b241-58b8683f7853 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___netsh_exe.yml b/bin/lolba_enrichment/output/ssa___netsh_exe.yml index 2c242bfc6e..320355c2a8 100644 --- a/bin/lolba_enrichment/output/ssa___netsh_exe.yml +++ b/bin/lolba_enrichment/output/ssa___netsh_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Netsh exe LOLBAS in Non Standard Path -id: 031f33d2-2885-4636-a4cd-b6a6fe486219 +id: a3aa5f0b-5e64-40ce-9251-9502bc0782c5 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___ntdsutil_exe.yml b/bin/lolba_enrichment/output/ssa___ntdsutil_exe.yml index 42b090b71d..cc0ae2142d 100644 --- a/bin/lolba_enrichment/output/ssa___ntdsutil_exe.yml +++ b/bin/lolba_enrichment/output/ssa___ntdsutil_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Ntdsutil exe LOLBAS in Non Standard Path -id: cd032dae-ec33-4e4e-8146-19c7c22354ca +id: 3083a087-c7ac-48b3-aa6e-936e8baaa9fc version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___odbcconf_exe.yml b/bin/lolba_enrichment/output/ssa___odbcconf_exe.yml index 1173eb4933..5d48ba3555 100644 --- a/bin/lolba_enrichment/output/ssa___odbcconf_exe.yml +++ b/bin/lolba_enrichment/output/ssa___odbcconf_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Odbcconf exe LOLBAS in Non Standard Path -id: f9071baf-f478-4b27-83ec-e12fc7b314af +id: d8420544-9e5c-4b93-b4de-8b941ff83e3d version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___offlinescannershell_exe.yml b/bin/lolba_enrichment/output/ssa___offlinescannershell_exe.yml index 84cd333369..9432633440 100644 --- a/bin/lolba_enrichment/output/ssa___offlinescannershell_exe.yml +++ b/bin/lolba_enrichment/output/ssa___offlinescannershell_exe.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Offlinescannershell exe LOLBAS in Non Standard Path -id: 347f7605-bc67-4a52-839e-9b5e459bba36 +id: 3a003375-e207-41ee-987e-5aeef00cb61f version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___pcalua_exe.yml b/bin/lolba_enrichment/output/ssa___pcalua_exe.yml index f010439de5..74d73c1c4d 100644 --- a/bin/lolba_enrichment/output/ssa___pcalua_exe.yml +++ b/bin/lolba_enrichment/output/ssa___pcalua_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Pcalua exe LOLBAS in Non Standard Path -id: fa7fd32d-406f-4055-9f46-e10b3b4b64b7 +id: 1d50072e-23b7-4ba3-b3d7-8344cf167dcd version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___pcwrun_exe.yml b/bin/lolba_enrichment/output/ssa___pcwrun_exe.yml index 4343301196..ec6e26f710 100644 --- a/bin/lolba_enrichment/output/ssa___pcwrun_exe.yml +++ b/bin/lolba_enrichment/output/ssa___pcwrun_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Pcwrun exe LOLBAS in Non Standard Path -id: e3d1aaee-abf8-4d6e-97ac-7b170792d2bb +id: ccf2ac56-7cff-4c9e-87af-d25d66f9dd61 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___pcwutl_dll.yml b/bin/lolba_enrichment/output/ssa___pcwutl_dll.yml index ec9f72466c..934dc35286 100644 --- a/bin/lolba_enrichment/output/ssa___pcwutl_dll.yml +++ b/bin/lolba_enrichment/output/ssa___pcwutl_dll.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Pcwutl dll LOLBAS in Non Standard Path -id: 37212469-2095-4b78-b7f5-b95147740147 +id: 0757b899-ed7e-445a-b67d-c5f297846478 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___pester_bat.yml b/bin/lolba_enrichment/output/ssa___pester_bat.yml index c062322861..36a175ac1c 100644 --- a/bin/lolba_enrichment/output/ssa___pester_bat.yml +++ b/bin/lolba_enrichment/output/ssa___pester_bat.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Pester bat LOLBAS in Non Standard Path -id: 4a3f92cf-2e0b-4919-a9a6-21eff8f7f8a2 +id: aa6db9ce-d51c-4814-b3bd-a48338355387 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___pktmon_exe.yml b/bin/lolba_enrichment/output/ssa___pktmon_exe.yml index bc488961f0..27e9d24b1d 100644 --- a/bin/lolba_enrichment/output/ssa___pktmon_exe.yml +++ b/bin/lolba_enrichment/output/ssa___pktmon_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Pktmon exe LOLBAS in Non Standard Path -id: d5c1e0d6-bd7e-4409-a6b6-e40f6229aa4e +id: e02cf071-cc34-4755-b39a-4f2baaa767d7 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___pnputil_exe.yml b/bin/lolba_enrichment/output/ssa___pnputil_exe.yml index e227df8208..7caf8c4a39 100644 --- a/bin/lolba_enrichment/output/ssa___pnputil_exe.yml +++ b/bin/lolba_enrichment/output/ssa___pnputil_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Pnputil exe LOLBAS in Non Standard Path -id: 9d07ecc7-384a-44e4-ae7a-348d6cb548dd +id: 445364f4-92f4-48fb-8da9-4279202a90f9 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___powerpnt_exe.yml b/bin/lolba_enrichment/output/ssa___powerpnt_exe.yml index 5472a578f8..76b257dca3 100644 --- a/bin/lolba_enrichment/output/ssa___powerpnt_exe.yml +++ b/bin/lolba_enrichment/output/ssa___powerpnt_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Powerpnt exe LOLBAS in Non Standard Path -id: 184e41c3-e35c-48b0-bedd-a9a0940bb624 +id: 459cc44e-61a4-457a-91c2-f3c27295e2a9 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___presentationhost_exe.yml b/bin/lolba_enrichment/output/ssa___presentationhost_exe.yml index 6749704d1e..87f0cbb15b 100644 --- a/bin/lolba_enrichment/output/ssa___presentationhost_exe.yml +++ b/bin/lolba_enrichment/output/ssa___presentationhost_exe.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Presentationhost exe LOLBAS in Non Standard Path -id: 9062fd96-c0c4-4c26-bb5e-62f5e9665f6f +id: 8e8b72de-1db9-4d55-b681-55f3ae32183e version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___print_exe.yml b/bin/lolba_enrichment/output/ssa___print_exe.yml index 9abb77c84d..7592357bf2 100644 --- a/bin/lolba_enrichment/output/ssa___print_exe.yml +++ b/bin/lolba_enrichment/output/ssa___print_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Print exe LOLBAS in Non Standard Path -id: 1b50de1e-2d7c-4748-b3f6-1c7255ad709d +id: a3720c97-9aa4-448d-ad60-8179407e3398 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___printbrm_exe.yml b/bin/lolba_enrichment/output/ssa___printbrm_exe.yml index cea0c98124..2c446518a1 100644 --- a/bin/lolba_enrichment/output/ssa___printbrm_exe.yml +++ b/bin/lolba_enrichment/output/ssa___printbrm_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Printbrm exe LOLBAS in Non Standard Path -id: d5db0481-91d7-412f-ac48-956c9569de05 +id: b3bad5a2-5ad9-49d2-8a42-cee1bd372db8 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___psr_exe.yml b/bin/lolba_enrichment/output/ssa___psr_exe.yml index ac4a524722..40145e4e4d 100644 --- a/bin/lolba_enrichment/output/ssa___psr_exe.yml +++ b/bin/lolba_enrichment/output/ssa___psr_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Psr exe LOLBAS in Non Standard Path -id: b3e328d2-1f6c-4303-9c21-62bdd110dc1f +id: 537f9e80-01d8-4eca-8f43-8fbf0e29a8a9 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___pubprn_vbs.yml b/bin/lolba_enrichment/output/ssa___pubprn_vbs.yml index c85f8d0d80..ff481b3b77 100644 --- a/bin/lolba_enrichment/output/ssa___pubprn_vbs.yml +++ b/bin/lolba_enrichment/output/ssa___pubprn_vbs.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Pubprn vbs LOLBAS in Non Standard Path -id: 40f0aa11-521b-4185-a462-c6482f5f8756 +id: 7d90df95-b47a-4072-88d8-73eb0c484492 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___rasautou_exe.yml b/bin/lolba_enrichment/output/ssa___rasautou_exe.yml index a58a70c831..072a991edc 100644 --- a/bin/lolba_enrichment/output/ssa___rasautou_exe.yml +++ b/bin/lolba_enrichment/output/ssa___rasautou_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Rasautou exe LOLBAS in Non Standard Path -id: c277db1a-7fae-4363-8226-a8b846518dda +id: 6e1fe1e1-9821-4d4a-9d06-947b8e1de376 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___rdrleakdiag_exe.yml b/bin/lolba_enrichment/output/ssa___rdrleakdiag_exe.yml index 8233abf897..f448d4349a 100644 --- a/bin/lolba_enrichment/output/ssa___rdrleakdiag_exe.yml +++ b/bin/lolba_enrichment/output/ssa___rdrleakdiag_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Rdrleakdiag exe LOLBAS in Non Standard Path -id: f4930cbd-542a-4024-b308-228b535a0677 +id: 8b104ba0-f625-4d93-a7ca-45b5fbc26a79 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___reg_exe.yml b/bin/lolba_enrichment/output/ssa___reg_exe.yml index 96615b272b..b4230ba8dd 100644 --- a/bin/lolba_enrichment/output/ssa___reg_exe.yml +++ b/bin/lolba_enrichment/output/ssa___reg_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Reg exe LOLBAS in Non Standard Path -id: b856f9bc-e8b0-44c1-b6f9-4a366822df24 +id: 98d639a5-e4f0-42ac-8bc3-bd7e917606e8 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___regasm_exe.yml b/bin/lolba_enrichment/output/ssa___regasm_exe.yml index a180ac525e..11ccd103d1 100644 --- a/bin/lolba_enrichment/output/ssa___regasm_exe.yml +++ b/bin/lolba_enrichment/output/ssa___regasm_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Regasm exe LOLBAS in Non Standard Path -id: a701c9ab-b703-41da-958e-a223b8d91a35 +id: 2cc40362-a8e3-488c-ab44-1883825b7703 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___regedit_exe.yml b/bin/lolba_enrichment/output/ssa___regedit_exe.yml index 73fba9097c..4da4761c21 100644 --- a/bin/lolba_enrichment/output/ssa___regedit_exe.yml +++ b/bin/lolba_enrichment/output/ssa___regedit_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Regedit exe LOLBAS in Non Standard Path -id: efa1f373-1a42-41c1-b405-d62280d05de9 +id: 35e94749-e4c9-4a7e-8a79-777e30139fcb version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___regini_exe.yml b/bin/lolba_enrichment/output/ssa___regini_exe.yml index bc0887be1c..d3a801d8a0 100644 --- a/bin/lolba_enrichment/output/ssa___regini_exe.yml +++ b/bin/lolba_enrichment/output/ssa___regini_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Regini exe LOLBAS in Non Standard Path -id: 1f047a87-9848-4870-91ea-70c7c0928cd3 +id: 07c8dc15-bd1c-4a4e-b031-708465342007 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___register-cimprovider_exe.yml b/bin/lolba_enrichment/output/ssa___register-cimprovider_exe.yml index 82f7af55ce..67e6619da3 100644 --- a/bin/lolba_enrichment/output/ssa___register-cimprovider_exe.yml +++ b/bin/lolba_enrichment/output/ssa___register-cimprovider_exe.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Register-cimprovider exe LOLBAS in Non Standard Path -id: f68142cd-5264-408f-89a4-dc509fcade9b +id: db893b2f-d317-4547-abb9-e9beed33bdb9 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___regsvcs_exe.yml b/bin/lolba_enrichment/output/ssa___regsvcs_exe.yml index f2a694a330..d5139df9e1 100644 --- a/bin/lolba_enrichment/output/ssa___regsvcs_exe.yml +++ b/bin/lolba_enrichment/output/ssa___regsvcs_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Regsvcs exe LOLBAS in Non Standard Path -id: 1aa72036-2548-4420-9adb-060076e2fe63 +id: f46e6851-9da9-4956-9c16-102a6c4bf0ed version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___regsvr32_exe.yml b/bin/lolba_enrichment/output/ssa___regsvr32_exe.yml index 9ec9ec43a4..b50a9fe156 100644 --- a/bin/lolba_enrichment/output/ssa___regsvr32_exe.yml +++ b/bin/lolba_enrichment/output/ssa___regsvr32_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Regsvr32 exe LOLBAS in Non Standard Path -id: b285ccfc-3dfb-48d0-8774-55da33bc6d8a +id: 080762a3-ee65-44e9-8721-234c2802d8b1 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___remote_exe.yml b/bin/lolba_enrichment/output/ssa___remote_exe.yml index 96578c8cd9..222d9098cf 100644 --- a/bin/lolba_enrichment/output/ssa___remote_exe.yml +++ b/bin/lolba_enrichment/output/ssa___remote_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Remote exe LOLBAS in Non Standard Path -id: 407aa4a9-ce61-451e-a514-2c591811de75 +id: 4d6eade1-7358-4f5b-babf-ecf9c8ad3fa0 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___replace_exe.yml b/bin/lolba_enrichment/output/ssa___replace_exe.yml index d7a30b7872..30e0a0f174 100644 --- a/bin/lolba_enrichment/output/ssa___replace_exe.yml +++ b/bin/lolba_enrichment/output/ssa___replace_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Replace exe LOLBAS in Non Standard Path -id: 830618c0-e655-4405-a895-5cba3506ebda +id: 33b25a32-a963-4d4b-aa50-c4c7fc9a9559 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___rpcping_exe.yml b/bin/lolba_enrichment/output/ssa___rpcping_exe.yml index 27894d076f..3a0560e11b 100644 --- a/bin/lolba_enrichment/output/ssa___rpcping_exe.yml +++ b/bin/lolba_enrichment/output/ssa___rpcping_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Rpcping exe LOLBAS in Non Standard Path -id: 7318c48c-12b1-43a2-a120-e56a495fadc5 +id: c8bec124-4e09-4200-a1c6-8e0e5c036827 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___rundll32_exe.yml b/bin/lolba_enrichment/output/ssa___rundll32_exe.yml index b71b6c930a..c3168a4474 100644 --- a/bin/lolba_enrichment/output/ssa___rundll32_exe.yml +++ b/bin/lolba_enrichment/output/ssa___rundll32_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Rundll32 exe LOLBAS in Non Standard Path -id: e664f2eb-4a3e-4e20-aa7a-8fea36e56a1c +id: fe917b8d-2313-4c4c-8e7c-c0f5a13561fb version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___runonce_exe.yml b/bin/lolba_enrichment/output/ssa___runonce_exe.yml index 51fce4376f..6e02367f2c 100644 --- a/bin/lolba_enrichment/output/ssa___runonce_exe.yml +++ b/bin/lolba_enrichment/output/ssa___runonce_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Runonce exe LOLBAS in Non Standard Path -id: 2d13fc2b-2c15-4f81-b6f6-eb362744502f +id: a0f9a335-8338-4e41-a805-43c97ac887f7 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___runscripthelper_exe.yml b/bin/lolba_enrichment/output/ssa___runscripthelper_exe.yml index fa79b13923..8414e4def9 100644 --- a/bin/lolba_enrichment/output/ssa___runscripthelper_exe.yml +++ b/bin/lolba_enrichment/output/ssa___runscripthelper_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Runscripthelper exe LOLBAS in Non Standard Path -id: c4d404f5-742b-4c9e-b090-338f06b5d418 +id: 6b98c190-a10b-42da-8d2d-de5d31472f28 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___sc_exe.yml b/bin/lolba_enrichment/output/ssa___sc_exe.yml index 4b5805d5b9..6ebd448f10 100644 --- a/bin/lolba_enrichment/output/ssa___sc_exe.yml +++ b/bin/lolba_enrichment/output/ssa___sc_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Sc exe LOLBAS in Non Standard Path -id: 8861e47e-ae44-453f-a562-939ff70feec6 +id: 9c1c1d76-b529-4d27-83d3-72d9100c78ab version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___schtasks_exe.yml b/bin/lolba_enrichment/output/ssa___schtasks_exe.yml index ae491a996e..c55e182e02 100644 --- a/bin/lolba_enrichment/output/ssa___schtasks_exe.yml +++ b/bin/lolba_enrichment/output/ssa___schtasks_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Schtasks exe LOLBAS in Non Standard Path -id: 575bc6fe-83c1-4cd6-924e-3ad2c554e8e2 +id: 737198c8-a3bc-4edd-b449-32e3567859e8 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___scriptrunner_exe.yml b/bin/lolba_enrichment/output/ssa___scriptrunner_exe.yml index c8e42d941c..9a6fc2bb1c 100644 --- a/bin/lolba_enrichment/output/ssa___scriptrunner_exe.yml +++ b/bin/lolba_enrichment/output/ssa___scriptrunner_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Scriptrunner exe LOLBAS in Non Standard Path -id: 4f2ccb1d-32e0-4d7d-9260-4a0b71277cda +id: 04e0eb49-ef99-4a7a-8d3f-680b0a3a1627 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___settingsynchost_exe.yml b/bin/lolba_enrichment/output/ssa___settingsynchost_exe.yml index a69102c397..4a4011eb12 100644 --- a/bin/lolba_enrichment/output/ssa___settingsynchost_exe.yml +++ b/bin/lolba_enrichment/output/ssa___settingsynchost_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Settingsynchost exe LOLBAS in Non Standard Path -id: 3862405e-c6d8-402c-a564-f0fbea82311e +id: 38d81659-0d8a-41be-a8ec-af7e69f2f748 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___setupapi_dll.yml b/bin/lolba_enrichment/output/ssa___setupapi_dll.yml index 83d1248c75..fdaf5644a3 100644 --- a/bin/lolba_enrichment/output/ssa___setupapi_dll.yml +++ b/bin/lolba_enrichment/output/ssa___setupapi_dll.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Setupapi dll LOLBAS in Non Standard Path -id: 4343134a-220d-4751-959b-9470cb252a2c +id: 34d53e5d-652f-4ba2-a2bc-0b2f6a23c5f1 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___shdocvw_dll.yml b/bin/lolba_enrichment/output/ssa___shdocvw_dll.yml index e52e580dbc..98782607f6 100644 --- a/bin/lolba_enrichment/output/ssa___shdocvw_dll.yml +++ b/bin/lolba_enrichment/output/ssa___shdocvw_dll.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Shdocvw dll LOLBAS in Non Standard Path -id: 95285b76-c806-4851-a706-63187ab3daa7 +id: 4c0ac49b-2a4b-4f20-bf6e-47aff8ba9d0c version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___shell32_dll.yml b/bin/lolba_enrichment/output/ssa___shell32_dll.yml index fc2b95ecf3..801b76c724 100644 --- a/bin/lolba_enrichment/output/ssa___shell32_dll.yml +++ b/bin/lolba_enrichment/output/ssa___shell32_dll.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Shell32 dll LOLBAS in Non Standard Path -id: 3d03a191-8b6e-48d9-85fb-e290812af482 +id: 575abff2-b3e4-4736-bc06-ac31d96e1896 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___sqldumper_exe.yml b/bin/lolba_enrichment/output/ssa___sqldumper_exe.yml index 487cb868d3..d58881bed6 100644 --- a/bin/lolba_enrichment/output/ssa___sqldumper_exe.yml +++ b/bin/lolba_enrichment/output/ssa___sqldumper_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Sqldumper exe LOLBAS in Non Standard Path -id: df870ce4-b764-41f5-94fa-de057869594f +id: 41a949ba-17bc-41b5-b9d9-aea929e19f3a version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___sqlps_exe.yml b/bin/lolba_enrichment/output/ssa___sqlps_exe.yml index a7fa501570..c722e472fa 100644 --- a/bin/lolba_enrichment/output/ssa___sqlps_exe.yml +++ b/bin/lolba_enrichment/output/ssa___sqlps_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Sqlps exe LOLBAS in Non Standard Path -id: 6b233c23-e322-4ae3-ba5c-ff371c9c7e68 +id: 6f4e8532-e145-4c0b-ade1-357e9b4fdb0c version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___sqltoolsps_exe.yml b/bin/lolba_enrichment/output/ssa___sqltoolsps_exe.yml index 2db336b9a3..35ce4476f9 100644 --- a/bin/lolba_enrichment/output/ssa___sqltoolsps_exe.yml +++ b/bin/lolba_enrichment/output/ssa___sqltoolsps_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Sqltoolsps exe LOLBAS in Non Standard Path -id: d1126e5e-6e14-4c89-a79c-872efad8dfcf +id: 8d471f85-fea8-48a5-9b1c-c4a609890a21 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___stordiag_exe.yml b/bin/lolba_enrichment/output/ssa___stordiag_exe.yml index b668617dce..22306dbc66 100644 --- a/bin/lolba_enrichment/output/ssa___stordiag_exe.yml +++ b/bin/lolba_enrichment/output/ssa___stordiag_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Stordiag exe LOLBAS in Non Standard Path -id: f0267f5e-c13d-4983-a428-9129aca774ca +id: c3f93bb8-c788-4840-9bfa-0ec995467b8d version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___syncappvpublishingserver_exe.yml b/bin/lolba_enrichment/output/ssa___syncappvpublishingserver_exe.yml index 2d72af258c..857d9a5c5a 100644 --- a/bin/lolba_enrichment/output/ssa___syncappvpublishingserver_exe.yml +++ b/bin/lolba_enrichment/output/ssa___syncappvpublishingserver_exe.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Syncappvpublishingserver exe LOLBAS in Non Standard Path -id: cf6eb874-1e13-4eab-9ac1-93246bd5a48e +id: 42b2e979-6c0d-42a2-8414-97b8c6e6105a version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___syncappvpublishingserver_vbs.yml b/bin/lolba_enrichment/output/ssa___syncappvpublishingserver_vbs.yml index afac24121a..31ce7ba7ff 100644 --- a/bin/lolba_enrichment/output/ssa___syncappvpublishingserver_vbs.yml +++ b/bin/lolba_enrichment/output/ssa___syncappvpublishingserver_vbs.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Syncappvpublishingserver vbs LOLBAS in Non Standard Path -id: 186ced8c-1314-4915-b8b6-0d8ccba31c80 +id: 2c6f9379-1882-447e-8672-c63b03c5cba8 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___syssetup_dll.yml b/bin/lolba_enrichment/output/ssa___syssetup_dll.yml index 7112bc05b8..0f6d3d32bd 100644 --- a/bin/lolba_enrichment/output/ssa___syssetup_dll.yml +++ b/bin/lolba_enrichment/output/ssa___syssetup_dll.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Syssetup dll LOLBAS in Non Standard Path -id: eb71032c-de95-40f5-baf5-fe2486065bc8 +id: 3de09cfd-e8b0-41e8-8598-c4711aeb7ed0 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___ttdinject_exe.yml b/bin/lolba_enrichment/output/ssa___ttdinject_exe.yml index 1e43bae72d..8206839cd1 100644 --- a/bin/lolba_enrichment/output/ssa___ttdinject_exe.yml +++ b/bin/lolba_enrichment/output/ssa___ttdinject_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Ttdinject exe LOLBAS in Non Standard Path -id: 9e1225ba-6220-4284-be04-33e935b4b38f +id: c79a3667-80ac-4bb4-9ae4-353635eebe19 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___tttracer_exe.yml b/bin/lolba_enrichment/output/ssa___tttracer_exe.yml index 461523b8ea..45aa2fe87a 100644 --- a/bin/lolba_enrichment/output/ssa___tttracer_exe.yml +++ b/bin/lolba_enrichment/output/ssa___tttracer_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Tttracer exe LOLBAS in Non Standard Path -id: 49ab4c80-ca6e-4ffc-ac1d-fc8cff26d8dd +id: b8f8a539-93ca-4d4d-9359-661700699f40 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___url_dll.yml b/bin/lolba_enrichment/output/ssa___url_dll.yml index 7c5e7c88fb..b5acf2ff3b 100644 --- a/bin/lolba_enrichment/output/ssa___url_dll.yml +++ b/bin/lolba_enrichment/output/ssa___url_dll.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Url dll LOLBAS in Non Standard Path -id: d5957b1b-a487-42f2-8737-009f008004f3 +id: 320c8064-8994-4984-b5bb-61ba18585e71 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___utilityfunctions_ps1.yml b/bin/lolba_enrichment/output/ssa___utilityfunctions_ps1.yml index 545fa7ce67..d64721c061 100644 --- a/bin/lolba_enrichment/output/ssa___utilityfunctions_ps1.yml +++ b/bin/lolba_enrichment/output/ssa___utilityfunctions_ps1.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Utilityfunctions ps1 LOLBAS in Non Standard Path -id: deb1d8e5-31ee-4fc4-8f84-21f86c67e96b +id: a4f94604-7d49-464b-b94c-82ec395f6000 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___vbc_exe.yml b/bin/lolba_enrichment/output/ssa___vbc_exe.yml index 4eec63efec..5411d154dc 100644 --- a/bin/lolba_enrichment/output/ssa___vbc_exe.yml +++ b/bin/lolba_enrichment/output/ssa___vbc_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Vbc exe LOLBAS in Non Standard Path -id: f695c320-853c-423d-b151-720ca8b7a38a +id: 34adcf98-962b-483b-83fd-3b5bf26affd8 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___verclsid_exe.yml b/bin/lolba_enrichment/output/ssa___verclsid_exe.yml index 66aa7c70b3..dd20f608ec 100644 --- a/bin/lolba_enrichment/output/ssa___verclsid_exe.yml +++ b/bin/lolba_enrichment/output/ssa___verclsid_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Verclsid exe LOLBAS in Non Standard Path -id: 0840aa70-f0d0-46db-a339-af54b562643d +id: ed65ec53-e2e9-4031-b9b2-ea8ca2b6cded version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___visualuiaverifynative_exe.yml b/bin/lolba_enrichment/output/ssa___visualuiaverifynative_exe.yml index 89cecaf122..8e87ddef8a 100644 --- a/bin/lolba_enrichment/output/ssa___visualuiaverifynative_exe.yml +++ b/bin/lolba_enrichment/output/ssa___visualuiaverifynative_exe.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Visualuiaverifynative exe LOLBAS in Non Standard Path -id: 3df6ba54-cd72-4b70-ab9a-e8d288c09f39 +id: 2f1a4fd1-62d1-452f-ad99-f92d82774f7a version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___vsiisexelauncher_exe.yml b/bin/lolba_enrichment/output/ssa___vsiisexelauncher_exe.yml index 775271e72d..6193451125 100644 --- a/bin/lolba_enrichment/output/ssa___vsiisexelauncher_exe.yml +++ b/bin/lolba_enrichment/output/ssa___vsiisexelauncher_exe.yml @@ -1,8 +1,8 @@ name: Windows Rename System Utilities Vsiisexelauncher exe LOLBAS in Non Standard Path -id: e934ec11-4865-4a47-8c6d-1a9f92e4f1ab +id: 89635386-8666-4358-b294-22260a2fe1a6 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___vsjitdebugger_exe.yml b/bin/lolba_enrichment/output/ssa___vsjitdebugger_exe.yml index d42fcc2d12..eb573c4313 100644 --- a/bin/lolba_enrichment/output/ssa___vsjitdebugger_exe.yml +++ b/bin/lolba_enrichment/output/ssa___vsjitdebugger_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Vsjitdebugger exe LOLBAS in Non Standard Path -id: 3a814104-fdef-43e3-b905-eef6f5d12e67 +id: db6f6243-9a61-4d2c-990a-111031b68aba version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___wab_exe.yml b/bin/lolba_enrichment/output/ssa___wab_exe.yml index a1bcc2408f..73d8bf80d3 100644 --- a/bin/lolba_enrichment/output/ssa___wab_exe.yml +++ b/bin/lolba_enrichment/output/ssa___wab_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Wab exe LOLBAS in Non Standard Path -id: f321da8a-6701-476b-a9cc-4b24d5199ee7 +id: 799965d5-c2be-4b83-a807-57f50a2875e0 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___wfc_exe.yml b/bin/lolba_enrichment/output/ssa___wfc_exe.yml index ef236702d8..6de69414a5 100644 --- a/bin/lolba_enrichment/output/ssa___wfc_exe.yml +++ b/bin/lolba_enrichment/output/ssa___wfc_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Wfc exe LOLBAS in Non Standard Path -id: 49feae3b-85ab-4daf-a854-e50dfe91bc04 +id: 158ecf79-6ffa-4b32-8220-843f23070dec version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___winrm_vbs.yml b/bin/lolba_enrichment/output/ssa___winrm_vbs.yml index 3eefd65201..58d81514b9 100644 --- a/bin/lolba_enrichment/output/ssa___winrm_vbs.yml +++ b/bin/lolba_enrichment/output/ssa___winrm_vbs.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Winrm vbs LOLBAS in Non Standard Path -id: b0895252-7f3b-47c2-8f0d-2ea2cc1bf7a3 +id: 6f8df404-85a6-4534-9e22-241c68fee490 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___winword_exe.yml b/bin/lolba_enrichment/output/ssa___winword_exe.yml index 1e9c8aaf6e..6eeb90d8b7 100644 --- a/bin/lolba_enrichment/output/ssa___winword_exe.yml +++ b/bin/lolba_enrichment/output/ssa___winword_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Winword exe LOLBAS in Non Standard Path -id: 745bb75f-485e-4ef5-a76d-26d38ec960c2 +id: 420e9385-1e99-4585-b663-cdc9e539ca6d version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___wlrmdr_exe.yml b/bin/lolba_enrichment/output/ssa___wlrmdr_exe.yml index 88904e3916..cb77f0f808 100644 --- a/bin/lolba_enrichment/output/ssa___wlrmdr_exe.yml +++ b/bin/lolba_enrichment/output/ssa___wlrmdr_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Wlrmdr exe LOLBAS in Non Standard Path -id: cf4ea566-98d7-4f7e-b02d-875b6b092fa0 +id: 343f7052-5896-4374-9dab-5a63d21ed594 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___wmic_exe.test.yml b/bin/lolba_enrichment/output/ssa___wmic_exe.test.yml new file mode 100644 index 0000000000..7705da820b --- /dev/null +++ b/bin/lolba_enrichment/output/ssa___wmic_exe.test.yml @@ -0,0 +1,13 @@ +name: Windows Rename System Utilities Wmic exe LOLBAS in Non Standard Path Unit Test +tests: +- name: Windows Rename System Utilities Wmic exe LOLBAS in Non Standard Path + file: endpoint/ssa___wmic_exe.yml + pass_condition: '@count_eq(1)' + description: ' Test Windows Rename System Utilities Wmic exe LOLBAS in Non Standard + Path' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security +file_path: ba_test_template.yml +file: endpoint/ssa___wmic_exe.yml diff --git a/bin/lolba_enrichment/output/ssa___wmic_exe.yml b/bin/lolba_enrichment/output/ssa___wmic_exe.yml new file mode 100644 index 0000000000..c2c2841dcd --- /dev/null +++ b/bin/lolba_enrichment/output/ssa___wmic_exe.yml @@ -0,0 +1,77 @@ +name: Windows Rename System Utilities Wmic exe LOLBAS in Non Standard Path +id: 7bb1f4ea-2879-446b-9d91-35e428f3492d +version: 1 +date: '2022-10-18' +author: Splunk Threat Research Bot, Splunk +type: Anomaly +datamodel: +- Endpoint_Processes +description: The following analytic identifies Wmic.exe which is a native living off + the land binary or script (LOLBAS) within the Windows operating system that may + be abused by adversaries by moving it to a new directory. The list of binaries was + derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="wmic.exe"| where process_path IS NOT + NULL AND match_regex(process_path, /(?i)\\windows\\syswow64\\wbem/)=false | eval + start_time=timestamp,end_time=timestamp, entities=mvappend(device, user), body=create_map(["event_id", + event_id, "process_path", process_path, "process_name", process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/dotnet_lolbin-windows-security.log + impact: 20 + kill_chain_phases: + - Actions on Objectives + message: A system process $process_name$ with path $process_path$ spawn in non-default + folder path on host $dest_device_id$ + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + type: Hostname + role: + - Victim + - name: dest_user_id + type: User + role: + - Victim + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + risk_severity: low + security_domain: endpoint + asset_type: Endpoint +file_path: ba_detection_template.yml diff --git a/bin/lolba_enrichment/output/ssa___workfolders_exe.yml b/bin/lolba_enrichment/output/ssa___workfolders_exe.yml index db3f034490..c191602195 100644 --- a/bin/lolba_enrichment/output/ssa___workfolders_exe.yml +++ b/bin/lolba_enrichment/output/ssa___workfolders_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Workfolders exe LOLBAS in Non Standard Path -id: db250a82-0d56-4da0-90f6-c26e6f02711a +id: ebe86f07-d7a0-4ddc-8f9c-ea326bf46bbb version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___wscript_exe.yml b/bin/lolba_enrichment/output/ssa___wscript_exe.yml index 60d4b59c47..bdc39057c9 100644 --- a/bin/lolba_enrichment/output/ssa___wscript_exe.yml +++ b/bin/lolba_enrichment/output/ssa___wscript_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Wscript exe LOLBAS in Non Standard Path -id: 434a44cc-ce9d-41fe-baaa-02294d15bc22 +id: 955b186d-3c8d-4c1e-8b89-945d6645afe0 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___wsl_exe.yml b/bin/lolba_enrichment/output/ssa___wsl_exe.yml index eca0c8559e..6dd906b0dd 100644 --- a/bin/lolba_enrichment/output/ssa___wsl_exe.yml +++ b/bin/lolba_enrichment/output/ssa___wsl_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Wsl exe LOLBAS in Non Standard Path -id: 97116fa4-861f-467c-9a77-bc6a4ebc16d4 +id: 11c30b12-63e8-45a0-afd8-a09973d6929e version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___wsreset_exe.yml b/bin/lolba_enrichment/output/ssa___wsreset_exe.yml index bba2129aea..92880b6af4 100644 --- a/bin/lolba_enrichment/output/ssa___wsreset_exe.yml +++ b/bin/lolba_enrichment/output/ssa___wsreset_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Wsreset exe LOLBAS in Non Standard Path -id: aef2f59f-fad8-4d1d-99bc-854bd0d2ef2e +id: 4835efef-4d92-44a5-bede-76eabd53a1e7 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___wuauclt_exe.yml b/bin/lolba_enrichment/output/ssa___wuauclt_exe.yml index bd8fac1919..4dcff32672 100644 --- a/bin/lolba_enrichment/output/ssa___wuauclt_exe.yml +++ b/bin/lolba_enrichment/output/ssa___wuauclt_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Wuauclt exe LOLBAS in Non Standard Path -id: e91141e1-7d58-46c0-a052-b206a5ed42ee +id: c3d1e7cf-a130-4242-be50-8130f5568a5e version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___xwizard_exe.yml b/bin/lolba_enrichment/output/ssa___xwizard_exe.yml index 0524f72c44..1270707288 100644 --- a/bin/lolba_enrichment/output/ssa___xwizard_exe.yml +++ b/bin/lolba_enrichment/output/ssa___xwizard_exe.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Xwizard exe LOLBAS in Non Standard Path -id: 933c9ba4-284c-4847-b982-b17c4adafce2 +id: 6ae23268-a909-4d71-8181-d136b1e6a409 version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/bin/lolba_enrichment/output/ssa___zipfldr_dll.yml b/bin/lolba_enrichment/output/ssa___zipfldr_dll.yml index 883bffd0f5..314b9505b5 100644 --- a/bin/lolba_enrichment/output/ssa___zipfldr_dll.yml +++ b/bin/lolba_enrichment/output/ssa___zipfldr_dll.yml @@ -1,7 +1,7 @@ name: Windows Rename System Utilities Zipfldr dll LOLBAS in Non Standard Path -id: 370d4f3c-d980-4169-9443-8fb4e688b67e +id: 41d3a675-fd16-48e4-bc1b-3c8f5893ebcb version: 1 -date: '2022-10-17' +date: '2022-10-18' author: Splunk Threat Research Bot, Splunk type: Anomaly datamodel: diff --git a/detections/endpoint/ssa___acccheckconsole_exe.test.yml b/detections/endpoint/ssa___acccheckconsole_exe.test.yml new file mode 100644 index 0000000000..9798fef37b --- /dev/null +++ b/detections/endpoint/ssa___acccheckconsole_exe.test.yml @@ -0,0 +1,15 @@ +name: Windows Rename System Utilities Acccheckconsole exe LOLBAS in Non Standard Path + Unit Test +tests: +- name: Windows Rename System Utilities Acccheckconsole exe LOLBAS in Non Standard + Path + file: endpoint/ssa___acccheckconsole_exe.yml + pass_condition: '@count_eq(1)' + description: ' Test Windows Rename System Utilities Acccheckconsole exe LOLBAS in + Non Standard Path' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security +file_path: ba_test_template.yml +file: endpoint/ssa___acccheckconsole_exe.yml diff --git a/detections/endpoint/ssa___acccheckconsole_exe.yml b/detections/endpoint/ssa___acccheckconsole_exe.yml new file mode 100644 index 0000000000..8c8144b809 --- /dev/null +++ b/detections/endpoint/ssa___acccheckconsole_exe.yml @@ -0,0 +1,78 @@ +name: Windows Rename System Utilities Acccheckconsole exe LOLBAS in Non Standard Path +id: c842931e-661f-42bc-a4df-0460d93cfb69 +version: 1 +date: '2022-10-18' +author: Splunk Threat Research Bot, Splunk +type: Anomaly +datamodel: +- Endpoint_Processes +description: The following analytic identifies AccCheckConsole.exe which is a native + living off the land binary or script (LOLBAS) within the Windows operating system + that may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="acccheckconsole.exe"| where process_path + IS NOT NULL AND match_regex(process_path, /(?i)\\program files (x86)\\windows kits\\10\\bin\\10.0.22000.0\\arm64\\accchecker/)=false + | eval start_time=timestamp,end_time=timestamp, entities=mvappend(device, user), + body=create_map(["event_id", event_id, "process_path", process_path, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/dotnet_lolbin-windows-security.log + impact: 20 + kill_chain_phases: + - Actions on Objectives + message: A system process $process_name$ with path $process_path$ spawn in non-default + folder path on host $dest_device_id$ + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + type: Hostname + role: + - Victim + - name: dest_user_id + type: User + role: + - Victim + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + risk_severity: low + security_domain: endpoint + asset_type: Endpoint +file_path: ba_detection_template.yml diff --git a/detections/endpoint/ssa___adplus_exe.yml b/detections/endpoint/ssa___adplus_exe.yml new file mode 100644 index 0000000000..8552b8a3c1 --- /dev/null +++ b/detections/endpoint/ssa___adplus_exe.yml @@ -0,0 +1,78 @@ +name: Windows Rename System Utilities Adplus exe LOLBAS in Non Standard Path +id: ecaaf956-c516-4980-b08e-8c01c19614ca +version: 1 +date: '2022-10-18' +author: Splunk Threat Research Bot, Splunk +type: Anomaly +datamodel: +- Endpoint_Processes +description: The following analytic identifies adplus.exe which is a native living + off the land binary or script (LOLBAS) within the Windows operating system that + may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="adplus.exe"| where process_path IS NOT + NULL AND match_regex(process_path, /(?i)\\program files (x86)\\windows kits\\10\\debuggers\\x86/)=false + | eval start_time=timestamp,end_time=timestamp, entities=mvappend(device, user), + body=create_map(["event_id", event_id, "process_path", process_path, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/dotnet_lolbin-windows-security.log + impact: 20 + kill_chain_phases: + - Actions on Objectives + message: A system process $process_name$ with path $process_path$ spawn in non-default + folder path on host $dest_device_id$ + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + type: Hostname + role: + - Victim + - name: dest_user_id + type: User + role: + - Victim + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + risk_severity: low + security_domain: endpoint + asset_type: Endpoint +file_path: ba_detection_template.yml diff --git a/detections/endpoint/ssa___advpack_dll.yml b/detections/endpoint/ssa___advpack_dll.yml new file mode 100644 index 0000000000..c557b3ba61 --- /dev/null +++ b/detections/endpoint/ssa___advpack_dll.yml @@ -0,0 +1,77 @@ +name: Windows Rename System Utilities Advpack dll LOLBAS in Non Standard Path +id: 3284e4f4-67f7-49b6-ad5e-a8fcead2eef8 +version: 1 +date: '2022-10-18' +author: Splunk Threat Research Bot, Splunk +type: Anomaly +datamodel: +- Endpoint_Processes +description: The following analytic identifies Advpack.dll which is a native living + off the land binary or script (LOLBAS) within the Windows operating system that + may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="advpack.dll"| where process_path IS NOT + NULL AND match_regex(process_path, /(?i)\\windows\\syswow64/)=false | eval start_time=timestamp,end_time=timestamp, + entities=mvappend(device, user), body=create_map(["event_id", event_id, "process_path", + process_path, "process_name", process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/dotnet_lolbin-windows-security.log + impact: 20 + kill_chain_phases: + - Actions on Objectives + message: A system process $process_name$ with path $process_path$ spawn in non-default + folder path on host $dest_device_id$ + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + type: Hostname + role: + - Victim + - name: dest_user_id + type: User + role: + - Victim + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + risk_severity: low + security_domain: endpoint + asset_type: Endpoint +file_path: ba_detection_template.yml diff --git a/detections/endpoint/ssa___agentexecutor_exe.yml b/detections/endpoint/ssa___agentexecutor_exe.yml new file mode 100644 index 0000000000..765e415cb4 --- /dev/null +++ b/detections/endpoint/ssa___agentexecutor_exe.yml @@ -0,0 +1,77 @@ +name: Windows Rename System Utilities Agentexecutor exe LOLBAS in Non Standard Path +id: e124f71f-11bc-47e4-9931-6046d256005d +version: 1 +date: '2022-10-18' +author: Splunk Threat Research Bot, Splunk +type: Anomaly +datamodel: +- Endpoint_Processes +description: The following analytic identifies AgentExecutor.exe which is a native + living off the land binary or script (LOLBAS) within the Windows operating system + that may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="agentexecutor.exe"| where process_path + IS NOT NULL AND match_regex(process_path, /(?i)\\program files (x86)/)=false | eval + start_time=timestamp,end_time=timestamp, entities=mvappend(device, user), body=create_map(["event_id", + event_id, "process_path", process_path, "process_name", process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/dotnet_lolbin-windows-security.log + impact: 20 + kill_chain_phases: + - Actions on Objectives + message: A system process $process_name$ with path $process_path$ spawn in non-default + folder path on host $dest_device_id$ + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + type: Hostname + role: + - Victim + - name: dest_user_id + type: User + role: + - Victim + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + risk_severity: low + security_domain: endpoint + asset_type: Endpoint +file_path: ba_detection_template.yml diff --git a/detections/endpoint/ssa___appinstaller_exe.yml b/detections/endpoint/ssa___appinstaller_exe.yml new file mode 100644 index 0000000000..0c0c895bee --- /dev/null +++ b/detections/endpoint/ssa___appinstaller_exe.yml @@ -0,0 +1,78 @@ +name: Windows Rename System Utilities Appinstaller exe LOLBAS in Non Standard Path +id: 057c06c7-ef31-4749-b5c9-199152e53a06 +version: 1 +date: '2022-10-18' +author: Splunk Threat Research Bot, Splunk +type: Anomaly +datamodel: +- Endpoint_Processes +description: The following analytic identifies AppInstaller.exe which is a native + living off the land binary or script (LOLBAS) within the Windows operating system + that may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="appinstaller.exe"| where process_path + IS NOT NULL AND match_regex(process_path, /(?i)\\program files\\windowsapps\\microsoft.desktopappinstaller_1.11.2521.0_x64__8wekyb3d8bbwe/)=false + | eval start_time=timestamp,end_time=timestamp, entities=mvappend(device, user), + body=create_map(["event_id", event_id, "process_path", process_path, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/dotnet_lolbin-windows-security.log + impact: 20 + kill_chain_phases: + - Actions on Objectives + message: A system process $process_name$ with path $process_path$ spawn in non-default + folder path on host $dest_device_id$ + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + type: Hostname + role: + - Victim + - name: dest_user_id + type: User + role: + - Victim + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + risk_severity: low + security_domain: endpoint + asset_type: Endpoint +file_path: ba_detection_template.yml diff --git a/detections/endpoint/ssa___appvlp_exe.yml b/detections/endpoint/ssa___appvlp_exe.yml new file mode 100644 index 0000000000..ad703a8861 --- /dev/null +++ b/detections/endpoint/ssa___appvlp_exe.yml @@ -0,0 +1,78 @@ +name: Windows Rename System Utilities Appvlp exe LOLBAS in Non Standard Path +id: 93862a89-abe0-4094-909a-08ec390aa5e3 +version: 1 +date: '2022-10-18' +author: Splunk Threat Research Bot, Splunk +type: Anomaly +datamodel: +- Endpoint_Processes +description: The following analytic identifies Appvlp.exe which is a native living + off the land binary or script (LOLBAS) within the Windows operating system that + may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="appvlp.exe"| where process_path IS NOT + NULL AND match_regex(process_path, /(?i)\\program files (x86)\\microsoft office\\root\\client/)=false + | eval start_time=timestamp,end_time=timestamp, entities=mvappend(device, user), + body=create_map(["event_id", event_id, "process_path", process_path, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/dotnet_lolbin-windows-security.log + impact: 20 + kill_chain_phases: + - Actions on Objectives + message: A system process $process_name$ with path $process_path$ spawn in non-default + folder path on host $dest_device_id$ + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + type: Hostname + role: + - Victim + - name: dest_user_id + type: User + role: + - Victim + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + risk_severity: low + security_domain: endpoint + asset_type: Endpoint +file_path: ba_detection_template.yml diff --git a/detections/endpoint/ssa___aspnet_compiler_exe.yml b/detections/endpoint/ssa___aspnet_compiler_exe.yml new file mode 100644 index 0000000000..efc87d96de --- /dev/null +++ b/detections/endpoint/ssa___aspnet_compiler_exe.yml @@ -0,0 +1,78 @@ +name: Windows Rename System Utilities Aspnet_compiler exe LOLBAS in Non Standard Path +id: d75cc561-3828-4d0a-92c4-0eb93bfe0929 +version: 1 +date: '2022-10-18' +author: Splunk Threat Research Bot, Splunk +type: Anomaly +datamodel: +- Endpoint_Processes +description: The following analytic identifies Aspnet_Compiler.exe which is a native + living off the land binary or script (LOLBAS) within the Windows operating system + that may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="aspnet_compiler.exe"| where process_path + IS NOT NULL AND match_regex(process_path, /(?i)\\windows\\microsoft.net\\framework64\\v4.0.30319/)=false + | eval start_time=timestamp,end_time=timestamp, entities=mvappend(device, user), + body=create_map(["event_id", event_id, "process_path", process_path, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/dotnet_lolbin-windows-security.log + impact: 20 + kill_chain_phases: + - Actions on Objectives + message: A system process $process_name$ with path $process_path$ spawn in non-default + folder path on host $dest_device_id$ + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + type: Hostname + role: + - Victim + - name: dest_user_id + type: User + role: + - Victim + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + risk_severity: low + security_domain: endpoint + asset_type: Endpoint +file_path: ba_detection_template.yml diff --git a/detections/endpoint/ssa___at_exe.yml b/detections/endpoint/ssa___at_exe.yml new file mode 100644 index 0000000000..c402402187 --- /dev/null +++ b/detections/endpoint/ssa___at_exe.yml @@ -0,0 +1,77 @@ +name: Windows Rename System Utilities At exe LOLBAS in Non Standard Path +id: 6401d583-0052-4dc5-a713-68b510826d2b +version: 1 +date: '2022-10-18' +author: Splunk Threat Research Bot, Splunk +type: Anomaly +datamodel: +- Endpoint_Processes +description: The following analytic identifies At.exe which is a native living off + the land binary or script (LOLBAS) within the Windows operating system that may + be abused by adversaries by moving it to a new directory. The list of binaries was + derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="at.exe"| where process_path IS NOT NULL + AND match_regex(process_path, /(?i)\\windows\\syswow64/)=false | eval start_time=timestamp,end_time=timestamp, + entities=mvappend(device, user), body=create_map(["event_id", event_id, "process_path", + process_path, "process_name", process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/dotnet_lolbin-windows-security.log + impact: 20 + kill_chain_phases: + - Actions on Objectives + message: A system process $process_name$ with path $process_path$ spawn in non-default + folder path on host $dest_device_id$ + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + type: Hostname + role: + - Victim + - name: dest_user_id + type: User + role: + - Victim + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + risk_severity: low + security_domain: endpoint + asset_type: Endpoint +file_path: ba_detection_template.yml diff --git a/detections/endpoint/ssa___atbroker_exe.yml b/detections/endpoint/ssa___atbroker_exe.yml new file mode 100644 index 0000000000..ff6495644c --- /dev/null +++ b/detections/endpoint/ssa___atbroker_exe.yml @@ -0,0 +1,77 @@ +name: Windows Rename System Utilities Atbroker exe LOLBAS in Non Standard Path +id: b8da7ea5-8c16-4eff-9787-54ec271159e0 +version: 1 +date: '2022-10-18' +author: Splunk Threat Research Bot, Splunk +type: Anomaly +datamodel: +- Endpoint_Processes +description: The following analytic identifies Atbroker.exe which is a native living + off the land binary or script (LOLBAS) within the Windows operating system that + may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="atbroker.exe"| where process_path IS + NOT NULL AND match_regex(process_path, /(?i)\\windows\\syswow64/)=false | eval start_time=timestamp,end_time=timestamp, + entities=mvappend(device, user), body=create_map(["event_id", event_id, "process_path", + process_path, "process_name", process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/dotnet_lolbin-windows-security.log + impact: 20 + kill_chain_phases: + - Actions on Objectives + message: A system process $process_name$ with path $process_path$ spawn in non-default + folder path on host $dest_device_id$ + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + type: Hostname + role: + - Victim + - name: dest_user_id + type: User + role: + - Victim + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + risk_severity: low + security_domain: endpoint + asset_type: Endpoint +file_path: ba_detection_template.yml diff --git a/tests/endpoint/ssa___adplus_exe.test.yml b/tests/endpoint/ssa___adplus_exe.test.yml new file mode 100644 index 0000000000..b9387f6a4e --- /dev/null +++ b/tests/endpoint/ssa___adplus_exe.test.yml @@ -0,0 +1,14 @@ +name: Windows Rename System Utilities Adplus exe LOLBAS in Non Standard Path Unit + Test +tests: +- name: Windows Rename System Utilities Adplus exe LOLBAS in Non Standard Path + file: endpoint/ssa___adplus_exe.yml + pass_condition: '@count_eq(1)' + description: ' Test Windows Rename System Utilities Adplus exe LOLBAS in Non Standard + Path' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security +file_path: ba_test_template.yml +file: endpoint/ssa___adplus_exe.yml diff --git a/tests/endpoint/ssa___advpack_dll.test.yml b/tests/endpoint/ssa___advpack_dll.test.yml new file mode 100644 index 0000000000..5a711a0e11 --- /dev/null +++ b/tests/endpoint/ssa___advpack_dll.test.yml @@ -0,0 +1,14 @@ +name: Windows Rename System Utilities Advpack dll LOLBAS in Non Standard Path Unit + Test +tests: +- name: Windows Rename System Utilities Advpack dll LOLBAS in Non Standard Path + file: endpoint/ssa___advpack_dll.yml + pass_condition: '@count_eq(1)' + description: ' Test Windows Rename System Utilities Advpack dll LOLBAS in Non Standard + Path' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security +file_path: ba_test_template.yml +file: endpoint/ssa___advpack_dll.yml diff --git a/tests/endpoint/ssa___agentexecutor_exe.test.yml b/tests/endpoint/ssa___agentexecutor_exe.test.yml new file mode 100644 index 0000000000..d2512df23a --- /dev/null +++ b/tests/endpoint/ssa___agentexecutor_exe.test.yml @@ -0,0 +1,14 @@ +name: Windows Rename System Utilities Agentexecutor exe LOLBAS in Non Standard Path + Unit Test +tests: +- name: Windows Rename System Utilities Agentexecutor exe LOLBAS in Non Standard Path + file: endpoint/ssa___agentexecutor_exe.yml + pass_condition: '@count_eq(1)' + description: ' Test Windows Rename System Utilities Agentexecutor exe LOLBAS in + Non Standard Path' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security +file_path: ba_test_template.yml +file: endpoint/ssa___agentexecutor_exe.yml diff --git a/tests/endpoint/ssa___appinstaller_exe.test.yml b/tests/endpoint/ssa___appinstaller_exe.test.yml new file mode 100644 index 0000000000..2d732b02d3 --- /dev/null +++ b/tests/endpoint/ssa___appinstaller_exe.test.yml @@ -0,0 +1,14 @@ +name: Windows Rename System Utilities Appinstaller exe LOLBAS in Non Standard Path + Unit Test +tests: +- name: Windows Rename System Utilities Appinstaller exe LOLBAS in Non Standard Path + file: endpoint/ssa___appinstaller_exe.yml + pass_condition: '@count_eq(1)' + description: ' Test Windows Rename System Utilities Appinstaller exe LOLBAS in Non + Standard Path' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security +file_path: ba_test_template.yml +file: endpoint/ssa___appinstaller_exe.yml diff --git a/tests/endpoint/ssa___appvlp_exe.test.yml b/tests/endpoint/ssa___appvlp_exe.test.yml new file mode 100644 index 0000000000..5d1b2bf3a0 --- /dev/null +++ b/tests/endpoint/ssa___appvlp_exe.test.yml @@ -0,0 +1,14 @@ +name: Windows Rename System Utilities Appvlp exe LOLBAS in Non Standard Path Unit + Test +tests: +- name: Windows Rename System Utilities Appvlp exe LOLBAS in Non Standard Path + file: endpoint/ssa___appvlp_exe.yml + pass_condition: '@count_eq(1)' + description: ' Test Windows Rename System Utilities Appvlp exe LOLBAS in Non Standard + Path' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security +file_path: ba_test_template.yml +file: endpoint/ssa___appvlp_exe.yml diff --git a/tests/endpoint/ssa___aspnet_compiler_exe.test.yml b/tests/endpoint/ssa___aspnet_compiler_exe.test.yml new file mode 100644 index 0000000000..24f4f61687 --- /dev/null +++ b/tests/endpoint/ssa___aspnet_compiler_exe.test.yml @@ -0,0 +1,15 @@ +name: Windows Rename System Utilities Aspnet_compiler exe LOLBAS in Non Standard Path + Unit Test +tests: +- name: Windows Rename System Utilities Aspnet_compiler exe LOLBAS in Non Standard + Path + file: endpoint/ssa___aspnet_compiler_exe.yml + pass_condition: '@count_eq(1)' + description: ' Test Windows Rename System Utilities Aspnet_compiler exe LOLBAS in + Non Standard Path' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security +file_path: ba_test_template.yml +file: endpoint/ssa___aspnet_compiler_exe.yml diff --git a/tests/endpoint/ssa___at_exe.test.yml b/tests/endpoint/ssa___at_exe.test.yml new file mode 100644 index 0000000000..34e1e5b4aa --- /dev/null +++ b/tests/endpoint/ssa___at_exe.test.yml @@ -0,0 +1,13 @@ +name: Windows Rename System Utilities At exe LOLBAS in Non Standard Path Unit Test +tests: +- name: Windows Rename System Utilities At exe LOLBAS in Non Standard Path + file: endpoint/ssa___at_exe.yml + pass_condition: '@count_eq(1)' + description: ' Test Windows Rename System Utilities At exe LOLBAS in Non Standard + Path' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security +file_path: ba_test_template.yml +file: endpoint/ssa___at_exe.yml diff --git a/tests/endpoint/ssa___atbroker_exe.test.yml b/tests/endpoint/ssa___atbroker_exe.test.yml new file mode 100644 index 0000000000..785fd95c82 --- /dev/null +++ b/tests/endpoint/ssa___atbroker_exe.test.yml @@ -0,0 +1,14 @@ +name: Windows Rename System Utilities Atbroker exe LOLBAS in Non Standard Path Unit + Test +tests: +- name: Windows Rename System Utilities Atbroker exe LOLBAS in Non Standard Path + file: endpoint/ssa___atbroker_exe.yml + pass_condition: '@count_eq(1)' + description: ' Test Windows Rename System Utilities Atbroker exe LOLBAS in Non Standard + Path' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security +file_path: ba_test_template.yml +file: endpoint/ssa___atbroker_exe.yml From aef8daef2f5fefb074df12aee4b63cbfa1322b77 Mon Sep 17 00:00:00 2001 From: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com> Date: Tue, 18 Oct 2022 09:58:21 -0700 Subject: [PATCH 2/5] moved test file from detections folder to tests folder --- {detections => tests}/endpoint/ssa___acccheckconsole_exe.test.yml | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename {detections => tests}/endpoint/ssa___acccheckconsole_exe.test.yml (100%) diff --git a/detections/endpoint/ssa___acccheckconsole_exe.test.yml b/tests/endpoint/ssa___acccheckconsole_exe.test.yml similarity index 100% rename from detections/endpoint/ssa___acccheckconsole_exe.test.yml rename to tests/endpoint/ssa___acccheckconsole_exe.test.yml From 300131dfdf9637bb6c81f28aab9eaa0663ab1f71 Mon Sep 17 00:00:00 2001 From: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com> Date: Tue, 18 Oct 2022 12:27:07 -0700 Subject: [PATCH 3/5] Removing underscore from the name of a detection, which caused validate problems --- detections/endpoint/ssa___aspnet_compiler_exe.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/ssa___aspnet_compiler_exe.yml b/detections/endpoint/ssa___aspnet_compiler_exe.yml index efc87d96de..3e6138a542 100644 --- a/detections/endpoint/ssa___aspnet_compiler_exe.yml +++ b/detections/endpoint/ssa___aspnet_compiler_exe.yml @@ -1,4 +1,4 @@ -name: Windows Rename System Utilities Aspnet_compiler exe LOLBAS in Non Standard Path +name: Windows Rename System Utilities Aspnet compiler exe LOLBAS in Non Standard Path id: d75cc561-3828-4d0a-92c4-0eb93bfe0929 version: 1 date: '2022-10-18' From 5e3cc4f60525e53f67036907c8db6141ba2cfea5 Mon Sep 17 00:00:00 2001 From: patel-bhavin Date: Tue, 18 Oct 2022 13:14:20 -0700 Subject: [PATCH 4/5] remove underscore from test file --- tests/endpoint/ssa___aspnet_compiler_exe.test.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/tests/endpoint/ssa___aspnet_compiler_exe.test.yml b/tests/endpoint/ssa___aspnet_compiler_exe.test.yml index 24f4f61687..2089df2c82 100644 --- a/tests/endpoint/ssa___aspnet_compiler_exe.test.yml +++ b/tests/endpoint/ssa___aspnet_compiler_exe.test.yml @@ -1,7 +1,7 @@ -name: Windows Rename System Utilities Aspnet_compiler exe LOLBAS in Non Standard Path +name: Windows Rename System Utilities Aspnet compiler exe LOLBAS in Non Standard Path Unit Test tests: -- name: Windows Rename System Utilities Aspnet_compiler exe LOLBAS in Non Standard +- name: Windows Rename System Utilities Aspnet compiler exe LOLBAS in Non Standard Path file: endpoint/ssa___aspnet_compiler_exe.yml pass_condition: '@count_eq(1)' From 602b7b0a97f1a0e62ba7e1c5ae9b2779b70f6282 Mon Sep 17 00:00:00 2001 From: patel-bhavin Date: Tue, 18 Oct 2022 13:29:18 -0700 Subject: [PATCH 5/5] adding SSA generated files --- ...onsole_exe_lolbas_in_non_standard_path.yml | 64 +++++++++++++++++++ ...adplus_exe_lolbas_in_non_standard_path.yml | 63 ++++++++++++++++++ ...dvpack_dll_lolbas_in_non_standard_path.yml | 62 ++++++++++++++++++ ...ecutor_exe_lolbas_in_non_standard_path.yml | 63 ++++++++++++++++++ ...taller_exe_lolbas_in_non_standard_path.yml | 64 +++++++++++++++++++ ...appvlp_exe_lolbas_in_non_standard_path.yml | 63 ++++++++++++++++++ ...mpiler_exe_lolbas_in_non_standard_path.yml | 64 +++++++++++++++++++ ...ies_at_exe_lolbas_in_non_standard_path.yml | 61 ++++++++++++++++++ ...broker_exe_lolbas_in_non_standard_path.yml | 62 ++++++++++++++++++ 9 files changed, 566 insertions(+) create mode 100644 dist/ssa/srs/ssa___windows_rename_system_utilities_acccheckconsole_exe_lolbas_in_non_standard_path.yml create mode 100644 dist/ssa/srs/ssa___windows_rename_system_utilities_adplus_exe_lolbas_in_non_standard_path.yml create mode 100644 dist/ssa/srs/ssa___windows_rename_system_utilities_advpack_dll_lolbas_in_non_standard_path.yml create mode 100644 dist/ssa/srs/ssa___windows_rename_system_utilities_agentexecutor_exe_lolbas_in_non_standard_path.yml create mode 100644 dist/ssa/srs/ssa___windows_rename_system_utilities_appinstaller_exe_lolbas_in_non_standard_path.yml create mode 100644 dist/ssa/srs/ssa___windows_rename_system_utilities_appvlp_exe_lolbas_in_non_standard_path.yml create mode 100644 dist/ssa/srs/ssa___windows_rename_system_utilities_aspnet_compiler_exe_lolbas_in_non_standard_path.yml create mode 100644 dist/ssa/srs/ssa___windows_rename_system_utilities_at_exe_lolbas_in_non_standard_path.yml create mode 100644 dist/ssa/srs/ssa___windows_rename_system_utilities_atbroker_exe_lolbas_in_non_standard_path.yml diff --git a/dist/ssa/srs/ssa___windows_rename_system_utilities_acccheckconsole_exe_lolbas_in_non_standard_path.yml b/dist/ssa/srs/ssa___windows_rename_system_utilities_acccheckconsole_exe_lolbas_in_non_standard_path.yml new file mode 100644 index 0000000000..3040de34f1 --- /dev/null +++ b/dist/ssa/srs/ssa___windows_rename_system_utilities_acccheckconsole_exe_lolbas_in_non_standard_path.yml @@ -0,0 +1,64 @@ +name: Windows Rename System Utilities Acccheckconsole exe LOLBAS in Non Standard Path +id: c842931e-661f-42bc-a4df-0460d93cfb69 +version: 1 +description: The following analytic identifies AccCheckConsole.exe which is a native + living off the land binary or script (LOLBAS) within the Windows operating system + that may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="acccheckconsole.exe"| where process_path + IS NOT NULL AND match_regex(process_path, /(?i)\\program files (x86)\\windows kits\\10\\bin\\10.0.22000.0\\arm64\\accchecker/)=false + | eval start_time=timestamp,end_time=timestamp, entities=mvappend(device, user), + body=create_map(["event_id", event_id, "process_path", process_path, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + kill_chain_phases: + - Actions on Objectives + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + security_domain: endpoint + risk_severity: low + research_site_url: https://research.splunk.com/endpoint/c842931e-661f-42bc-a4df-0460d93cfb69/ +test: + name: Windows Rename System Utilities Acccheckconsole exe LOLBAS in Non Standard + Path Unit Test + tests: + - name: Windows Rename System Utilities Acccheckconsole exe LOLBAS in Non Standard + Path + file: endpoint/ssa___acccheckconsole_exe.yml + pass_condition: '@count_eq(1)' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security diff --git a/dist/ssa/srs/ssa___windows_rename_system_utilities_adplus_exe_lolbas_in_non_standard_path.yml b/dist/ssa/srs/ssa___windows_rename_system_utilities_adplus_exe_lolbas_in_non_standard_path.yml new file mode 100644 index 0000000000..e9149427f6 --- /dev/null +++ b/dist/ssa/srs/ssa___windows_rename_system_utilities_adplus_exe_lolbas_in_non_standard_path.yml @@ -0,0 +1,63 @@ +name: Windows Rename System Utilities Adplus exe LOLBAS in Non Standard Path +id: ecaaf956-c516-4980-b08e-8c01c19614ca +version: 1 +description: The following analytic identifies adplus.exe which is a native living + off the land binary or script (LOLBAS) within the Windows operating system that + may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="adplus.exe"| where process_path IS NOT + NULL AND match_regex(process_path, /(?i)\\program files (x86)\\windows kits\\10\\debuggers\\x86/)=false + | eval start_time=timestamp,end_time=timestamp, entities=mvappend(device, user), + body=create_map(["event_id", event_id, "process_path", process_path, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + kill_chain_phases: + - Actions on Objectives + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + security_domain: endpoint + risk_severity: low + research_site_url: https://research.splunk.com/endpoint/ecaaf956-c516-4980-b08e-8c01c19614ca/ +test: + name: Windows Rename System Utilities Adplus exe LOLBAS in Non Standard Path Unit + Test + tests: + - name: Windows Rename System Utilities Adplus exe LOLBAS in Non Standard Path + file: endpoint/ssa___adplus_exe.yml + pass_condition: '@count_eq(1)' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security diff --git a/dist/ssa/srs/ssa___windows_rename_system_utilities_advpack_dll_lolbas_in_non_standard_path.yml b/dist/ssa/srs/ssa___windows_rename_system_utilities_advpack_dll_lolbas_in_non_standard_path.yml new file mode 100644 index 0000000000..c0f6f2662a --- /dev/null +++ b/dist/ssa/srs/ssa___windows_rename_system_utilities_advpack_dll_lolbas_in_non_standard_path.yml @@ -0,0 +1,62 @@ +name: Windows Rename System Utilities Advpack dll LOLBAS in Non Standard Path +id: 3284e4f4-67f7-49b6-ad5e-a8fcead2eef8 +version: 1 +description: The following analytic identifies Advpack.dll which is a native living + off the land binary or script (LOLBAS) within the Windows operating system that + may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="advpack.dll"| where process_path IS NOT + NULL AND match_regex(process_path, /(?i)\\windows\\syswow64/)=false | eval start_time=timestamp,end_time=timestamp, + entities=mvappend(device, user), body=create_map(["event_id", event_id, "process_path", + process_path, "process_name", process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + kill_chain_phases: + - Actions on Objectives + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + security_domain: endpoint + risk_severity: low + research_site_url: https://research.splunk.com/endpoint/3284e4f4-67f7-49b6-ad5e-a8fcead2eef8/ +test: + name: Windows Rename System Utilities Advpack dll LOLBAS in Non Standard Path Unit + Test + tests: + - name: Windows Rename System Utilities Advpack dll LOLBAS in Non Standard Path + file: endpoint/ssa___advpack_dll.yml + pass_condition: '@count_eq(1)' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security diff --git a/dist/ssa/srs/ssa___windows_rename_system_utilities_agentexecutor_exe_lolbas_in_non_standard_path.yml b/dist/ssa/srs/ssa___windows_rename_system_utilities_agentexecutor_exe_lolbas_in_non_standard_path.yml new file mode 100644 index 0000000000..f1a3c1871b --- /dev/null +++ b/dist/ssa/srs/ssa___windows_rename_system_utilities_agentexecutor_exe_lolbas_in_non_standard_path.yml @@ -0,0 +1,63 @@ +name: Windows Rename System Utilities Agentexecutor exe LOLBAS in Non Standard Path +id: e124f71f-11bc-47e4-9931-6046d256005d +version: 1 +description: The following analytic identifies AgentExecutor.exe which is a native + living off the land binary or script (LOLBAS) within the Windows operating system + that may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="agentexecutor.exe"| where process_path + IS NOT NULL AND match_regex(process_path, /(?i)\\program files (x86)/)=false | eval + start_time=timestamp,end_time=timestamp, entities=mvappend(device, user), body=create_map(["event_id", + event_id, "process_path", process_path, "process_name", process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + kill_chain_phases: + - Actions on Objectives + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + security_domain: endpoint + risk_severity: low + research_site_url: https://research.splunk.com/endpoint/e124f71f-11bc-47e4-9931-6046d256005d/ +test: + name: Windows Rename System Utilities Agentexecutor exe LOLBAS in Non Standard Path + Unit Test + tests: + - name: Windows Rename System Utilities Agentexecutor exe LOLBAS in Non Standard + Path + file: endpoint/ssa___agentexecutor_exe.yml + pass_condition: '@count_eq(1)' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security diff --git a/dist/ssa/srs/ssa___windows_rename_system_utilities_appinstaller_exe_lolbas_in_non_standard_path.yml b/dist/ssa/srs/ssa___windows_rename_system_utilities_appinstaller_exe_lolbas_in_non_standard_path.yml new file mode 100644 index 0000000000..7b89bad0ba --- /dev/null +++ b/dist/ssa/srs/ssa___windows_rename_system_utilities_appinstaller_exe_lolbas_in_non_standard_path.yml @@ -0,0 +1,64 @@ +name: Windows Rename System Utilities Appinstaller exe LOLBAS in Non Standard Path +id: 057c06c7-ef31-4749-b5c9-199152e53a06 +version: 1 +description: The following analytic identifies AppInstaller.exe which is a native + living off the land binary or script (LOLBAS) within the Windows operating system + that may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="appinstaller.exe"| where process_path + IS NOT NULL AND match_regex(process_path, /(?i)\\program files\\windowsapps\\microsoft.desktopappinstaller_1.11.2521.0_x64__8wekyb3d8bbwe/)=false + | eval start_time=timestamp,end_time=timestamp, entities=mvappend(device, user), + body=create_map(["event_id", event_id, "process_path", process_path, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + kill_chain_phases: + - Actions on Objectives + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + security_domain: endpoint + risk_severity: low + research_site_url: https://research.splunk.com/endpoint/057c06c7-ef31-4749-b5c9-199152e53a06/ +test: + name: Windows Rename System Utilities Appinstaller exe LOLBAS in Non Standard Path + Unit Test + tests: + - name: Windows Rename System Utilities Appinstaller exe LOLBAS in Non Standard + Path + file: endpoint/ssa___appinstaller_exe.yml + pass_condition: '@count_eq(1)' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security diff --git a/dist/ssa/srs/ssa___windows_rename_system_utilities_appvlp_exe_lolbas_in_non_standard_path.yml b/dist/ssa/srs/ssa___windows_rename_system_utilities_appvlp_exe_lolbas_in_non_standard_path.yml new file mode 100644 index 0000000000..570d894852 --- /dev/null +++ b/dist/ssa/srs/ssa___windows_rename_system_utilities_appvlp_exe_lolbas_in_non_standard_path.yml @@ -0,0 +1,63 @@ +name: Windows Rename System Utilities Appvlp exe LOLBAS in Non Standard Path +id: 93862a89-abe0-4094-909a-08ec390aa5e3 +version: 1 +description: The following analytic identifies Appvlp.exe which is a native living + off the land binary or script (LOLBAS) within the Windows operating system that + may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="appvlp.exe"| where process_path IS NOT + NULL AND match_regex(process_path, /(?i)\\program files (x86)\\microsoft office\\root\\client/)=false + | eval start_time=timestamp,end_time=timestamp, entities=mvappend(device, user), + body=create_map(["event_id", event_id, "process_path", process_path, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + kill_chain_phases: + - Actions on Objectives + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + security_domain: endpoint + risk_severity: low + research_site_url: https://research.splunk.com/endpoint/93862a89-abe0-4094-909a-08ec390aa5e3/ +test: + name: Windows Rename System Utilities Appvlp exe LOLBAS in Non Standard Path Unit + Test + tests: + - name: Windows Rename System Utilities Appvlp exe LOLBAS in Non Standard Path + file: endpoint/ssa___appvlp_exe.yml + pass_condition: '@count_eq(1)' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security diff --git a/dist/ssa/srs/ssa___windows_rename_system_utilities_aspnet_compiler_exe_lolbas_in_non_standard_path.yml b/dist/ssa/srs/ssa___windows_rename_system_utilities_aspnet_compiler_exe_lolbas_in_non_standard_path.yml new file mode 100644 index 0000000000..5745bd6e9c --- /dev/null +++ b/dist/ssa/srs/ssa___windows_rename_system_utilities_aspnet_compiler_exe_lolbas_in_non_standard_path.yml @@ -0,0 +1,64 @@ +name: Windows Rename System Utilities Aspnet compiler exe LOLBAS in Non Standard Path +id: d75cc561-3828-4d0a-92c4-0eb93bfe0929 +version: 1 +description: The following analytic identifies Aspnet_Compiler.exe which is a native + living off the land binary or script (LOLBAS) within the Windows operating system + that may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="aspnet_compiler.exe"| where process_path + IS NOT NULL AND match_regex(process_path, /(?i)\\windows\\microsoft.net\\framework64\\v4.0.30319/)=false + | eval start_time=timestamp,end_time=timestamp, entities=mvappend(device, user), + body=create_map(["event_id", event_id, "process_path", process_path, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + kill_chain_phases: + - Actions on Objectives + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + security_domain: endpoint + risk_severity: low + research_site_url: https://research.splunk.com/endpoint/d75cc561-3828-4d0a-92c4-0eb93bfe0929/ +test: + name: Windows Rename System Utilities Aspnet compiler exe LOLBAS in Non Standard + Path Unit Test + tests: + - name: Windows Rename System Utilities Aspnet compiler exe LOLBAS in Non Standard + Path + file: endpoint/ssa___aspnet_compiler_exe.yml + pass_condition: '@count_eq(1)' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security diff --git a/dist/ssa/srs/ssa___windows_rename_system_utilities_at_exe_lolbas_in_non_standard_path.yml b/dist/ssa/srs/ssa___windows_rename_system_utilities_at_exe_lolbas_in_non_standard_path.yml new file mode 100644 index 0000000000..b70ae6d0d9 --- /dev/null +++ b/dist/ssa/srs/ssa___windows_rename_system_utilities_at_exe_lolbas_in_non_standard_path.yml @@ -0,0 +1,61 @@ +name: Windows Rename System Utilities At exe LOLBAS in Non Standard Path +id: 6401d583-0052-4dc5-a713-68b510826d2b +version: 1 +description: The following analytic identifies At.exe which is a native living off + the land binary or script (LOLBAS) within the Windows operating system that may + be abused by adversaries by moving it to a new directory. The list of binaries was + derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="at.exe"| where process_path IS NOT NULL + AND match_regex(process_path, /(?i)\\windows\\syswow64/)=false | eval start_time=timestamp,end_time=timestamp, + entities=mvappend(device, user), body=create_map(["event_id", event_id, "process_path", + process_path, "process_name", process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + kill_chain_phases: + - Actions on Objectives + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + security_domain: endpoint + risk_severity: low + research_site_url: https://research.splunk.com/endpoint/6401d583-0052-4dc5-a713-68b510826d2b/ +test: + name: Windows Rename System Utilities At exe LOLBAS in Non Standard Path Unit Test + tests: + - name: Windows Rename System Utilities At exe LOLBAS in Non Standard Path + file: endpoint/ssa___at_exe.yml + pass_condition: '@count_eq(1)' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security diff --git a/dist/ssa/srs/ssa___windows_rename_system_utilities_atbroker_exe_lolbas_in_non_standard_path.yml b/dist/ssa/srs/ssa___windows_rename_system_utilities_atbroker_exe_lolbas_in_non_standard_path.yml new file mode 100644 index 0000000000..69dfdf75c4 --- /dev/null +++ b/dist/ssa/srs/ssa___windows_rename_system_utilities_atbroker_exe_lolbas_in_non_standard_path.yml @@ -0,0 +1,62 @@ +name: Windows Rename System Utilities Atbroker exe LOLBAS in Non Standard Path +id: b8da7ea5-8c16-4eff-9787-54ec271159e0 +version: 1 +description: The following analytic identifies Atbroker.exe which is a native living + off the land binary or script (LOLBAS) within the Windows operating system that + may be abused by adversaries by moving it to a new directory. The list of binaries + was derived from the https://lolbas-project.github.io site. +search: '| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null)| where + process_name IS NOT NULL AND process_name="atbroker.exe"| where process_path IS + NOT NULL AND match_regex(process_path, /(?i)\\windows\\syswow64/)=false | eval start_time=timestamp,end_time=timestamp, + entities=mvappend(device, user), body=create_map(["event_id", event_id, "process_path", + process_path, "process_name", process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you must be ingesting logs + with the process name, command-line arguments, and parent processes from your endpoints. + Collect endpoint data such as Sysmon or Windows Events 4688. +known_false_positives: False positives may be present and filtering may be required. + Certain utilities will run from non-standard paths based on the third-party application + in use. +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036.003/T1036.003.yaml +- https://attack.mitre.org/techniques/T1036/003/ +- https://lolbas-project.github.io/ +tags: + analytic_story: + - Unusual Processes + - Living Off The Land + cis20: + - CIS 8 + kill_chain_phases: + - Actions on Objectives + mitre_attack_id: + - T1036 + - T1036.003 + nist: + - PR.PT + - DE.CM + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 14 + security_domain: endpoint + risk_severity: low + research_site_url: https://research.splunk.com/endpoint/b8da7ea5-8c16-4eff-9787-54ec271159e0/ +test: + name: Windows Rename System Utilities Atbroker exe LOLBAS in Non Standard Path Unit + Test + tests: + - name: Windows Rename System Utilities Atbroker exe LOLBAS in Non Standard Path + file: endpoint/ssa___atbroker_exe.yml + pass_condition: '@count_eq(1)' + attack_data: + - file_name: dotnet_lolbin-windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log + source: WinEventLog:Security